Privacy Policy

Effective date: April 2026

Enzure is built to help Trinidad & Tobago businesses file national insurance contributions with less friction. We handle payroll data on your behalf, so we take privacy seriously. This policy explains what we collect, why we collect it, and how we protect it.

If you have questions that this document does not answer, email us at reach out on LinkedIn.

1. Information we collect

Account information

When you sign up, authentication is handled by Clerk. Clerk collects your name, email address, and any social login credentials you choose to use. We receive a user identifier and basic profile details from Clerk to associate your account with your organisation in Enzure. We do not store your password — Clerk manages credentials securely.

Employee and payroll data

To generate NIS forms, you enter employee details: full name, NIS registration number, salary, and pay period. This data belongs to your organisation. We store it on your behalf to allow form generation and re-use across pay periods, but we do not use it for any purpose beyond providing the Enzure service to you.

We do not sell, share, or use your employee data for advertising, profiling, or training machine-learning models.

Usage analytics

We use PostHog to collect anonymised product analytics — which features are used, where users encounter friction, and how the product is performing. PostHog captures events such as page views, button clicks, and feature interactions. It does not capture personally identifiable information or the content of your payroll data.

2. How we use your information

We use the information we collect for three purposes:

  • To provide the service. Your account information lets us authenticate you and associate you with the correct organisation. Your employee and salary data is used exclusively to calculate NIS contribution classes and rates, populate NI184 and NI187 forms, and archive generated PDFs.
  • To improve the product. Anonymised usage analytics help us understand which features work well and which need attention. We use this to prioritise fixes and improvements.
  • To communicate with you. We may email you about important service changes, security issues, or significant product updates. We do not send marketing emails unless you have opted in.

3. Data storage and security

All application data — employee records, salary information, and generated form metadata — is stored in Convex, a cloud database platform with encryption at rest and in transit. Data is logically isolated per organisation: members of one organisation cannot access the data of another.

Enzure is hosted on Vercel. Application traffic is served over HTTPS. We do not store raw PDF content server-side; forms are generated on demand and streamed directly to your browser.

Your employee and salary data belongs to your organisation. We act as a data processor on your behalf, not a data controller in our own right with respect to that information. You remain responsible for ensuring your use of employee data complies with applicable law.

4. Third-party services

Enzure uses the following third-party services to operate:

Authentication and user management. Handles sign-up, sign-in, and session management. Governed by Clerk's own privacy policy.

Backend database and serverless functions. Stores all application data with encryption at rest.

Product analytics. Collects anonymised usage events to help us understand how Enzure is used.

Application hosting and edge network. Serves the Enzure web application and handles CDN delivery.

We do not sell data to third parties. We do not use any advertising networks or tracking pixels beyond the analytics described above.

5. Data retention

Generated forms are archived for 12 months from the date of generation. After this period, form records may be deleted from the archive. You can download any form at any time during this window.

Employee records and salary data are retained for as long as your organisation account is active. If you delete an employee record, it is removed from your active employee list immediately, though it may be referenced in historical form records until those records expire.

Account data is retained while your account remains active. If you close your account, we will delete your personal data within 30 days, except where retention is required by law.

6. Your rights

You have the following rights with respect to your data:

  • Access. You can view all employee records and generated forms at any time from within the Enzure dashboard.
  • Correction. You can update employee records and account details at any time.
  • Deletion. You can delete employee records, generated form history, or your entire account. Reach out via our contact page to request full account deletion.
  • Export. You can download any generated PDF from the archive at any time. If you need a bulk export of your data, email us and we will accommodate your request.
  • Objection. If you object to any aspect of how we process your data, contact us and we will address your concern.

7. Cookies

Enzure uses a minimal number of cookies:

  • Authentication cookies. Set by Clerk to maintain your login session. These are strictly necessary for the service to function and cannot be opted out of while using Enzure.
  • Analytics cookies. Set by PostHog to track anonymised usage sessions. These are not linked to personally identifiable information.

We do not use advertising cookies or third-party tracking cookies of any kind.

8. Trinidad & Tobago context

Enzure is built specifically for businesses operating in Trinidad & Tobago and is designed with local data handling practices in mind. We aim to align our practices with the principles of fairness, purpose limitation, and data minimisation as reflected in Trinidad & Tobago’s data protection framework.

If you have concerns about how we handle data in the context of local regulations, please contact us at reach out on LinkedIn. We are committed to responding in good faith.

9. Changes to this policy

We may update this privacy policy from time to time. When we make material changes, we will update the effective date at the top of this page and, where appropriate, notify you by email. Continued use of Enzure after a policy update constitutes acceptance of the revised terms.

Privacy inquiries

For any privacy-related questions or requests, contact us at:

reach out on LinkedIn