Privacy Policy
Last updated: September 17, 2026.
Template — review with counsel before launch. This document is a starting point that ships with the product. It is not legal advice and has not been reviewed by an attorney. Edit it in app/src/content/legal/privacy.ts and rebuild to publish changes.
1. Overview
This Privacy Policy explains how ReynCon Security ("ReynCon", "we", "us") handles personal information in connection with the Business Continuity Tabletop Exercises platform (the "Service"). It covers two kinds of people: facilitators and administrators who hold accounts, and participants who join an exercise with a short code.
2. Information we collect
- Account information. For facilitators and administrators: name, email address, organization, and authentication data needed to sign in.
- Participant information. For participants joining an exercise: the display name they enter and the role they select. Participants do not create standing accounts and receive only short-lived access to the exercise they join.
- Exercise content. The scenarios, decisions, observations, responses, and after-action reports created during an exercise. This content belongs to the organization running the exercise.
- Technical information. Standard log and device information generated when the Service is used, used to operate and secure the platform.
3. How we use information
We use information to provide and secure the Service: to authenticate users, run exercises, produce after-action reports, isolate each organization's data, and prevent abuse. We do not sell personal information.
4. How information is shared
Information within an organization's workspace is available to that organization's authorized users. A facilitator holds context that the room does not; participant-facing views deliberately show only what a participant's role should see. We share information with service providers who help us operate the platform, and where required by law.
5. Data isolation
The Service is multi-tenant. Each organization's data is isolated at the data layer, and access is scoped to the organization that owns it. Enterprise customers may be offered a dedicated database.
6. Retention
We retain account and exercise information for as long as an organization maintains its workspace, and as needed to comply with legal obligations. An organization can request deletion of its workspace data.
7. Your choices
Depending on where you live, you may have rights to access, correct, or delete personal information about you. Requests can be made through the organization that runs your exercises, or by contacting us directly.
8. Security
We use technical and organizational measures designed to protect information, including tenant isolation, encrypted transport, and least-privilege access. No system is perfectly secure, and we cannot guarantee absolute security.
9. Changes
We may update this Policy from time to time. Material changes will be reflected by the "last updated" date above.
10. Contact
Privacy questions can be sent to ReynCon Security at privacy@reynconsecurity.com.
