Skip to main content

Legal

LocateIQ Privacy Policy

Version: 1.0 · Effective: August 10, 2026

1. Scope

This Privacy Policy explains how LocateIQ handles personal information in connection with authenticated accounts, organization administration, case-management and investigative workflows, research, analysis, reporting, support, security, and related services. It covers information about users and organization representatives as well as information processed in organization-directed cases.

An applicable government contract, task order, agency addendum, data or security term, records requirement, provider restriction, or jurisdiction-specific notice may provide additional or different requirements and controls for a particular organization.

2. Our role depends on the processing activity

Government and investigative organizations generally determine the mission, legal authority, case purpose, subjects, users, and authorized use of case information processed through LocateIQ. For those activities, LocateIQ processes information under the applicable organization agreement and instructions and may act as a contractor, processor, service provider, or another role required by law.

LocateIQ separately determines certain purposes and methods for account administration, authentication, Service security, provider management, usage accounting, support, misuse prevention, legal compliance, and operation of the Service. LocateIQ remains responsible for those activities and for its own contractual obligations.

The organization remains responsible for its investigative authority, records obligations, required privacy or system notices, user approvals, and downstream use of information except where an agreement or law expressly assigns a responsibility to LocateIQ.

3. Information we process

The categories depend on the organization, user, enabled features, approved purpose, and authorized sources:

  • Account and contact information: name, work contact details, username, authentication records, identity-provider identifiers, role, organization, team or project, preferences, account status, and communications.
  • Organization and authorization information: agency or organization details, jurisdiction, administrator, professional role, verification materials, approved purposes, source entitlements, policy acceptance, and access status.
  • Case and subject information: case, matter, mission, incident, or legal-process references; names and aliases; identifiers; birth and citizenship information; contact information; addresses and locations; physical characteristics; associates and relatives; vehicles; business, facility, incarceration, immigration, allegation, or other investigative information; assignments; and status history.
  • Documents and media: reports, notes, PDFs, spreadsheets, images, profile photographs, public-web images, extracted content, metadata, and evidence or source references.
  • Research and provider information: licensed records, public records, public-web material, provider responses, search criteria, source and query metadata, provenance, and possible matches or relationships.
  • Sensitive information: government identifiers, Social Security number or partial SSN, driver's-license or vehicle information, citizenship or immigration status, racial or ethnic information, detailed location information, criminal allegations or history, and other sensitive information when authorized for an approved workflow.
  • Analyst and automated work product: annotations, validation decisions, source selections, confidence or status labels, facial-similarity results, comparisons, inferred relationships, summaries, suggestions, reports, and AI-assisted outputs. These outputs may contain personal information and may not be verified facts.
  • Usage, security, audit, and support information: IP address, browser and device details, session data, timestamps, searches, declared purpose, result access, exports, administrative actions, error diagnostics, usage and cost allocation, security events, support requests, and related communications.

4. Sources of information

Information may come from users and their organizations; organization-provided documents, systems, images, and instructions; licensed data and research providers; public records and official sources; publicly accessible websites and search services; identity, security, cloud, mapping, address, telephone, communications, AI, and other approved providers; or information derived through authorized use of the Service.

Public availability does not guarantee accuracy, authorize every use, or make a possible match, confidence indicator, or inferred relationship a verified fact.

5. How we use information

Subject to the applicable agreement, role, purpose, source, and authorization, LocateIQ uses information to:

  • create, verify, administer, authenticate, and secure users and organizations;
  • provide organization-directed case management, research, analysis, collaboration, reporting, export, and support features;
  • submit approved queries to authorized providers and return results with available provenance;
  • normalize, compare, deduplicate, organize, and display information;
  • generate and review workflow suggestions, summaries, similarity indicators, reports, and other enabled assistance;
  • enforce role, purpose, source, usage, retention, export, and disclosure restrictions;
  • allocate provider costs, measure usage, and administer organization agreements;
  • diagnose errors, prevent misuse, respond to incidents, and protect the Service;
  • process privacy, correction, records, preservation, legal, and security requests; and
  • meet contractual, records-management, audit, provider, legal, and regulatory obligations.

LocateIQ does not authorize organization case information to be used for targeted advertising, unrelated commercial profiling, or an unapproved development, demonstration, or model-training purpose.

6. AI-assisted features

Where enabled and authorized, AI-assisted features may receive selected case context, subject information, notes, provider records, public-web results, documents, prompts, or chat history to produce summaries, structured extractions, comparisons, proposed reports, suggestions, or other assistance. LocateIQ uses the AI provider selected for the applicable Service configuration.

AI outputs may be inaccurate, incomplete, biased, unsupported, or attributed to the wrong person. They are intended to assist qualified personnel and must not be treated as proof or used as the sole basis for an enforcement, legal, eligibility, biometric, or other consequential decision. Users may submit only information authorized by their organization, source terms, applicable law, and the enabled workflow.

