DOSSR · Legal

Privacy Policy

Effective June 9, 2026

1. Introduction

[COMPANY LEGAL NAME] (“DOSSR,” “we,” “us,” or “our”) provides a private, access-controlled case-management and travel-risk platform. This Privacy Policy explains what information we collect, how we use and protect it, and the choices and rights available to you. It applies to the DOSSR application and related services (collectively, the “Service”).

DOSSR is an enterprise tool used by authorized organizational users. In most cases your organization is the “controller” of the personal data processed in the Service and we act as a “processor” on its behalf. Where your organization administers your account, its own privacy policies may also apply.

2. Information We Collect

We collect the following categories of information:

  • Account & authentication data. Name, email address, role, hashed password, and multi-factor authentication (TOTP) secrets and recovery codes, stored in encrypted or hashed form.
  • Content you submit. Records you create within the Service — including cases, persons of interest, executives, trips, notes, uploaded files, and travel-risk assessments — which may contain sensitive personal information about you or third parties.
  • Usage & security logs. Audit records of actions taken in the Service, including the acting user, action type, timestamp, IP address, and user-agent string, retained for security and accountability.
  • Technical data. Information your browser or device automatically provides when accessing the Service, such as IP address, device and browser type, and session cookies.

Some content processed in the Service may constitute special categories of data under applicable law. You are responsible for ensuring you have a lawful basis to submit such information.

3. How We Use Information

We use information to:

  • Provide, operate, secure, and maintain the Service;
  • Authenticate users and enforce role-based access controls;
  • Generate travel-risk assessments and related documents using third-party public data sources and automated language models;
  • Maintain audit trails, detect and prevent fraud, abuse, and unauthorized access;
  • Comply with legal obligations and enforce our terms.

4. Legal Bases for Processing (EEA/UK)

Where the EU or UK General Data Protection Regulation applies, we process personal data on the bases of: performance of a contract; our or our customers’ legitimate interests in operating and securing the Service; compliance with legal obligations; and, where required, consent. Where we act as a processor, processing is governed by our agreement with the controlling organization.

5. How We Share Information

We do not sell personal information. We share information only as necessary to operate the Service:

  • Service providers (sub-processors). We use vetted infrastructure providers to host and run the Service, including cloud hosting and deployment, managed database, file storage, transactional email, and automated language-model providers. These providers process data only on our instructions and under contractual confidentiality and security obligations.
  • Within your organization. Authorized users in your organization may access content according to their assigned role.
  • Legal & safety. Where required by law, legal process, or to protect the rights, safety, and security of users or the public.
  • Business transfers. In connection with a merger, acquisition, or sale of assets, subject to this Policy.

6. Data Retention

We retain information for as long as your account is active or as needed to provide the Service, then for the period necessary to satisfy our legal, accounting, security, or reporting obligations. Audit logs are retained on an append-only basis for accountability. Your organization may set its own retention preferences.

7. Security

We employ technical and organizational safeguards designed to protect information, including encryption in transit, password hashing (bcrypt), encryption of sensitive secrets at rest, mandatory multi-factor authentication, role-based access controls, brute-force lockout, instant session revocation, and authentication-gated file delivery. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

8. Your Rights

Depending on your jurisdiction, you may have rights to access, correct, delete, restrict, or object to the processing of your personal data, to data portability, and to withdraw consent. Residents of certain U.S. states (e.g., California under the CCPA/ CPRA) have rights to know, delete, and correct personal information and to opt out of its sale or sharing — we do not sell or share personal information as those terms are defined.

Because much of the data in the Service is controlled by your organization, please direct rights requests to your organization first, or contact us using the details below and we will assist the relevant controller.

9. International Data Transfers

We and our service providers may process information in countries other than your own. Where we transfer personal data across borders, we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms required by applicable law.

10. Cookies & Similar Technologies

The Service uses strictly necessary cookies to authenticate sessions and enforce multi-factor verification. These are required for the Service to function and do not track you for advertising.

11. Children’s Privacy

The Service is intended for use by authorized professional users and is not directed to children. We do not knowingly collect personal information from children.

12. Changes to This Policy

We may update this Policy from time to time. Material changes will be indicated by updating the effective date above and, where appropriate, through in-product notice. Continued use of the Service after changes become effective constitutes acceptance.

13. Contact Us

For questions about this Policy or our privacy practices, contact [COMPANY LEGAL NAME] at [privacy@your-domain].