Debrief ("Debrief," "we," "us") provides performance-management and HR software to employers ("Customers"). This policy explains how we handle personal information when a Customer's organization uses Debrief and when an individual ("you," an employee, manager, or administrator of a Customer) uses the service.
Debrief is a business-to-business service. For most data we process, the Customer (your employer) is the controller and Debrief is the processor acting on the Customer's instructions. If you are an employee, please also review your employer's own privacy notice.
We do not sell your personal information, and we do not use your organization's content to train external advertising or general-purpose AI models.
HR tickets may include sensitive information (for example, medical-leave or accommodation requests). Access to this content is restricted server-side to the person who filed it and authorized HR/administrator roles at your organization. We apply the same access controls to calibration notes and 1:1 documentation.
We share information only with: (a) authorized users within your own organization according to their role; (b) service providers that host and operate Debrief under contract (our database and edge infrastructure providers); and (c) authorities where required by law. Our sub-processors are bound to protect your data and use it only to provide their services to us.
Data is stored in managed PostgreSQL and served over encrypted connections (HTTPS/TLS). Passwords are hashed with a per-user salt. We apply role-based access controls, session expiry, and login-abuse protections. No method of transmission or storage is perfectly secure, but we work to protect your information using industry-standard measures.
We retain personal information for as long as your organization maintains its account, and as needed to provide the service, comply with law, resolve disputes, and enforce agreements. When a Customer's account ends, we delete or return organization data in line with our agreement with that Customer.
You can update your profile and password in the app. Because your employer controls most of your data, requests to access, correct, export, or delete personal information are generally directed to your employer (the controller), and we will assist them. You may also contact us using the details below. Depending on your location, you may have rights under laws such as the GDPR or CCPA/CPRA; we honor applicable rights.
Debrief is an employer-controlled system. Because your employer is the controller of your employment records, individual accounts are provisioned and removed by your organization's account owner and administrators, not through self-service. To have your personal data corrected or deleted, contact your employer's HR or account administrator, who can remove you from the owner console; you may also contact us and we will assist the controller. When your employer's account ends, Debrief deletes or returns the organization's data in line with our agreement with the Customer, subject to any legal or regulatory retention requirements.
Debrief is a workplace tool and is not directed to children under 16. We do not knowingly collect information from children.
We may update this policy. Material changes will be posted here with a new "Last updated" date.
Questions or requests: privacy@debrief.team.
This document is a general template provided for transparency and is not legal advice. Debrief and its Customers should have counsel review and tailor it to their jurisdictions and practices before relying on it.