Data protection
Your organization owns its data, can export all of it at any time without asking us, and can have it deleted. This page is the specific version of those promises.
Your organization owns its data
Employee records, training history, certificates and uploads belong to your organization. In data-protection terms your organization is the controller of that information and Solvesoft Corp is a processor acting on your instructions: we process your records only to provide the service, as described in our Privacy Policy.
We never sell customer data, never use your records for advertising, and never train machine-learning models on them.
Where your data lives
The database, authentication and file storage run on Supabase-managed PostgreSQL in the Canada Central (ca-central-1) region — chosen deliberately, because our customers operate in Canada. Data is encrypted in transit and at rest.
To be precise about what that does and does not mean: it locates the primary database and file storage in Canada. It is not a promise that every processor handles every copy only in Canada. Application requests are executed by Vercel and transactional email content is processed by Resend, including in the United States or other locations permitted by their terms.
Portability — no lock-in
At any time during your subscription, and for 30 days after it ends, you can export everything from inside the product itself, without asking us and without a fee: employees including custom fields, all training records, the training matrix, courses, all six standard compliance reports, any custom report, individual transcripts, and the audit log — each as CSV. Attachments download as their original files.
CSV downloads are timestamped in their filenames so you can tell when a set was taken. On written request we will additionally provide, at no charge, a complete structured export of your organization's data including attachments, so nothing is trapped behind the interface.
No hostage-taking. Access to export is never withheld over a billing dispute. If a subscription lapses the workspace becomes read-only — you can still read, print and export everything; you simply cannot add new records until it is reactivated.
Retention and deletion
Your data is retained for as long as your organization has an account. When an organization is deleted, its records are permanently removed from production systems within 30 days. Encrypted backup copies then age out on the backup rotation, which runs on a 90-day retention window— so a deleted organization's data can persist in backups for up to 90 days after the production purge before expiring.
Deletion covers operational database records, uploaded files and organization access. Residual copies in managed-provider backups, logs or email-delivery systems expire according to each provider's applicable retention schedule. Written confirmation of the completed operational deletion is available on request.
Subprocessors
We use a small set of subprocessors to run TrainGrid:
Supabase — database, authentication and file storage; all application data. Vercel— application hosting; the request data needed to execute the application, plus platform logs and telemetry under Vercel's terms. Resend — transactional email; recipient address, delivery metadata and message content. Stripe — subscription billing; billing contact and payment details only.
Each processes data only as needed to provide their service to us, and each may use its own authorized subprocessors under its applicable agreement.
Employee data rights
Where an employer manages employee records in TrainGrid, the employer is the controller. Employees who want access to, correction of, or deletion of their personal information should direct the request to their employer, and we will support every such request the employer makes.
One practical note: employees are not required to have accounts. Optional read-only portal access shows an employee only their own training record and transcript, and nothing else in the organization.
Security controls and breach notification
The controls behind all of the above — database-level tenant isolation, role-based access with location scoping, an append-only audit log, encryption, and nightly encrypted backups of both the database and your uploaded files — are described on our security page.
If we become aware of a breach affecting your data we will notify your organization's administrators without undue delay, consistent with applicable breach-notification requirements.
Questions and requests
Export requests, deletion requests and data-protection questions go to contact@solvesoftcorp.com, or reach us through the contact page. The full legal detail is in our Privacy Policy and Terms of Service.