This policy explains what Pocket DICO collects, how it is used and protected, and the rights you have over your information.
1Introduction
DRSE Consulting ("we," "us," or "our") operates Pocket DICO, an exposure case management and compliance tracking application for Texas first responder departments. This Privacy Policy describes how we collect, use, store, and protect your information when you use our Service.
2Information We Collect
Account Information. When you create an account, we collect your name, email address, department affiliation, and assigned role (DICO Admin, DICO User, or Read Only).
Exposure Case Data. Information you enter regarding exposure incidents, including responder names, incident dates and times, exposure types, PPE usage, risk assessments, source patient information (initials only), and circumstances descriptions.
Checklist and Compliance Data. Records of compliance checklist item completion, status changes, and timeline events associated with exposure cases.
Sharps Injury Log Data. Information recorded in sharps injury logs as required by TAC §96.401 and HSC §81.306.
HCID Screening Data. Traveler screening information, symptom assessments, and documentation collected through the HCID Traveler Tool.
Department Configuration. Department name, type, address, county, and Local Health Authority contact information.
Audit Log Data. Records of user actions within the application for accountability and compliance purposes.
Usage Data. Technical information such as browser type, device type, and general usage patterns to improve the Service.
3How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Pocket DICO service
- Facilitate exposure case documentation and compliance tracking
- Generate compliance reports and PDF exports
- Manage user accounts and department access
- Send account-related communications (password resets, invitations)
- Maintain audit trails as required for compliance purposes
- Ensure the security and integrity of the Service
4Data Storage and Security
Pocket DICO uses Supabase, a cloud-hosted database platform, to store application data. Data is hosted on infrastructure located in the United States (us-east-1 region).
Security measures include:
- Row-Level Security (RLS) ensuring departments can only access their own data
- Encrypted data transmission (HTTPS/TLS)
- Role-based access controls (Admin, User, Read Only)
- Secure authentication with hashed passwords
- Department-scoped data isolation
While we implement reasonable security measures, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security of your data.
5Confidentiality and Legal Protections
Exposure case information is confidential under Texas Health and Safety Code §81.046. Sharps injury log data is confidential under Government Code §552 per TAC §96.402 and is not subject to disclosure, discovery, subpoena, or other means of legal compulsion for release.
We will not voluntarily disclose protected exposure data except as required by law, court order, or valid legal process. We will notify affected departments of any legally compelled disclosure to the extent permitted by law.
6Data Sharing and Third Parties
We do not sell, rent, or trade your personal information or exposure case data.
We may share information with:
- Service Providers: Third-party services that help us operate the application (e.g., Supabase for database hosting, Vercel for application hosting)
- Legal Requirements: When required by law, court order, or valid legal process
- Safety: When necessary to protect the safety of any person or to prevent illegal activity
7Data Retention and Deletion
Exposure case data is retained for as long as your department account is active or as needed to comply with legal retention requirements.
DICO Administrators may export all case data (PDF or CSV) and permanently delete all cases through the Data and Privacy section in Settings. Individual user accounts may be deleted by the department administrator.
Upon account or department deletion, we will delete associated data within a reasonable timeframe, except where retention is required by law.
8Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate information
- Request deletion of your personal information
- Export your data in a portable format
- Withdraw consent to data processing
To exercise these rights, contact us at drseadmin@drseconsulting.com or through the Data and Privacy section within the application.
9Children's Privacy
Pocket DICO is not intended for use by individuals under 18 years of age. We do not knowingly collect personal information from children under 18. If we become aware that we have collected information from a child under 18, we will take steps to delete it promptly.
10Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice through the Service or by other appropriate means. Your continued use of Pocket DICO after the effective date of a revised Privacy Policy constitutes acceptance of the updated policy.
11Contact Information
For privacy-related questions, concerns, or requests, please contact:
DRSE Consulting
10924 Middleglen Rd
Haslet, Texas 76052
United States
Email: drseadmin@drseconsulting.com
Website: https://drseconsulting.com