
Privacy Notice
Version: 29 September 2026 · Local pilot draft. This notice must be reviewed with the deploying organization before any operational use.
Who handles the information
Cybersecurity & Cloudware Solutions Inc. (CCSI) develops this pilot. The deploying organization must determine its operational role, authorized users, data sharing arrangements, and official privacy contact before launch.
Information collected
The pilot records access requests, account identity and contact details, identifier type and reference, optional rank and unit, password hashes, Authenticator enrollment metadata for privileged users, incident reports, locations, descriptions, status updates, and audit events. Mobile and email contact verification are not configured and remain unverified.
Optional device location
With your browser permission and confirmation that the incident is there, a submitted report can include latitude, longitude, estimated accuracy and capture time. Previously allowed location can be suggested automatically. You may remove it and enter an address manually. Report capture is separate from on-duty sharing. On-duty sharing refreshes only while the field page is open and enabled; mobile browser suspension can interrupt updates. Coordinates are retained with the incident and visible to authorized reviewers and the reporter. Choosing View location on map opens OpenStreetMap and sends the coordinates to that provider.
Purpose and access
Information is used to administer accounts, receive and coordinate pilot reports, and maintain an audit trail. Administrator access is restricted; normal users see reports linked to their account. Do not enter live police, emergency, medical, or other sensitive personal data into the local pilot.
Retention and rights
The pilot retains records in its Sentinel360Data folder until an authorized operator removes or migrates them. An approved retention schedule, request process, DPO contact, and legal basis must be set by the deploying organization before production. Requests for access, correction, or other applicable privacy rights should be directed through the organization's official privacy channel.
Media and police response
Optional photographs and videos are stored in the same database/media folder as the incident. Authorized reporters, assigned police and permitted Command Center staff can access them. Uploads are size- and type-limited; malware scanning, metadata removal and formal evidence retention are not implemented. Police availability is updated while the field page is connected; this is not continuous GPS tracking. Area fallback uses authorized jurisdiction. Optional proximity offers use on-duty phone coordinates shared through an explicit checkbox and browser permission. Dispatchers with responder-location permission can inspect current positions; community reporters cannot. Coordinates older than 90 seconds or accuracy worse than 200 m are excluded from radius matching. Stopping sharing or signing out clears current coordinates. No route history is stored.
Protection
The application uses account access controls, hashed passwords, Authenticator MFA for Administrator access, audit logging, and local-only network binding. These controls do not make the pilot suitable for live operations. See Privacy & Security by Design.
On-duty location controls
Location sharing is off by default. Verified responders may enable it while on duty and stop it at any time. The browser also requires location permission. Only dispatchers granted responder-location access can query precise current positions, with audited access. Station coordinates are not treated as officer locations. Proximity is straight-line distance and must be reviewed by the human dispatcher. Deployment must establish its location-sharing policy, access authorization, retention and privacy contacts before operational use.
