Controller and scope
Our Local Solution is currently an unincorporated website, not a separate legal entity. Before real submissions are accepted, this notice must identify the full legal name and service address of the individual operating it, or of a newly formed entity. That person or entity will be the Controller responsible for the processing described here.
The proposed Controller is based in Colorado, United States. Adults may apply from anywhere in the world, although a submission may be outside service scope. Counsel must determine whether EEA and UK representatives are required and publish their details before launch.
Information we collect
- Email, display name, account role, and verification information.
- Private case text, desired outcome, country and locality, optional region, neighborhood and encrypted exact address, affected people, timing, previous attempts, and safety-screen answers.
- Messages, files, assessments, private plan PDFs and integrity hashes, evidence, sources, stakeholders, tasks, approvals, disputes, correspondence, complaints, and outcomes.
- Separately drafted public fields, publication choices, ideas, and endorsements.
- Hashed sign-in and session tokens, passkey public credential material, hashed network identifiers, rate limits, request identifiers, and restricted audit records.
- Privacy-minimized automation input, draft output, citations, model and prompt versions, moderation, token, cost, and failure records.
- Case-stage timings, delivery outcomes, queue health, and other non-advertising service metrics.
A case may incidentally reveal sensitive information about you or someone else, including health, disability, race or ethnicity, religion, sexual life or orientation, citizenship, or alleged criminal conduct. Please omit it unless genuinely necessary. Unexpected sensitive material is restricted and requires a documented lawful-basis and necessity review before further use, outreach, or publication.
Sources
Information comes from submitters, account holders, contributors, authorized staff, parties replying to approved outreach, uploaded files, official or public research sources, and security or service operations. Where required, we will notify a person when information about them comes from someone else.
Purposes and proposed legal bases
- To receive and administer a requested case: steps requested before a service relationship, performance of that relationship, or legitimate interests where contract is unavailable.
- To secure accounts, prevent abuse, preserve evidence, and handle complaints: legitimate interests and applicable legal obligations.
- To communicate with you: service performance and legitimate interests.
- To contact an outside organization: case-specific permission where required and a documented necessity review.
- To publish a redacted case or contribution: specific, informed, versioned consent.
- To prepare automated research drafts: legitimate interests only after the DPIA and balancing assessment approve the use, or consent where law requires it.
- To retain or delete records: legal obligations and legitimate accountability, security, and legal-claims interests.
Optional outreach and publication consent are not bundled into general terms. You may refuse or withdraw them prospectively. We do not use solely automated processing to make decisions with legal or similarly significant effects.
Submission produces only a receipt and reference. Staff must first vet the application before automated research can run. A proposed plan then remains internal until staff inspects its exact private PDF and decides to proceed. Only that decision releases the plan and triggers its notice to you.
What becomes public
Nothing from a new case is public. An operator must prepare and approve separate public fields, complete redaction checks, and obtain your affirmative consent to the exact draft version. Changing the draft invalidates earlier consent.
Exact addresses, email addresses, private messages, original files, internal notes, stakeholder contacts, raw intake text, and private assessments are not public fields. You may request correction or withdrawal of public material.
Recipients and service providers
Authorized operators may access information only as needed. Approved providers may process data for application hosting, the dedicated MongoDB service, private object storage, email, security, backups, error reporting, and automated analysis. A third-party organization receives case facts only through a human-approved minimum-disclosure message after the necessary permission is recorded.
Providers proposed for contract review are DigitalOcean for Kubernetes, the dedicated MongoDB deployment, object storage, and backups; MXroute for email; and OpenAI for optional privacy-minimized moderation and draft analysis. An error-reporting provider has not been selected. The final notice and processor register must match what is actually enabled.
We do not sell personal data, share it for cross-context behavioral advertising, use it for targeted advertising, or run advertising analytics. A Global Privacy Control signal will be honored if a covered opt-out use is introduced in the future.
Automated research and OpenAI
If automated analysis is enabled, names, emails, recognizable phone numbers, exact street addresses, unit numbers, and attachments are omitted by default. Redacted problem text, country, locality, and a pseudonymous safety identifier may be sent. Additional geographic detail requires recorded operator approval.
