SummaGuard Privacy Policy
SummaGuard is a product of SummaCore LLC.
Version: 1.0 Effective date: 2026-09-08 Last updated: 2026-09-06
1. Who We Are
SummaCore LLC ("SummaCore", "we", "us") is a Texas limited liability company. We operate SummaGuard, a software-as-a-service environmental, health, and safety (EHS) platform available at guard.summacore.com (the "Service"). SummaGuard helps employers manage incidents, near misses, corrective and preventive actions (CAPAs), inspections, OSHA 300/300A/301 recordkeeping and Injury Tracking Application (ITA) submissions, safety KPIs, and related notifications. The Service includes eva, an AI assistant that runs entirely on SummaCore-controlled, self-hosted infrastructure.
This Privacy Policy describes how we handle personal information in connection with the Service and our public website. It should be read together with the SummaGuard Subscription Terms, the Data Processing Addendum, and the Security Exhibit, which govern our contractual obligations to Customers. Those documents are provided to Customers as part of the subscription agreement; where a Customer has not yet entered into them, the commitments in this Policy apply on their own terms.
Questions: see Section 15.
In brief
- Your employer controls the safety records in SummaGuard; we process them on its behalf. For questions about your records, start with your employer (Section 2).
- We collect account, billing, and support information directly; everything else is Customer Data.
- We do not sell personal information, do not advertise, and do not use Customer Data to train any AI model (Section 5).
- Our anonymous reporting channel is built to carry no reporter identity (Section 3.4).
2. Our B2B Posture — We Process Data on Behalf of Employers
SummaGuard is a business-to-business service sold to employers ("Customers"). We have no consumer offering.
Almost all personal information in the Service — workforce rosters, incident and injury records, investigation and inspection findings — is entered and controlled by the Customer. For that data ("Customer Data"), the Customer is the controller/business and SummaCore acts as a service provider / processor on the Customer's behalf, under the instructions in the Data Processing Addendum. Each Customer's data is kept in its own separate database.
If you are an employee, contractor, or other individual whose information appears in a Customer's SummaGuard account, please direct any privacy question or request (access, correction, deletion, etc.) to your employer. We do not have the authority to act on Customer Data independently; we will assist the Customer in responding to your request as required by the Data Processing Addendum and applicable law. We do not verify, use, or disclose Customer Data except to provide the Service as instructed.
The limited information we control directly — Customer account and billing contacts, in-app support tickets, website visit data, and correspondence with us — is described below, and for that information SummaCore is the responsible party.
3. Information We Process (Notice at Collection)
3.1 Account data (we control)
Name, work email address, and role of a Customer's administrators and users, and the session information created when you sign in. Sign-in and authentication are handled by our identity provider (Section 7); your role and tenant assignment are stored and enforced in our own database. Billing contact details and subscription records are also account data we control. Payment card data is not part of this category — see Section 7.
3.2 Workforce roster data (Customer Data)
Employee, contractor, temporary-worker, and visitor names, titles, establishments/work locations, contact information, and — where the Customer uses our roster-import tool — additional identifiers such as a Human Resources Information System (HRIS) key. Some Customers also enter more sensitive identifiers (date of birth, gender, government identification numbers, and wage information) for specific state filings, such as non-subscriber workers'-compensation reporting; these fields are encrypted at rest and restricted to a narrower set of permissioned users than ordinary roster data.
3.3 Incident, injury, and safety records (Customer Data)
Incident and near-miss reports, investigation notes, CAPA records, inspection results, and OSHA 300/300A/301 form contents entered by the Customer. These records can include health-related details (nature of injury or illness, body part affected, treatment, hospitalization, physician and treatment- facility information, and days away or restricted) about identified employees, because that is what OSHA recordkeeping requires. Free-text fields (incident narratives, immediate actions, investigation notes, "what happened" descriptions) are encrypted at rest because free text can carry health information or a person's identity.
SummaGuard implements the privacy-case protections of 29 CFR 1904.29(b)(6)–(9), including name masking for privacy-concern cases. Employer OSHA injury and illness records are employment records maintained by the employer; SummaGuard is not a healthcare service, and we make no HIPAA compliance claims. See Section 11.4.
