Legal

Privacy Policy

Version 2.1 · Effective June, 2026

1. Introduction

Actum Sonne LLC ("Actum", "we", "us") provides Actum Track, a workforce management platform for private security companies. This Privacy Policy explains how we collect, use, share, and retain information when our software (the "Service") is used.

Important context on who we serve: Actum Track is a business-to-business (B2B) software platform. Our customers are private security companies ("Customers"). Our Customers' employees, contractors, dispatchers, supervisors, and other workforce members ("Workforce Members") use the Service in the course of their work.

This Privacy Policy applies to:

  • Information we collect from Workforce Members using the Actum Track mobile and web applications.
  • Information our Customers provide to us about their Workforce Members.

Important roles under data protection law:

  • Our Customer (the security company) is the "data controller" or "business" for the personal information of its Workforce Members.
  • Actum is the "data processor" or "service provider" that processes that information on the Customer's behalf under a written services agreement.
  • This means Workforce Members should direct privacy requests (access, correction, deletion subject to legal limits) to their employer, not directly to Actum. Actum will assist Customers in responding to such requests as their agreement requires.

2. Information we collect

We collect the following categories of personal information from Workforce Members in the course of their work and from Customers when configuring the Service:

2.1 Account and identity information

  • Name, email address, phone number
  • Profile photo
  • Employee identifier, guard card number (where applicable by Customer), role/position
  • Hire date, employment status
  • Compensation parameters (hourly rate, salary band) — for shift reporting and time tracking only; not transmitted to third parties
  • Emergency contact information
  • Postal address (where the Customer collects it)
  • Uploaded credential documents (security guard card, firearm permit, first-aid certificate, driver's license, training certificates, contracts)

2.2 Authentication credentials

  • Hashed password (stored using industry-standard one-way hashing — bcrypt)
  • Authentication session tokens
  • Push notification device token (provided by Firebase Cloud Messaging)

2.3 Precise location

  • Latitude and longitude with associated accuracy, heading, and speed
  • Collected only while a Workforce Member is clocked in to an active shift (between Clock In and Clock Out events)
  • Captured on discrete events only — there is no continuous background location tracking. A location point is recorded at: Clock In and Clock Out, geofence perimeter crossings (entering or leaving the post), checkpoint scans, report and incident submissions, SOS, and when a dispatcher requests a one-time location update
  • Used to verify Clock In and Clock Out within the Customer's designated geofence, to display the Workforce Member's location on the Customer's live monitoring dashboard, and to provide audit history of patrol routes
  • Not collected outside of active shifts. When clocked out, the Service does not request or use location.

2.4 Photos, videos, and audio recordings

  • Photos and videos captured by the Workforce Member as part of incident reports, hourly status reports, checkpoint scans, and vehicle violation entries
  • Voice messages recorded by Workforce Members within the in-app messaging feature
  • Photos may be timestamped and watermarked with the Workforce Member's name and the location at capture, for chain-of-evidence purposes

2.5 Scanned data

  • Contents of QR codes and barcodes scanned at checkpoints, used to verify a Workforce Member's presence at a designated location
  • Optical character recognition (OCR) results of license plate images submitted as part of vehicle violation reports

2.6 Communication content

  • Text and media messages exchanged within the in-app messaging feature between Workforce Members and their dispatchers, supervisors, or other authorized recipients
  • Read/unread state, timestamps, and attachment references

2.7 Activity and operational data

  • Shift events (Clock In, Clock Out, breaks, incidents, scans, reports)
  • Patrol completion data
  • Vehicle violation entries
  • Diagnostic information (locally retained crash and error logs; the most recent eighty entries only; not transmitted to Actum or any third party)

2.8 Device information

  • Device platform (iOS or Android)
  • Push notification token issued by Firebase Cloud Messaging

2.9 Information we do not collect

The Service does not collect:

  • Biometric data (no fingerprint or Face ID is used for authentication)
  • Health or medical records (incident reports may textually describe medical emergencies the Workforce Member responded to, but no structured health data is captured)
  • Government-issued identification numbers beyond the Customer's internal guard card number where applicable
  • Financial account numbers, banking information, or payment card data
  • Information from third-party analytics, advertising, or marketing platforms

3. How we use information

We use information solely to:

  • Authenticate Workforce Members and authorize access to the Service
  • Operate the core functions of the Service (shift management, location verification, incident reporting, scanning, messaging, alerts)
  • Validate that Workforce Members are at their assigned post (geofence verification at Clock In and Clock Out)
  • Provide our Customers with the operational visibility they require (live dashboards, shift history, incident records)
  • Generate audit records that our Customers may be legally required to maintain under private security industry regulations
  • Deliver push notifications about shifts, breaks, and operational events
  • Diagnose and resolve technical issues
  • Comply with our legal obligations and respond to lawful requests
  • Enforce our Terms of Service

We do not use personal information for advertising, marketing to Workforce Members, or any purpose unrelated to the Service.

4. How we share information

We share personal information only as described below:

4.1 With our Customer (the employing security company)

The security company that employs or contracts the Workforce Member has full access to that Workforce Member's information generated through the Service. This is the foundational purpose of the Service.

4.2 With service providers (subprocessors)

We share limited information with the following subprocessors that help us operate the Service:

SubprocessorPurposeCategories of data
DigitalOcean, LLCManaged PostgreSQL database hostingAll operational data
Cloudflare, Inc.R2 object storage for filesMedia files (photos, video, audio)
Google LLC (Firebase)Push notification deliveryPush token, notification payload
Plate Recognizer (ParkPow, Inc.)License plate OCR for vehicle violation entriesLicense plate photo and recognized text
Resend, Inc.Transactional email deliveryEmail address, message content
Anthropic, PBCAI-assisted incident analysis and report draftingIncident text and photos submitted for analysis
Apple Inc. and Google LLCApp distribution (App Store / Google Play)App identifier, device platform

Each subprocessor processes information only on our written instructions and is contractually required to maintain appropriate security and confidentiality.

