Privacy and the access log
How photographs and personal files are protected, and what CommonLynk records about who looked at a record.
A register of people is the most sensitive thing a workspace holds, and CommonLynk treats it that way.
Photographs and personal files
A photograph attached to a person is never published at a guessable web address. It is stored outside the area the web server can reach at all, and every request for it is checked before a single byte is sent.
The check confirms that you are signed in, that the record belongs to your workspace, that your role may view registrations, that the record is one you are allowed to see, and that photographs are not hidden from your role. If any of those fails, the answer is that the file was not found rather than that you were refused, so nobody can learn what exists by asking.
What the access log records
CommonLynk keeps a record of who opened a person, household or establishment page, and who exported registration data. Two things are worth being precise about.
- It records which record was opened and by whom, never what the record contained. No field values are copied into the log.
- Only full record pages and exports are logged. Browsing a list, searching or looking at a dashboard is not.
Entries are deleted automatically after a set period. Settings, then Security, shows whether the log is switched on and how long entries are kept.
Emergency access
Where a member of staff needs to open a record outside their normal reach, CommonLynk asks them to type a reason first and then opens it for a limited time. That page confirms only that the record exists, the reason is kept, and the access appears in the log like any other.
Telling your staff
The access log is information about your own employees as well as about the people you serve. In most places you are required to tell your staff that it exists. The Security page says so plainly for that reason, and the wording there is a good starting point for your own staff notice.