Uploading, fingerprinting, reserving, or assigning a TECRID does not itself publish the underlying report.
Privacy & data governance
Private by default.
Published by choice.
TECRID is operated by the Institute of Contaminant Standards (“ICS”). A TECRID can exist without its report or findings becoming public. Access follows the authority, scope, recipient, and purpose recorded for the evidence.
Controlled evidence moves only through an authorized grant, code, integration, or legal obligation.
ICS does not sell confidential evidence, use it for targeted advertising, or train general-purpose AI models on it.
Global analysis is governed to prevent an organization, product, lot, laboratory, or person from being identified.
Plain-language boundary
A private TECRID cannot be turned into a public record by a requester.
A laboratory, retailer, certification body, regulator, customer, or member of the public cannot change a private record's visibility merely by knowing its identifier, requesting it, paying ICS, or creating an account. Publication requires a separate authorized action. A legally required confidential disclosure does not change the TECRID to public or create a public resolver page.
01 / Scope and roles
ICS operates the registry; participating organizations control their evidence.
This policy covers tecrid.com, the TEC Registry service, its APIs, organization workspaces, evidence-routing tools, laboratory confirmation workflows, and related support and billing interactions.
ICS generally acts as the service operator for confidential evidence submitted by a laboratory, brand, supplier, retailer, certification body, research organization, or government program. The participating organization is responsible for having authority to submit the data and to name its permitted recipients. ICS separately determines how account, security, billing, registry-integrity, and de-identified network analytics data are processed.
A data-processing agreement, certification agreement, laboratory agreement, or enterprise contract may add protections and instructions. If a contract is more protective than this policy, ICS will follow the contract.
02 / Data we process
We collect what is needed to identify authority, preserve evidence, and operate the network.
Name, work email, organization, role, website, membership, issuer application, and contacts you invite.
Reports, findings, analytes, units, methods, sample and matrix descriptions, SKUs, lots, dates, report numbers, chain-of-custody context, and source-document metadata.
TECRIDs, hashes, signatures, public keys, confirmation events, version history, disputes, verification checks, grants, revocations, redemptions, and audit receipts.
Plan, billing status, transaction references, implementation briefs, support communications, and integration settings. Payment-card details are handled by the payment provider rather than stored by TECRID.
Authentication identifiers, IP and device information made available by infrastructure providers, request logs, API-key usage, error records, and security events.
Authority states, coverage summaries, exceptions, descriptive portfolio insights, and safeguarded aggregate trends. These are not automatic safety or compliance conclusions.
Sources include users and their organizations, issuing laboratories, authorized recipients, connected systems and APIs, identity and payment providers, and ordinary technical operation of the service.
03 / Public and private states
A TECRID is an identifier—not consent to disclose.
Access to one record, SKU, analyte set, or recipient does not authorize access to another. A recipient may not forward controlled evidence unless a separate authorization or applicable law permits it.
04 / How ICS uses data
Every use must fit a stated registry purpose.
- Provide organization workspaces, TECRID issuance, resolution, verification, evidence routing, certification intake, and integrations.
- Confirm laboratory identity and authority; validate signatures and fingerprints; preserve version, correction, and audit history.
- Fulfill a user's scoped sharing instruction and notify the organizations involved.
- Operate billing, support, onboarding, service communications, and contracted implementation work.
- Detect abuse, fabrication indicators, security threats, conflicts, anomalous submissions, and attempts to bypass authorization.
- Comply with law, enforce agreements, protect legal rights, and investigate disputes.
- Create safeguarded internal statistics and global trend analysis as described below.
Where data-protection law applies, processing may be necessary to perform a contract, comply with legal obligations, pursue legitimate interests in registry integrity, evidence security, research, and service improvement, or act on consent for optional publication and directory features. ICS does not use confidential evidence for unrelated advertising or commercial data brokerage.
05 / Global trends and certification standards
ICS may learn from the network without exposing the participants.
ICS may analyze safeguarded data to detect emerging contaminant patterns, method gaps, recurring documentation failures, inter-laboratory variation, geographic or category-level changes, and areas where certification sampling, analyte panels, audit frequency, or technical standards may need review.
Use only the fields needed for the question and separate direct organization and person identifiers from analytical work where feasible.
Use pseudonymized, de-identified, or aggregated data when the purpose can be achieved without identified records.
Externally reported trends must suppress small cohorts, rare combinations, and organization, laboratory, product, SKU, lot, report, and person identifiers.
Identified confidential evidence is not provided to standards committees or commercial participants unless authorized, legally required, or necessary for a documented integrity investigation.
Trend signals may inform research priorities or proposed standards. They do not, by themselves, create an adverse certification decision against a named organization. Program decisions require the applicable certification process, relevant evidence, and human review. ICS may keep fraud-detection logic, alert thresholds, and security methods confidential when disclosure would enable evasion or increase re-identification risk.
