Introduction
Teamital is committed to protecting the confidentiality, integrity and availability of the information entrusted to our platform.
This Security Policy outlines the technical and organisational measures we use to protect customer and employee information while providing our workforce management platform.
Our security practices are designed to support compliance with:
- EU General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679)
- Irish Data Protection Act 2018
Security is integrated into the design, development and operation of Teamital to help reduce risk, protect customer data and support secure business operations.
Company Information
Teamital
Kandoy House, 2 Fairview Strand
Clontarf West, Dublin, D03 R8P3
Ireland
Privacy & Security Contact
contact@teamital.com
Scope
This Security Policy applies to:
- Teamital website
- Web application
- Mobile applications
- APIs
- Cloud infrastructure
- Customer data
- Employee data
- Internal administrative systems
- Third-party services supporting the platform
Security Principles
Teamital follows these core security principles:
- Confidentiality
- Integrity
- Availability
- Least Privilege Access
- Security by Design
- Privacy by Design
- Continuous Improvement
These principles guide how we build, maintain and operate our platform.
Hosting Infrastructure
Teamital is hosted on Amazon Web Services (AWS).
Primary hosting infrastructure is located within Ireland (Europe) to support secure and reliable service delivery.
AWS provides enterprise-grade infrastructure including physical security, redundancy and availability features.
Database Security
Teamital uses Supabase as its database platform.
Our database environment is protected through:
- Secure authentication
- Encrypted communications
- Controlled access permissions
- Role-based access
- Secure backups
- Infrastructure monitoring
Access to production databases is restricted to authorised personnel with a legitimate business need.
Encryption
Teamital protects information using industry-standard encryption.
This includes:
Encryption in Transit
All communication between users, mobile applications, browsers and our servers is protected using HTTPS with TLS encryption.
This helps protect information from interception while transmitted over public networks.
Encryption at Rest
Where supported by our infrastructure, stored information is protected using encryption technologies designed to reduce the risk of unauthorised access.
Password Security
Passwords are never stored in plain text.
Teamital uses secure password hashing mechanisms designed to protect authentication credentials.
Users are encouraged to:
- Create strong passwords.
- Avoid password reuse.
- Keep credentials confidential.
- Change passwords if compromise is suspected.
Authentication
The platform currently supports:
- Email and Password authentication
Administrative access is additionally protected through internal security controls and multi-factor authentication where applicable.
Access Control
Teamital follows the principle of least privilege.
Users are granted access only to the information and functionality required for their role.
Role-based permissions may include:
- Organisation Owner
- Administrator
- Manager
- Supervisor
- Employee
Customers are responsible for configuring user permissions within their organisation.
Multi-Factor Authentication
Administrative accounts are protected using Multi-Factor Authentication (MFA) wherever applicable.
MFA provides an additional layer of security beyond passwords to reduce the risk of unauthorised administrative access.
Network Security
Teamital uses multiple security measures to protect network infrastructure, including:
- HTTPS
- Secure API communication
- Firewall protection
- Network monitoring
- Secure cloud infrastructure
- Traffic filtering
- DDoS mitigation through Cloudflare
Cloudflare Protection
Teamital uses Cloudflare to improve both security and performance.
Cloudflare assists with:
- DDoS protection
- Traffic filtering
- Bot mitigation
- Content delivery optimisation
- Website performance
- Network resilience
GPS and Location Data Security
Location information is handled securely and only processed where enabled by the customer.
GPS information may include:
- Live location
- Route history
- Geofence events
- Attendance verification
- Site visit information
Location information is processed only for legitimate workforce management purposes configured by the customer.
Biometric and Attendance Security
Where enabled by customers, Teamital supports:
- Face Recognition
- Fingerprint Authentication
- PIN Authentication
Customers remain responsible for ensuring lawful use of biometric-related attendance features in accordance with applicable laws.
Teamital recommends restricting access to attendance information to authorised personnel only.
File Upload Security
Teamital supports secure upload of:
- Employee selfies
- Site photographs
- Documents
- Work reports
- Project files
Uploaded content is protected using platform access controls.
Customers are responsible for ensuring uploaded content complies with applicable laws and organisational policies.
Logging and Audit Trails
Teamital maintains audit logs to support security, operational monitoring and troubleshooting.
Audit records may include:
- User logins
- Administrative actions
- Configuration changes
- Attendance activity
- Security events
- System errors
Audit logs are accessible only to authorised personnel where necessary.
Monitoring and Incident Detection
Teamital continuously monitors platform health and security.
Monitoring may include:
- Infrastructure monitoring
- Service availability
- Error detection
- Authentication events
- Suspicious activity
- Application performance
Potential security incidents are investigated promptly.
Crash Reporting
Teamital uses Firebase Crashlytics to identify technical issues affecting application stability.
Crash reports may include:
- Device model
- Operating system
- App version
- Error logs
- Technical diagnostic information
Crash reporting data is used solely to improve platform reliability and performance.
Analytics
Teamital uses Google Analytics to better understand website usage and improve customer experience.
Analytics information may include:
- Device information
- Browser information
- Website interactions
- Traffic sources
- Anonymous usage statistics
Analytics data is not used to make employment decisions.
Data Backups
Regular backups are maintained to support business continuity and disaster recovery.
Backup procedures are designed to:
- Reduce data loss
- Support restoration
- Improve resilience
- Protect customer information
Backups are protected using appropriate security controls.
Business Continuity
Teamital maintains procedures intended to support continued service during unexpected events.
These procedures may include:
- Infrastructure redundancy
- Cloud resilience
- Backup restoration
- Incident response processes
- Operational recovery planning
Security Incident Response
If a security incident is identified, Teamital will:
- Investigate the incident.
- Contain the issue.
- Assess potential impact.
- Restore affected systems.
- Notify affected customers where required by applicable law.
- Review security controls to reduce future risk.
Where GDPR applies, breach notifications will be handled in accordance with applicable legal requirements.
Customer Responsibilities
Customers also play an important role in maintaining security.
Customers should:
- Use strong passwords.
- Restrict administrator accounts.
- Remove inactive users promptly.
- Configure permissions appropriately.
- Inform employees about platform usage.
- Protect devices used to access the platform.
- Keep operating systems and browsers updated.
- Report suspected security issues immediately.
Third-Party Service Providers
Teamital relies on carefully selected service providers including:
- Amazon Web Services (AWS)
- Supabase
- Cloudflare
- Firebase
- Firebase Crashlytics
- Google Analytics
- Google Maps
- Stripe
- Revolut
- Resend
These providers maintain their own security controls and privacy obligations.
Teamital reviews third-party services as part of ongoing security management.
Security Reviews
Our security practices are reviewed periodically to improve protection against evolving threats.
Reviews may include:
- Infrastructure assessments
- Configuration reviews
- Access reviews
- Software updates
- Dependency updates
- Security improvements
Policy Updates
This Security Policy may be updated from time to time to reflect changes in technology, legal requirements or our security practices.
The latest version will always be available on our website.
Contact Us
If you have questions regarding security or wish to report a potential security issue, please contact:
Teamital
Kandoy House, 2 Fairview Strand
Clontarf West, Dublin, D03 R8P3
Ireland
Email: contact@teamital.com
