1. Scope and our role
This Privacy Policy applies to DutySuite websites, applications, portals, forms, and related services that link to it (collectively, the “Services”). It does not apply to a third party's independent website or service.
Public safety agencies and other DutySuite customers decide what information their authorized users enter into the Services and how their operational records are used. For that customer-controlled information, DutySuite generally acts as a service provider or processor on the customer's behalf. DutySuite acts on its own behalf for information used to operate the public website, respond to inquiries, secure the Services, manage customer relationships, and satisfy legal obligations.
2. Information we collect
The information collected depends on how you interact with DutySuite and which applications your organization enables. It may include:
- Contact and inquiry information, such as your name, work email address, telephone number, agency or organization, job title, demo interests, and messages.
- Account and identity information, such as your name, email address, telephone number, authentication records, agency membership, rank or title, roles, permissions, and multi-factor authentication status.
- Agency, employer, and operational records,such as agency settings, employer contacts, job requests, assignments, schedules, invoices, payment status, approvals, messages, acknowledgements, audit history, K-9 records, and other application-specific records.
- Content and files, including documents, images, attachments, message content, agreement records, and other material submitted by authorized users.
- Communications and delivery information,including support correspondence, transactional email content, recipient addresses, delivery status, and related message identifiers.
- Technical, usage, and security information,such as request and event timestamps, pages or features used, browser and device type, approximate location derived from network information, IP address or related network signals, referral source, session information, and security or audit events.
DutySuite is designed for administrative and operational workflows and is not represented as a criminal justice records management or evidence-management system. Users are instructed not to submit CJIS/CJI, Social Security numbers, criminal-history information, RMS/CAD report content, or subject or suspect details unless DutySuite and the customer have expressly approved an expanded scope with appropriate safeguards.
3. How we use information
We use information to:
- Provide, configure, maintain, and support the Services.
- Authenticate users and enforce agency, role, permission, portal, and application access controls.
- Process agency workflows, communications, requests, records, notifications, agreements, invoices, and reports.
- Respond to demo requests, questions, support needs, and customer communications.
- Monitor reliability, understand aggregate website and product usage, troubleshoot problems, and improve the Services.
- Detect, prevent, investigate, and respond to abuse, fraud, security incidents, unauthorized access, and violations of applicable agreements.
- Maintain operational, security, contract, and audit records and comply with legal obligations.
Where applicable law requires a legal basis, processing may be based on performance of a contract, legitimate interests in operating and securing the Services, compliance with legal obligations, or consent where requested.
4. How we disclose information
DutySuite may disclose information in the following circumstances:
- With the customer organization and its authorized administrators, users, employers, or other participants as directed by the customer and required by a configured workflow.
- With service providers that host, secure, support, or deliver the Services, subject to appropriate contractual or confidentiality obligations.
- For legal and safety reasons when required by law, legal process, or a valid government request, or when reasonably necessary to protect rights, safety, property, users, customers, or the Services.
- In a business transaction involving a merger, financing, acquisition, reorganization, or sale of assets, subject to applicable confidentiality and notice requirements.
- With your direction or consent or as otherwise described when information is collected.
DutySuite does not sell personal information and does not use customer operational data for targeted advertising.
5. Service providers and subprocessors
DutySuite currently relies on the providers below. The data each provider receives depends on the feature used and does not necessarily include every category listed in this policy.
| Provider | Purpose | Relevant information |
|---|---|---|
| Supabase | Authentication, database, and file storage | Account, customer, operational, security, and uploaded content data |
| Vercel | Application hosting, delivery, security, scheduled operations, and web analytics | Hosted application traffic, runtime and security logs, and aggregated website usage data |
| Resend | Transactional email delivery | Recipient addresses, message content, and delivery metadata |
| Cloudflare | Turnstile bot and abuse prevention | Browser, device, network, challenge, and security signals |
DutySuite does not currently use its public website to collect payment card numbers. If integrated payment processing is enabled, this policy and the provider list will be updated before that processing goes live.
6. Cookies, analytics, and security tools
DutySuite uses essential session and authentication technologies to keep users signed in, maintain account security, and provide requested functionality. Disabling essential browser storage or cookies may prevent parts of the Services from working.
Vercel Web Analytics provides aggregated measurements such as page views, referral sources, approximate geography, browser, operating system, and device type. DutySuite does not send names, email addresses, telephone numbers, or free-text form responses in its custom analytics events. Vercel states that its Web Analytics product does not use third-party cookies and does not associate analytics events with an individual or IP address.
Cloudflare Turnstile may evaluate browser, device, and network signals when displayed on login, registration, demo-request, or other abuse-sensitive forms. Its use is governed by Cloudflare's Privacy Policy, including the Turnstile privacy disclosures linked from that policy.
7. Data retention
DutySuite retains customer operational records while an account is active so the customer can administer its work and maintain an appropriate history. Retention and deletion periods may differ by customer, record category, contract, records schedule, legal hold, and applicable law. DutySuite does not assume one universal public-safety retention period.
Account closure and deletion requests require confirmation of scope, any required customer export, and whether a legal hold or other retention obligation applies. DutySuite may also retain limited contract, billing, security, audit, backup, or support records for legitimate operational and legal needs. When information is no longer required, it may be deleted, anonymized, or retained in an archive consistent with the applicable customer arrangement and law.
8. Security
DutySuite uses administrative, technical, and organizational safeguards intended to protect information. Current controls include authenticated access, agency and role-based access controls, server-side authorization checks, private storage for operational documents, encrypted network transport, audit and security events, input validation, and abuse protections for public workflows.
No system can guarantee absolute security. Customers and users are responsible for maintaining the confidentiality of account credentials, using available security features, and promptly reporting suspected unauthorized access. Additional information is available on the DutySuite Security and Data Handling page.
9. Your choices and privacy rights
You may update certain account or contact information through the Services or by contacting your organization's administrator. If your information was submitted through a public safety agency, employer portal, or other customer account, that organization generally controls the record and should be your first contact for access, correction, export, or deletion requests.
Depending on where you live, applicable law may provide rights to request access to, correction of, deletion of, or a copy of personal information, or to object to or restrict certain processing. DutySuite will respond to verified requests as required by applicable law and may refer customer-controlled requests to the relevant organization. We may need to verify your identity and authority before completing a request.
10. Children's privacy
The Services are intended for public safety agencies, authorized workforce users, employers, and professional contacts. They are not directed to children under 13, and DutySuite does not knowingly collect personal information directly from children under 13 through the public website. If you believe such information has been submitted, contact us so the circumstances can be reviewed.
11. Data location and transfers
DutySuite and its service providers may process information in the United States and other locations where they operate. Those locations may have data-protection laws different from the laws where you live. Where required, DutySuite uses contractual and other appropriate safeguards for applicable cross-border transfers.
12. Changes to this policy
DutySuite may update this policy as the Services, providers, or legal requirements change. The “last updated” date will be revised when changes are published. If a change materially affects how customer-controlled information is handled, additional notice may be provided through the Services, customer communications, or another appropriate method.
13. Contact us
For questions about this policy, DutySuite's privacy practices, or a privacy request, email info@dutysuite.com. Please do not include passwords, Social Security numbers, CJIS/CJI, or other sensitive operational information in an email request.