Requests use the OpenAI API with store: false, moderation, structured output, and source capture. OpenAI states that API inputs and outputs are not used for model training by default unless the customer opts in. It also states that default abuse-monitoring logs may retain customer content for up to 30 days and that background Responses requests are retained to disk for roughly 10 minutes for polling before application-state deletion. Abuse-monitoring retention is separate. Therefore, store: false is a minimization measure, not a zero-retention promise. See OpenAI API data controls.
No real case data will be sent for automated analysis until the DPIA, processor contract, transfer mechanism, evaluation, and operator authorization are complete. Even then, submission alone does not start automated research. Staff vetting and a separate internal PDF review are required before a plan can be released, and you may dispute it.
International transfers
The service is proposed to operate from Colorado and use United States infrastructure. If you are elsewhere, expect your information to be processed in the United States and potentially in other approved provider or case-recipient locations.
Where required, transfers will use an applicable adequacy decision, verified Data Privacy Framework participation, approved standard contractual clauses, the UK International Data Transfer Agreement or Addendum, or another lawful mechanism. Provider participation and contractual coverage must be checked for the specific legal entity and service. Consent is not the default mechanism for routine infrastructure transfers.
The transfer assessment is not approved. The current email-provider contract, processor locations and agreements, EEA and UK representative decisions, and global jurisdiction analysis remain launch blockers. Request a copy or safeguard information at solutions@ourlocalsolution.org.
Retention
- Device-only intake drafts: up to 30 days, without contact details, exact address, or safety answers.
- Active cases: while the case is being worked.
- Closed cases and related work: normally 730 days from closure, then a human-reviewed deletion decision.
- Released or discarded quarantined mail: normally 90 days.
- Expired sign-in tokens, sessions, and passkey challenges: expiry plus no more than 30 days.
- Security buckets, audit evidence, and backups: only for their approved security, accountability, legal-hold, and recovery periods.
An active complaint, dispute, security investigation, or legal hold may pause deletion. Backup copies expire through their controlled rotation. Final periods require counsel approval.
Cookies and device storage
We use only storage necessary for secure operation, including session and CSRF-protection cookies and a device-local form draft. We do not use advertising cookies or nonessential analytics. The form draft can be cleared and expires automatically.
Security
Planned measures include encryption in transit, application-layer encryption for exact addresses and external contacts, private storage, short-lived file links, malware checks, role and object authorization, administrator passkeys, hashed tokens and network identifiers, throttling, redaction, approval gates, audit records, monitoring, backups, and restoration testing. No internet service can guarantee absolute security.
Your rights
Depending on your location, you may have rights to know, access, correct, delete, restrict or object, receive portable data, withdraw consent, opt out of covered sale, advertising or profiling, obtain human review, and complain to a regulator. We intend to offer access, correction, deletion, portability, withdrawal, and complaint review to all users where reasonably possible.
Email solutions@ourlocalsolution.org with the request and case reference, but not sensitive evidence. We may request proportionate identity or agent verification. We will respond within the legally required period—ordinarily one month under EU or UK rules and 45 days under the Colorado Privacy Act—and explain any lawful extension, exception, or refusal.
We will not unlawfully discriminate against you for exercising a privacy right, although deleting or withholding information may prevent an action that genuinely requires it.
If a Colorado request is denied, reply requesting an appeal. The appeal will receive a separate review where practicable and explain the available route to the Colorado Attorney General. EEA and UK users may complain to the supervisory authority where they live or work or where the alleged issue occurred.
Children, changes, and contact
The service is for adults aged 18 or older. If we learn that a child submitted personal data, we will restrict it, assess immediate safety, and delete it unless limited retention or referral is lawfully necessary.
An effective notice will show its version and date. Material changes will be notified where required, and data will not be used for an incompatible new purpose merely because the notice changed.
Privacy, rights, security, correction, complaint, and appeal contact: solutions@ourlocalsolution.org. Do not send sensitive case evidence by ordinary email.
Draft version 0.3 · Prepared 3 September 2026.