Legal

Privacy Policy

Security records describe real people in vulnerable settings. This page explains plainly what we hold, why, and who can reach it.

What we hold

Operator and community records, staff accounts and roles, and the security records your team creates: patrol rounds, checkpoint scans, incident reports, visitor and vehicle entries, shift reports, follow-up tasks, resident and staff directory entries, and emergency contacts. Photographs attached to rounds and incidents are stored in private storage and are never publicly addressable.

Why we hold it

Solely to provide the service to the operator that entered the data. We do not sell data, and we do not use resident or incident information to train models or for advertising.

Tenant isolation

Every record is scoped to a community and an organisation, and access is enforced in the database itself through row-level security — not only in the interface. A signed-in user can read a community's records only when they are assigned to that community or hold a leadership role over it.

Resident information

Resident directory entries, care levels and emergency contacts exist to support an emergency response. Access follows the same community scoping as every other record, and changes are attributable to the account that made them.

Access, audit and accountability

Administrative changes — role changes, community configuration, invitations — are written to an immutable audit log recording the actor, the action, and the previous and new values. Audit records cannot be edited or deleted from the application.

Retention and deletion

Security records are retained for as long as the operator's agreement requires, since they routinely serve incident, insurance and regulatory review. An operator may request export or deletion of their organisation's data at any time.

Sub-processors

We use infrastructure providers for hosting, database, authentication, file storage and transactional messaging. Each is bound by a data-processing agreement, and none receives access beyond what is needed to run the service.

Contact

Privacy questions, access requests and deletion requests can be sent through the contact form on this site and are answered by a person, not a queue.