Organization-scoped access
PostgreSQL row-level policies and application permissions restrict covered records to the current organization and authorized roles.
For procurement and data-protection review
An evidence-based overview of how Humanitarian Ops controls access to organizational and beneficiary information. This page distinguishes product controls from deployment choices, operating procedures and customer responsibilities.
PostgreSQL row-level policies and application permissions restrict covered records to the current organization and authorized roles.
Selected identifying fields are stored encrypted and revealed only through permission-aware, logged workflows.
Managed cloud and scoped self-hosted deployments support different infrastructure and residency requirements.
Verified product controls
Security is layered across the database, authentication, application permissions and selected operational workflows. The descriptions below avoid extending a specific control beyond the records and actions it covers.
Organization and role context are applied to covered product records and actions.
Authentication establishes the user session before protected application routes become available.
Selected sensitive actions create traceable records for authorized review.
Control coverage varies by workflow. Audit records are useful evidence, but this page does not describe them as immutable, universal or independently certified.
Sensitive humanitarian data
Beneficiary information receives additional controls because names, identifiers, contact details, locations and protection context can create direct risk for affected people.
Consent history can record method, witness, version and exceptions, while teams remain responsible for a lawful purpose and appropriate notice.
Names, identifiers, phone numbers, addresses, dates of birth, GPS, notes and household-head names are stored in protected fields using organization-specific key material.
PII reveal requires the relevant permission and a reason; the access event records the user, fields, time and stated purpose.
Beneficiary photos remain in private storage. Viewing requires permission and a reason, uses a short-lived link and creates an access record.
An authorized erasure workflow clears identifying beneficiary fields and witness identities while retaining non-identifying operational measures needed for reporting. The action and reason are logged.
Data lifecycle
Each needs a defined owner, documented scope and an agreed operational or contractual procedure.
Required periods are reviewed during implementation against program, donor, legal and safeguarding obligations. The customer remains responsible for approving the applicable schedule.
The in-product workflow addresses an individual beneficiary record. It removes protected identifying fields but intentionally retains non-identifying measures and the erasure audit event.
Organization-level export and deletion are handled as a separate, scoped service request. Required data, storage, legal holds, timing and verification must be agreed before action.
Hosting and residency
The applicable architecture, operating responsibility and data location depend on the deployment selected during procurement.
United Flows operates the agreed application environment. The hosting location, service boundaries and contractual terms are confirmed for the proposed deployment rather than assumed from this website.
A self-hosted deployment can be scoped where an organization needs control of its own infrastructure. Infrastructure security, operations, monitoring and recovery responsibilities must be allocated in the implementation agreement.
No named managed-cloud region or residency guarantee is published here. Procurement teams should request the location and responsibility details for their proposed deployment.
Shared responsibility
The exact split is documented for each deployment, but these responsibilities provide a practical starting point for review.
Procurement resources
Approved documents and deployment-specific answers are provided through the existing United Flows contact channel. Requests are kept separate from the sales tier form.
Published policy
Review the published United Flows privacy information.
Read the policyPublished policy
Review the currently published service terms.
Read the termsAvailable on request
Request the legally approved DPA for review. No draft agreement is presented as binding website content.
Request the DPAAvailable on request
Send your organization’s questionnaire and identify the deployment being considered.
Start a security reviewAvailable on request
Report a suspected vulnerability through the existing public contact channel with the subject “Responsible disclosure”.
Report a security issueAvailable on request
Raise a privacy, data-subject or organization-offboarding request and identify the organization concerned.
Submit a privacy requestUse the subject “Responsible disclosure” and include the affected URL or component, observed impact and safe reproduction steps. Do not include beneficiary data, passwords, access tokens or secret keys in the initial message. No response-time commitment is made on this page.