← Back to HR Strategix

Terms, Privacy & Accessibility

Last updated 19 August 2026

Terms of Use Privacy Notice Cookies Security Accessibility Contact

Terms of Use

HR Strategix is a private business system operated by HR Strategix (“we”, “us”). It is not a public website.

We provide it to client organisations — employers who use it to run their own people operations. If you are signing in, it is almost certainly because your employer, or a company you work with, gave you an account. These terms cover your use of the system. Your own organisation’s policies apply to you as well, and where they are stricter, they govern what you may do with the information you find here.

Who may use it

Access is granted individually, through the organisation you belong to. You may use it only with the account issued to you and only for the purpose it was issued for. Accounts are not shared, and you are responsible for what is done with yours.

If you no longer need access — or you believe somebody else has used your account — tell an administrator at your own organisation first, since they can close or reset it immediately. You can also reach us at TL.Johnson@tlurbandev.com.

What you may not do

  • Sign in with an account that is not yours, or let anybody else use yours.
  • Try to reach data or features your access does not give you, including another organisation’s.
  • Copy, export or pass on information about other people except as your role requires.
  • Interfere with the system, or attempt to test its security without our written consent.

Information entered here

Content entered by an organisation’s users — goals, documents, notes, meeting records, org charts — belongs to that organisation, not to us. We hold it on their behalf and act on their instructions. We do not use it for our own purposes, and we do not use it to train anything.

Do not enter anything you would not want retained, seen by an administrator at your organisation, or produced in a legal or regulatory process.

Availability, and no warranty

The system is provided as-is. We do not promise it will be available at any particular time or free of faults, and we may change or withdraw any part of it. Where a written agreement with your organisation says otherwise, that agreement governs.

Ending access

Your organisation may remove your access at any time, including automatically when you leave or an engagement ends. We may suspend access where it is being misused or where required by our agreement with your organisation.

Governing law

These terms are governed by the laws of the State of California, without regard to its conflict-of-laws rules. Where a signed agreement between us and your organisation covers the same ground, that agreement takes precedence.

Privacy Notice

We hold two different kinds of information, under two different sets of rules. Which one applies decides who you should ask about it, so it is worth a moment:

  • Information we hold for your organisation. Almost everything in this system: who works there, their goals and projects, documents, meeting notes. Your employer decides what goes in and why. We act on their instructions and nothing else.
  • Information we hold about you directly. A small amount, needed to run the service at all: your account, the record of your sign-ins, and anything you send us yourself — a support case, for example.

In the language of the California Consumer Privacy Act, your employer is the business for the first kind and we are a service provider. We do not sell or share personal information, and we do not retain, use or disclose it for any purpose other than providing the service.

Who this covers

  • Workforce users — employees and contractors of a client organisation who sign in.
  • Client users — people at organisations we have given access to.
  • People recorded who never sign in — staff who appear on an org chart or in a directory without an account. They hold no account, but information about them is still processed, and this notice covers that.

What is collected

  • Account details — name, work email, job title, department, location, employee or file number, and whether the account can sign in.
  • What you do here — sign-in times and failures, and a record of changes made, including who made them and when.
  • Content your organisation enters — goals and their owners, projects and tasks, documents and approvals, 1:1 meeting records, support cases and their replies.
  • Technical data — a session cookie, and ordinary web server logs kept by our hosting provider.

There is no advertising, no third-party analytics, and no tracking across other websites.

Monitoring

Use of this system is recorded. Sign-ins, failed sign-in attempts, and changes to records are logged along with the account that made them, and where an administrator acts on behalf of another user that is recorded too. Administrators at your own organisation can view and export this activity. It exists for security and accountability — being able to establish who did what — not for measuring individual productivity. How your employer uses it is a matter for their policies.

Who sees it

  • Colleagues at your own organisation, to the extent their access allows — access is granted per person, per tool.
  • Administrators at your own organisation, who can see everything belonging to it.
  • Us, only as needed to operate, support and secure the service.
  • Our hosting provider, which stores the data on our behalf.
  • Others where the law requires it, or to establish or defend a legal claim.

Organisations are kept separate. One client’s users cannot see another’s data.

How long

Content belongs to your organisation and is kept for as long as they keep it, and afterwards for as long as our agreement with them and the law require. Deleting a person does not delete the record of what they did, because an activity log that can be edited by the thing it records is not a log.

Specific retention periods have not yet been set. Ask TL.Johnson@tlurbandev.com for the current position.

Your rights, and who to ask

Depending on where you live, you may be able to ask for a copy of the personal information held about you, to have it corrected or deleted, or to limit how it is used. If you are in California, the CCPA gives you these rights and the right not to be treated differently for using them.

Ask your own employer first. For almost everything in this system they decide what is held and why, so they are the ones who can answer — and they are who the law points you to. Speak to your HR or People team.

If your request is about information we hold about you directly, or your employer cannot help, write to TL.Johnson@tlurbandev.com. Where we receive a request that belongs to a client organisation, we pass it to them and support them in answering it. We will need to confirm who you are before acting on any request.

