Legal

eFileIQ Privacy Policy

Last updated: July 3, 2026

This Privacy Policy explains how Corporate Systems Associates, Inc. (“Corporate Systems Associates,” “we,” or “us”) collects, uses, and protects information when you use the eFileIQ website and our CPSC eFiling service (the “Service”). It applies to information we handle on behalf of the businesses that use the Service and their authorized users. Capitalized terms not defined here have the meaning given in our Terms of Service.

Roles and responsibilities

For Customer Data (the products, reports, certificates, and related records your company uploads to the Service), your company is the data controller and we act as processor on your company’s documented instructions. For Account information and demo and contact requests, we act as data controller and process that information as described below.

Information we collect

How we use information

We do not sell your data, and we do not share it for cross-context behavioral advertising. Neither of these constitutes a “sale” or “sharing” of personal information as defined by the California Consumer Privacy Act. We never use one company’s Customer Data for the benefit of another.

Data isolation

The Service is multi-tenant by design. Every record is scoped to the company that owns it, sensitive credentials are encrypted in a hardware-backed key vault, and no customer can access another customer’s data. Our staff do not have standing access to your Customer Data; any support access is explicit, limited in time, and recorded in an audit log.

Where data is stored and how it is shared

The Service is hosted on Microsoft Azure, with Customer Data processed and stored in Azure regions located in the United States. Uploaded documents are held in private object storage; structured data is held in our managed database; secrets are held in a hardware-backed key vault.

We share data only with:

A current subprocessor list is maintained on our Subprocessors page. We will provide reasonable prior notice before adding a new subprocessor that materially changes how Customer Data is processed.

We do not sell or rent personal information, and we do not share it for cross-context advertising.

Security

We protect data using industry-standard measures, including:

Additional detail, including our responsible-disclosure process, is available on our Security page.

No system is perfectly secure. If we become aware of a security incident that affects the confidentiality or integrity of your Customer Data, we will notify your account’s administrative email without undue delay and as required by applicable law.

International data transfers

The Service is operated from and hosted in the United States, and your data is transferred to and processed there. Where applicable data-protection law requires safeguards for international transfers — for example, for customers in the European Economic Area, the United Kingdom, or Switzerland — we rely on appropriate transfer mechanisms, such as the European Commission’s Standard Contractual Clauses and their UK and Swiss equivalents, which we will enter into with your company on request as part of its agreement with us.

Legal disclosures

We may disclose information where required by law, subpoena, or court order; to enforce our Terms of Service; or to protect the rights, safety, or property of our users, the public, or the Service. If Corporate Systems Associates, Inc. is involved in a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction under protections consistent with this policy, and we will notify you of any change in ownership.

Cookies

We use only essential cookies and short-lived access tokens issued by our identity provider (Microsoft Entra External ID) to keep you logged in, together with an optional “remember this device” cookie for multi-factor authentication. We do not use advertising or cross-site tracking cookies.

Retention and deletion

We retain your Customer Data while your account is active. You can delete products, reports, and uploaded documents at any time from within the Service.

After termination or cancellation, for a period of thirty (30) days we retain Customer Data so that, on your written request, we can make it available for export in a commonly used format (see Section 12 of our Terms of Service). Thereafter, we delete Customer Data in the ordinary course of operations, except records we are required to retain to comply with law, resolve disputes, or enforce our agreements. Your CPSC credentials are permanently deleted from the Service within thirty (30) days after termination or your written request, whichever is earlier. Security and audit logs are retained for a limited period for the purposes described above.

Notices and requests may be sent through our contact page or to privacy@efileiq.com.

Your choices and rights

You can update your account details, rotate your CPSC credentials, and change your password at any time in your account settings. Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, and to object to or restrict certain processing. To exercise these rights, contact us at privacy@efileiq.com and we will respond as required by applicable law. We will not discriminate against you for exercising them.

For personal information contained in Customer Data (for example, contact information for laboratory technicians or signatories printed in test reports you upload), we act as processor and will forward the request to the customer company on whose account the data resides.

Children

The Service is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with information, contact us and we will delete it.

Changes to this policy

If we make material changes to this policy, we will update this page and the “Last updated” date above and, where appropriate, notify your account email.


Contact

Questions about this policy may be directed to Corporate Systems Associates, Inc. through our contact page or to privacy@efileiq.com.