Privacy & data governance

Private by default.
Published by choice.

TECRID is operated by the Institute of Contaminant Standards (“ICS”). A TECRID can exist without its report or findings becoming public. Access follows the authority, scope, recipient, and purpose recorded for the evidence.

01Private is a real state.

Uploading, fingerprinting, reserving, or assigning a TECRID does not itself publish the underlying report.

02Sharing is recipient-specific.

Controlled evidence moves only through an authorized grant, code, integration, or legal obligation.

03Data is not merchandise.

ICS does not sell confidential evidence, use it for targeted advertising, or train general-purpose AI models on it.

04Trends do not expose sources.

Global analysis is governed to prevent an organization, product, lot, laboratory, or person from being identified.

Plain-language boundary

A private TECRID cannot be turned into a public record by a requester.

A laboratory, retailer, certification body, regulator, customer, or member of the public cannot change a private record's visibility merely by knowing its identifier, requesting it, paying ICS, or creating an account. Publication requires a separate authorized action. A legally required confidential disclosure does not change the TECRID to public or create a public resolver page.

01 / Scope and roles

ICS operates the registry; participating organizations control their evidence.

This policy covers tecrid.com, the TEC Registry service, its APIs, organization workspaces, evidence-routing tools, laboratory confirmation workflows, and related support and billing interactions.

ICS generally acts as the service operator for confidential evidence submitted by a laboratory, brand, supplier, retailer, certification body, research organization, or government program. The participating organization is responsible for having authority to submit the data and to name its permitted recipients. ICS separately determines how account, security, billing, registry-integrity, and de-identified network analytics data are processed.

Customer agreements still matter.

A data-processing agreement, certification agreement, laboratory agreement, or enterprise contract may add protections and instructions. If a contract is more protective than this policy, ICS will follow the contract.

02 / Data we process

We collect what is needed to identify authority, preserve evidence, and operate the network.

Account and organization

Name, work email, organization, role, website, membership, issuer application, and contacts you invite.

Laboratory evidence

Reports, findings, analytes, units, methods, sample and matrix descriptions, SKUs, lots, dates, report numbers, chain-of-custody context, and source-document metadata.

Integrity and authority

TECRIDs, hashes, signatures, public keys, confirmation events, version history, disputes, verification checks, grants, revocations, redemptions, and audit receipts.

Commercial and support

Plan, billing status, transaction references, implementation briefs, support communications, and integration settings. Payment-card details are handled by the payment provider rather than stored by TECRID.

Technical and security

Authentication identifiers, IP and device information made available by infrastructure providers, request logs, API-key usage, error records, and security events.

Derived information

Authority states, coverage summaries, exceptions, descriptive portfolio insights, and safeguarded aggregate trends. These are not automatic safety or compliance conclusions.

Sources include users and their organizations, issuing laboratories, authorized recipients, connected systems and APIs, identity and payment providers, and ordinary technical operation of the service.

03 / Public and private states

A TECRID is an identifier—not consent to disclose.

Private intake or draftNot publicly resolvable. Original PDFs, transcriptions, contacts, and findings stay inside the authorized workflow.
Controlled credentialFindings are withheld from the public. A limited identity or status record may resolve when required for verification, while results require a scoped recipient grant.
Public credentialThe authorized issuer has intentionally released the structured record. Public records carry version and correction history; the original PDF is not public unless separately and explicitly released.
Participant directoryOrganization listing is opt-in. Directory participation does not make its evidence public or imply endorsement.

Access to one record, SKU, analyte set, or recipient does not authorize access to another. A recipient may not forward controlled evidence unless a separate authorization or applicable law permits it.

04 / How ICS uses data

Every use must fit a stated registry purpose.

  • Provide organization workspaces, TECRID issuance, resolution, verification, evidence routing, certification intake, and integrations.
  • Confirm laboratory identity and authority; validate signatures and fingerprints; preserve version, correction, and audit history.
  • Fulfill a user's scoped sharing instruction and notify the organizations involved.
  • Operate billing, support, onboarding, service communications, and contracted implementation work.
  • Detect abuse, fabrication indicators, security threats, conflicts, anomalous submissions, and attempts to bypass authorization.
  • Comply with law, enforce agreements, protect legal rights, and investigate disputes.
  • Create safeguarded internal statistics and global trend analysis as described below.

