Privacy engineered the way compliance should be.
Privacy isn't a legal checkbox for us — it's engineered into how we handle data, the same way compliance is engineered into how we build monitoring systems. This policy explains what we collect, why, and the control you have over it.
Who we are & what this covers
Qualified Controls, LLC is the engineering firm regulated facilities trust to design, install, validate, and continuously monitor compliance-grade environmental infrastructure. This policy explains how we handle personal data across our business.
We operate under the principles of the EU General Data Protection Regulation (GDPR) — transparency, purpose limitation, data minimization, and user control — and we apply those principles to every person whose data we hold, regardless of where they live.
This policy covers:
- qualifiedcontrols.com and its subdomains
- The REM Risk Assessment and ROI Calculator tools
- The MySirius customer portal
- Our business relationships with clients, prospects, vendors, and partners
- Marketing communications you receive from us
It does not cover the websites of third parties we link to, even if we mention them. When you leave our site, their privacy rules apply.
What we collect and why
We collect personal data in a few distinct contexts. For each, we specify the data, the purpose, and the legal basis under GDPR.
| Context | Data | Purpose | Legal basis |
|---|---|---|---|
| Website visit | IP address, browser, device, pages viewed, referrer | Site security, performance, aggregate analytics | Legitimate interest |
| Contact form | Name, email, company, phone, message | Respond to your inquiry | Legitimate interest / pre-contract |
| Newsletter | Email, subscription preferences | Send content you requested | Consent |
| REM Risk Assessment / ROI Calculator | Inputs you provide, email (only if you request results delivered) | Generate your assessment, deliver results | Consent / legitimate interest |
| MySirius Portal user | Name, email, role, credentials, activity logs | Provide and audit portal access, deliver support | Contract performance |
| Client facility data | Environmental readings, validation records, documentation | Deliver monitoring services, maintain audit trail | Contract / legal obligation |
| Business contacts | Name, email, phone, title at client or prospect organization | CRM, sales, account management | Legitimate interest |
We don't collect special-category data (health, biometric, political, religious) and we don't knowingly collect data from anyone under 16. If you believe we have, contact us at Support@QualifiedControls.com and we'll delete it.
How we share it
We share personal data with a limited set of service providers who help us run the business — including cloud hosting and infrastructure, email delivery, CRM and marketing automation, and website analytics. Each provider is selected for its security posture and operates under a data protection agreement that requires them to handle personal data with the same standards we apply.
Regulators and lawful requests: we may disclose data when legally required — for example, a valid subpoena, court order, or FDA inspection request. We don't volunteer data to regulators.
Business transfers: if our business is merged or acquired, personal data may transfer as part of the transaction. We would notify affected individuals before the transfer.
We do not transfer personal data to third countries except through our service providers, and only under the appropriate safeguards (EU Standard Contractual Clauses or equivalent).
How long we keep it
We retain personal data only as long as necessary for the purpose we collected it, plus any legally required period.
| Data | Retention period |
|---|---|
| Website access logs | 90 days |
| Contact form submissions | 24 months after last contact |
| Newsletter subscribers | Until unsubscribe + 30 days |
| Risk / ROI Assessment submissions | 12 months |
| MySirius Portal accounts | Duration of active account + 90 days |
| Client monitoring records | Per contract (typically 7+ years, as required under 21 CFR Part 11) |
| Business relationship contacts | Duration of relationship + 24 months |
| Financial / billing records | 7 years (tax and audit obligations) |
When the retention period ends, data is deleted or anonymized so it can no longer be linked to an individual.
Your rights
Under GDPR and applicable US state privacy laws, you have the following rights regarding the personal data we hold about you:
- Access — request a copy of what we hold about you.
- Correction — ask us to fix anything that's inaccurate.
- Deletion — ask us to delete your data. Subject to legal retention obligations — some regulated monitoring records must be preserved by law.
- Portability — receive your data in a structured, machine-readable format you can take to another provider.
- Objection — object to processing based on legitimate interest, especially for marketing.
- Withdraw consent — at any time, without affecting lawful processing that occurred while consent was valid.
- Complain — lodge a complaint with a supervisory authority. EU residents: your national data protection authority. US residents: your state Attorney General or the Federal Trade Commission.
To exercise any of these rights, email us at Support@QualifiedControls.com or write to us at the address in section 08. We'll respond within 30 days. If your request requires verification or extended time, we'll let you know why.
Cookies & tracking
We use a small set of cookies, grouped by purpose:
- Essential cookies. Session, authentication, and CSRF protection. The site can't function without these — they can't be disabled without breaking basic functionality.
- Analytics cookies. Anonymous usage statistics via our web analytics service, with IP anonymization enabled. Helps us understand which content is useful. You can decline on your first visit or disable them via your browser settings.
- Marketing cookies. None. We don't run retargeting campaigns or third-party ad tracking on our site.
Most browsers let you block or delete cookies via their settings. Doing so may reduce site functionality — for example, you may need to re-authenticate on each visit.
Security & policy updates
We treat personal data with the same engineering rigor we apply to regulated monitoring infrastructure.
- Encryption in transit — TLS 1.2+ on every connection to our systems.
- Encryption at rest — AES-256 on sensitive stores.
- Access control — role-based. Team members access client data only when necessary to deliver services.
- Regular security reviews — vulnerability scans and penetration testing on customer-facing systems. Our controls operate under ISO 27001 principles.
- Breach notification — if a personal data breach affects you, we will notify you and the relevant supervisory authorities within 72 hours of becoming aware of it.
Policy changes. We'll post updates to this page with a revised "Last updated" date at the top. Material changes that affect how we handle your data will trigger an email notice if we have your address on file.
Contact us
For privacy questions, rights requests, or anything else related to this policy:
- Email: Support@QualifiedControls.com
- Mail: Qualified Controls, LLC · 600 Park Offices Dr, STE 300 · Durham, NC 27709
- Phone: 919-225-3327
We respond to privacy requests within 30 days. For general business inquiries, please use info@qualifiedcontrols.com.