Privacy Policy
Last updated 31st July, 2026
This policy explains what information TDARS collects from organisations, administrators, and users who access the TDARS Digital Archive System, how we use it, and the choices you have.
Information we collect
- Organisation profile: name, sector, deployment type, Hub configuration, and administrator contact details
- User identity: full name, email address, role, service ID, and biometric identifiers (where enabled for personnel matching)
- Documents and records: all files uploaded, scanned, or ingested into the archive — including metadata, OCR-extracted text, classification tags, and approval history
- Device and access data: IP address, browser fingerprint, session timestamps, and geolocation used to enforce access policies and detect anomalies
- Audit trail data: every action performed within the system, including views, edits, exports, approvals, and permission changes
How we use this information
- To verify user identity and enforce role-based access controls within each Hub
- To process, classify, and store documents using OCR, forgery detection, and automated indexing
- To link records to personnel profiles using name, service ID, and biometric matching
- To maintain complete audit trails for regulatory compliance and institutional accountability
- To monitor system health, scanner connectivity, and processing performance
- To communicate platform updates, security alerts, and policy changes to administrators
Data retention
Documents, personnel records, and audit logs are retained for as long as your organisation's Hub is active and for a minimum retention period afterward as required by applicable records management regulations. Audit trails are immutable and cannot be modified or deleted. Upon Hub decommissioning, all data is securely wiped following certified data destruction protocols, and a destruction certificate is issued to the organisation.
Your rights and choices
- Request a full export of your organisation's data in standard archival formats
- Request deletion of your Hub and all associated data, subject to mandatory retention periods
- Manage user access, roles, and permissions through your Hub administration panel
- Review and audit all system activity through the built-in audit log
- Appeal access decisions or escalate data concerns through the designated Data Protection Officer
Security
TDARS is built with security as a foundational requirement, not an add-on. All records are encrypted at rest using AES-256 and in transit using TLS 1.3. Each Hub operates in complete tenant isolation with no shared infrastructure. Role-based access is enforced through zero-trust boundaries — even system administrators cannot access records without dual-approver authorisation. Backup archives use physically disconnected encryption keys. The platform supports cloud, on-premise, and air-gapped deployments to meet your organisation's specific security posture.
Changes to this policy
If we make material changes to this policy, we will notify all Hub administrators via the platform notification system and email. Continued use of the platform after notification constitutes acceptance of the updated terms. Previous versions of this policy are archived and available upon request.
Contact us
Questions about this policy or data handling practices can be directed to privacy@tdars.com, or through your organisation's designated account manager.
Ready to go digital?
Replace paper files and scattered spreadsheets with a secure, searchable archive your whole organisation can trust.
Talk to our team