In Case of Crisis AI
Privacy Policy
This Privacy Policy governs In Case of Crisis AI, a connector offered by RockDove Solutions, Inc. (“RockDove,” “the Company”). In Case of Crisis AI lets an employee of a customer organization ask their AI assistant a question and receive that organization’s approved crisis protocols in response.
This policy covers processing performed through the In Case of Crisis AI connector, including the audit copies created when protocols are retrieved. In Case of Crisis AI is a separate product from the In Case of Crisis mobile and web platform, and protocols held in that platform are governed by its own privacy policy.
Our Privacy Commitment
RockDove uses personal information for the purposes described in this policy and, when acting as a processor, under the customer organization’s documented instructions and applicable law. RockDove does not sell personal information, does not use it for advertising, and does not use it to profile individual employees. Disclosures are described under Third-Party Sharing and Subprocessors and under Legal Disclosures below.
Legal disclosures
RockDove discloses personal information when required by applicable law or by valid, binding legal process. Disclosures are limited to the information legally required. Other disclosures for safety, fraud prevention, or enforcement must be permitted by applicable law and consistent with the Company’s obligations under the customer agreement.
RockDove will notify the affected customer organization of a legal demand before disclosure where permitted and reasonably practicable, unless legally prohibited from doing so.
Controller and Processor Roles
In Case of Crisis AI is a business product. It is licensed to an organization and used by that organization’s personnel.
For customer protocols, connector requests, responses, and associated audit records processed on a customer organization’s behalf, RockDove acts as a processor under that organization’s documented instructions and the applicable Data Processing Addendum.
An individual who wants to access, correct, or delete information about themselves should contact their own organization first, since that organization directs how the information is handled. Individuals may also contact RockDove using the details below. For information processed on a customer organization’s behalf, RockDove will assist that organization in responding. Requests concerning any processing for which RockDove determines its own purposes are handled directly by the Company.
Information Collected and Recorded
Registration information
RockDove creates accounts for the personnel a customer organization nominates. For each account RockDove holds the work email address that serves as the username, the customer organization the account belongs to, and the subject identifier issued by the identity provider used to sign in, so that an account remains correctly attributed if an email address changes.
Audit records
Each time a request reaches the connector, RockDove writes an audit record covering the following. The records exist so that a customer organization can review, after an incident, what the connector received, what it returned, and when.
- Identity and scope. The organization identifier, the account email address that scoped the request, and the subject identifier from the identity provider. These identifiers attribute the request to an account and a customer organization. Server-side authorization, rather than the record itself, is what limits the protocol content an account may retrieve.
- The request and the response. The request text received by the connector from the AI assistant, and the protocol content returned by the connector, including any customer plan text in that response. The connector records what it received; where an AI assistant reformulates or composes a request from surrounding conversation, the recorded text is the assistant’s request rather than necessarily the words the user typed. The audit record likewise does not establish the assistant’s final answer to the user, whether the user saw it, or what the user did next. This material is written to a separate, access-restricted store described under Storage and Security below.
- Incidental personal information. Requests and returned protocols may contain personal information about the requesting user or about other individuals, including emergency contacts and members of the public. That information forms part of the verbatim audit record. Requests should be limited to the information needed to retrieve the relevant protocol.
- Operational detail. Which tool was called, the date and time, how long the request took, whether it succeeded, and the exception type if it did not.
- Information about the assistant application. The name, title and version of the AI assistant application making the request, the protocol version and transport it used, the session and request identifiers it supplied, its User-Agent string, and whether it supports interactive display. RockDove uses this for compatibility diagnostics and customer support. The User-Agent is the only HTTP header recorded, and it may describe the device, operating system or browser making the request.
- Query shape. Which stored procedures ran, how long they took, how many rows and protocols were returned, the size and structure of the response, and character counts. These are counts and sizes rather than the underlying values.
Information not collected
- RockDove does not collect precise device or geographic location. Network infrastructure receives an IP address in the ordinary course of serving a request, and the User-Agent described above may indicate device or browser characteristics.
- A telephone number is not required to create an In Case of Crisis AI account, and the connector does not send SMS or text messages.
