Effective June 9, 2026
[COMPANY LEGAL NAME] (“DOSSR,” “we,” “us,” or “our”) provides a private, access-controlled case-management and travel-risk platform. This Privacy Policy explains what information we collect, how we use and protect it, and the choices and rights available to you. It applies to the DOSSR application and related services (collectively, the “Service”).
DOSSR is an enterprise tool used by authorized organizational users. In most cases your organization is the “controller” of the personal data processed in the Service and we act as a “processor” on its behalf. Where your organization administers your account, its own privacy policies may also apply.
We collect the following categories of information:
Some content processed in the Service may constitute special categories of data under applicable law. You are responsible for ensuring you have a lawful basis to submit such information.
We use information to:
Where the EU or UK General Data Protection Regulation applies, we process personal data on the bases of: performance of a contract; our or our customers’ legitimate interests in operating and securing the Service; compliance with legal obligations; and, where required, consent. Where we act as a processor, processing is governed by our agreement with the controlling organization.
We do not sell personal information. We share information only as necessary to operate the Service:
We retain information for as long as your account is active or as needed to provide the Service, then for the period necessary to satisfy our legal, accounting, security, or reporting obligations. Audit logs are retained on an append-only basis for accountability. Your organization may set its own retention preferences.
We employ technical and organizational safeguards designed to protect information, including encryption in transit, password hashing (bcrypt), encryption of sensitive secrets at rest, mandatory multi-factor authentication, role-based access controls, brute-force lockout, instant session revocation, and authentication-gated file delivery. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Depending on your jurisdiction, you may have rights to access, correct, delete, restrict, or object to the processing of your personal data, to data portability, and to withdraw consent. Residents of certain U.S. states (e.g., California under the CCPA/ CPRA) have rights to know, delete, and correct personal information and to opt out of its sale or sharing — we do not sell or share personal information as those terms are defined.
Because much of the data in the Service is controlled by your organization, please direct rights requests to your organization first, or contact us using the details below and we will assist the relevant controller.
We and our service providers may process information in countries other than your own. Where we transfer personal data across borders, we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms required by applicable law.
The Service uses strictly necessary cookies to authenticate sessions and enforce multi-factor verification. These are required for the Service to function and do not track you for advertising.
The Service is intended for use by authorized professional users and is not directed to children. We do not knowingly collect personal information from children.
We may update this Policy from time to time. Material changes will be indicated by updating the effective date above and, where appropriate, through in-product notice. Continued use of the Service after changes become effective constitutes acceptance.
For questions about this Policy or our privacy practices, contact [COMPANY LEGAL NAME] at [privacy@your-domain].