Security & Privacy Overview
Mise Logic Lab holds health and safety records for restaurants: temperature logs, checklists, incidents, training, and written policies. Some of it is sensitive, and some of it may be read back years later by a regulator. This page sets out plainly how we protect it.
Last reviewed September 2026
Where your records live
- Records are held in a managed cloud database with automatic daily backups and point-in-time recovery.
- Data is encrypted in transit (TLS 1.2+) and encrypted at rest on disk.
- Files you attach — photos, safety data sheets, signed forms — go to private storage that is never publicly listable; each file is served through a short-lived, signed link only to someone already signed in with permission to see it.
Who can see what
- Every table enforces row-level access rules in the database itself, not just in the app. A request that isn't yours returns nothing, even if someone crafted it by hand.
- Each restaurant account only ever sees its own locations, team, logs and policies.
- Violence and harassment reports are stricter again: only people you designate as confidential handlers can open one. A reporter can name a manager who must be excluded, everyone else sees only that a report exists, and every single view is written to an access log.
- Administrative actions taken by Mise Logic Lab staff are recorded in an audit trail with who did it, to which account, and when.
Sign-in and accounts
- Sign-in uses email and password or Google. Passwords are stored only as salted hashes — nobody at Mise Logic Lab can read them.
- Sessions use short-lived tokens that refresh automatically and are revoked on sign-out.
- Password reset never reveals whether an email address has an account, so the form can't be used to discover your staff.
- Repeated failed sign-ins are rate limited.
Your data is yours
- We do not sell data, and we do not share your records with any third party for marketing.
- You can print or export your logs, policies, training records and incidents at any time — including after a trial ends.
- If you close your account, we delete your records on request; backups age out on their normal retention cycle.
- We collect the minimum personal information needed for health and safety records: name, work email, role, and the training or incident detail you enter.
Reliability and incident response
- The service runs on redundant, managed infrastructure with automated monitoring.
- The app keeps working offline in walk-ins and cold rooms, then syncs when the device is back on the network — nothing is lost if the signal drops.
- If we ever discover a breach affecting your data, we will notify the affected account without undue delay, describe what was involved, and tell you the steps we have taken.
Your responsibilities
- Use individual accounts rather than one shared login, so records show who actually did the check.
- Remove people in the team list when they leave.
- Keep the confidential-handler list short and current — those are the only people who can open sensitive reports.
Questions or a security concern
Write to security@miselogiclab.com. We answer security questionnaires from partners and associations, and we respond to reported vulnerabilities within two business days.