Privacy Policy
How Backoffice collects, uses and protects information for the accounts your organization provisions.
On this page
This System is operated for your organization, which decides who is provisioned an account and what data is entered into it. This policy explains how the System itself handles that information.
1. Overview
Backoffice is an internal business system used by your organization to manage finance, HR, inventory, procurement, sales and related operations. This policy covers information processed through the System in connection with your account.
2. Information we process
Depending on your role, the System may process: your account and identity information (name, username, email, role); HR and payroll information your organization has entered; financial and transactional records (invoices, payments, journals); and system activity such as sign-ins and the actions your account performs.
3. How information is used
Information is used solely to operate the System for your organization — running the business functions it has been configured for, securing accounts, and maintaining an audit trail of activity. It is not used for advertising or sold to third parties.
4. Access controls
Access to data within the System is governed by role-based permissions. A user can only see the modules and records their assigned role and permissions allow, enforced on every request rather than hidden only in the interface.
5. Security measures
Sign-in uses hashed, salted password storage and temporarily locks an account after repeated failed attempts. Optional two-factor authentication (TOTP) is available from account security settings. Sessions use HTTPS-only, HTTP-only cookies with an automatic idle sign-out, and only one session is active per account at a time.
6. Audit logging
Key actions — sign-ins, security-relevant changes and activity across financial and operational modules — are recorded in an audit trail your organization's administrators can review.
7. Data retention
Information is retained for as long as your organization keeps the System configured to do so and in line with its own record-keeping obligations. Removing a user's access does not by itself delete historical records they created, since those form part of your organization's business and audit history.
8. Your choices
You can update your own profile information and manage your account's security settings (including two-factor authentication) from within the System. For corrections to HR, payroll or other organization-managed data, contact your administrator.
9. Changes to this policy
This policy may be updated from time to time to reflect changes in the System. Continued use after a change constitutes acceptance of the revised policy.
10. Contact
Questions about this policy should be directed to your organization's system administrator, or to support@primeforce.africa.
Still have questions?
For account access, sign-in issues or questions about how your data is handled, reach out to support. We can't provide legal advice.