ODFSEC
Privacy

Privacy Policy

This notice explains how Onetrak Digital Forensics LLC collects, uses, discloses, retains, and protects personal data through ZNRC4 AIRPORT.

Effective
August 9, 2026
Last updated
August 9, 2026

1. Scope and Operator

Onetrak Digital Forensics LLC ("Onetrak," "we," "us," or "our") operates ZNRC4 AIRPORT and acts as the controller of personal data covered by this policy. This policy applies to the public website, secure reporting and recovery forms, account and API-access functions, downloadable clients, case collaboration, shared views, administrative tools, and related communications.

This policy does not govern a third-party service linked from ZNRC4 AIRPORT or data that we process solely under a separate customer agreement where that customer determines the purpose and means of processing. In those cases, the customer's privacy notice may apply.

2. Personal Data We Collect

Depending on how you use the service, we may collect:

  • Identity and contact data: name, email address, phone number, organization or agency, job title, and related identifiers.
  • Report and case data: domains, IP addresses, URLs, account or wallet identifiers, reason codes, observed times, narrative descriptions, case notes, status, assignments, and investigative conclusions.
  • Evidence and communication data: files, screenshots, headers, logs, documents, public PGP keys, support messages, and other material you choose to provide.
  • Account and authorization data: username, role, permissions, hashed credentials or API keys, session records, access approvals, login events, and account-security information.
  • Device and network data: IP address, request time, method, path, status code, listener port, browser or client characteristics customarily included in network requests, and security or rate-limit signals.
  • Operational and audit data: administrative actions, record access, exports, configuration changes, security events, system diagnostics, and related user or target identifiers.
  • Derived data: normalized indicators, risk or reputation results, relationship graphs, aggregated metrics, and investigative classifications derived from the data above.
Sensitive data

Reports and evidence may incidentally contain government identifiers, precise location, credentials, financial information, criminal-allegation data, or other sensitive data. Do not submit sensitive data unless it is necessary, lawful, and authorized. Never provide passwords, private cryptographic keys, contraband, or child sexual abuse material.

3. Sources of Personal Data

We collect data directly from you when you submit a form, create or use an account, request API access, upload evidence, communicate with us, or use a client. We collect request and security data automatically from browsers, applications, servers, and network controls. We may also receive data from authorized organizations, investigators, administrators, service providers, public sources, threat-intelligence sources, and other users who have a lawful basis to provide it.

If you provide another person's personal data, you are responsible for having authority to do so and for providing any legally required notice.

4. How We Use Personal Data

We process personal data to:

  • receive, validate, encrypt, store, route, review, and respond to reports and API-access requests;
  • operate accounts, authentication, permissions, downloads, shared views, case workflows, and user support;
  • investigate malicious infrastructure, abuse, security incidents, and related forensic matters;
  • communicate with reporters, users, authorized organizations, investigators, and administrators;
  • protect the service, users, evidence, and networks through logging, auditing, rate limiting, access control, abuse prevention, and incident response;
  • maintain, troubleshoot, test, measure, and improve reliability and functionality;
  • enforce agreements, establish or defend legal claims, comply with law, and respond to lawful process; and
  • create aggregated or de-identified statistics that do not reasonably identify an individual.

We do not use personal data for targeted advertising, and we do not sell personal data for money or other valuable consideration.

5. Cookies, Session Storage, and External Resources

ZNRC4 AIRPORT uses essential session technology to support security functions such as CSRF protection, authentication, and restricted management access. Authentication cookies are configured with security attributes such as Secure, HttpOnly, and SameSite where deployed as intended. The public interface may use browser session storage to remember that you dismissed a notice; this value ordinarily disappears when the browser session ends.

We do not use third-party advertising or behavioral-analytics cookies. Some pages may request static resources from a content-delivery provider; that provider may receive customary network-request data such as your IP address and user-agent information. Browser privacy signals do not change processing that is necessary to deliver or secure the service. If our practices later include a legally recognized opt-out activity, we will honor applicable opt-out signals as required.

