Privacy Policy
Last updated: September 26, 2026
This policy describes how Wavechrome Film Portal handles account data, operational records, and site usage data. The platform is intended for film QA and operational recordkeeping. Patient-identifying information is not permitted.
1. What We Collect
- Account data: username, email address, hashed password, organization membership, role, login timestamps, and legal acceptance records.
- Operational records: LOTs, boxes, films, measurements, calibration records, metadata you enter, uploaded files, QR identifiers, and audit logs.
- Technical data: IP address, browser/session data, request logs, and storage usage needed to secure and operate the service.
2. How We Use Data
- To provide the hosted Film Portal service and secure user access.
- To store, retrieve, search, and export your film and measurement records.
- To maintain auditability, prevent abuse, investigate incidents, and support customers.
- To meet legal obligations and enforce subscription, security, and contractual terms.
3. Legal Basis and Role Allocation
For customer accounts, we generally process data as needed to provide the service, pursue legitimate interests in security and operations, and comply with legal obligations. Each customer organization is responsible for the lawfulness of the data it enters into the platform.
4. No PHI / No Patient Identifiers
Wavechrome Film Portal is not intended for storing patient names, medical record numbers, dates of birth, or other directly identifying health data. Users must not upload files or enter metadata containing patient identifiers. We may block obviously prohibited entries or filenames.
5. Cookies and Session Data
The public site uses a basic consent banner for non-authenticated visitors. The application also uses session cookies and related browser storage necessary for login, security, and core functionality. We do not rely on non-essential tracking cookies to operate the app.
6. Sharing and Subprocessors
We use service providers to host the application, store uploaded files, and send transactional email. Current subprocessors and infrastructure notes are listed in the operational documentation and may change over time as the service evolves.
7. Retention
We retain account and operational records for as long as needed to provide the service, preserve audit history, comply with legal obligations, and support legitimate business operations. If you request account deletion, we currently anonymize the user account and disable access immediately.
8. Your Privacy Rights
Depending on applicable law, you may have rights to access, export, correct, or request deletion of your personal data. The current application supports a self-service data export and account anonymization workflow in account settings.
9. Security Measures
We use authentication controls, scoped organization access, audit logging, transport-layer protections provided by our hosting stack, and session expiration controls. No system can guarantee absolute security, and customer organizations remain responsible for their own credential management, workstation security, and local handling of exported data.
10. Contact
For privacy questions or requests, contact stevan.pecic.mobile@gmail.com.