A record can include a photo or other file attachment uploaded as evidence. Attachments are stored on infrastructure we control, are subject to the same account-level access permissions as the record they are attached to, and are not automatically screened for content.
3.4 Anonymous-intake reports (Customer Data)
The Service offers an anonymous reporting channel through which workers can submit safety concerns or near-miss reports without identifying themselves. This channel does not require a name, login, or contact information; the Service is built so that a report submitted through this channel carries no reporter identity — the database itself rejects an anonymous report that names one — and we do not log or associate identifying network details (such as an IP address) with a submission made through this channel for the purpose of identifying the reporter. Because the report is free text, please avoid identifying yourself in the narrative if you do not wish to be identified: we do not remove identifying details you choose to write. We do not attempt to re-identify anonymous reporters, and we do not offer Customers tools to do so. This scoped non-collection statement describes the anonymous-intake channel specifically — it does not describe every other part of the Service, where a signed-in user's activity is, as with any web application, associated with their account.
As with any request to any website, technical details including your IP address pass through, and may appear briefly in, our network-security provider's and hosting platform's own operational logs (Section 3.7). We do not read those logs to identify reporters, and nothing in them is linked to your report in the Service.
If you use the Service's installable mobile app in a location with no signal, a report you submit can be queued on your own device until you are back online. That queue is encrypted on your device with a key that also stays on your device, and it is never uploaded until the report is sent.
3.5 CAPA action links
Some corrective actions are completed by a person who does not sign in — for example, a contractor asked to close out a corrective action. We send that person a single-use emailed link. The link itself expires 14 days after it is sent and cannot be reused once it has been used. The record of the corrective action, and the fact that the link was sent, used, or expired, is kept with the CAPA's audit history for as long as the underlying record is retained (Section 9).
3.6 Support tickets
If you submit a support request from inside the Service, we forward your name, work email, role, your organization's identifier, the screen and route you were on, and your browser and app version, together with the details you typed, to a support ticketing system we operate. SummaCore is the responsible party for the ticket record; the underlying issue you are describing may itself be about your organization's Customer Data.
3.7 Usage, audit, and log data
The Service keeps an append-only audit trail of user and API/automated-client actions within a Customer's account; audit-trail entries are Customer Data. Separately, our hosting platform keeps its own operational logs (timestamps, IP address, requested resource, browser/device information) for security, troubleshooting, and capacity planning. We use those operational logs only for that purpose.
3.8 Cookies and similar technologies
We use cookies and similar technologies only for session management, authentication, and security — for example, keeping you signed in and remembering your language or display preference. Our identity provider and our content-delivery/network-security provider may each set their own operational or security cookies as part of providing sign-in and edge protection. We do not use advertising, cross-site tracking, or analytics-for-advertising cookies, and we do not permit third parties to place tracking cookies through the Service. Because we do not engage in cross-site tracking, a browser's Do Not Track or Global Privacy Control signal has no additional effect on how the Service operates — we treat every visitor as if that signal were set.
3.9 Mobile devices and permissions
If you use the Service on a phone or tablet, the app asks your permission before using the camera or microphone — the camera to attach a photo to a record or inspection, the microphone for eva's voice feature. You can refuse or withdraw either permission in your device settings and still use the rest of the Service. We do not ask for, access, or track your device's location; a report's location comes from the site or the posted code you select.
3.10 Our public website
Our public website (summaguard.com) has no contact form, newsletter signup, or account creation; the ways to reach us are an email link and a link into the Service. We do not use advertising or analytics trackers on the website. The site loads its typefaces from a third-party font service, which receives your IP address in order to deliver those files, as it would for any website using that service.
4. Why We Process Information
We process personal information only to:
- Provide, operate, secure, and support the Service under our agreements with Customers;
- Authenticate users and protect accounts;
- Process subscription payments (once activated — Section 7) and manage the customer relationship (invoices, renewal notices, service announcements);
- Send transactional notifications the Customer configures (for example, incident alerts, CAPA due-date reminders, and CAPA action links);
- Maintain the audit trail and meet our security and legal obligations;
- Respond to support requests; and
- Improve the reliability and performance of the Service using operational logs and aggregate, non-identifiable usage statistics.
