Organization Data Processing
2026-10-11.2 · 2026-10-11
This schedule covers the free workspace accepted by its authorized owner. The organization determines purposes for its member, role, site, plan and task records. PBS processes those records to provide the workspace; its own account/security processing remains separately governed by the Privacy Notice. Do not enter health, biometric, child or personal movement data.
The processing consists of storage, authorized retrieval, updates, role checks, member invitations, activity logging, export and deletion during workspace use. Sites/plans/tasks/membership records remain until deletion; audit records expire after 90 days; invitations expire after 24 hours; restricted backups expire after seven days. HTTPS uses Cloudflare; storage is on PBS-administered infrastructure. Device-notification providers apply only to separately consented notifications. No research pipeline is included.
PBS uses authenticated access, role and tenant checks, encrypted private messages/tokens, restricted host credentials and logged operator case access. Each party protects credentials and supplies lawful instructions. Workspace deletion removes its current records; restored backups reapply deletion records. An authorized owner can export site records. Incident and rights requests go through info@pragmaticsolutions.app and are handled under applicable requirements without exposing other organizations.
A separate signed commercial processing agreement must identify any changed categories, features, processors, countries, retention, transfers and support commitments. This schedule does not itself declare international-transfer adequacy or regulatory certification.
Workspace drill campaigns and voluntary responses are included only within authorized membership and configured role access. Account-associated communications and resources retain their separate feature permissions. PBS processes workspace information on documented, lawful instructions, assists with applicable rights and security duties, and reports legally notifiable incidents without undue delay as applicable law requires.
Subprocessors and international transfers must satisfy applicable contractual and legal requirements. PBS will not knowingly follow an unlawful processing instruction and will notify the organization where legally permitted. Reasonable compliance information and any agreed audit arrangements must protect other tenants and infrastructure security. A commercial DPA may specify additional binding security and audit commitments.