Security

Accounts are individual and access is granted per person and per tool. Passwords are stored hashed, never in a form we can read. Repeated failed sign-ins lock an account. Activity is logged. No system is perfectly secure, and we do not claim otherwise — if you believe something here has gone wrong, tell us at TL.Johnson@tlurbandev.com and say what you saw.

Cookies

This system uses one cookie, to keep you signed in from one page to the next. It is strictly necessary for the site to work, holds no personal information itself, and is removed when you sign out.

There are no advertising, tracking or analytics cookies, which is why you are not asked to consent to any. Your browser also stores some of your own settings — your colour theme, which filters you had open — on your device; that never leaves your browser except where it is saved to your account so it follows you between machines.

Security

This system holds information about people — who reports to whom, what was said in a one-to-one, who is on a performance conversation. That is the reason for everything below. We would rather describe what we actually do than make claims that sound better.

Getting in

  • Accounts are individual. There are no shared or generic logins.
  • Passwords are stored as bcrypt hashes, never in a form anybody — including us — can read back.
  • A password created for you by an administrator has to be changed the first time you sign in. It was shown on somebody else’s screen, so it was never private to you.
  • Three wrong passwords locks the account for a short period, or until an administrator clears it.
  • Sessions end after a period of inactivity, so an unattended screen does not stay signed in.
  • There is no password reset by email. A new password comes from an administrator, in person. The owner account — which no administrator can reset — instead has a single-use recovery code, held offline, which goes through the same lockout as a normal sign-in and is destroyed the moment it is used.
  • Every sign-in, failed attempt, lock and use of a recovery code is recorded.

What you can see

Access is granted per application, at one of three levels — none, read, or full — and can come from your department, from a team you belong to, or from a grant made to you personally. Where more than one applies, the highest wins. Permissions are checked on the server on every request, including the ones the page makes in the background: hiding a button is a courtesy, not a control, and is never the only thing standing between somebody and a record.

Administrators, and acting as somebody else

An administrator at your organisation can sign in as another user to see what they see — which is how most “it does not work for me” problems get solved. When that happens, both identities are recorded against everything done, so the trail always shows who was actually at the keyboard. One administrator cannot do this to another. The site owner can — it is the only way to see what an administrator sees without borrowing their password — and while doing so they have that administrator’s powers and not their own. Nobody, including the owner, can sign in as the owner.

One account is the owner of the site. No administrator can change it — not its password, its rights, or its access — because an administrator who could reset the owner’s password could sign in as the owner. Some administrative screens are the owner’s alone, and an attempt to reach one is recorded like any other action.

In transit and at rest

The site is served over HTTPS only; plain HTTP is redirected, and browsers are told to refuse it thereafter. The session cookie is restricted to HTTPS, is not readable by JavaScript, and is not sent to other sites.

Data is held in a database on hosting operated by GoDaddy in the United States. Backups, physical security and the underlying platform are theirs; the application, its access rules and its records are ours.

What is written down

Changes to records are logged with who made them, when, and from what address, and the site owner can export that history. The log is there so a question about a record has an answer — not to monitor how anybody spends their day.

What we do not do

  • No multi-factor authentication. A password is currently the only thing between an account and its data.
  • No password reset by email. Mail from this host is unreliable, so a forgotten password is reset by an administrator at your own organisation. This is deliberate, and it means an administrator must be reachable.
  • No independent security audit or certification. No penetration test, no SOC 2, no ISO 27001. We are not going to imply otherwise.
  • No application-level encryption of stored data beyond what the hosting platform provides.
  • Shared hosting, not dedicated infrastructure.

These are the trade-offs of a small, focused system rather than an enterprise platform, and they are the right things to weigh before deciding what to keep in here. If any of them matters to your organisation, say so — some are fixable.

Telling us about a problem

If you think you have found a security problem, write to TL.Johnson@tlurbandev.com and describe what you saw and how to reproduce it. Please do not test it further against live data, and please give us a chance to fix it before telling anybody else. We will not pursue anybody who reports something in good faith and in that way.

If you believe an account has been used by somebody other than its owner, tell an administrator at your own organisation first — they can lock or reset it immediately, which is faster than anything we can do from outside.

Accessibility

We want everybody who is given an account to be able to use this system. We aim to meet the Web Content Accessibility Guidelines (WCAG) 2.1 at Level AA. It has not been formally audited, so this is a statement of intent and current practice rather than a certification.

If something here is difficult or impossible for you to use — with a screen reader, a keyboard alone, at a larger text size, or for any other reason — write to TL.Johnson@tlurbandev.com. Tell us the page and what happened, and we will fix it or find you another way to get the same thing done.

Contact

HR Strategix
HR Strategix is a trading name of TL Urban Development.
2080 Empire Ave #1129, Burbank, CA 91504
Privacy and data requests: TL.Johnson@tlurbandev.com
Accessibility: TL.Johnson@tlurbandev.com

If you have an account through your employer and your question is about the information they hold, your HR or People team is the faster route — and for most requests, the correct one.

© 2026 HR Strategix. All rights reserved.