Privacy Policy

Effective Date: March 6, 2026

Last Updated: August 18, 2026

NIMS Logic (“we,” “our,” or “us”) provides a cloud-based incident management platform designed to support agencies and organizations operating under the National Incident Management System (NIMS) and the Incident Command System (ICS). This Privacy Policy describes how we collect, use, store, and protect information when you use our platform, including our web application, mobile application, and website (collectively, the “Services”).

By accessing or using our Services, you acknowledge that you have read and understand this Privacy Policy. If you are using the Services on behalf of an agency or organization, you represent that you have the authority to bind that entity to these terms.

1. Information We Collect

Account and Organization Information

When an agency or organization subscribes to NIMS Logic, we collect information necessary to establish and maintain the account. This includes agency name, contact information for designated administrators, and user credentials for authorized personnel.

Incident and Operational Data

In the course of using the platform, authorized users create and manage incident-related information. This includes data associated with incident operations, resource assignments, organizational structures, situational assessments, and related planning and logistics records. This data is created and controlled by your agency.

Personnel Information

The platform manages records about personnel involved in incident operations, including names, organizational affiliations, role assignments, qualifications, and contact information as entered by authorized agency users.

Location Data

When you are checked in to an active incident, the NIMS Logic mobile app reports your device's position to your agency's incident record. Each position includes latitude and longitude, accuracy, altitude, heading, speed, and a timestamp, together with your device's battery level and charging state so supervisors can tell a responder who has stopped reporting from one whose phone is running out of power.

This collection continues while the app is in the background and while it is closed. Responders work with the phone pocketed or the screen off, and reporting that stopped whenever the app was not open would not support the personnel accountability incident command depends on.

Position reporting is not always on. It runs only when all of the following are true: you have granted location permission and acknowledged the in-app background-location disclosure; you are checked in to an active incident; and the “Location sharing” control on your dashboard is enabled. It stops when you check out or are demobilized, and pauses while you are out of service for rest. Turning off “Location sharing” stops reporting immediately.

To limit collection, three limits apply together: positions are transmitted at most once every 60 seconds; a position that has moved less than 25 meters since the last is suppressed; and a move of more than 100 meters reports immediately. When you are stationary a heartbeat reports every 5 minutes, so “present and not moving” is distinguishable from “stopped reporting.” In the background, the operating system delivers position updates no more often than every 5 minutes.

While background reporting is active, your device displays its own persistent location indicator. The app enables this deliberately.

Your position is transmitted only to NIMS Logic. It is not sold, not shared with advertisers, and not used for tracking across apps or websites.

Device Information

We collect your device type, model, operating system version, and application version; a device identifier used to associate your sessions and to revoke access to a lost or stolen device; and a push notification token so incident alerts can reach you. As described above, battery level and charging state accompany each position report.

Photos, Documents, and Files

The app can attach photographs and documents to incident records — scene photos, geo-tagged captures, field reports, and escalations. You choose when to capture or attach; the app does not otherwise access your camera or photo library. Attachments are uploaded to encrypted cloud storage and linked to the incident record you attached them to.

Voice-to-Text

Activity-log entries can be dictated. The app requests microphone access and uses your device's built-in speech recognition to convert speech to text. NIMS Logic receives only the resulting text — we do not record, store, or transmit audio. The app requests on-device recognition. Where a device cannot perform recognition on-device, the operating system's own speech service may process the audio under Apple's or Google's privacy policy rather than ours.

Usage and Log Data

We automatically collect information about how users interact with the Services, including access times, pages and features used, and system performance data. We use server logs and similar technologies to maintain security and improve the platform.

Diagnostic and Performance Data

The mobile app sends crash reports and a sample of performance traces to an error-monitoring provider so we can find and fix faults, along with a record of which screens were opened before a fault. This diagnostic stream is deliberately configured not to carry your identity — your name, email address, and user identifier are not attached to it.

Separately, the operational telemetry described under Location Data — battery level, charging state, and network quality — is sent to NIMS Logic and is associated with your responder record, because its purpose is operational rather than diagnostic.

Cookies and Similar Technologies

Our website and web application use cookies and similar tracking technologies to maintain sessions, remember preferences, and analyze usage patterns. You can control cookie settings through your browser, though some features of the Services may not function properly without them.

2. How We Use Information

We use the information we collect for the following purposes:

  • Providing, operating, and maintaining the Services
  • Supporting incident management operations and resource coordination
  • Authenticating users and enforcing access controls
  • Generating reports, analytics, and operational summaries for subscribing agencies
  • Communicating with agency administrators about account-related matters, updates, and service changes
  • Improving, developing, and enhancing the platform and user experience
  • Ensuring the security, integrity, and availability of the Services
  • Complying with applicable laws, regulations, and government record-keeping requirements

3. Data Ownership and Control

Your agency retains full ownership of all incident data, personnel records, and operational information entered into the platform (collectively, “Agency Data”). NIMS Logic does not claim any ownership interest in Agency Data.

We process Agency Data solely to provide the Services and as directed by the subscribing agency. Agency administrators maintain control over user access, data entry, and the management of information within their organizational scope.

4. Data Sharing and Disclosure

We do not sell, rent, or trade personal information or Agency Data to third parties. We may share information only in the following limited circumstances:

  • Service Providers. We engage trusted third-party vendors to host infrastructure, provide technical support, and perform other services on our behalf. These providers are contractually obligated to protect data and may only use it to perform services for us. The categories of provider we use are listed below.
  • Multi-Agency Incidents. During multi-agency incident operations, certain operational data may be visible to authorized users from other participating agencies as configured by incident and agency administrators within the platform.
  • Legal Requirements. We may disclose information when required by law, regulation, court order, or governmental authority, or when we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.
  • Business Transfers. In the event of a merger, acquisition, or sale of assets, Agency Data and associated account information may be transferred as part of the transaction. We will notify affected agencies prior to any such transfer.

