Home / Data Protection and Security Policy
Data Protection and Security Policy
How does RTI Scheduler handle account and task security?
Understand the controls in the personal scheduling tool, the hosting details awaiting confirmation, and how to report a concern.
Last updated:
Related information: Terms of Service and Privacy Policy.
What data does this Security Policy cover?
This policy covers the independent RTI Scheduler website at rtischeduler.com.co, managed by Raza Mehdi. It explains how the personal planning tool stores tasks and what you can do to protect your account.
The tool handles account details and personal tasks. It is not presented as a verified system for confidential student records, patient information, or organization workspaces. Do not enter those records in task names or details.
Where are account details and tasks stored?
Guest tasks are stored in local storage in the browser you use. Anyone with access to that browser or its stored website data may be able to read them. The tool does not add encryption to guest task storage.
Account tasks are stored as task data linked to the user in the WordPress database. The scheduler does not encrypt task records separately before saving them. Protection of the database and any backup copies depends on the hosting configuration. Contact the owner if you need details about those protections before using an account.
The website owner and administrators with database or backup access may be able to access account information and saved tasks when maintaining the website.

How should I protect information during transmission?
Use the website’s HTTPS address and check for browser security warnings before entering account information. HTTPS can protect information in transit when the connection and certificate are valid. It does not by itself encrypt the information stored in a database or on your device.
If your browser reports a connection problem, stop entering information and contact the owner.
How does the tool check access to account tasks?
Accounts use WordPress registration and sign in. You must be signed in to save, load, or delete account tasks. Each request uses the task list associated with your account.
Task requests include a WordPress request token, commonly called a nonce, to help protect against certain unwanted requests. A token alone is not an access control or a guarantee of security. The account check and selection of the current user’s records remain essential.
The registration form requires a password of at least eight characters. The scheduler itself does not provide multi factor authentication, organization roles, or a separate login attempt limiter. Additional protections depend on the WordPress and hosting configuration.

What can I do to protect my schedule?
Use a unique password and keep it private. Do not reuse a school login password on this independent website. Sign out on shared devices and protect your device with its own access controls.
Keep confidential information out of task details and email messages. Clearing browser storage may remove guest tasks, so keep another copy of important planning information. No online service or storage method can guarantee absolute security.
Where can I ask about hosting and backups?
Contact Raza Mehdi if you need information about hosting, database protection, backup schedules, retention, or recovery before storing tasks in an account.
This page does not certify the website for sensitive records or promise a particular backup, monitoring, or security audit service. Keep a separate copy of important plans and avoid entering confidential information.

How can I report a security concern?
Email rtischeduler7@gmail.com with the affected page, what you observed, and when it happened. Do not exploit a suspected issue, access someone else’s account, or run disruptive testing without written authorization.
Do not send passwords, authentication cookies, access tokens, or confidential records. Remove sensitive details from screenshots. If account access appears compromised, stop using the affected session and contact the owner for help.
What happens after a security issue is reported?
The owner can review the report and determine what investigation or protective action is needed. Actions may include restricting access, correcting affected code, or seeking hosting support, depending on the issue.
Any notification obligations depend on the incident and applicable law. This page does not promise a response deadline, certify an incident response program, or guarantee that all incidents can be prevented.

How can I delete tasks or ask about backups?
Use the scheduler’s delete option to remove a task from the current list. Clearing local storage removes guest data from that browser but does not remove an account’s saved tasks.
For account deletion or questions about backup copies and retention, email the owner. Signing out is different from deleting an account. Read the Privacy Policy for the account information request process.
How will security information be updated?
This page will be revised as the implementation or confirmed hosting practices change. The update date identifies the current version of the statement; it is not the date of a security audit.

Who can I contact about data security?
Contact Raza Mehdi with a security question, a suspected vulnerability, or a request for information about the hosting and storage practices.
Raza Mehdi
6242 Rufe Snow DrFort Worth, Texas 76148
United States