Where data-protection law applies, processing may be necessary to perform a contract, comply with legal obligations, pursue legitimate interests in registry integrity, evidence security, research, and service improvement, or act on consent for optional publication and directory features. ICS does not use confidential evidence for unrelated advertising or commercial data brokerage.

06 / When data is disclosed

Disclosure follows instruction, infrastructure necessity, or law.

ICS may disclose the minimum necessary data to: a recipient expressly authorized through TECRID; personnel and contractors with a need to operate or secure the service and confidentiality duties; identity, hosting, storage, security, communications, support, and payment service providers acting under contract; professional advisers; or authorities when legally required.

Current service categories may include ChatGPT/OpenAI identity and application services, Cloudflare network, compute and storage infrastructure, and Stripe payment services. Those providers process information under their own terms and contractual roles. ICS does not sell personal information or confidential evidence and does not share it for cross-context behavioral advertising.

08 / Confidentiality and security

Confidentiality is enforced through people, permissions, and evidence trails.

ICS maintains strict confidentiality rules and uses technical and organizational measures designed for the sensitivity of laboratory and supply-chain data. Current controls include authenticated workspaces, role and organization boundaries, private document storage, cryptographic fingerprints and signatures, hashed API and sharing credentials, expiring and revocable grants, recipient and SKU scopes, restricted administrative access, and append-only audit or receipt records.

ICS personnel and contractors may access confidential data only for an authorized operational, security, support, legal, or integrity purpose and are expected to follow confidentiality duties. No online service can promise absolute security; ICS will investigate suspected incidents and provide notice when required by law or contract.

09 / Retention, correction, and deletion

Evidence integrity requires retention—but not unlimited identified use.

ICS retains account, private evidence, permission, security, billing, and support data only for as long as reasonably necessary for the service, the organization's instructions and contract, registry integrity, audit and dispute requirements, security, and applicable law. The relevant criteria include whether a credential remains active, whether evidence is part of a certification or dispute record, the risk of fabrication or inconsistent versions, and legal or contractual recordkeeping periods.

Issued public TECRIDs, their fingerprints, status, and correction history are designed as durable records and may be retained indefinitely. Corrections create a new version rather than silently rewriting history. When deletion of private or personal data is required, ICS may retain a minimal cryptographic tombstone, legal hold, or audit fact that no longer exposes the deleted content. De-identified aggregate statistics may be retained for longitudinal analysis when they cannot reasonably be linked back to a person or participating organization.

10 / Choices and privacy rights

Organizations control disclosure; people retain applicable privacy rights.

Depending on location and applicable law, a person may request access, correction, deletion, portability, restriction, or objection regarding personal information, and may appeal or complain to a regulator. ICS will verify the requester and may need to protect another organization's confidential information, trade secrets, legal rights, or immutable public-record history when responding.

  • Public participant profiles are optional and can be removed without changing private evidence.
  • Active grants and unredeemed share codes can be revoked from the controlling workspace.
  • Public publication and each recipient grant are separate choices.
  • ICS does not sell or share personal information for targeted advertising, so there is no such sale to opt out of.
  • Authorized correction and status procedures remain available when an evidentiary record cannot be erased without undermining integrity or legal obligations.

11 / International use and children

TECRID is a business evidence service used across borders.

Information may be processed in the United States and other locations where ICS or its service providers operate. ICS will use contractual or other recognized safeguards where required for international transfers. TECRID is intended for organizations and professional users, not children, and ICS does not knowingly collect personal information from children through the service.

12 / Contact, complaints, and policy changes

Privacy questions should reach the registry operator.

Contact ICS at privacy@tecrid.com for a privacy request, confidentiality concern, legal-process question, or complaint. Include the organization name and enough information to verify authority, but do not email a raw laboratory report or a share code.

ICS may update this policy as the registry, law, or data practices change. Material changes will be posted here with a new effective date and, when appropriate, presented in the organization workspace before the new use begins. ICS will not make a private record public through a policy update alone.