4.3 With third parties when legally required

We may disclose information when required by law, court order, subpoena, or to protect the safety, rights, or property of Actum, our Customers, Workforce Members, or the public.

4.4 In connection with business transactions

If Actum is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction. Successors will be required to honor this Privacy Policy.

4.5 We do not

  • Sell personal information
  • Share personal information for cross-context behavioral advertising
  • Engage data brokers
  • Use personal information for profiling outside of the operational purposes of the Service

5. How we store and protect information

5.1 Storage location

  • Database: PostgreSQL hosted on DigitalOcean Managed Databases (United States region)
  • File storage: Cloudflare R2 object storage (global edge)
  • Backups: Encrypted nightly snapshots managed by DigitalOcean plus archival exports to a private Cloudflare R2 bucket

5.2 Security measures

  • Encryption in transit: All connections between the Service's apps and our servers, and between our servers and our infrastructure providers, use HTTPS / TLS.
  • Credential protection: Authentication tokens are stored on the device using the operating system's secure storage (iOS Keychain / Android Keystore). Passwords are stored on the server using bcrypt hashing — never in plaintext.
  • Database security: Database connections use TLS. Production credentials are scoped to backend services and are not exposed in client applications.
  • Access controls: Access to production systems is restricted to a limited set of authorized Actum personnel. Privileged actions are logged for audit.
  • File storage: Media files (photos, videos, audio) are stored on Cloudflare R2 infrastructure and served through Cloudflare's content delivery network. References to those files are shared only within authenticated areas of the Service. Data exports and backups are stored in a private bucket accessible only by authenticated backend services.
  • Operational visibility for Customers: Because the Service is a workforce management platform for our Customers, Customers have the operational visibility required to audit and review the activity of their Workforce Members. This includes the ability to view shift data, incident reports, scans, and in-app communications generated by their Workforce Members.

6. How long we retain information

We retain personal information for the periods set out below, or for any longer period required by law or by our Customer's regulatory obligations.

CategoryRetention
Account information (name, role, identifiers)While active, plus five (5) years after deactivation
Authentication session tokensUntil logout, password change, or session expiry
Live-map location pings (transient)Seven (7) days, then deleted from active systems
Location recorded with a shift event, report, or incidentRetained with that record (five (5) years)
Shift events, incident reports, photos, videos, audioFive (5) years from contract termination or as required by regulation
Communication content (messages)Five (5) years from contract termination
Vehicle violation recordsFive (5) years from creation
Local diagnostic logs (device only)Most recent eighty (80) entries
Audit logsUp to five (5) years

Why the five-year retention period: Private security industry regulations in many jurisdictions require security companies to maintain operational records — including patrol logs, incident reports, time records, and media evidence — for a multi-year period. The five-year retention period is implemented to support our Customers' compliance with those obligations.

Implications for Workforce Members: As workforce data of our Customers, Workforce Member records are not unilaterally deletable on Workforce Member request. Workforce Members seeking access to, or correction of, their information should contact their employer.

7. Workforce Member rights

Subject to applicable law and the legal obligations of our Customers as data controllers:

  • You may access the information held about you through your account in the Service (most categories are visible directly within the app).
  • You may correct information that is inaccurate by contacting your employer; your employer may update the record on your behalf through the Service.
  • Deletion requests for shift events, incident records, communications, and media should be directed to your employer, who may grant or deny the request based on their legal retention obligations.
  • You may withdraw consent to location collection by clocking out; the Service will then immediately cease location collection. You may also revoke location and notification permissions in your device settings at any time, which may limit your ability to use the Service.

If you reside in California, the EU, the UK, or another jurisdiction with applicable privacy law, additional rights may apply. Please contact your employer first; if your employer's response does not resolve the matter, you may contact us at the address in Section 11.

8. Customer rights

Our Customers, as data controllers, may exercise the following rights with respect to the data of their Workforce Members through their account management with Actum:

  • Export of all data associated with their account, in machine-readable format
  • Bulk correction of records
  • Deletion of records subject to retention obligations (records that fall within active legal retention periods will be retained even after the Customer relationship ends)
  • Configuration of geofence radius, hourly report cadence, break policies, and other operational parameters

9. International data transfers

Our servers are located in the United States. If you access the Service from outside the United States, your information will be transferred to, stored in, and processed in the United States. By using the Service, you acknowledge such transfer.

10. Children

The Service is intended for use by adults employed or contracted as security workforce. It is not directed to children under the age of sixteen (16), and we do not knowingly collect information from children.

11. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top. Material changes will be communicated through the Service or by email to administrators of our Customer accounts. Continued use of the Service after the effective date of an update constitutes acceptance of the updated policy.

12. Contact

For privacy questions, please first contact your employer if you are a Workforce Member. For other inquiries, including those from Customers and administrators:

Actum Sonne LLC

Email: privacy@actumtrack.com

If you are not satisfied with our response, you may have the right to lodge a complaint with your local data protection authority.

This Privacy Policy is intended to comply with the California Consumer Privacy Act (CCPA / CPRA), Apple App Store Review Guideline 5.1, Google Play Data Safety requirements, and general principles of the EU General Data Protection Regulation (GDPR) where applicable. It does not constitute legal advice; Customers are encouraged to obtain independent legal review.