Privacy notice
Version 0.1-draft · Last updated [To be confirmed by the data controller: date]
1. Who is responsible for your information
Amebo is an incident reporting and investigation system operated by [To be confirmed by the data controller: organisation name], [To be confirmed by the data controller: registered address]. That organisation is responsible for (the "controller" of) the information recorded in Amebo.
Privacy contact: [To be confirmed by the data controller: privacy contact email]. Data protection officer: [To be confirmed by the data controller: data protection officer, or a statement that one is not appointed].
2. What information we collect
When you report an incident
- About the incident: title, type and severity, date and time, site or off-site address, exact location, vehicle registration, activity and conditions at the time, a description, what led up to it, the equipment involved and what has already been done.
- About you as reporter: if you are signed in, the report is linked to your account. If you report without signing in, your name, email address and phone number are optional; if you leave them blank the report does not identify you (but see "Anonymous reports" below).
- About other people: names or descriptions, contact details, age, whether they are under 18 or an adult at risk, how they were involved, any injury or harm, emergency contacts, witness statements, and who you told about the incident.
- Supporting files: documents or photos you upload (PDF, JPG, PNG, TXT or DOCX, up to 10 MB each and 20 per report). Photos can contain faces and location data.
- Specialist sections, only if they apply: injury and treatment details; food products involved; safeguarding concerns; personal-data breach details; and agencies you have already contacted.
When staff handle a report
Staff record assignment, investigation findings, corrective actions, decisions about reporting to outside agencies, review and closure notes, and a history of status and routing changes with who made them and when.
If you have an account
- Full name, email address, your role (for example employee or volunteer) and optional job title.
- Your password, stored only as a one-way cryptographic hash, and security data such as failed sign-in attempts and temporary lock-outs.
- The permissions (roles) an administrator has given you, and whether your account is active.
Anonymous reports
Amebo does not store your IP address or device details with a report. However, the servers hosting Amebo may keep technical logs: [To be confirmed by the data controller: hosting provider, location of servers and whether/for how long web server logs including IP addresses are kept]. Anything you type into the report itself (for example your name in the description) will be stored.
3. Why we use it
- To record incidents, route each report to the staff responsible for its categories, and investigate it.
- To take action to keep people safe and prevent a recurrence.
- To decide whether an incident must be reported to an outside body, and to make those reports.
- To send workflow emails — for example telling an investigator a report has been assigned, or telling the reporter (if they gave an email address) that it has been closed and its outcome.
- To produce statistics for authorised managers (counts by category, severity, site and month).
- To manage user accounts and keep the system secure.
Legal basis for using this information: [To be confirmed by the data controller: the lawful basis (and any relevant legal obligations) for each purpose above]
4. Injury, safeguarding and other sensitive information
Reports can include health information (injuries, illness, treatment), information about children and adults at risk, safeguarding concerns and allegations, and personal-data breaches. In Amebo:
- A reporter can only see reports they made themselves. They do not see internal investigation notes.
- Reports with a safeguarding or data-breach section, or a restricted classification, are only routed to staff who have specifically been authorised to handle sensitive reports, or who are directly assigned to that report.
- Everyone else, including other staff, cannot open, search for, download attachments from or count these reports.
Condition for using sensitive information: [To be confirmed by the data controller: the condition relied on for health, safeguarding and other special category or criminal-offence information]
5. Who can see it and who we share it with
- Case managers see submitted reports in the categories they are responsible for. Reports in categories with no assigned case manager go only to designated triage staff.
- Investigators see only the reports assigned to them.
- Administrators can see all reports and manage accounts and routing.
- Email: notification emails are sent through Microsoft 365 (Microsoft Graph), which processes them on our behalf.
- Outside organisations: where staff decide it is required, information may be reported to bodies such as the police, emergency services, environmental health, the Food Standards Agency, the Health and Safety Executive, the Information Commissioner's Office, the Charity Commission, local authority safeguarding teams, insurers, landlords, suppliers or distribution partners. [To be confirmed by the data controller: confirmation of which of these apply and any other recipients or processors (e.g. hosting provider)]
6. How long we keep it
Amebo does not currently delete reports, attachments or accounts automatically. Staff can record a "retention review date" when closing a report, and administrators can deactivate accounts. Our retention periods are: [To be confirmed by the data controller: retention periods for reports (including safeguarding, injury and data-breach records), attachments, accounts, audit history and email logs, and how deletion is carried out]
7. Your rights and how to contact us
Depending on the law that applies, you may have rights to ask for a copy of your information, to have it corrected or deleted, to restrict or object to its use, and to complain to a regulator. To make a request, contact [To be confirmed by the data controller: privacy contact email]. If you reported anonymously, quote your reference number so we can find the report; we may need to confirm your identity before releasing information.
If you are unhappy with how we have handled your information you can complain to [To be confirmed by the data controller: the relevant supervisory authority and its contact details].
8. Cookies and sign-in
Amebo uses only cookies it needs to work. It does not use advertising or analytics cookies.
| Name | Purpose | Duration |
|---|---|---|
.AspNetCore.Identity.Application | Keeps you signed in. | Up to 8 hours of inactivity; ends when you sign out (kept across browser restarts only if you tick "Remember me"). |
.AspNetCore.Antiforgery.* | Protects forms against cross-site request forgery. | Until the browser is closed. |
.AspNetCore.Mvc.CookieTempData | Carries one-off messages between pages, such as your reference number after submitting. | Deleted once read. |
amebo-sidebar-* (browser storage, not a cookie) | Remembers whether you collapsed a menu section. | Until you clear your browser data. |
You can sign in with an email address and password. You don't need an account to report an incident.
9. Security
Passwords are stored as hashes, accounts are locked temporarily after repeated failed sign-ins, and uploaded files are stored outside the public website and can only be downloaded by people allowed to see the report. Deactivated accounts cannot sign in.
10. Changes to this notice
We will update the version and date at the top of this page when the notice changes.