Privacy Policy
Notice describing how Cordial Systems collects, uses, discloses, retains, and protects information in connection with the website, platform, applications, support, and related services.
1. Scope
This Privacy Notice applies to personal information and operational information processed through the website, platform, account workflows, support channels, public lead forms, legal request forms, dashboards, modules, and related services.
This Notice does not replace any signed Business Associate Agreement, Data Processing Addendum, customer contract, or agency policy that applies to a specific customer relationship.
2. Roles and Responsibilities
For many platform records, Customer determines what information is entered, who may access it, how forms are configured, how long records are retained, and how exports are used. In those contexts, Customer is responsible for its own privacy notices, legal basis, policies, and user instructions.
Company processes information to provide, secure, support, maintain, bill, and improve the Services. Where applicable law treats Company as a processor or service provider, Company will process personal information according to Customer documented instructions and applicable contract terms.
3. Information We Collect
We may collect account information, contact information, organization information, role and permission information, authentication information, billing information, support communications, legal request communications, user preferences, and administrative settings.
We may process operational records submitted by users, including form responses, readiness checks, training records, incident reports, public education records, transfer risk assessments, notes, attachments, certificate files, photos, dashboards, exports, and audit-related metadata.
We may automatically collect technical information such as device type, browser type, IP address, approximate location derived from technical data, session information, log data, page activity, feature usage, error data, performance data, and security events.
4. Sensitive Information and PHI
The Services are not intended to process HIPAA-regulated protected health information unless a signed Business Associate Agreement or other written agreement expressly authorizes that use case.
Customer and users must not submit patient-identifying information unless authorized by contract and permitted by Customer policy. Customer is responsible for evaluating whether information is sensitive, regulated, confidential, or subject to retention, public-records, employment, or medical-record requirements.
5. Sources of Information
We may collect information directly from users, from Customer administrators, from other authorized users in the same organization, from public forms, from support interactions, from payment or procurement channels, from service providers, and from automated platform activity.
6. How We Use Information
We use information to provide and operate the Services; create and manage accounts; authenticate users; enforce permissions; process forms, reports, dashboards, certificates, notifications, and exports; provide support; implement customer configurations; process billing; respond to requests; maintain security; detect abuse; troubleshoot; improve performance; develop features; comply with law; and enforce agreements.
We may use aggregated, anonymized, or de-identified information for analytics, product improvement, operational benchmarking, security, and reporting, provided it does not identify an individual or customer except as permitted by law or contract.
7. Cookies, Local Storage, and Similar Technologies
We may use cookies, local storage, session storage, analytics tools, and similar technologies to maintain login sessions, remember preferences, support security, measure usage, improve navigation, and diagnose performance issues.
Browser settings may allow users to limit cookies or storage, but doing so may affect login, preferences, security controls, and platform functionality.
8. Disclosures
We may disclose information to service providers and subprocessors that host, secure, monitor, maintain, analyze, support, deliver, bill, or improve the Services.
We may disclose information to Customer administrators and authorized users according to Customer configurations and permissions; to professional advisers; to comply with law, legal process, or government request; to protect rights, safety, security, and service integrity; in connection with business transfers; and with consent or direction.
We do not sell personal information in the ordinary commercial sense. We do not use Customer Data for third-party advertising.
9. Customer Administrator Access
Customer administrators may be able to view, export, edit, deactivate, or manage records, users, permissions, reports, certificates, attachments, and module data within their organization.
Users should contact their organization first for questions about agency-specific records, corrections, access restrictions, exports, and internal use of information.
10. Data Retention
We retain information for as long as reasonably necessary to provide the Services, comply with contracts and law, maintain records, resolve disputes, enforce agreements, protect security, support audits, and continue business operations.
Customer may be able to export, deactivate, or delete certain records depending on role, module, and contract. Deleted or deactivated records may remain in backups, logs, audit records, or archival systems for a limited period where necessary for security, continuity, or legal purposes.
11. Security
We use administrative, technical, and organizational safeguards designed to protect information in a manner appropriate to the nature of the Services and the risk involved.
No security measure is perfect. Users and customers are responsible for protecting credentials, devices, local downloads, printed reports, screenshots, email attachments, and information moved outside the Services.
12. Privacy Rights
Depending on applicable law and the relationship involved, individuals may have rights to request access, correction, deletion, portability, limitation, objection, appeal, or opt-out of certain processing.
Because many records are controlled by Customer, we may direct requests to the applicable Customer or require Customer authorization before acting. We may verify identity, authority, residency, and request scope before responding.
13. Colorado and Other State Privacy Rights
Residents of Colorado and other states may have additional rights under state privacy laws. Where those laws apply, we will respond to verified requests as required and will provide appeal rights where required.
State privacy laws may not apply to all information processed through the Services, such as employment records, publicly available information, de-identified information, protected health information governed by HIPAA, or information processed on behalf of a customer under a statutory exemption.
14. Children
The Services are not directed to children under 13. We do not knowingly collect personal information from children under 13 through the Services.
15. International Use
The Services are operated primarily from the United States. If users access the Services from outside the United States, information may be processed in the United States and other jurisdictions where Company or providers operate.
16. Business Transfers
Information may be transferred or disclosed in connection with a merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or similar transaction, subject to applicable law and contractual restrictions.
17. Changes to This Notice
We may update this Privacy Notice from time to time. The updated version will identify the effective date. Continued use of the Services after the updated effective date constitutes acknowledgment of the updated Notice where permitted by law.
18. Contact
Privacy questions, rights requests, complaints, and appeal requests should be sent to support@cordialsystemlogistics.com, or submitted through the privacy or support contact channels made available by Cordial Systems, LLC. Requests should include enough information to identify the requester, organization, account, relevant records, and requested action.

