Back to home

Privacy Policy

Last updated: July 2, 2026

In short

This policy explains what personal information Incidenta collects, how we use and protect it, and the choices you have. For our school products, the school is the data controller and Incidenta acts as its service provider.

On this page

1. Introduction & Scope

Incidenta, a product of Baind LLC (“Baind”, “we”, “us”, or “our”), provides software that helps schools and educational institutions receive, investigate, and resolve safety and safeguarding incidents. This Privacy Policy describes how we handle personal information across two contexts: (a) our public website at incidenta.co, including the waitlist (the “Website”); and (b) the Incidenta application provided to institutions at app.incidenta.co (the “Service”).

Incidenta is currently offered on an early-access / beta basis. Features, data practices, and this policy may evolve as the Service matures; we will update the “last updated” date when we make material changes.

This policy is provided in English and Spanish. If there is any conflict between versions, the English version governs unless local law requires otherwise.

2. Our Role: Controller and Processor

Our responsibilities depend on the data involved:

  • Website & waitlist data — Incidenta is the data controller. We decide why and how this information is processed.
  • Service (institutional) data — The school or institution is the data controller. Incidenta acts as a processor / service provider, handling personal information only on the institution’s documented instructions and to provide the Service. In the United States, we act as a “school official” with a legitimate educational interest under FERPA where applicable; under Colombia’s Ley 1581 de 2012, we act as the “encargado del tratamiento.”

If you are a student, parent, staff member, or other individual whose information is in the Service, your school is responsible for it. Please direct privacy requests to your institution; we will support them in responding.

3. Information We Collect

Website visitors and the waitlist

  • Waitlist details you submit: institution name, your role, your institutional email, any free-text role description, and your selected language.
  • Usage and device data collected through analytics, such as pages viewed, approximate location derived from IP, browser and device type, and referring links.
  • Bot-mitigation signals used to protect our forms from automated abuse.

Service data (processed on behalf of institutions)

When an institution uses the Service, we process information it and its users provide or generate, which may include:

  • Account and identity data for authorized users (name, email, single sign-on profile, organizational role) managed through our authentication provider.
  • Student roster information imported by the institution (such as name, grade, and a student identifier).
  • Incident reports and case records, including descriptions, dates, locations, status, and details of people involved — which may include names, contact details, ages, grades, and notes.
  • Categories and circumstances of reported incidents (for example harassment, cyber-harassment, or abuse allegations).
  • Files and evidence uploaded to a report or case (documents, images, audio, or video).
  • Staff training progress and completion records.
  • In-app notifications and the operational logs needed to run, secure, and audit the Service.

Incident reports may be submitted anonymously where the institution enables that option; in that case we do not require the reporter to provide identifying details.

4. Sensitive Data & Minors

The Service is designed to handle sensitive information, including data about minors and allegations of harm. We process this information solely on behalf of, and under the instructions of, the institution.

  • FERPA (U.S.): Where the Service stores student education records, we handle them consistent with the institution’s obligations and use such records only to provide the Service.
  • COPPA (U.S.): For students under 13, the institution provides and is responsible for any consent required. Incidenta does not knowingly collect personal information directly from children for our own purposes.
  • Ley 1581 (Colombia): Information about minors and “datos sensibles” is processed with heightened care and only as instructed by the institution acting in the minor’s best interest.

We do not use sensitive or student data for advertising, profiling unrelated to the Service, or to train artificial-intelligence models.

5. How We Use Information

We use personal information to:

  • Provide, operate, secure, and improve the Website and the Service.
  • Respond to waitlist requests and communicate with you about access, updates, and support.
  • Maintain audit trails, prevent fraud and abuse, and protect the rights and safety of users.
  • Comply with legal obligations and respond to lawful requests.

We do not sell personal information, we do not use it for third-party advertising, and — as of the date of this policy — the Service does not use artificial-intelligence or large-language-model providers to process your data.

7. Service Providers & Subprocessors

We rely on a small number of vetted providers to deliver the Website and Service. They process personal information only as needed to perform their function and under contractual confidentiality and security obligations.

ProviderPurposeLocation
WorkOSAuthentication, identity, and access (Service)United States
ConvexApplication database and file/evidence storage (Service)United States
ResendTransactional and notification emailUnited States
VercelWebsite and application hostingUnited States
PostHogWebsite product analyticsUnited States / EU
BotId (Vercel)Bot detection and form-abuse preventionUnited States

Because these providers are based primarily in the United States, using the Website or Service may involve transferring personal information to the United States. We will maintain an up-to-date list of subprocessors and provide it to institutions on request.

8. Cookies & Similar Technologies

  • Website: a language-preference cookie (“incidenta-locale”) and local storage, plus analytics cookies/identifiers from PostHog.
  • Service: a secure, http-only session cookie set by our authentication provider, and a small cookie that remembers interface preferences (such as sidebar state).

We do not use advertising or cross-site tracking cookies. You can control cookies through your browser settings; disabling some cookies may affect functionality. For a full, itemized list of the cookies we use, see our Cookie Policy.

9. Data Retention

We retain waitlist information until you ask us to delete it or until it is no longer needed for the purpose collected. Service data is retained for the duration of the institution’s use of the Service and for a reasonable period afterward, then deleted or returned according to our agreement with the institution and applicable law.

Some records (such as incident case files) may be retained longer where the institution’s legal or safeguarding obligations require it. Deletion requests are honored as described below; if you have questions about a specific retention period, contact us.

10. Your Privacy Rights

Depending on your location, you may have rights to access, correct, delete, export, or restrict the processing of your personal information, to object to processing, and to withdraw consent. Colombia’s Ley 1581 also recognizes the right to know, update, and rectify your data (“habeas data”).

  • Website & waitlist data: email contacto@incidenta.co and we will respond as required by law. We currently handle these requests manually.
  • Service data: please contact your institution, which controls the data. We will assist the institution in fulfilling your request.

We will verify your identity before acting and will not discriminate against you for exercising your rights.

11. Security

We use technical and organizational measures designed to protect personal information, including encryption in transit, role-based access controls, secure http-only session handling, and reputable infrastructure providers. No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a personal-data breach affecting your information, we will notify the affected institution without undue delay and, where we are the controller, notify affected individuals, consistent with FERPA, applicable U.S. state student-privacy laws, and Colombia’s Ley 1581.

12. International Data Transfers

Incidenta and its providers are based primarily in the United States, and your information may be processed there. Where we transfer personal information across borders, we rely on appropriate safeguards, such as standard contractual clauses or the institution’s authorization, as required by applicable law.

13. Children’s Privacy

The Website and the Service are intended for use by institutions and adults acting in a professional capacity. We do not offer accounts directly to children, and we do not knowingly collect personal information from children for our own purposes. Where the Service contains information about students (including minors), it is provided and controlled by the institution.

14. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will revise the “last updated” date and, where appropriate, provide additional notice. Your continued use after changes take effect constitutes acceptance of the updated policy.

15. Contact Us

For privacy questions or to exercise your rights, contact Baind LLC at contacto@incidenta.co. If your question concerns information held in the Service on behalf of an institution, please also contact that institution.

This document is provided for general information and is not legal advice. Please review it with qualified counsel before relying on it.

Questions? Contact us at contacto@incidenta.co