This document is a launch-readiness draft and is not legal advice. Gate Keypers Inc. will have it reviewed by qualified counsel.
Scope
GateKeypers is a product of Gate Keypers Inc., an Ontario corporation. We build a door for secure units in long-term care and memory care, and an admin portal where a care home reads what its own doors reported.
This policy covers two things: the public pages of this website, and that admin portal. It does not cover a care home's own records or the written agreement we sign with a care home, which governs the information we hold on its behalf.
The public pages collect nothing
There is no form, no sign-up, no account and no newsletter on the public pages. We do not run advertising or analytics, we set no cookies here, and we do not sell or share information with anyone for advertising.
Two small things are kept in your own browser and are never sent to us: whether you chose the light or the dark theme, and whether you dismissed the cookie notice. Clearing your browsing data removes both.
Getting in touch
The about page lists the three founders and links to their LinkedIn profiles. There is nothing to submit on this site. If you write to one of us, that message and our reply sit in the mailbox or the LinkedIn account you sent it to, and we keep them for as long as the conversation is useful.
Server logs
The site is hosted on Amazon Web Services, which records an ordinary web server log line for each request: the network address it came from, the page asked for, the time, and the browser user agent. We use those logs to keep the site up and to look into abuse, and we do not use them to build a profile of anyone.
What the admin portal holds
The portal shows a care home what its own doors reported: which reader, when, what the outcome was, and a reference to the person involved. Where the door can supply one, a person is stored as a salted reference rather than a name, and that reference cannot be turned back into a name without a salt that never leaves the database. Whether a key issued for reading the record also receives names is fixed when that key is created and cannot be changed afterwards.
Those records belong to the care home that runs the doors. We hold them on its behalf, under our agreement with it, and we act on its instruction. Portal accounts themselves are named staff accounts with a role, created by us at a customer's request.
Security
The database is private, inside AWS, with no public network path to it. The portal reaches it through one authenticated function, sign-in is handled by Amazon Cognito, and each read through an issued key is written to an audit log with the filters it asked for. No system is perfectly secure, so please do not send us sensitive information we did not ask for.
How long we keep things
Door records are kept for as long as the care home that owns them needs them, and are deleted when it tells us to. Correspondence is kept while the conversation is live. Server logs are kept for the retention period configured on the hosting service and then age out on their own.
Service providers
Amazon Web Services hosts the pages, the database and the sign-in service, and processes information on our behalf under its own terms. We do not send information to any other processor from this website.
Your choices
You can ask what we hold about you, ask us to correct it, or ask us to delete it, and we will answer. If the information you are asking about sits in a care home's door records, ask that home first: it decides, and we act on its instruction.
Changes
We update this page when what the site does changes. The date at the top of the page is when this wording last changed.
Contact
Questions about this policy go to the founders listed on the about page, and each of us answers. A dedicated privacy address will replace that here once there is one.