- Payment card details are entered directly into Stripe’s hosted checkout and are not received or stored by RockDove. Billing contact and subscription details necessary to administer an account are held by RockDove.
- The connector does not independently access an AI assistant’s memory, chat history, conversation summaries, or uploaded files. It receives the request the assistant sends, which may include information the assistant draws from that surrounding context.
Limits on what audit records contain
Summary audit records contain the identity and operational metadata listed above. They exclude request text, response text, and database result values. The verbatim tier retains the request and returned protocol content described above.
Authorization headers, bearer tokens and session cookies are not written to audit records. RockDove does not write request or protocol content to its audit records other than in the verbatim tier described above.
Use of Information
Registration information is used to authenticate a user, to scope their access to what their organization permits, and to administer the customer organization’s subscription.
Request information is processed to retrieve the protocol content the account is authorized to access. Audit records are retained for customer incident review, fault diagnosis, abuse investigation, and customer support, subject to the access restrictions described below.
RockDove does not use customer protocols, connector requests, or responses to train or fine-tune AI models, and does not provide them to a third party for that purpose. The AI provider a customer organization selects processes information under the agreement and settings applicable to the account used to connect.
Retrieval, not decision-making
In Case of Crisis AI retrieves protocols that the customer organization has already written and approved. It does not independently generate crisis guidance, and it does not make decisions about an individual’s treatment or emergency response. The customer’s AI assistant may summarize or otherwise transform the content returned; the audit record captures the content the connector returned.
Any decision about how to act on a protocol is made by the people the customer organization holds responsible for it. This is a deliberate design constraint, and it reflects RockDove’s own governance requirement that an AI system may inform a consequential decision but never make one.
Storage and Security
RockDove stores and processes In Case of Crisis AI data in United States regions of Amazon Web Services and Microsoft Azure. The connector application runs on Amazon Web Services, the database is hosted on Microsoft Azure, and audit records are stored in Amazon S3. This commitment covers the RockDove-operated services described in this policy. Processing by the AI provider and the identity provider a customer organization selects is governed by that organization’s agreements with those providers.
Database contents, including account records, are encrypted at rest using Microsoft Azure Transparent Data Encryption with an AES-256 algorithm. Audit records are encrypted at rest in Amazon S3 using server-side encryption with AWS KMS keys that RockDove creates and manages. All information is encrypted in transit, including where it moves between the two providers and wherever a user signs in.
Audit records are written in two tiers. The summary tier holds the identity and operational metadata described above. The verbatim tier holds the request and protocol content, and access to it is restricted to a controlled exception process rather than being available for routine support work.
Breach notification
No set of safeguards is absolute, and RockDove cannot guarantee that information will never be accessed, disclosed, altered, or destroyed through a breach of its physical, technical, or managerial safeguards.
If RockDove becomes aware of a security incident or personal data breach affecting information held for In Case of Crisis AI, it will notify affected customer organizations without undue delay and in any event within seventy-two (72) hours of becoming aware. Initial notification is not delayed until an investigation is complete, and RockDove provides further information as it becomes available, including the information reasonably necessary for the organization to meet its own notification obligations.
Data Retention
Audit records
Audit records are retained for 365 days from the date of the request and are then deleted. This applies to both the summary tier and the verbatim tier. Throughout that period they are held in United States regions, as described above. The standard period runs from the date of each request and does not restart when a subscription ends.
Deletion at the end of the retention period is carried out by an automated lifecycle process. Expiry is processed on a scheduled basis, so a record may be removed shortly after the period ends rather than at a precise instant.
Earlier return or deletion follows the customer organization’s documented instructions and the applicable Data Processing Addendum, subject to any retention required by law.
Account records
Account records, meaning the username and the associated organization and authentication details, are retained for as long as the account is active. When a customer organization’s subscription ends, or when an organization asks for an account to be closed, the account record is deleted within 90 days.
Deleting an account record does not by itself remove the email address and subject identifier contained in audit records already written. Those identifiers are governed by the audit retention period above.
Other records
Customer protocol content, support correspondence, billing records and authentication session records are held for the periods set out in the customer organization’s agreement with RockDove or for as long as needed for the purpose for which they were created, and are then deleted.