5. What We Do NOT Do
- We do not sell personal information. We do not share personal information for cross-context behavioral advertising. (These terms have specific meanings under California law; we do neither.)
- We do not use personal information for advertising of any kind.
- We do not use Customer Data — identifiable or otherwise — to train, tune, or improve any AI model. eva, the AI assistant included in SummaGuard, performs inference on SummaCore-controlled, self-hosted infrastructure. No Customer Data is sent to any third-party AI provider, because none is in our processing chain (Section 7a). This commitment is unconditional and is also stated in the AI Terms Exhibit and the Data Processing Addendum.
- We do not combine Customer Data across Customers, and we do not use one Customer's data for another Customer's benefit.
6. How We Disclose Information
We disclose personal information only to:
- The processors listed in Section 7, strictly to provide the Service;
- The Customer that controls the relevant Customer Data (including through the Service's export features);
- Professional advisers (lawyers, accountants) under confidentiality obligations, where necessary;
- Authorities or litigants when required by law, subpoena, or court order — where legally permitted, we will notify the affected Customer before disclosing Customer Data and will challenge overbroad demands where reasonable;
- A successor entity in a merger, acquisition, or sale of assets, subject to this Policy's commitments continuing to apply.
7. Processors We Use
All Service hosting is in the United States; encrypted backup copies stay in North America. We use the following categories of service providers to help us operate the Service:
| Category | What it does | Region |
|---|---|---|
| Identity provider | Authentication, session management, and sign-in security, with support for multi-factor sign-in | US |
| Cloud hosting provider | Application servers and database hosting, with a dedicated, separate database for each Customer | US |
| Transactional email service | Delivery of notifications, CAPA reminders, and CAPA action links | US |
| Business email and productivity suite | Our own correspondence with you, including replies to support and sales inquiries | US |
| Support ticketing system | A system we operate ourselves (not a third party) that holds the support-ticket content described in Section 3.6 | US |
| Content delivery and network security provider | DNS, content delivery, and network security in front of the Service | US |
| Payment processor | Not yet active — no payment data is processed today. When billing is turned on, your card details will be entered directly into pages served by the payment processor; we will not receive or store full card numbers. | US |
| Cloud backup storage | Encrypted backup copies of Service data, held on infrastructure we control and with cloud storage providers. Backups are encrypted before they leave our systems, with keys we hold. | North America (US-based providers) |
There are no AI processors. See Section 7a. The categories above are the current list. We describe our providers by category here; the named list is part of the Data Processing Addendum and is available to Customers and prospective Customers on request. Customers receive advance notice of a change and a right to object, as described in the Data Processing Addendum.
7a. eva — our self-hosted AI assistant
eva runs entirely on infrastructure SummaCore controls; no third-party AI company receives Customer Data through eva. eva can assist with drafting incident narratives, suggesting classifications, drafting investigation content, suggesting corrective actions, translating submitted text, and converting spoken narratives to text. A draft eva produces is never saved to a Customer's records until a person reviews and confirms it — eva does not decide recordability, activate a checklist, or file anything on its own. When you use eva's voice feature, your audio is processed in memory to produce a transcript and is not written to disk or to any database; only the fact that a transcription happened (not the audio or the transcript itself) is recorded in the audit trail.
We do not create or store biometric identifiers. eva's voice feature converts speech to text in memory; we do not build a voiceprint, and we do not use audio to recognize or verify who is speaking. Photos and other attachments are stored as uploaded; we do not process them to extract face, fingerprint, or other biometric geometry.
8. Security
We maintain administrative, technical, and physical safeguards appropriate to the sensitivity of workplace injury and illness data, including: a separate database for each Customer; encryption of sensitive fields at rest; encryption of data in transit (TLS); role-based access controls with least-privilege administration; an append-only audit trail of record changes; network-level restriction of production systems to authorized paths; and US-based hosting. The full description of our security program — including how our AI features are informed by the NIST AI Risk Management Framework — is in the Security Exhibit, which is incorporated into Customer agreements. A summary of our security program, including the controls listed above, is available to prospective Customers on request; the full Security Exhibit is provided as part of the subscription agreement. We do not currently hold a SOC 2 or ISO 27001 certification, and we do not claim one.
