Privacy policy
Last updated 28 August 2026
This policy explains what personal information IMT Logic collects, why we collect it, how long we keep it and what you can ask us to do with it. It covers two different things, and the distinction matters throughout:
- This website — imtlogic.com, including the enquiry form.
- The platform — the incident management application at app.imtlogic.com, used by our customers' response teams.
1. Who we are
IMT Logic (Integrated Management Technology) provides incident management software and exercise delivery for organisations managing emergency response.
For information you send us through this website — an enquiry, a question, a request for a tabletop exercise — IMT Logic is the data controller: we decide what is collected and why.
For information recorded inside the platform by a customer's response team — incidents, actions, decisions, log entries, the names of the people who made them — IMT Logic is a data processor. The customer organisation is the controller of that information and decides what goes into it, who may see it and how long it is kept. We handle it on their instructions and under our agreement with them. If you are a member of a response team and want to know how your employer uses that record, ask your organisation; we cannot answer for them.
2. What we collect through this website
The enquiry form is the only place this website asks you for anything. When you submit it we record:
- Your name.
- Your organisation, if you give one.
- Your work email address.
- The sector you selected, and what you would like — a tabletop exercise, a shorter demonstration, or a question.
- Anything you typed into the message box.
- The IP address the enquiry came from, and the browser identification string your browser sends with every request.
- The date and time it arrived.
The last two are not there to profile you. They are how we limit the number of submissions from one source in an hour, and how we identify a burst of automated spam after the fact. There is no analytics, advertising or tracking software of any kind on this website — see the cookie information page.
Why we are allowed to hold it
Because you asked us to contact you. We use it to reply, to arrange an exercise or demonstration if that is what you asked for, and to keep a record that we did. We do not add enquiry addresses to a mailing list — there is no mailing list — and we do not use them for unrelated marketing.
3. What the platform holds
For people with a platform account, the application holds:
- Account details: display name, email address, the role assigned to the account, and whether the account is active.
- A password, stored only as a one-way cryptographic hash. Nobody at IMT Logic can read or recover a password; it can only be replaced.
- Sign-in activity: when a session began, when it ended or was revoked, and the address it was used from.
- Everything the account records during an incident or exercise — actions, checklist entries, decisions, messages, position handovers — each one time-stamped and attributed to the account that made it.
Attribution is the point of the product rather than a side effect of it. An incident record whose entries cannot be attributed to a person and a time is of no use in a debrief, an investigation or a regulatory review. Anyone using the platform should expect their entries to be permanently attributed to them.
4. The record cannot be quietly edited
The incident log is append-only, enforced by the database rather than by a rule somebody could change in the software. Entries can be added; they cannot be edited or deleted afterwards, by a user, by an administrator, or by us. Corrections are made by adding a further entry, so both the original and the correction remain visible with their times.
This has a direct consequence for erasure requests. A request to delete an individual entry from a customer's incident record cannot be honoured without destroying the integrity of the whole record, and that record may be evidence the customer is legally required to retain. Such requests go to the customer organisation as controller, and are handled as part of their own retention obligations.
5. Who else sees it
We do not sell personal information and we do not share it for advertising. It is seen by:
- Us. Enquiries are read by IMT Logic staff in order to answer them.
- Our hosting provider. The servers running this website and the platform are operated by a third-party infrastructure provider, which necessarily stores the data on our behalf.
- The customer organisation, for anything recorded inside their own incidents. Separation between customer organisations is enforced in the database itself, below the application, so that a fault in the software still cannot show one customer another customer's data.
- Anyone we are legally required to disclose to, where a valid legal obligation applies.
Where a customer has the platform deployed into their own cloud tenancy, their data stays in their own environment and their own hosting arrangements apply instead of ours.
6. How long we keep it
| Information | Kept for |
|---|---|
| Website enquiries | While we are in contact with you and for a reasonable period afterwards, so we can pick up a conversation you started. Deleted on request. |
| Platform accounts | For as long as the customer's agreement with us is in place. Accounts can be deactivated at any time by the customer's administrator. |
| Incident and exercise records | Determined by the customer organisation, in line with their own retention policy and regulatory obligations. |
| Sign-in sessions | Sessions expire automatically 12 hours after sign-in, and are revoked immediately when a password is changed. |
| Backups | Taken nightly and kept for 14 days. Deleted information disappears from backups as the rotation passes over it, rather than instantly. |
7. How it is protected
- Everything is encrypted in transit using TLS. There is no unencrypted route to either the website or the platform.
- Passwords are stored as one-way Argon2id hashes — a memory-hard algorithm designed to resist offline cracking — never as recoverable text.
- The session cookie cannot be read by JavaScript, which means a scripting flaw in a page cannot be used to steal a session.
- Separation between customer organisations is enforced by the database, not by application code.
- The incident log is append-only at the database level.
- Backups are taken nightly and each one is automatically checked for readability and structural integrity when it is written, rather than being assumed sound.
- Repeated failed sign-in attempts are throttled, per account and per address.
8. Your rights
Depending on where you live, you may have the right to ask us for a copy of the personal information we hold about you, to have it corrected, to have it deleted, to object to how we are using it, or to have it provided in a portable form. You can also withdraw consent where our use rests on consent.
To exercise any of these, write to us at the address in section 10. We will respond within 30 days. If your request concerns information recorded inside a customer's incident record, we will pass it to that customer as controller and tell you we have done so.
9. Changes to this policy
If this policy changes, the revised version is published on this page and the date at the top is updated. Material changes affecting existing customers are notified to them directly rather than left to be noticed here.
10. Contacting us
Questions about this policy, or a request about your own information, go to admin@imtlogic.com.