Where applicable law requires information to be retained, access and use are restricted to that legal requirement, and the information is deleted when the required retention period ends.
Third-Party Sharing and Subprocessors
The providers below fall into two categories. RockDove service providers are engaged by RockDove and process information on its instructions. Customer-selected services are contracted by the customer organization directly; RockDove does not control their independent practices.
| Provider | Relationship | Purpose | What it receives |
|---|---|---|---|
| Amazon Web Services | RockDove service provider | Application hosting and audit-record storage | The connector application environment, which transiently processes requests, protocol content, identity information and error information, and the audit records described above. United States regions. |
| Microsoft Azure | RockDove service provider | Database hosting | Account records, customer protocol content, and the query inputs used to retrieve it. United States regions. This is a hosting relationship, separate from any Microsoft AI product a customer may license. |
| Stripe | RockDove service provider | Payment processing | Card details entered directly into Stripe’s hosted checkout. RockDove receives billing and subscription information necessary to administer the account. |
| The customer organization’s identity provider | Customer-selected | Authentication | Selected and operated by the customer organization. RockDove receives the assertion or token it issues. |
| Anthropic, OpenAI, or Microsoft | Customer-selected | AI assistant | The connector returns customer protocol content to the AI assistant the organization has selected, which makes that content available for processing by that provider under the organization’s own agreement with it. |
RockDove does not engage an additional AI inference provider in order to operate the connector.
RockDove will provide advance notice of intended additions to or replacements of its subprocessors, and the opportunity to object, under the applicable Data Processing Addendum. The published list above is updated accordingly. This procedure applies to RockDove’s own subprocessors and not to services a customer organization selects directly.
International Transfers
In Case of Crisis AI is hosted in the United States. For transfers subject to European Economic Area data protection law, RockDove uses the applicable European Commission Standard Contractual Clauses, incorporated into the customer organization’s Data Processing Addendum. Where required, the UK International Data Transfer Addendum to those Clauses, and the adaptations required under Swiss data protection law, also apply.
These safeguards do not change the hosting locations described under Storage and Security. Processing by the AI provider and identity provider a customer organization selects is governed by that organization’s own agreements and transfer arrangements with those providers.
A customer organization may request a copy of the clauses applicable to its agreement by contacting RockDove at the address below.
Children’s Privacy
In Case of Crisis AI is a business product. Accounts are created for personnel of a customer organization at that organization’s direction, and the service is not directed at individuals under the age of thirteen. RockDove does not knowingly create accounts for them.
Requests and protocols submitted by a customer organization may nevertheless contain information about other individuals, including children. That information is processed under the customer organization’s instructions and the applicable data processing terms. If an account has been created contrary to the age restriction, contact RockDove using the details below and it will be closed.
This website
incaseofcrisis.ai is hosted by Netlify, Inc. The site sets no cookies and runs no analytics or advertising scripts. It has two forms: a trial request, which collects your name, work email address, organization, optional role, the plan and organization size you selected, and a Boardroom Risk Radar subscription, which collects your work email address. Submissions are stored by Netlify in United States regions and delivered to RockDove by email. RockDove uses trial-request information to set up and administer your account and to contact you about your trial, and Risk Radar information to send the quarterly brief and any material updates about it. You may ask RockDove to delete a form submission at any time using the contact details below.
Changes to This Policy
RockDove may revise this policy from time to time. A revised policy states its own effective date. Material changes to the handling of customer data are communicated to customer organizations under the customer agreement. Changes that require consent or a contractual amendment follow the applicable process under that agreement.
Contact
RockDove accepts questions about this policy and privacy requests from customer organizations and from individuals:
| Privacy and security | support@incaseofcrisis.com |
|---|---|
| Telephone | 800-878-1649 |
Reports of a suspected security vulnerability in In Case of Crisis AI should be sent to support@incaseofcrisis.com and are routed to the RockDove Solutions security team. Do not include crisis protocol content, credentials, or other sensitive material in an initial report; RockDove will arrange a secure channel for supporting evidence.
Mailing address on our Contact page.