DirectorOS Privacy Policy
Effective date: June 13, 2026
This Privacy Policy explains how DirectorOS handles information when funeral homes, care centers, transport teams, crematory operators, administrators, and other authorized users use DirectorOS.
This document is intended as a practical policy draft for DirectorOS operations. It should be reviewed by qualified legal counsel before commercial use, customer onboarding, or publication as a final legal commitment.
1. Who We Are
DirectorOS is an operations platform for funeral home and death care workflows. The system helps authorized organizations manage case intake, custody tracking, QR-ledger events, service planning, prep service workflows, personal effects, communications, forms, calendar tasks, integrations, reporting, audit logs, and compliance evidence.
For most case and family information, the customer organization using DirectorOS is the controller or owner of the data. DirectorOS processes that data to provide the software, secure the platform, support authorized workflows, and maintain operational records.
2. Information We Process
DirectorOS may process the following categories of information:
- Account information: usernames, names, job titles, roles, email addresses, phone numbers, authentication status, session data, passkey/MFA records, and admin permissions.
- Case information: decedent name, dates, locations, next-of-kin details, service preferences, care center status, cremation or burial workflow details, prep service details, custody events, and related notes.
- Sensitive operational information: medical or hospice notes entered by users, initial condition analysis details, autopsy indicators, trauma observations, personal effects, custody transfers, and audit records.
- Communications: internal team messages, system-generated messages, family communication drafts, notes, and review history.
- Forms and files: uploaded intake documents, blank form templates, completed case forms, photos, PDFs, DOCX files, and related extracted field data.
- Integration data: information exchanged with configured services such as Passare, Trello, Coupa, Outlook, calendar providers, AI services, hosting services, or other tools enabled by the customer organization.
- Security and usage information: IP address, user agent, login attempts, failed login events, session events, audit logs, access review records, backup evidence, and system health records.
3. How We Use Information
DirectorOS uses information to:
- Provide and improve the DirectorOS platform.
- Authenticate users and enforce role-based access.
- Support case management, custody tracking, care center workflows, forms, tasks, services, communications, and reporting.
- Generate operational suggestions, summaries, draft messages, form-fill proposals, and workflow guidance through Atticus and related automation tools.
- Maintain audit logs, security logs, access reviews, compliance evidence, and chain-of-custody records.
- Troubleshoot, secure, back up, monitor, and support the service.
- Comply with legal, contractual, security, incident response, and customer support obligations.
DirectorOS does not use customer case records or family data for advertising.
4. Customer Control of Case Records
Customer organizations are responsible for deciding what case data is entered into DirectorOS, who may access it, how long it should be retained, and when it should be exported, deleted, or archived.
DirectorOS provides tools for role-based access, audit logs, case deletion with reason capture, privacy request tracking, evidence records, and export workflows to help customer organizations manage those responsibilities.
5. Sensitive and Decedent Information
DirectorOS is designed for death care operations and may contain sensitive decedent, family, health-adjacent, custody, and service information. Users should only enter information that is necessary for authorized business purposes.
Some customer organizations may have obligations under HIPAA, state privacy laws, funeral regulations, consumer protection rules, contractual duties, or professional standards. DirectorOS provides security and workflow tools, but each customer organization remains responsible for determining which laws apply to its own operations.
6. AI and Automation
DirectorOS includes Atticus and related automation features that may analyze case data, uploaded documents, messages, tasks, and operational context to help users work more efficiently.
AI-generated outputs are assistance tools. Users must review and approve case updates, communications, forms, service details, and other operational outputs before relying on them. DirectorOS should not be treated as legal, medical, regulatory, or professional advice.
Where external AI providers are configured, DirectorOS may send the minimum necessary prompt context to those providers to perform requested features. DirectorOS should be configured so that only approved providers and authorized workflows are used.
7. Sharing and Disclosure
DirectorOS may share information:
- With authorized users inside the customer organization.
- With service providers that host, secure, back up, monitor, or support the platform.
- With configured integrations selected by the customer organization.
- With AI providers used to power approved automation features.
- When required by law, legal process, security investigation, or to protect the rights, safety, or integrity of DirectorOS, users, customers, or affected individuals.
- As part of a business transaction, such as a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality protections.
DirectorOS does not sell customer case data.
8. Security
DirectorOS uses administrative, technical, and operational safeguards designed to protect customer data, including:
- Role-based workspace visibility and admin permissions.
- Session controls and secure cookie support in production.
- Passkey/MFA support.
- Tamper-evident audit logging.
- Encrypted uploads and backup handling where configured.
- Production secret and encryption key checks.
- Security Center visibility for owner/admin users.
- Access review and evidence workflows.
- Incident, vendor, privacy request, and policy registers.
No system is perfectly secure. Customers and users must protect account credentials, limit access to authorized personnel, use strong authentication, and report suspected security issues promptly.
9. Retention and Deletion
DirectorOS retains information as needed to provide the service, maintain security, support legal and compliance obligations, preserve audit trails, and follow customer instructions.
Customer organizations may request exports, corrections, deletions, or retention changes through authorized administrative workflows. Certain records, such as custody ledger events, audit logs, compliance records, and security events, may be retained where necessary to preserve operational integrity, legal evidence, or security history.
10. User Choices
Authorized users may be able to:
- Update profile information.
- Change passwords.
- Configure passkeys where enabled.
- Request admin review of access, data correction, export, or deletion.
- Ask the customer organization to review role permissions or workspace access.
Family members, representatives, or other individuals should contact the funeral home or customer organization responsible for the case record.
11. Children
DirectorOS is a business operations platform and is not intended for use by children. Users must be authorized by a customer organization.
12. Changes to This Policy
DirectorOS may update this Privacy Policy as the product, legal requirements, or security practices change. Material updates should be reviewed, approved, versioned, and communicated through appropriate customer or administrator channels.
13. Contact
Privacy questions should be directed to the customer organization responsible for the case record. DirectorOS platform privacy or security questions may be directed to: