Employee Center Privacy Notice
No Raw Database Data Claim
For clarity, this document does not claim that Quintin N. Mahan owns raw facts, raw database rows, independent outside source records, CRS-owned operational records, customer-owned records, third-party-owned records, or customer relationships merely because such information is entered into, stored in, processed by, displayed through, backed up with, or exported from EC.
This document protects EC Protected Materials: the application, software, source code, schemas, database design, data model, relationships, indexes, workflows, dashboards, reports, queries, automations, integrations, APIs, access controls, credentials, hardware, infrastructure, legal records, certificate records, hashes, metadata systems, audit systems, methods, processes, techniques, trade secrets, documentation, and EC-created structural organization.
Version: 1.0
Effective Date: June 1, 2026
Platform: Employee Center / EC
Owner: Quintin N. Mahan
Legal Hub: /legal
Policy URL: /legal/privacy-notice
1. Purpose
This Privacy Notice explains how Employee Center (“EC”) collects, uses, stores, logs, preserves, backs up, and protects information.
EC is a private operational platform owned by Quintin N. Mahan. EC is used for authorized operational, administrative, service, customer-support, reporting, legal, evidence, and continuity purposes.
This Privacy Notice is intended to explain EC’s data practices while preserving the ownership, access, retention, evidence, backup, and EC Protected Materials rights stated in the Employee Center Terms and Conditions.
2. Scope
This Privacy Notice applies to information processed through EC, including information related to:
- EC users;
- employees;
- administrators;
- company-authority users;
- customers;
- companies;
- contacts;
- stores;
- service locations;
- service reports;
- timecards;
- tasks;
- call logs;
- attachments;
- integrations;
- automations;
- APIs;
- legal records;
- acceptance certificates;
- audit logs;
- backups;
- generated exhibits.
This Privacy Notice applies to EC itself. It does not replace the privacy notices, terms, or data practices of Zoho, Google, Google Voice, UniFi, GL.iNet, payment processors, carriers, email providers, or other connected third-party systems.
3. Relationship to the Terms and Conditions
This Privacy Notice works together with the Employee Center Terms and Conditions.
If this Privacy Notice conflicts with the Terms and Conditions, the Terms and Conditions control unless Quintin N. Mahan signs a separate written agreement stating otherwise.
Nothing in this Privacy Notice transfers ownership of EC, EC source code, EC workflows, EC reports, EC dashboards, EC automations, EC integrations, EC data structures, EC databases, EC certificates, EC legal records, EC backups, EC hardware, EC infrastructure, or the EC Protected Materials.
4. Information EC May Collect
EC may collect and maintain information entered into EC, generated by EC, imported into EC, connected to EC, synchronized with EC, or logged by EC.
This may include:
- names;
- usernames;
- email addresses;
- phone numbers;
- job titles;
- roles;
- authority levels;
- company names;
- customer names;
- store names;
- contact names;
- physical addresses;
- service addresses;
- billing/shipping references;
- task records;
- service records;
- service notes;
- service reports;
- timecard records;
- work/drive/lunch/remote segments;
- call-log records;
- caller ID data;
- SMS/modem command logs if enabled;
- attachments;
- uploaded files;
- signatures;
- device records;
- network records;
- API records;
- webhook records;
- automation records;
- dashboard/report records;
- acceptance records;
- decline records;
- certificate PDFs;
- Terms/policy views;
- IP addresses;
- user agents;
- session metadata;
- audit logs;
- security logs;
- backup records.
5. Sensitive or Regulated Information
EC is not intended to be a general-purpose storage location for unnecessary sensitive personal information.
Users should not enter sensitive information into EC unless it is necessary for an authorized EC-related purpose.
Sensitive information may include:
- Social Security numbers;
- driver’s license numbers;
- government ID numbers;
- payment card data;
- bank account information;
- medical information;
- health insurance information;
- passwords;
- private credentials;
- security codes;
- personal identity documents;
- legally protected information.
If sensitive information is accidentally entered, uploaded, attached, imported, or synchronized into EC, EC may preserve it as part of audit, security, backup, evidence, or legal-preservation records until it can be reviewed and handled appropriately.
6. How EC Uses Information
EC may use information for authorized EC-related purposes, including:
- operating EC;
- authenticating users;
- enforcing permissions;
- assigning work;
- tracking tasks;
- recording time;
- supporting customers;
- creating service reports;
- maintaining directories;
- logging calls;
- managing attachments;
- generating reports;
- displaying dashboards;
- running automations;
- processing integrations;
- troubleshooting;
- auditing;
- preserving evidence;
- generating acceptance certificates;
- maintaining Terms/policy records;
- enforcing EC policies;
- supporting legal defense;
- preserving evidence preservation and authorized transition support;
- backing up and restoring EC;
- improving EC;
- maintaining EC security.
7. Monitoring and Logs
EC may monitor, log, audit, preserve, and review activity within EC.
