Privacy Policy
This policy describes how Incident Ledger handles account, organization, incident, evidence, billing, and operational records.
Data we process
Incident Ledger stores account details, organization settings, incident metadata, reporter-provided descriptions, witness and involved-person entries, photos, signatures, audit events, billing records, and transactional email delivery events.
Data minimization
The product is not designed to collect Social Security numbers, national IDs, passport numbers, insurance identifiers, bank details, detailed medical diagnoses, biometric authentication data, or criminal background information.
Customer control
Customers are responsible for configuring lawful reporting notices, consent language, retention settings, access roles, and employee communication for their jurisdiction and workplace.
Reporting limits
Incident Ledger is not an emergency service or legal advisory service. It helps keep workplace incident records organized for internal documentation.
Storage and access
Incident attachments are stored privately and accessed through short-lived authorization paths. Email notifications avoid full incident descriptions and require sign-in for sensitive details.
Deletion and export
Organizations may request exports and deletion workflows from the dashboard. Some activity records may be retained where appropriate for security, fraud prevention, or required recordkeeping.