Privacy Policy

SXI - CapexLog · Last updated: February 26, 2026

GDPR Compliant

This privacy policy complies with the General Data Protection Regulation (EU) 2016/679 and applicable data protection laws.

SXI - CapexLog ("the Platform") is an internal capital expenditure planning and reporting application operated by the FP&A department. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use this Platform.

1. What Data Is Collected and Why

  • Identity data: Full name, email address, job title, department, and division — collected to create your user account and assign appropriate role-based access.
  • Authentication data: Hashed password credentials and session tokens — used for secure login and session management per OWASP ASVS Level 1 requirements.
  • Activity data: Timestamps of login events, form submissions, approval actions, and session activity — used for audit trails, compliance monitoring, and security purposes.
  • Financial data:Capital expenditure requests, budget figures, forecasts, and actuals you submit or approve — required for the Platform's core business functions.
  • Access metadata: IP addresses, browser type, and device information — logged for security monitoring and rate-limit enforcement.

We only collect data that is strictly necessary for the Platform's operation and your role within it (data minimisation principle, GDPR Art. 5(1)(c)).

2. How Data Is Stored and Protected

  • All data is stored in SQL Server on-premises with encryption in transit (TLS 1.2+, SQLSERVER_ENCRYPT=true) and optional encryption at rest (TDE).
  • Session tokens are stored in browser sessionStorage (tab-scoped) and are automatically cleared on tab close per ASVS 8.2.2.
  • Passwords are never stored in plaintext. In production, bcrypt hashing with a work factor of 12+ is used.
  • Rate limiting (ASVS 2.2.1) prevents brute-force attacks on authentication endpoints.
  • Automatic session expiry after 30 minutes of inactivity (ASVS 3.3.2).
  • Role-based access control (RBAC) ensures users can only access data appropriate to their role.

3. Who Has Access to the Data

  • You: Your own submissions, requests, and profile data.
  • Your direct manager and division approvers: Data related to approvals within their scope.
  • Division Leaders and Corporate: Aggregated financial data across entities as required by their roles.
  • System administrators: Technical access for user management and Platform maintenance only.
  • No third parties: We do not share your personal data with external parties unless required by law.

4. Data Retention Policy

  • Active user accounts and associated data are retained for the duration of employment or Platform access.
  • Financial records (CERs, LERs, budgets, actuals) are retained for a minimum of 7 years in accordance with corporate financial record-keeping policies.
  • Audit logs and session records are retained for 3 years.
  • Inactive accounts are flagged after 90 days and data is archived after 12 months of inactivity.
  • Upon deletion request, personal data is anonymised or removed within 30 days, except where retention is required by law.

5. User Rights (GDPR Articles 15–22)

Under applicable data protection law, you have the following rights:

  • Right of access (Art. 15): Request a copy of all personal data held about you.
  • Right to rectification (Art. 16): Request correction of inaccurate or incomplete data.
  • Right to erasure (Art. 17):Request deletion of your personal data ("right to be forgotten"), subject to legal retention requirements.
  • Right to restriction (Art. 18): Request restriction of processing in certain circumstances.
  • Right to data portability (Art. 20): Receive your data in a structured, machine-readable format.
  • Right to object (Art. 21): Object to processing based on legitimate interests.

6. Contact for Data-Related Requests

For any questions, requests, or concerns regarding your personal data, please contact:

Data Protection Officer

FP&A Department — SXI Group

Email: dpo@sxi-capexlog.com

We will respond to all data subject requests within 30 days as required by GDPR Art. 12(3).