🏪 Serving Georgia local governments & authorities — independent guidance for O.C.G.A. § 36-81-7 audit & agreed-upon-procedures compliance
⚠️

Draft template — not yet reviewed by an attorney

This policy was drafted to accurately describe how this site’s systems actually work, but it has not been reviewed by legal counsel. Because this site collects government financial records and personal information (including data that may contain Social Security numbers in payroll documents), it should be reviewed by an attorney before you rely on it as your organization’s official privacy policy — particularly for Georgia Open Records Act and data breach notification considerations.

What we collect

Contact form

When you submit the form on our Contact page, we collect your name, entity/local government name, email address, role, and message. This is stored in our database and is not readable through any public interface — only Georgia Audit Ready staff can view submissions.

Client Portal accounts

Creating a Client Portal account collects your name, email address, password (stored as a one-way cryptographic hash, never in plain text), and your organization’s name and entity type (city, county, authority, or special district).

Documents you upload

Files you upload to the Client Portal — financial records, payroll data, and other audit-preparation documents — are stored as you provide them. These may contain sensitive information, including Social Security numbers in payroll records. We do not inspect, scan, or analyze the content of uploaded files; they are stored and retrieved as opaque files.

Local browser storage

The compliance checklist on our Resources page and your audit-threshold results are saved only in your own browser’s local storage — this data is never transmitted to us and stays on your device until you clear it.

How your data is protected

Where your data lives

Our database, authentication, and file storage are hosted by Supabase (backed by AWS infrastructure in the United States). This website is hosted by Vercel and/or GitHub Pages. We do not sell, rent, or share your information with third parties for marketing purposes.

Data retention

We currently retain Client Portal documents and contact form submissions until you ask us to delete them or your engagement with us ends. We do not yet have an automated deletion schedule tied to Georgia's local government records retention rules — if your organization needs documents removed, contact us and we will do so promptly.

Your choices

You can request a copy of your data, ask us to correct it, or ask us to delete it by emailing bernard@truenorth-inc.com. Client Portal users can delete their own uploaded documents at any time directly from the portal.

Cookies and analytics

This site does not currently use advertising cookies or third-party analytics/tracking scripts. The only client-side storage is the browser local storage described above, and standard authentication session storage used by the Client Portal.

Changes to this policy

If this policy changes, we’ll update the date at the top of this page. Material changes affecting Client Portal users will be communicated directly.

Contact

Questions about this policy or your data: bernard@truenorth-inc.com.