HR Strategix is a private business system operated by HR Strategix (“we”, “us”). It is not a public website.
We provide it to client organisations — employers who use it to run their own people operations. If you are signing in, it is almost certainly because your employer, or a company you work with, gave you an account. These terms cover your use of the system. Your own organisation’s policies apply to you as well, and where they are stricter, they govern what you may do with the information you find here.
Access is granted individually, through the organisation you belong to. You may use it only with the account issued to you and only for the purpose it was issued for. Accounts are not shared, and you are responsible for what is done with yours.
If you no longer need access — or you believe somebody else has used your account — tell an administrator at your own organisation first, since they can close or reset it immediately. You can also reach us at TL.Johnson@tlurbandev.com.
Content entered by an organisation’s users — goals, documents, notes, meeting records, org charts — belongs to that organisation, not to us. We hold it on their behalf and act on their instructions. We do not use it for our own purposes, and we do not use it to train anything.
Do not enter anything you would not want retained, seen by an administrator at your organisation, or produced in a legal or regulatory process.
The system is provided as-is. We do not promise it will be available at any particular time or free of faults, and we may change or withdraw any part of it. Where a written agreement with your organisation says otherwise, that agreement governs.
Your organisation may remove your access at any time, including automatically when you leave or an engagement ends. We may suspend access where it is being misused or where required by our agreement with your organisation.
These terms are governed by the laws of the State of California, without regard to its conflict-of-laws rules. Where a signed agreement between us and your organisation covers the same ground, that agreement takes precedence.
We hold two different kinds of information, under two different sets of rules. Which one applies decides who you should ask about it, so it is worth a moment:
In the language of the California Consumer Privacy Act, your employer is the business for the first kind and we are a service provider. We do not sell or share personal information, and we do not retain, use or disclose it for any purpose other than providing the service.
There is no advertising, no third-party analytics, and no tracking across other websites.
Use of this system is recorded. Sign-ins, failed sign-in attempts, and changes to records are logged along with the account that made them, and where an administrator acts on behalf of another user that is recorded too. Administrators at your own organisation can view and export this activity. It exists for security and accountability — being able to establish who did what — not for measuring individual productivity. How your employer uses it is a matter for their policies.
Organisations are kept separate. One client’s users cannot see another’s data.
Content belongs to your organisation and is kept for as long as they keep it, and afterwards for as long as our agreement with them and the law require. Deleting a person does not delete the record of what they did, because an activity log that can be edited by the thing it records is not a log.
Depending on where you live, you may be able to ask for a copy of the personal information held about you, to have it corrected or deleted, or to limit how it is used. If you are in California, the CCPA gives you these rights and the right not to be treated differently for using them.
Ask your own employer first. For almost everything in this system they decide what is held and why, so they are the ones who can answer — and they are who the law points you to. Speak to your HR or People team.
If your request is about information we hold about you directly, or your employer cannot help, write to TL.Johnson@tlurbandev.com. Where we receive a request that belongs to a client organisation, we pass it to them and support them in answering it. We will need to confirm who you are before acting on any request.
Accounts are individual and access is granted per person and per tool. Passwords are stored hashed, never in a form we can read. Repeated failed sign-ins lock an account. Activity is logged. No system is perfectly secure, and we do not claim otherwise — if you believe something here has gone wrong, tell us at TL.Johnson@tlurbandev.com and say what you saw.
This system uses one cookie, to keep you signed in from one page to the next. It is strictly necessary for the site to work, holds no personal information itself, and is removed when you sign out.
There are no advertising, tracking or analytics cookies, which is why you are not asked to consent to any. Your browser also stores some of your own settings — your colour theme, which filters you had open — on your device; that never leaves your browser except where it is saved to your account so it follows you between machines.
This system holds information about people — who reports to whom, what was said in a one-to-one, who is on a performance conversation. That is the reason for everything below. We would rather describe what we actually do than make claims that sound better.
Access is granted per application, at one of three levels — none, read, or full — and can come from your department, from a team you belong to, or from a grant made to you personally. Where more than one applies, the highest wins. Permissions are checked on the server on every request, including the ones the page makes in the background: hiding a button is a courtesy, not a control, and is never the only thing standing between somebody and a record.
An administrator at your organisation can sign in as another user to see what they see — which is how most “it does not work for me” problems get solved. When that happens, both identities are recorded against everything done, so the trail always shows who was actually at the keyboard. One administrator cannot do this to another. The site owner can — it is the only way to see what an administrator sees without borrowing their password — and while doing so they have that administrator’s powers and not their own. Nobody, including the owner, can sign in as the owner.
One account is the owner of the site. No administrator can change it — not its password, its rights, or its access — because an administrator who could reset the owner’s password could sign in as the owner. Some administrative screens are the owner’s alone, and an attempt to reach one is recorded like any other action.
The site is served over HTTPS only; plain HTTP is redirected, and browsers are told to refuse it thereafter. The session cookie is restricted to HTTPS, is not readable by JavaScript, and is not sent to other sites.
Data is held in a database on hosting operated by GoDaddy in the United States. Backups, physical security and the underlying platform are theirs; the application, its access rules and its records are ours.
Changes to records are logged with who made them, when, and from what address, and the site owner can export that history. The log is there so a question about a record has an answer — not to monitor how anybody spends their day.
These are the trade-offs of a small, focused system rather than an enterprise platform, and they are the right things to weigh before deciding what to keep in here. If any of them matters to your organisation, say so — some are fixable.
If you think you have found a security problem, write to TL.Johnson@tlurbandev.com and describe what you saw and how to reproduce it. Please do not test it further against live data, and please give us a chance to fix it before telling anybody else. We will not pursue anybody who reports something in good faith and in that way.
If you believe an account has been used by somebody other than its owner, tell an administrator at your own organisation first — they can lock or reset it immediately, which is faster than anything we can do from outside.
We want everybody who is given an account to be able to use this system. We aim to meet the Web Content Accessibility Guidelines (WCAG) 2.1 at Level AA. It has not been formally audited, so this is a statement of intent and current practice rather than a certification.
If something here is difficult or impossible for you to use — with a screen reader, a keyboard alone, at a larger text size, or for any other reason — write to TL.Johnson@tlurbandev.com. Tell us the page and what happened, and we will fix it or find you another way to get the same thing done.
HR Strategix
HR Strategix is a trading name of TL Urban Development.
2080 Empire Ave #1129, Burbank, CA 91504
Privacy and data requests: TL.Johnson@tlurbandev.com
Accessibility: TL.Johnson@tlurbandev.com
If you have an account through your employer and your question is about the information they hold, your HR or People team is the faster route — and for most requests, the correct one.