Last updated: September 20, 2026
OVR365 ("we," "us," "OVR365") provides incident and occurrence-reporting software to hospitals, utilities, municipalities, and similar organizations ("Customers"). This policy explains what data we collect, why, and how it is handled across the OVR365 web portal, iOS app, and Android app.
Each Customer's reporting content — incident reports, evidence photos and video, reporter and staff accounts, routing and resolution records — belongs to that Customer. OVR365 acts as a data processor on the Customer's behalf, not as the owner of that content. Requests to access, correct, or delete incident data should go to the reporting Customer (e.g. your hospital or municipality), who controls that data.
Every piece of uploaded evidence receives a server-side SHA-256 hash at the time of upload, which is retained even if the underlying file is later purged under a Customer's retention policy — so a report's audit trail survives independently of the media itself.
Incident data is hosted on infrastructure OVR365 operates or a Customer's own on-premise servers, depending on the Customer's chosen deployment model. Data in transit is encrypted (HTTPS/TLS); data at rest depends on the underlying storage backend the deployment uses.
Retention is configured per Customer. Where a Customer sets an evidence retention period, expired evidence files are removed while the report record, its SHA-256 hash, and its audit trail are kept — consistent with the incident record-keeping duties many regulated industries operate under.
Where a Customer enables it, an uploaded photo and the reporter's description may be analysed by an AI model to suggest an incident category and priority, and a voice recording may be transcribed by a speech-to-text model. Depending on the Customer's configuration this is performed either on the Customer's own servers or by a third-party AI service (currently Google's Gemini API) acting only as a processor on our and the Customer's instructions. AI output is a draft: the reporter reviews and can change every field before anything is submitted, and a person, not the model, decides what is filed.
We do not sell data. Sub-processors are limited to the infrastructure and communication providers needed to run the service (hosting, email delivery for report notifications, and, where a Customer enables it, the AI service described above), each bound to process data only as instructed.
If you are an individual reporter or staff member using a Customer's OVR365 deployment, contact that Customer's own administrator for access, correction, or deletion requests regarding your account or the reports you filed.
Questions about this policy: info@operva.co