Legal · Cordial Systems

Data Use and Ownership

Effective September 26, 2026 · Last updated September 26, 2026

Who owns the records created in the CORDIALSYSTEMS platform, what Cordial Systems is permitted to do with them, what cannot be deleted, and how this policy sits alongside the Terms of Use, the Privacy Policy and any signed agreement.

  • Effective Date: September 26, 2026
  • Last Updated: September 26, 2026
  • Company: Cordial Systems, LLC
  • Website: cordialsystemlogistics.com
  • Platform: CORDIALSYSTEMS Platform
  • Contact: support@cordialsystemlogistics.com

1. Purpose and Scope

This policy explains who owns, controls, and may use the information created, collected, or processed through the CORDIALSYSTEMS platform, the website, the mobile applications, and related services (together, the "Services").

It applies to every record entered, uploaded, generated, or transmitted through the Services, and to every agency and user that accesses them. It works alongside the Terms of Use and the Privacy Policy. Where this policy and the Privacy Policy both address the handling of personal information, the Privacy Policy governs the detail.

2. Definitions

"Customer Data" means information a customer agency or its users provide to Cordial Systems or generate through use of the Services, including personnel records, readiness checks, incident reports, risk assessments, schedules, training records, uploaded files, and configured forms and templates.

"The Services" means the software itself, including source code, workflows, scoring logic, templates, reports, dashboards, designs, interfaces, documentation, and branding.

"Aggregated Information" means information that has been combined, summarized, or de-identified so that it does not identify a customer agency or an individual.

3. The Agency Owns Its Records

Customer owns Customer Data. Customer grants Company the rights necessary to host, process, transmit, store, secure, analyze, back up, display, and support Customer Data to provide the Services and comply with law.

Customer is responsible for the legality, accuracy, completeness, and appropriateness of Customer Data and for maintaining independent records where required.

4. Cordial Systems Owns the Platform

Company owns all right, title, and interest in the Services, including software, source code, object code, workflows, scoring logic, templates, reports, designs, interfaces, documentation, branding, trademarks, trade secrets, and derivative works.

Customer retains ownership of Customer Data and Customer-owned marks, files, policies, and materials. Customer grants Company a license to use Customer Data and customer-provided materials as needed to provide and support the Services.

No rights are transferred except as expressly stated in these Terms or a signed agreement.

5. The Licence the Agency Grants, and Its Limits

Customer is responsible for the accuracy, completeness, legality, quality, and appropriateness of Customer Data. Company does not independently verify Customer Data, submitted form responses, uploaded files, agency-specific templates, or administrative settings.

Customer grants Company the right to host, process, transmit, store, display, back up, analyze, secure, support, and otherwise use Customer Data as necessary to provide, maintain, protect, troubleshoot, and improve the Services and to comply with law.

Customer is responsible for maintaining independent copies of information that Customer is required to preserve by law, regulation, contract, agency policy, retention schedule, or litigation hold.

6. No Protected Health Information

The Services are a no-PHI-by-design platform. They are not intended to receive, store, transmit, or process HIPAA-regulated protected health information or patient identifiers unless Company has entered into a written Business Associate Agreement or other signed agreement expressly authorizing that use case.

By using the Services, Customer and its users agree not to enter protected health information or patient identifiers into any field, form, note, narrative, comment, supplement, or attachment. This includes, unless separately authorized in writing, patient names, full dates of birth, Social Security numbers, medical record numbers, patient care report numbers, patient phone numbers, patient email or precise patient addresses, insurance or policy numbers, driver’s license numbers, photographs that identify patients, or other information reasonably capable of identifying an individual patient.

To reference a specific transport, use the trip number together with non-identifying operational data (such as unit, crew, times, facilities, and risk factors) rather than patient-identifying information.

Cordial applies automated safeguards to support this policy, including blocking custom form fields that request patient identifiers and reminding users not to enter identifiers into free-text fields. These safeguards are aids only; Customer remains solely responsible for the content it submits and for determining whether information submitted to the Services is regulated by HIPAA, state privacy law, employment law, public records law, agency policy, contract, or other requirements.

7. Feedback and Aggregated Information

If Customer or users provide feedback, ideas, requests, suggestions, or recommendations, Company may use them without restriction, payment, attribution, or obligation.

Company may use aggregated, anonymized, or de-identified information to understand usage, improve the Services, develop new features, maintain security, and produce operational insights, provided the information does not identify Customer or individuals except as permitted by law or contract.

8. What the Platform Is For

The Services are operational software tools for EMS agencies, ambulance services, public safety organizations, and related entities. The Services may support risk assessment, readiness checks, training documentation, incident reporting, public education tracking, supply order tracking, medication readiness, dashboards, and administrative oversight.

The Services are not a replacement for clinical judgment, medical direction, dispatch protocol, legal advice, regulatory advice, or agency policy. Customer remains responsible for all transport, staffing, clinical, operational, legal, billing, employment, disciplinary, and administrative decisions.

Scores, alerts, dashboards, recommendations, maps, time estimates, reports, and summaries are informational aids only. Customer must independently evaluate all outputs before relying on them.

9. Administrator Access Within an Agency

Customer administrators may be able to view, export, edit, deactivate, or manage records, users, permissions, reports, certificates, attachments, and module data within their organization.

Users should contact their organization first for questions about agency-specific records, corrections, access restrictions, exports, and internal use of information.

10. Retention, Export, and Deletion

We retain information for as long as reasonably necessary to provide the Services, comply with contracts and law, maintain records, resolve disputes, enforce agreements, protect security, support audits, and continue business operations.

Customer may be able to export, deactivate, or delete certain records depending on role, module, and contract. Deleted or deactivated records may remain in backups, logs, audit records, or archival systems for a limited period where necessary for security, continuity, or legal purposes.

11. Records That Cannot Be Deleted

Controlled substance records cannot be deleted or edited by anyone, including Cordial Systems. Federal recordkeeping rules require a complete, unalterable chain of custody for Schedule II-V medications, and the database enforces that: administrations, wastes, counts, seal events and the ledger are append-only, and no administrator, no support engineer and no service account can remove an entry. The same is true of signed quality reviews and the audit trail.

Operational records filed on behalf of an agency remain the agency’s records. A readiness check, an incident report, a transfer risk assessment or a work order documents what the agency did on a date, and it belongs to the agency rather than to the person who typed it.

A person asking to have their own account and personal data removed should follow the steps published at app.cordialsystemlogistics.com/legal/delete-my-data.

12. Conflicts and Precedence

If this policy conflicts with a written agreement signed with Cordial Systems, the signed agreement controls for that subject. If it conflicts with the Privacy Policy regarding the handling of personal information, the Privacy Policy controls. Nothing in this policy replaces a signed Business Associate Agreement or an agency’s own retention schedule, public records obligations, or litigation holds.

13. Changes to This Policy

Cordial Systems may update this policy to reflect changes in practice, technology, or law. Material changes are reflected in the "Last Updated" date above and, where appropriate, notified through the Services.

14. Contact

Questions about data ownership, export requests, and deletion requests should be sent to support@cordialsystemlogistics.com. Requests should include enough information to identify the requester, organization, account, relevant records, and requested action.

The full legal library Master Business Agreement, Mutual Nondisclosure Agreement, HIPAA Business Associate Addendum, Security Overview and account deletion instructions are published at app.cordialsystemlogistics.com/legal, where every document can also be downloaded as PDF or Word. Questions about this document go to support@cordialsystemlogistics.com.