Purpose
LEAF-C handles information that is often confidential, legally sensitive, or entrusted to us under professional duty. This policy sets the standards our people and systems follow when collecting, storing, using, and disposing of that information.
It should be read with our Privacy Policy, which explains what we collect from website visitors and account holders.
Scope
This policy covers:
- Public website inquiries and follow-up correspondence.
- Client, organisation, and staff accounts in the workspace.
- Case files, notes, assignments, and training records.
- Materials received for consultancy, investigations, polygraph examinations, and related reporting.
Principles
- Collect only what is needed for the stated engagement.
- Use information only for that purpose, or a compatible legal duty.
- Limit access to authorised personnel on a need-to-know basis.
- Keep records accurate and update them when we are told they have changed.
- Retain information no longer than the engagement and applicable duties require.
- Protect information in transit and at rest with appropriate controls.
Roles and access
Administrators manage accounts, assignments, and platform settings. Senior agents and agents see the cases and records assigned to them. Customers see their own inquiries and account details. Staff invite codes are required to create member accounts.
Passwords are stored as irreversible hashes. Session tokens are held in the signed-in browser and are cleared on sign-out.
Safeguards
- Encrypted connections to the public site and the workspace.
- Encrypted document handling for engagement materials, as described to clients at intake.
- Role-based access to cases, notes, and training records.
- Audit-oriented case notes and assignment history for accountability.
- Hosted infrastructure (site, database, and email) operated under our configuration and access policies.
No control eliminates all risk. We design for confidentiality appropriate to investigative and integrity work, and we review access when roles or engagements change.
Special-category and examination data
Polygraph and integrity-testing work may involve sensitive personal data. Examinations are conducted under chain-of-custody and confidentiality protocols. Results and related notes are available only to authorised examiners and designated engagement staff, and are retained as required for legal admissibility or client instruction.
Processors
We use third-party processors for website hosting, database hosting, and email delivery. Those processors act on our instructions and must not use LEAF-C data for their own purposes. Inquiry notices and receipts are sent from info@leafc.net.
Retention and disposal
Working files are kept for the life of the engagement and for any period required by law, contract, or professional standards. When that period ends, we delete or irreversibly anonymise the record, or return it to the client if that was agreed.
Incidents
If we become aware of unauthorised access, loss, or disclosure of personal or engagement data, we will contain the incident, assess the risk, and notify affected clients and, where required, competent authorities without undue delay.
Requests and complaints
Data-subject and client requests — including access, correction, and deletion — should be sent to info@leafc.net. We may need to verify identity before releasing or changing a record. If you are not satisfied with our response, you may raise the matter with the supervisory authority that applies to you.
Updates
This policy is reviewed as our systems, processors, or legal duties change. The effective date at the top of the page shows the current version.