No system is perfectly secure. If we determine that a breach of system security has affected personal information we hold, we will notify the affected Customer without unreasonable delay, consistent with Tex. Bus. & Com. Code § 521.053 and other applicable breach-notification laws, so the Customer can meet its own notification duties. See also Section 11.3.
9. Retention and Deletion
| Category | Retention | Notes |
|---|---|---|
| Incidents, near misses, injuries, investigations, CAPAs, inspections (and their attached-file records) | 5 years after the calendar year the record covers, by default | Customer-configurable; a record under an active legal hold is not purged |
| Anonymous-reporting access codes, anonymous Q&A threads, and translation copies | Deleted with the record they belong to | Same 5-year default above |
| CAPA action links | The link itself expires 14 days after it is sent | The corrective-action record and its audit history follow the record's own retention, above |
| Roster-import files (raw uploaded file) | 30 days after the import is applied, and no later than 365 days regardless of status | — |
| Notification outbox (queued and sent messages) | 90 days | — |
| Audit trail | Life of the account | Append-only; not affected by the periodic purges above |
| Terms and Privacy acceptance records | Life of the account | Kept as evidence of acceptance for as long as the account exists; deleted with the account |
| Operational server logs | Only as long as needed for security and troubleshooting | — |
| Account and billing/subscription records | For as long as needed for the customer relationship, plus any period required by tax or accounting law | — |
| Encrypted backups | Up to about 40 days | Rolling; one offsite copy is write-protected for a fixed period and cannot be deleted early, so a record deleted from active systems can persist in an encrypted backup until it ages out |
Uploaded files. The periodic purge described above removes the record that references an attachment. An attachment's underlying file is deleted as part of the account-offboarding process described below, not on the same periodic schedule as the record it was attached to.
Ending an account. The Customer has a 60-day post-termination export window to retrieve its records using the Service's export tools — CSV export of the event register, KPI data, the OSHA 300 Log and the OSHA ITA upload files, and a printable OSHA Form 300A. Records outside those exports can be requested from us during the window. After that window, we delete Customer Data — including uploaded files — from active systems on our deletion schedule, allowing up to 40 additional days for the deletion to work through rotating encrypted backups, one of which is write-protected and expires on a fixed schedule rather than on request.
Important — OSHA retention is the employer's duty. 29 CFR 1904.33 requires employers to retain injury and illness records for five years. That legal obligation belongs to the Customer, not to SummaCore. Customers are responsible for exporting and retaining any records required by law before deletion occurs, as stated in the SummaGuard Subscription Terms.
OSHA access is also the employer's duty. 29 CFR 1904.35 gives employees, former employees, and their representatives a right to access the OSHA 300 Log and their own OSHA 301 report. That obligation belongs to the Customer; the Service's report views and exports are tools the Customer can use to meet it.
10. Your Rights and Requests
If you are an employee of a SummaGuard Customer, please contact your employer first — see Section 2. We will support your employer's response to your request as required by the Data Processing Addendum and applicable law.
For the account, billing, and support information we control directly, you may have rights to know, access, correct, or delete your personal information, depending on where you live. To make a request, use the contact information in Section 15.
Response timeframe. We aim to respond within a reasonable time, generally no more than 45 days after we receive a verifiable request. If we need longer, we will tell you why.
Verification. We verify a request using the email address on your account, or another reasonable method if you do not have an account. We may decline a request we cannot verify.
Your rights. For the information we control, you may ask us to confirm what we hold about you, provide a copy, correct it, or delete it. You may make a request through an authorized agent; we will ask the agent for proof that you authorized them. We will not deny you service, charge a different price, or provide a different level of service because you exercised a privacy right. If we decline a request, we will tell you why, and you may ask us to reconsider by replying to our response.
11. State Privacy Laws
11.1 California (CCPA/CPRA)
For Customer Data, SummaCore acts as a service provider as defined in Cal. Civ. Code § 1798.140(ag). We process that data only for the business purposes specified in our agreements, do not sell or share it, do not retain, use, or disclose it outside our contract with the Customer, and do not combine it with data from other sources except as the CCPA permits. California employees and job applicants whose data is in a Customer's account should submit CCPA requests (to know, delete, correct, etc.) to their employer; we will assist the employer in fulfilling verified requests as set out in the Data Processing Addendum. For the limited account and billing data we control, contact us directly (Section 15) and we will honor applicable rights.