7. Images and facial comparison

When an authorized facial-comparison feature is enabled, LocateIQ may send a source image and a candidate image to Amazon Rekognition to generate a similarity result. LocateIQ may store the result and, depending on the workflow, retain a qualifying candidate image and related source information for authorized review.

A similarity result is not an identification or proof that two images depict the same person. Authorized personnel must review image quality, provenance, context, applicable restrictions, and other evidence. Facial comparison may be limited or disabled based on organization, purpose, jurisdiction, source, subject type, or Service environment.

8. How information is disclosed

Subject to the applicable agreement, authorization, provider restrictions, and law, LocateIQ may disclose information to:

  • authorized users, administrators, reviewers, and recipients within the organization's approved workspace;
  • licensed-data and research providers when performing an authorized query;
  • approved cloud hosting, storage, security, identity, mapping, address or telephone validation, communications, support, AI, and image-analysis providers;
  • professional advisers, auditors, insurers, or transaction participants subject to appropriate duties;
  • courts, regulators, government authorities, or other parties when required by valid legal process, necessary to protect rights or safety, or otherwise permitted by law; and
  • another recipient at the organization's lawful direction or with appropriate authorization.

Case information is not made public merely because it is stored in the Service. A possible cross-case overlap, user mention, or technical integration does not automatically authorize cross-organization disclosure.

9. Cookies and browser storage

The Service uses session cookies, security tokens, and browser storage needed for authentication, session security, cross-site request forgery protection, user preferences such as display theme, and core operation. LocateIQ does not authorize case information to be used for cross-context behavioral advertising. Third-party resources loaded by a page may receive ordinary network and browser information as part of delivering the resource.

10. Retention, deletion, and legal holds

LocateIQ retains information according to the applicable organization agreement, approved organization or government records schedule, source restrictions, security and audit needs, preservation duties, and law. Different rules may apply to accounts, verification records, active and closed cases, provider responses, documents, images, AI inputs and outputs, exports, usage and cost records, audit events, support records, policy acceptance, and backups.

Deletion may be delayed or limited by a legal hold, records schedule, preservation duty, active dispute, security investigation, provider requirement, backup cycle, or other lawful exception. A legal hold suspends ordinary deletion; it does not create broader access. When deletion is authorized, LocateIQ deletes or deidentifies affected information from applicable active systems and addresses provider or backup copies under the governing agreement and retention process.

11. Security

LocateIQ maintains administrative, technical, and organizational measures designed to protect information against unauthorized access, use, alteration, disclosure, or destruction. Depending on the environment and feature, these measures include individual accounts, role and organization or project restrictions, authentication and session protections, encryption, secure transport, upload validation, rate limits, provider controls, security logging, audit records, and incident-response procedures.

No system can guarantee absolute security. Specific government, criminal-justice, controlled-information, cloud-authorization, or other security requirements apply only when identified in the governing agreement and approved for the applicable Service environment. Users must protect their accounts, devices, exports, and downstream disclosures and promptly report suspected incidents.

12. Privacy, access, correction, and records requests

Depending on the requester, information, governing organization, and applicable law, a person may have rights or administrative processes to request access, correction, deletion, restriction, or information about certain disclosures or processing. These rights and processes are not absolute. Investigative, law-enforcement, national-security, public-record, legal, confidential-source, safety, security, records-retention, and provider restrictions may limit a response.

Requests concerning an organization-directed investigation, agency record, or government system should ordinarily be submitted to the organization responsible for that matter. LocateIQ may receive and route a request to the organization, coordinate with an authorized source or records custodian, verify the requester's identity and authority, and retain a record of the request and outcome. A correction may require an annotation or source dispute rather than alteration of an original public record or licensed-provider response.

13. Minors and protected persons

The Service is not offered for use by children or for personal or consumer purposes. Information about a minor, victim, witness, protected official, confidential source, or other protected person may be processed only when necessary for an authorized matter and when the organization has the required authority and safeguards. Users must not use the Service to exploit, target, or circumvent protections for a minor or protected person.

14. Processing locations and restricted information

Information is processed in locations used by LocateIQ and its approved providers, subject to the applicable deployment, organization agreement, source terms, and legal requirements. The organization must not submit classified information, Controlled Unclassified Information, Criminal Justice Information, national-security-system information, or another specially restricted category unless the governing agreement expressly authorizes that category and the applicable Service environment.

15. Changes to this Policy

LocateIQ may update this Policy to reflect changes in the Service, law, security practices, provider requirements, or approved operations. Material changes will be communicated through the Service or an organization-approved channel and may require renewed notice or acceptance. A governing organization agreement may establish a different change or notice process for its scope.

16. Contact and requests

Authenticated users should contact their organization administrator or the LocateIQ support representative identified for their account. A person whose information appears in an organization-directed matter should ordinarily contact the organization responsible for that matter. LocateIQ will route a privacy, records, correction, or security request to the appropriate responsible organization or provider when applicable.