ICS does not use private laboratory reports or controlled findings to train a general-purpose artificial-intelligence model. A materially different future use would require advance notice and, where appropriate, affirmative contractual authorization.
06 / When data is disclosed
Disclosure follows instruction, infrastructure necessity, or law.
ICS may disclose the minimum necessary data to: a recipient expressly authorized through TECRID; personnel and contractors with a need to operate or secure the service and confidentiality duties; identity, hosting, storage, security, communications, support, and payment service providers acting under contract; professional advisers; or authorities when legally required.
Current service categories may include ChatGPT/OpenAI identity and application services, Cloudflare network, compute and storage infrastructure, and Stripe payment services. Those providers process information under their own terms and contractual roles. ICS does not sell personal information or confidential evidence and does not share it for cross-context behavioral advertising.
07 / Legal and government requests
Government access is not automatic, and legal disclosure is not publication.
A regulator or government account receives controlled evidence through the same recorded authorization model as another recipient unless a valid legal obligation applies. When ICS receives compulsory legal process, it will, where legally permitted and reasonably practicable:
- verify the authority, jurisdiction, authenticity, and scope of the demand;
- seek to narrow or challenge demands that are defective, overbroad, or inconsistent with protected confidentiality;
- notify the affected organization before disclosure unless legally prohibited or an emergency makes prior notice impracticable;
- disclose only the information legally required and seek confidential treatment where available; and
- record the request and response in a restricted legal-access log.
No policy can lawfully guarantee that data will never be disclosed under valid compulsory process. Such a disclosure does not change a private TECRID's registry visibility, authorize onward public release, or make the underlying record public on tecrid.com.
08 / Confidentiality and security
Confidentiality is enforced through people, permissions, and evidence trails.
ICS maintains strict confidentiality rules and uses technical and organizational measures designed for the sensitivity of laboratory and supply-chain data. Current controls include authenticated workspaces, role and organization boundaries, private document storage, cryptographic fingerprints and signatures, hashed API and sharing credentials, expiring and revocable grants, recipient and SKU scopes, restricted administrative access, and append-only audit or receipt records.
ICS personnel and contractors may access confidential data only for an authorized operational, security, support, legal, or integrity purpose and are expected to follow confidentiality duties. No online service can promise absolute security; ICS will investigate suspected incidents and provide notice when required by law or contract.
09 / Retention, correction, and deletion
Evidence integrity requires retention—but not unlimited identified use.
ICS retains account, private evidence, permission, security, billing, and support data only for as long as reasonably necessary for the service, the organization's instructions and contract, registry integrity, audit and dispute requirements, security, and applicable law. The relevant criteria include whether a credential remains active, whether evidence is part of a certification or dispute record, the risk of fabrication or inconsistent versions, and legal or contractual recordkeeping periods.
Issued public TECRIDs, their fingerprints, status, and correction history are designed as durable records and may be retained indefinitely. Corrections create a new version rather than silently rewriting history. When deletion of private or personal data is required, ICS may retain a minimal cryptographic tombstone, legal hold, or audit fact that no longer exposes the deleted content. De-identified aggregate statistics may be retained for longitudinal analysis when they cannot reasonably be linked back to a person or participating organization.
10 / Choices and privacy rights
Organizations control disclosure; people retain applicable privacy rights.
Depending on location and applicable law, a person may request access, correction, deletion, portability, restriction, or objection regarding personal information, and may appeal or complain to a regulator. ICS will verify the requester and may need to protect another organization's confidential information, trade secrets, legal rights, or immutable public-record history when responding.
- Public participant profiles are optional and can be removed without changing private evidence.
- Active grants and unredeemed share codes can be revoked from the controlling workspace.
- Public publication and each recipient grant are separate choices.
- ICS does not sell or share personal information for targeted advertising, so there is no such sale to opt out of.
- Authorized correction and status procedures remain available when an evidentiary record cannot be erased without undermining integrity or legal obligations.
11 / International use and children
TECRID is a business evidence service used across borders.
Information may be processed in the United States and other locations where ICS or its service providers operate. ICS will use contractual or other recognized safeguards where required for international transfers. TECRID is intended for organizations and professional users, not children, and ICS does not knowingly collect personal information from children through the service.
12 / Contact, complaints, and policy changes
Privacy questions should reach the registry operator.
Contact ICS at privacy@tecrid.com for a privacy request, confidentiality concern, legal-process question, or complaint. Include the organization name and enough information to verify authority, but do not email a raw laboratory report or a share code.
ICS may update this policy as the registry, law, or data practices change. Material changes will be posted here with a new effective date and, when appropriate, presented in the organization workspace before the new use begins. ICS will not make a private record public through a policy update alone.