11.2 Texas (TDPSA)
The Texas Data Privacy and Security Act generally does not apply to data processed in the employment context, and SummaCore likely qualifies for the statute's small-business treatment at the Service's current scale; nonetheless, we offer Customers TDPSA-style processor commitments contractually in the Data Processing Addendum, and we never sell personal data of any kind. Separately, individuals acting in an employment context are not "consumers" under that Act, so workforce and incident data fall outside it on that basis as well.
11.3 Texas breach notification
Regardless of TDPSA applicability, Tex. Bus. & Com. Code § 521.053 applies to the data we hold. We commit to notifying affected Customers of a breach of system security without unreasonable delay, and in any case consistent with applicable law, as described in Section 8.
11.4 HIPAA
SummaGuard is not a HIPAA covered entity or business associate in its ordinary use, and we do not claim HIPAA compliance. Employer OSHA 300/301 injury and illness records are employment records excluded from HIPAA's definition of protected health information (45 CFR § 160.103). The operative privacy regime for these records is OSHA's own privacy-case rule, 29 CFR 1904.29(b)(6)–(9), which the platform implements (including name masking).
11.5 Other states
State privacy laws — including those of Virginia, Colorado, Connecticut, Utah, Oregon, Montana, and Texas — largely exempt B2B and employment-context data or treat us as a processor. Where a state law grants rights over data in a Customer's account, requests should go to the employer, and we will assist per the Data Processing Addendum. The Service is offered in the United States and is not directed to individuals in the European Union, European Economic Area, or United Kingdom.
12. Children
The Service is a workplace tool for business Customers. It is not directed to children, and we do not knowingly collect personal information from anyone under 16 outside the employment records a Customer lawfully maintains (for example, records concerning workers under applicable youth-employment rules, which remain Customer Data under the Customer's control).
13. The Public Demonstration
SummaGuard's public demonstration site uses fictional people and fictional events. It runs on a separate database that contains no Customer Data.
If you sign in to try the demonstration, you are signed in as a shared demonstration identity through our identity provider, along with everyone else trying the demo at the same time. We keep no per-visitor record of what a visitor does in the demonstration beyond the operational logs described in Section 3.7 and our identity provider's routine session records for that shared identity.
The demonstration is read-only and is reset on a schedule, so nothing a visitor enters persists. Any backup copy made before a reset rotates out of encrypted backups on the same basis described in Section 9.
The demonstration is not the Service, and nothing entered there is treated as a report, an incident, or any other record under this Policy.
14. Changes to This Policy
We may update this Policy from time to time. For a material change affecting Customer Data, we will notify Customer administrators before the change takes effect, consistent with the Subscription Terms' 30-day notice for material changes. We will post the updated Policy at summaguard.com/privacy with a new effective date. The Data Processing Addendum controls over this Policy for Customer Data if they conflict.
15. Contact
SummaCore LLC 5900 Balcones Drive, Ste 100 Austin, Texas 78731
Privacy questions and requests: privacy@summacore.com Security reports: security@summacore.com
If you are an employee of a SummaGuard Customer, please contact your employer first (Section 2); we will support their response.
If you need this Policy in another format for accessibility reasons, email privacy@summacore.com and we will provide it.
SummaGuard is a product of SummaCore LLC.
Version History
- v1.0 — 2026-09-08 — First published version. Supersedes draft v0.1 (2026-07-07, never published). Changes from v0.1: scoped the anonymous-reporting non-collection claim to the anonymous channel specifically; named processors generically and added the business-correspondence email suite and our own support-ticketing system to that list; marked the payment processor "not yet active"; added a retention table (Section 9) with specific numbers per record category; and corrected the attachments and backup-retention wording to match what the Service actually does today, rather than an idealized description; described backup copies held with cloud storage providers and the write-protected copy; stated the export tools that exist rather than a general export promise; added a demonstration-site section; added an in-brief summary, mobile-permission and public-website subsections, a biometric statement, an expanded rights paragraph, the OSHA access-rights note, the TDPSA employment-context basis, and a stated position on security certifications.