Smart Team Communicator  ·  Rapid Cyber Solutions, Inc.

Privacy Policy

Our role
Processor / service provider
Controller
Your organization
Storage & retention
As set in the Customer Agreement
Last updated
29 July 2026

Smart Team Communicator (“STC”) is a communication, productivity and monitoring platform that Rapid Cyber Solutions, Inc. (“Rapid Cyber,” “we,” “us”) licenses to organizations. This policy explains what information the Service handles, why, and who decides.

The short version

  • 1Your organization licenses STC, configures it, and controls the records it produces. We process information on its instructions.
  • 2STC includes monitoring features. Depending on your organization’s configuration, your workplace activity may be logged, viewed by supervisors, recorded and retained.
  • 3We do not sell information and do not use it for advertising.
  • 4Records in the Service are your organization’s business records. Storage location and retention are set in its agreement with us.
  • 5Questions or requests about your information go to your organization’s HR or IT team — not to us.

1Scope of this policy

This policy applies to information handled in and through the STC platform, including its hosted application, desktop and mobile clients, web application and administrative portal (together, the “Service”), and to this website.

STC is not available to individual consumers. You have access because an organization — your employer or the entity that engaged you (the “Customer”) — licenses the Service and has provisioned an account for you (an “Authorized User”). This policy does not cover your organization’s own privacy practices, employment policies or other systems. For those, see your organization’s privacy notice.

2Who controls the information

Who decides what

Your organization is the controller (or “business”) of information in the Service. It decides which features are enabled, what data is entered, who may view it, where it is stored and how long it is kept. As far as you are concerned, your organization provides the Service.

Rapid Cyber is the processor (or “service provider”). We handle that information only to deliver, secure and support the Service, on your organization’s documented instructions and under a written agreement with it.

We act as a controller in our own right only for a narrow set of information: our business contacts at the Customer, billing and account-administration records, and security and operational telemetry we need to run the Service safely.

Aggregated and de-identified data

Separately from the records described above, we generate aggregated and statistical data from the operation of the Service — for example volumes, counts, performance measurements and system logs. This data is owned by Rapid Cyber and is distinct from the information your organization controls. We use it to operate, secure, support, benchmark and improve the Service. It is held in a form that does not identify any individual, any organization, or any organization’s own clients; we do not attempt to re-identify it, and we do not release it in a form that would identify any of them.

3Information in the Service

The categories below reflect what the Service is capable of handling. What is actually collected in your organization’s environment depends on the features it has enabled and how it has configured them.

Account and identity information

Name, work email address, sign-in name, employee or user identifier, job level, team and assignment, reporting relationship, and account status, supplied and maintained by your organization within the Service. Sign-in is with credentials issued within STC — passwords are not stored in readable form — or by single sign-on through your organization’s identity provider (Microsoft Entra ID or Active Directory, Google Workspace, Okta, Ping Identity, or another SAML or OpenID Connect provider), which sends us only your sign-in identifier and gives us no access to anything else in that account. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Communications and content

Any communication sent, received or stored through the Service, and any file or content created or uploaded in it, together with the associated senders, recipients, timestamps and metadata. Content is stored as generated, subject to any masking rules your organization has chosen to configure.

Activity, supervisory and recording data

Where your organization enables the relevant features: status and schedule-adherence logs; application and website activity; keyboard and mouse activity signals used to determine whether you are active or idle (not the content of what you type); screen images; photos captured from your device camera to verify your identity, together with the result of any automated comparison of a photo against your profile photo; records of live monitoring or remote control of your screen, device or calls by personnel your organization authorizes, such as supervisors or quality, IT and training staff; recordings of voice, video or screen-sharing sessions; and call metadata such as participants, start time and duration.

The screen and audio content of live monitoring and remote-control sessions is encrypted between the participating devices and is not accessible to us.

Where automated photo comparison is enabled, the comparison is used solely to verify identity and alert your organization to a mismatch. Only the profile photo, the submitted photo and the comparison result are stored, retained as configured by your organization (section 8); facial-geometry data generated to perform a comparison is not retained by us or by the subprocessor that performs it. Verification photos and comparison results are never sold and are not used to train facial-recognition or other AI models.

Technical and security information

Device and operating system details, including version and hardware characteristics; client application version; IP address; the sign-in method and identity used to authenticate; sign-in and session records; error and diagnostic logs; and audit trails of administrative actions.

Automated and assistive features

Where your organization enables features that use automated processing, analytics, or artificial intelligence or machine learning — whether provided by us, by your organization, or by a third party it selects — that processing is carried out on your organization’s instruction and is governed by its agreement with us and its own policies.

