Privacy and data controls
Updated 12 September 2026. This notice covers the OTS Web application and OTS Mobile.
What OTS processes
- Account and operation data: account and workspace identity, roles, assignments, contacts, objectives, phases, messages, notes, Assistant prompts and replies, operational logs, documents, acknowledgements, check-ins, and closeout records.
- Emergency profiles and identity documents: where supplied for an authorized operation, passport or travel-document details and scans, date of birth, emergency contacts, insurance details, blood type, allergies, and medical notes. These may be available in authorized workspace and operation profile or emergency workflows. Provide only information needed for the agreed purpose; do not use these fields as a general medical record.
- Device and delivery data: app and operating-system version, installation/session identifiers, Firebase Cloud Messaging registration tokens, permission state, network availability, battery or connection telemetry, and security or crash diagnostics needed to operate and protect the service.
- Location: current or background location, accuracy, time, and related tracking state when the required Android permissions are granted and authorized operation tracking is enabled. OTS Mobile shows the required persistent foreground-service notification while active background tracking runs.
- Camera and microphone: live-stream signals, recorded segments, recording metadata, and microphone or camera input only when the relevant feature is enabled and Android grants access.
- Local-network report: with the user's scan-specific consent, Android's active Wi-Fi metadata, such as network name where Android permits it, a protected network fingerprint, device and gateway addresses, DNS, signal and link information, and labels voluntarily advertised by devices through mDNS or SSDP. The feature does not read passwords or traffic, sweep address ranges or ports, attempt logins, or test exploits.
- Trust and moderation: report reason and comment, the referenced account or content identifier, integrity digests and limited technical evidence, communication blocks, report status, and immutable moderator actions. OTS avoids copying reported plaintext into a second moderation store where the authoritative record can remain the source.
- Platform administration: specifically authorized, TOTP-protected Irtaf3 Systems Administrators may access a bounded global overview needed to operate OTS, including package and operation status, operative role and assignment summaries, map-region activity, Professional OverWatch review queues, billing-attention state, aggregate usage, and service health. The OTS Mobile Administrator view is read-only, does not duplicate operative email or phone details, uses a short-lived memory-only session, does not join an operation or register for operational push notifications, and records only fixed security-event labels for access auditing.
Why it is processed
Data is used to authenticate users; enforce workspace, role, and Operation boundaries; provide coordination, safety check-ins, tracking, Team Chat, OTS Assistant, recorded Operator camera streams, Op Cloud, notifications, support, abuse prevention, moderation, and auditable closeouts; and meet contractual or legal duties. OTS does not sell personal information and does not use operation data for behavioral advertising.
Service providers and external requests
OTS sends only the fields needed for an enabled feature to configured processors. These may include hosting and private object storage, Firebase Cloud Messaging for push delivery, map or geocoding providers for requested map functions, an AI provider for OTS Assistant prompts and the minimum operation context needed for the reply, speech processing for requested transcription, transactional email, support, security monitoring, and payment providers for Web purchases. A provider may receive technical request data such as an IP address as part of the connection. Current provider categories are also described in the Subprocessors and External Providers notice.
Control and transparency
- Android permission prompts remain under the device user's control. An authorized Overwatch may issue an operation tracking command only after the device has the required permissions; active background tracking remains visible through Android's persistent foreground-service notification and can be stopped from OTS Mobile or the device controls.
- Camera and microphone access are requested before an Operator starts a stream. Recorded segments may be uploaded to the operation's Op Cloud and made available to assigned operation participants.
- The local-network report asks for scan-specific consent when Scan Network is selected. Denying it leaves other OTS Mobile functions available.
- Users can report supported user content or accounts and can block ordinary user-to-user Team Chat and camera communication within an Operation. Blocks do not suppress Emergency safety events, system or legal notices, safety-critical tracking controls, or required operational broadcasts.
- Provider-derived public posts are leads for human review, not verified facts. OTS stores only operationally necessary metadata and does not permanently copy provider videos.
- Workspace administrators manage assignments and authorized operational access. Retention and erasure follow the applicable reviewed policy and legal-hold decisions; an account-deletion request does not automatically erase every shared operational record or provider copy. Cross-package and cross-operation access is denied by the application.
- Platform Administrator access is limited to authorized service administration and oversight. Mobile exposes no create, edit, approve, assign, delete, payment, or configuration control; those controlled actions remain in protected OTS Web workflows.
Retention and deletion
Account data is retained while the service is active and for the period needed to deliver support, protect the service, satisfy contractual or legal obligations, and preserve authorized operation records. Installation sessions and invalid push tokens are expired or removed when they are no longer usable. Communication blocks can be revoked; moderation reports, minimized evidence, legal acceptances, and moderator actions may be retained to investigate abuse and demonstrate decisions. Signed-in users can submit a reviewed access, export, correction, or processing-restriction request. You may separately submit an account deletion request. Irtaf3 Systems verifies identity, removes or anonymizes data that is eligible for deletion, and confirms completion. Records subject to an operation, contractual, fraud-prevention, safety, abuse-prevention, or legal hold may be retained for the required period.
Contact
Privacy, access, correction, and deletion questions: systems@irtaf3.org.