This Privacy Policy explains how Corporate Systems Associates, Inc. (“Corporate Systems Associates,” “we,” or “us”) collects, uses, and protects information when you use the eFileIQ website and our CPSC eFiling service (the “Service”). It applies to information we handle on behalf of the businesses that use the Service and their authorized users. Capitalized terms not defined here have the meaning given in our Terms of Service.
Roles and responsibilities
For Customer Data (the products, reports, certificates, and related records your company uploads to the Service), your company is the data controller and we act as processor on your company’s documented instructions. For Account information and demo and contact requests, we act as data controller and process that information as described below.
Information we collect
- Account information — your name, email address, company name, and role, provided when your account is created or when you accept an invitation to join a company account.
- CPSC credentials — the CPSC eFiling API token and secret your company connects so the Service can file on its behalf. These are encrypted at rest in a FIPS 140-2 Level 2 hardware-backed key vault, are never displayed back to you after entry, and are never shared or used for any other company’s filings.
- Compliance data (Customer Data) — the products, factories, laboratory test reports (including uploaded PDFs), certificates, and related records you add to the Service. The contents of your uploaded reports typically include names and contact information for laboratory technicians and signatories, which you represent you are entitled to share with us.
- Email-intake data — if your company enables the email-upload feature, we receive laboratory reports at a tenant-specific inbound address, together with the sender email address, subject line, timestamp, and message identifier. This traffic is delivered through our inbound email subprocessor (Mailgun).
- Demo and contact requests — the name, company, email, phone number, and message you submit through our demo or contact forms are delivered to
contact@efileiq.comand processed on our own infrastructure. - Security and usage data — sign-in events, IP address, browser and device information, and a tamper-evident audit trail of actions taken within your account. Audit records are hash-chained so tampering is detectable.
How we use information
- To operate the Service — reading your laboratory reports, helping prepare Children’s Product Certificates (CPCs), General Certificates of Conformity (GCCs), and CPSC disclaim filings, and submitting filings to the CPSC Product Registry at your direction under your company’s own CPSC account.
- AI processing — to extract structured fields from uploaded reports, classify certificate types, and answer in-app assistant queries, we transmit relevant portions of your reports to our AI subprocessor, currently Anthropic PBC, via Anthropic’s Claude API. Anthropic does not use Customer Data submitted through its API to train its models. AI-generated outputs are provisional and require your review before any filing.
- To secure accounts — including authentication (via Microsoft Entra External ID), protection against automated attacks, and audit logging.
- To respond to demo, sales, and support requests, and to send transactional messages about your account.
- To maintain, troubleshoot, and improve the Service, and to comply with our legal obligations.
We do not sell your data, and we do not share it for cross-context behavioral advertising. Neither of these constitutes a “sale” or “sharing” of personal information as defined by the California Consumer Privacy Act. We never use one company’s Customer Data for the benefit of another.
Data isolation
The Service is multi-tenant by design. Every record is scoped to the company that owns it, sensitive credentials are encrypted in a hardware-backed key vault, and no customer can access another customer’s data. Our staff do not have standing access to your Customer Data; any support access is explicit, limited in time, and recorded in an audit log.
Where data is stored and how it is shared
The Service is hosted on Microsoft Azure, with Customer Data processed and stored in Azure regions located in the United States. Uploaded documents are held in private object storage; structured data is held in our managed database; secrets are held in a hardware-backed key vault.
We share data only with:
- (a) the U.S. Consumer Product Safety Commission’s eFiling system, at your direction and using your company’s own CPSC API credentials;
- (b) the customs broker or other recipients your company designates, when your company exports filed-certificate reference information for a shipment; and
-
(c) service providers (subprocessors) that help us operate the Service — each contractually bound to use the data only to provide their service to us. Our current subprocessors include:
- Microsoft Azure — hosting, storage, database, key vault, service bus, communication services (for outbound transactional email), and application insights;
- Anthropic PBC — AI-based extraction and assistant features via the Claude API;
- Mailgun — inbound email intake (when your company enables the email-upload feature).
A current subprocessor list is maintained on our Subprocessors page. We will provide reasonable prior notice before adding a new subprocessor that materially changes how Customer Data is processed.
We do not sell or rent personal information, and we do not share it for cross-context advertising.
Security
We protect data using industry-standard measures, including:
- Encryption in transit with TLS 1.2 or higher;
- Encryption at rest with AES-256 across storage, database, service bus, and application logs;
- Hardware-backed key vault (FIPS 140-2 Level 2) for secrets and CPSC credentials;
- Multi-factor authentication through our identity provider;
- Protection against automated login attacks including rate limiting;
- Tenant isolation enforced in code and verified by automated testing;
- Tamper-evident audit logging with hash-chained records;
- Regular security review of infrastructure and dependencies.
Additional detail, including our responsible-disclosure process, is available on our Security page.
No system is perfectly secure. If we become aware of a security incident that affects the confidentiality or integrity of your Customer Data, we will notify your account’s administrative email without undue delay and as required by applicable law.
International data transfers
The Service is operated from and hosted in the United States, and your data is transferred to and processed there. Where applicable data-protection law requires safeguards for international transfers — for example, for customers in the European Economic Area, the United Kingdom, or Switzerland — we rely on appropriate transfer mechanisms, such as the European Commission’s Standard Contractual Clauses and their UK and Swiss equivalents, which we will enter into with your company on request as part of its agreement with us.
Legal disclosures
We may disclose information where required by law, subpoena, or court order; to enforce our Terms of Service; or to protect the rights, safety, or property of our users, the public, or the Service. If Corporate Systems Associates, Inc. is involved in a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction under protections consistent with this policy, and we will notify you of any change in ownership.
Cookies
We use only essential cookies and short-lived access tokens issued by our identity provider (Microsoft Entra External ID) to keep you logged in, together with an optional “remember this device” cookie for multi-factor authentication. We do not use advertising or cross-site tracking cookies.
Retention and deletion
We retain your Customer Data while your account is active. You can delete products, reports, and uploaded documents at any time from within the Service.
After termination or cancellation, for a period of thirty (30) days we retain Customer Data so that, on your written request, we can make it available for export in a commonly used format (see Section 12 of our Terms of Service). Thereafter, we delete Customer Data in the ordinary course of operations, except records we are required to retain to comply with law, resolve disputes, or enforce our agreements. Your CPSC credentials are permanently deleted from the Service within thirty (30) days after termination or your written request, whichever is earlier. Security and audit logs are retained for a limited period for the purposes described above.
Notices and requests may be sent through our contact page or to privacy@efileiq.com.
Your choices and rights
You can update your account details, rotate your CPSC credentials, and change your password at any time in your account settings. Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, and to object to or restrict certain processing. To exercise these rights, contact us at privacy@efileiq.com and we will respond as required by applicable law. We will not discriminate against you for exercising them.
For personal information contained in Customer Data (for example, contact information for laboratory technicians or signatories printed in test reports you upload), we act as processor and will forward the request to the customer company on whose account the data resides.
Children
The Service is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with information, contact us and we will delete it.
Changes to this policy
If we make material changes to this policy, we will update this page and the “Last updated” date above and, where appropriate, notify your account email.
Contact
Questions about this policy may be directed to Corporate Systems Associates, Inc. through our contact page or to privacy@efileiq.com.