OpenMDT · Dispatch & Response

Privacy policy

Last updated: 28 September 2026

This policy explains how the OpenMDT iOS and Android apps and web dispatch portal handle personal information. OpenMDT supports organisations coordinating emergency responders, incidents and operational records.

Who is responsible for your information?

The organisation that provides your OpenMDT account decides why operational information is collected, who may use it and how long it needs to be retained. It is responsible for its incident and personnel records and should provide its own privacy information, including its lawful basis for processing and any health information. OpenMDT supplies the software and hosting used to process those records. For questions about the service or to route a privacy request, contact luke@coastmedic.org.uk. For an incident or employment-related request, contact your organisation’s manager first.

Information processed

How information is used

Information is used to authenticate users, coordinate dispatch, show relevant incident and responder locations, deliver notifications and messages, support offline working, record operational actions and protect the service. Your organisation determines its legal basis for operational processing, including any additional condition needed for health data. Permission to access your device location or notifications controls device access; it does not replace your organisation’s responsibility to identify an appropriate legal basis.

Who can see information?

Access is restricted by organisation, role and incident assignment. Managers can see their organisation’s operational records and on-duty responders. Responders see assigned incidents and relevant responding colleagues. Alerters are restricted to incidents they created and their assigned responders. Occupied unit locations and callsigns are visible on the team map to all accounts within the same organisation, including off-duty users and Alerters. One crew device supplies each unit’s position; the last received position remains visible while the unit has on-duty crew, and older positions are labelled stale. Private log entries are visible to their author and managers; shared entries are visible to eligible users in the organisation. Direct and group messages are provided to their intended recipients. Authorised service administrators may access server data where necessary to operate, support or secure the service.

Service providers and external services

The service uses a hosted server, Expo’s notification service, Apple Push Notification service and Firebase Cloud Messaging to deliver notifications. These services process device tokens and notification payloads; notifications may appear on a device’s lock screen according to its settings. OpenStreetMap supplies map tiles and can receive your IP address and the map areas requested. Address lookup uses Photon and Postcodes.io; address or postcode queries are sent to those providers without accompanying incident notes or user identities. Opening an external navigation app passes the selected destination to that app.

These providers may process information outside the UK. Their privacy terms and applicable transfer arrangements govern their processing. Contact us for information about the providers used for your organisation. OpenMDT does not include advertising or sell personal information.

Device permissions and offline data

You can manage location and notification permissions in your device settings. Refusing permissions can limit mapping, tracking or alerts. Signing off duty stops routine responder location sharing; signing out of the account is a separate action and is not a substitute for signing off duty. When connectivity is unavailable, the mobile app keeps local information and queues changes for later synchronisation. Other users cannot see queued changes until they reach the server. Downloaded policy documents and operational information may remain on the device while the account is in use. Protect your device with a passcode and report a lost device to your manager.

Security

The service uses HTTPS for communication, password hashing, access controls and an encrypted mobile operational cache. Messages are encrypted in server storage and decrypted by the service for authorised recipients; messaging is not end-to-end encrypted. These measures reduce risk but cannot guarantee absolute security. Keep your credentials private and install supported software updates.

Retention and deletion

Operational records are retained according to the organisation’s need to coordinate incidents, maintain audit and training records and meet applicable obligations. There is no universal automatic deletion period for incident, message, task, policy or account records in this version. The Log page’s 24-hour display window does not delete older records, and hiding or deleting a log from the interface does not necessarily erase retained database records or backups. Account closure, record deletion and retention requests should be sent to your organisation or the contact above, so they can be reviewed against operational and legal requirements. Ask your organisation for its retention schedule.

Your choices and rights

You can update your account details and password in the app or portal. Depending on the circumstances, you may have rights to access or correct your information, request deletion or restriction, object to processing and obtain a portable copy. Where processing relies on consent, you may withdraw it. Contact your organisation or luke@coastmedic.org.uk to request help or account deletion; identity verification may be needed. Some records must be retained for legal or operational reasons. You may complain to the UK Information Commissioner’s Office.

Public transport bookings

The public booking form sends the contact, journey and patient information you provide to Coast Medic Ambulance for review and transport planning. These details become a Scheduled incident, accessible to authorised managers and assigned personnel. Submission does not confirm a vehicle allocation. The form stores a temporary submission identifier in your browser to prevent duplicate bookings; it does not store patient details there.

Cookies, children and changes

The web portal uses an essential session cookie to keep users signed in. OpenMDT is intended for authorised organisation personnel and is not a service directed at children. Incident records may concern people of any age. Material changes to this policy will be reflected on this page with an updated date.

Return to OpenMDT