Logs may include:
- user identity;
- company identity;
- role;
- authority level;
- login activity;
- failed login activity;
- page views;
- profile access;
- Legal page access;
- Terms page access;
- certificate views;
- record changes;
- exports;
- imports;
- attachments;
- API activity;
- webhook activity;
- automation activity;
- IP address;
- user agent;
- timestamps;
- errors;
- security events.
Logs may be used for security, troubleshooting, business operations, evidence, legal defense, evidence preservation and authorized transition support, access review, and enforcement.
8. Who May Access Information
Access to EC information may be limited by role, permission, account type, authority level, module, route, integration, service account, or owner/admin decision.
Information may be accessible to:
- the user who entered it;
- authorized EC users;
- supervisors or managers where appropriate;
- company-authority users;
- owner/admin users;
- service accounts;
- approved integrations;
- support/maintenance processes;
- Quintin N. Mahan as EC owner/admin.
Normal users may not access another user’s individual acceptance certificate unless authorized. Users may be allowed to access the current company acceptance certificate and their own individual acceptance certificate.
9. Sharing and Disclosure
EC information may be shared or disclosed only for authorized EC-related purposes.
This may include disclosure to:
- authorized users;
- company-authority users;
- EC owner/admin;
- approved vendors or service providers;
- integrated systems such as Zoho, Google, Google Voice, UniFi, GL.iNet, or other approved systems;
- legal counsel;
- courts or lawful process;
- insurers or advisors where appropriate;
- customers or contacts where needed for authorized service or continuity.
EC does not sell personal information to advertisers.
10. Third-Party Services and Integrations
EC may connect to third-party services and systems.
These may include:
- Zoho;
- Google Workspace;
- Google Voice;
- email providers;
- SMS/modem systems;
- UniFi;
- GL.iNet;
- Tailscale;
- payment/customer/accounting systems;
- storage or backup systems;
- other approved APIs or integrations.
Third-party services may have their own terms, privacy policies, logging, retention, and security practices.
EC may store records received from or sent to those systems as part of the EC Protected Materials.
11. Retention and Backups
EC may retain records, logs, certificates, Terms versions, policy versions, attachments, backups, audit trails, generated exhibits, and historical data for operational, security, legal, evidence, evidence-preservation, and EC-ownership purposes.
EC may retain:
- active records;
- archived records;
- deleted-record metadata;
- audit logs;
- acceptance records;
- decline records;
- certificate records;
- certificate PDFs;
- Terms snapshots;
- policy snapshots;
- generated exhibits;
- backups;
- integration logs;
- API logs;
- security logs.
Retention may continue after a user leaves, after employment changes, after access is revoked, after CRS changes ownership, after a dispute, or after a trigger event described in the Terms.
12. Security
EC may use administrative, technical, physical, access-control, backup, audit, and monitoring measures intended to protect EC and EC data.
Security measures may include:
- authentication;
- role-based permissions;
- admin restrictions;
- server access controls;
- network restrictions;
- API controls;
- backup controls;
- logging;
- certificate hashes;
- Terms hashes;
- PDF hashes;
- audit trails;
- owner/admin review;
- access revocation;
- preservation controls.
No security measure can guarantee that information will never be accessed, disclosed, altered, or destroyed. EC may investigate and respond to suspected security incidents as appropriate.
13. Data Accuracy
Users should enter accurate and complete information when using EC.
Users should not knowingly enter false, misleading, incomplete, backdated, or fabricated records.
If a user identifies incorrect information, the user should correct it through authorized EC workflows or report it to an authorized EC owner/admin.
14. User Choices and Access
Users may access information available to them through their authorized EC account.
Users may review current legal documents through:
/legal
Users may review the current Terms through:
/legal/terms-and-conditions
Users may review their own acceptance certificate where enabled.
Users may not demand access to records, certificates, logs, backups, exports, source code, admin records, or other information outside their authorized permissions unless required by law or approved by Quintin N. Mahan.
15. Security Incidents
If EC detects or is notified of a possible security incident, EC may investigate, preserve logs, preserve backups, restrict access, rotate credentials, suspend accounts, notify appropriate parties where required, and take other steps appropriate to the situation.
EC may delay or limit disclosure of security information where needed to investigate, preserve evidence, restore system integrity, protect security, comply with law, or avoid increasing risk.
16. Children
EC is not intended for children or for use by the general public.
EC is intended for authorized business users, administrators, service accounts, integrations, and approved operational users.
17. Changes to This Privacy Notice
Quintin N. Mahan may update this Privacy Notice by publishing a new active version in EC.
The current active version will be displayed through the Legal hub.
Older versions may remain stored in Postgres for audit, evidence, and historical review.
18. Contact / Owner
Employee Center is owned by Quintin N. Mahan.
Legal and policy documents are available from:
/legal
The current Terms and Conditions are available from:
/legal/terms-and-conditions
End of Privacy Notice.