4What we do not do

  • We do not sell personal information, and do not share it for cross-context behavioral advertising.
  • We do not use information in the Service for our own marketing, or for any purpose other than providing, securing and supporting the Service to your organization.
  • We do not access data held in your Microsoft, Google or other organizational account — single sign-on is authentication only.
  • We do not act on an individual user’s instruction to access, amend, export or delete records — those instructions come from your organization.

5How we use information

We use information solely to:

  • authenticate users and deliver, maintain and support the Service;
  • route messages, calls and supervisory sessions, and apply the configuration your organization has set;
  • produce the reporting, audit and compliance records your organization has configured;
  • monitor, investigate and prevent security incidents, fraud, abuse and misuse;
  • troubleshoot faults, maintain service quality and plan capacity;
  • comply with our legal obligations and enforce our agreements; and
  • operate, secure, benchmark and improve the Service, including through the aggregated and de-identified data described in section 2.

7Sharing and subprocessors

We disclose information only:

  • To your organization. Its authorized administrators and supervisors can access records according to the roles it configures.
  • To subprocessors that help us run the Service, under written contracts limiting them to our instructions. These include our cloud infrastructure provider, the provider of our voice, video and conferencing capability, the provider of our automated photo-comparison capability where your organization enables it, and identity providers where single sign-on is enabled. A current subprocessor list is available to Customers on request.
  • Where required by law — in response to valid legal process, or to protect rights, safety or property. Where legally permitted, we notify the Customer before disclosing its data.
  • In a corporate transaction — in connection with a merger, acquisition or sale of assets, subject to this policy and the Customer Agreement.

8Storage location and retention

Where information is stored and processed, and how long it is kept, are set out in the agreement between your organization and us. Different organizations contract for different arrangements, so the specifics for your environment come from your organization, not from this page.

Your organization may export records from the Service and retain them in its own systems for as long as it chooses, independently of any retention period configured in the Service. On termination, data is returned or deleted in accordance with the Customer Agreement. We retain backups for a limited period as part of our disaster recovery process; data in backups is removed on the backup rotation cycle.

9Requests about your information

Where to send your request

Start with your organization — its HR, IT or privacy team. Your organization controls the information in the Service and is the only party that can act on a request about it. We do not respond to individual requests directly and cannot access, change or delete records on your instruction.

Depending on where you live, you may have rights to access, correct, receive a copy of, restrict or object to the processing of your information. Those rights are exercised through your organization, which will decide how to respond and instruct us where action is needed on its behalf.

Please note that records in the Service are business communication records that your organization is generally required to preserve for legal, regulatory, audit and evidentiary purposes. Requests to delete them may be declined on that basis, or may be limited to specific categories of information, at your organization’s determination.

If you are in the EEA or UK, you also have the right to lodge a complaint with your local supervisory authority.

10Security

We maintain administrative, technical and physical safeguards designed to protect information in the Service, including encryption in transit and at rest, one-way cryptographic protection of stored passwords, role-based access control, least-privilege administrative access, audit logging of administrative actions, vulnerability management and continuous monitoring. Independent audit and compliance reports are available to Customers on request under a confidentiality agreement.

No system is completely secure. If we become aware of a security incident affecting a Customer’s data, we notify that Customer without undue delay in accordance with its agreement with us and applicable law. The Customer, as controller, is responsible for notifying affected individuals.

11Cookies and local storage

The STC web application uses strictly necessary cookies and local storage to keep you signed in, maintain session state and protect against cross-site request forgery. We do not use advertising cookies, third-party analytics or cross-site tracking in the Service, and this page loads no third-party scripts, fonts or trackers.

12Minors

The Service is a workplace tool. It is not offered to the general public, is not directed to children, and accounts can be created only by a subscribing organization.

The Service is intended for individuals aged 18 or over. An organization may not give access to someone under 18 — an intern or apprentice, for example — unless we have agreed to it in writing. Where we have agreed, that organization is responsible for the legal basis for the access, for obtaining any parental or guardian consent required, and for complying with any restrictions that apply to monitoring a minor or processing a minor’s data. We do not agree to such access for anyone under 13, and we do not knowingly collect information from anyone under 13 in any circumstances.

13Changes to this policy

We may update this policy from time to time. The current version is always posted at this address with the “Last updated” date above. We notify Customers of material changes in accordance with their agreements with us.

14Contact

Authorized Users: please contact your own organization’s HR, IT or privacy team. They control the Service and the records in it.

Subscribing organizations and their authorized contacts: Rapid Cyber Solutions, Inc., Longwood, Florida, United States — privacy@rapidcyber.com.

Security reports: to report a suspected vulnerability in the Service, contact security@rapidcyber.com.

See also our Terms of Service.