6. When We Disclose Personal Data

We may disclose personal data to:

  • Service providers: vendors and contractors that support hosting, databases, security, communications, content delivery, storage, maintenance, and professional services under appropriate restrictions.
  • Authorized investigative recipients: approved users, customer organizations, cybersecurity teams, law-enforcement agencies, regulators, counsel, or other recipients when disclosure is authorized and relevant to the reported matter.
  • Legal and safety recipients: NCMEC, law-enforcement agencies, courts, regulators, affected organizations, online service providers, or others when we reasonably believe disclosure is required by law or necessary to protect rights, safety, evidence, systems, or the public, as further described in our External Reporting & Referral Policy.
  • Transaction participants: advisers, counterparties, and successors involved in a financing, reorganization, merger, sale, transfer, insolvency, or similar transaction, subject to appropriate confidentiality and legal requirements.
  • Recipients you direct: a person or organization you authorize us to contact or share with.

We do not permit a service provider to use covered personal data for its own targeted advertising. Public case-share links are created only by authorized users, are time-limited, and may also use passwords or access-count limits; anyone who receives a valid share link may be able to view the shared content until it expires or is revoked.

7. Retention

We retain personal data only for as long as reasonably necessary for the purposes described here, including active investigations, evidence integrity, account administration, security, dispute resolution, legal obligations, and enforcement. Retention can vary based on data type, sensitivity, case status, contractual requirements, legal holds, backup cycles, and administrator configuration.

Current operational defaults include a seven-day request-telemetry window, 30-day rotating server logs, and 90-day security audit logs. Standard authenticated sessions are designed to last up to 24 hours, and elevated server-management verification lasts up to 30 minutes. Authorized public shares are configured to expire between one and 720 hours. Administrators may shorten or extend configurable periods where permitted and necessary.

Reports, evidence, API requests, account records, case files, and legally significant audit records may be retained longer while active or when needed for an investigation, security, contractual duty, legal claim, preservation request, or applicable law. When data is no longer required, we delete, de-identify, or securely dispose of it where reasonably feasible; residual copies may remain temporarily in protected backups.

8. Security and Processing Location

We use administrative, technical, and physical safeguards designed for the nature of the data, including encryption in transit when correctly deployed behind HTTPS, authenticated encryption for protected data at rest, hashed credentials, access controls, role-based permissions, request limits, audit logging, protected credential storage, and restricted administrative functions.

Form data is necessarily processed in plaintext by the receiving application before protected fields or evidence are encrypted for storage. No system is completely secure, and we cannot guarantee that unauthorized access, loss, or misuse will never occur. If you believe data or credentials have been compromised, contact us immediately.

The service is operated from the United States. If you submit data from another jurisdiction, the data may be transferred to and processed in the United States, subject to applicable law and contractual safeguards.

9. Your Privacy Rights

Depending on where you live and subject to legal exceptions, you may have the right to confirm whether we process your personal data; access it; correct inaccuracies; delete data you provided or that we obtained about you; and obtain a portable copy. You may also have rights to opt out of targeted advertising, sale of personal data, or certain profiling. We do not currently engage in those opt-out activities.

To submit a request, email administration@odfsec.org with the subject Privacy Request, call +1 918-297-8696, or write to the address below. Describe the right you want to exercise and the service or submission involved. We will use reasonable steps to verify your identity and authority. An authorized agent may submit a request when permitted by law, but we may require proof of authorization and identity.

Where applicable, we will respond within 45 days, subject to a legally permitted extension with notice. We may deny or limit a request when an exception applies, including evidence preservation, security, fraud prevention, legal claims, another person's rights, or inability to verify the request. We will not discriminate against you for exercising an applicable privacy right.

To appeal a denied request, email the same address with the subject Privacy Appeal within 60 days and explain why you believe the decision should be reconsidered. We will provide a written appeal response within the period required by applicable law. Texas residents may contact the Texas Attorney General if an appeal is denied.

10. Children's Privacy

The service is not directed to children under 13, and we do not knowingly collect personal data directly from a child under 13. Account, API-request, and evidence-submission features are for adults with legal authority. A parent or guardian who believes a child provided personal data should contact us so we can investigate and take appropriate action.

Users between 13 and 17 may use a permitted public feature only through, or with authorization from, a parent or legal guardian and should not submit sensitive evidence.

11. Changes and Contact

We may update this policy as our services, laws, or practices change. We will post the revised policy with a new effective date and provide any additional notice or consent required by law. Review this page periodically for the current version.

Onetrak Digital Forensics LLC
5900 Balcones Dr., STE 23284
Austin, TX 78731
United States
administration@odfsec.org +1 918-297-8696 (USA Hotline)