Service Providers by Category

We use third-party providers to operate the Services. Each acts only on our instructions and may use data solely to provide its service to us. By category, these are:

  • Cloud hosting and storage — operates our infrastructure, databases, and encrypted file storage, and therefore holds platform and incident data including uploaded attachments.
  • Identity and authentication — processes sign-in.
  • Error and performance monitoring — receives crash reports, sampled performance traces, and screen-navigation breadcrumbs, configured without your identity.
  • Mapping — receives requests for the map area being viewed. Usage telemetry from the mapping component is disabled in our app.
  • Push notification delivery — Apple and Google deliver notifications to your device using your device push token.
  • Application update delivery — receives your platform and application version when the app checks for updates.

These categories are the only destinations mobile application data reaches. Agencies evaluating NIMS Logic may request the current named sub-processor list from support@nimslogic.com.

5. Data Security

We implement administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of information processed through our Services. These measures include:

  • Encryption of data in transit and at rest
  • Role-based access controls and multi-factor authentication
  • Continuous monitoring, logging, and intrusion detection
  • Regular security assessments and vulnerability testing
  • Incident response and breach notification procedures

Our platform is hosted on government-authorized cloud infrastructure and is designed to meet the security requirements expected by public-sector agencies. While no system can guarantee absolute security, we are committed to maintaining rigorous protections commensurate with the sensitivity of the data entrusted to us.

6. Data Retention and Deletion

We retain Agency Data for the duration of the subscription and for a reasonable period thereafter to allow for data export and transition. Specific retention periods may be governed by your subscription agreement or applicable record-keeping requirements, including those related to federal disaster reimbursement documentation.

Upon termination of a subscription, agencies may request export of their data. After the agreed-upon transition period, we will securely delete or de-identify Agency Data in accordance with our data disposal procedures, unless retention is required by law.

Data on Your Device

The app stores incident data locally so it works without a network. Sent position reports are removed from your device about an hour after transmission; manual location captures after 24 hours; other resources' positions after 7 days; and uploaded photographs after 7 days. Work that has not yet reached the server is never automatically deleted, because it may be the only copy.

Local incident data is encrypted on your device, and the encryption key and your sign-in tokens are held in your device's secure hardware store. Data in transit uses TLS 1.2 or higher, with certificate pinning to our own servers.

Deletion Requests

Incident data belongs to the agency, not to the individual account. Positions, activity-log entries, field reports, attachments, and check-in records form part of an agency's official incident record. Emergency management records are subject to public-records and records-retention obligations that vary by jurisdiction, and an agency is generally required to preserve them for a defined period. NIMS Logic therefore cannot delete incident records on the request of an individual user, because doing so would destroy a record the agency is obliged to keep.

What you can do:

  • Remove the local copy — sign out and uninstall the app. This clears incident data cached on your device.
  • Stop location collection — turn off “Location sharing,” or check out of the incident. Reporting stops immediately.
  • Request account deactivation — contact your agency administrator or support@nimslogic.com. Deactivation revokes your access and ends all active sessions. Your historical contributions remain in the agency's incident record.
  • Ask what is held about you — contact support@nimslogic.com.

Agency-level deletion. An agency may request deletion of its data on termination of its subscription, subject to its own retention obligations. Requests come from an authorized agency administrator to support@nimslogic.com.

7. Your Rights and Choices

Depending on your jurisdiction and the nature of your use of the Services, you may have the following rights:

  • Access and Portability. Agency administrators may access and export Agency Data through the platform's built-in tools at any time during an active subscription.
  • Correction. Authorized users may update or correct personnel and incident data directly within the platform.
  • Deletion. Agencies may request deletion of their data, subject to applicable legal retention requirements. Individual users should see Data Retention and Deletion above.
  • Location Permissions. Mobile application users may enable or disable location services at any time through their device settings.
  • Cookie Preferences. You may manage cookie settings through your browser. Opting out of certain cookies may affect platform functionality.

For individual data rights requests, please contact your agency administrator in the first instance. Agency administrators may contact us directly for assistance.

8. Children's Privacy

The Services are designed for use by emergency management professionals and authorized agency personnel. We do not knowingly collect personal information from individuals under the age of 13. If we become aware that we have inadvertently collected such information, we will take steps to delete it promptly.

9. Third-Party Services and Links

This section concerns third-party websites and services you may reach through links or integrations. It does not cover the service providers described in Section 4, who process data on our behalf and for whom we remain responsible.

The Services may contain links to or integrations with third-party websites, tools, or services. This Privacy Policy does not apply to the practices of third parties. We encourage you to review the privacy policies of any third-party services you access through or in connection with the platform.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Services, or applicable law. When we make material changes, we will notify subscribing agencies through the platform or by other appropriate means, and will update the “Last Updated” date above. Continued use of the Services following notice of changes constitutes acceptance of the updated policy.

11. Contact Information

If you have questions or concerns about this Privacy Policy or our data practices, please contact us at:

Gov Claim Technologies, LLC

d.b.a. NIMS Logic

7643 Gate Parkway

Suite 104-176

Jacksonville, FL 32256

Email: support@nimslogic.com