Skip to main content
Legal · Privacy

Privacy engineered the way compliance should be.

Privacy isn't a legal checkbox for us — it's engineered into how we handle data, the same way compliance is engineered into how we build monitoring systems. This policy explains what we collect, why, and the control you have over it.

Last updated: January 2026 ~5 min read Applies globally
01

Who we are & what this covers

Qualified Controls, LLC is the engineering firm regulated facilities trust to design, install, validate, and continuously monitor compliance-grade environmental infrastructure. This policy explains how we handle personal data across our business.

We operate under the principles of the EU General Data Protection Regulation (GDPR) — transparency, purpose limitation, data minimization, and user control — and we apply those principles to every person whose data we hold, regardless of where they live.

This policy covers:

  • qualifiedcontrols.com and its subdomains
  • The REM Risk Assessment and ROI Calculator tools
  • The MySirius customer portal
  • Our business relationships with clients, prospects, vendors, and partners
  • Marketing communications you receive from us

It does not cover the websites of third parties we link to, even if we mention them. When you leave our site, their privacy rules apply.

02

What we collect and why

We collect personal data in a few distinct contexts. For each, we specify the data, the purpose, and the legal basis under GDPR.

Context Data Purpose Legal basis
Website visit IP address, browser, device, pages viewed, referrer Site security, performance, aggregate analytics
Contact form Name, email, company, phone, message Respond to your inquiry
Newsletter Email, subscription preferences Send content you requested
REM Risk Assessment / ROI Calculator Inputs you provide, email (only if you request results delivered) Generate your assessment, deliver results
MySirius Portal user Name, email, role, credentials, activity logs Provide and audit portal access, deliver support
Client facility data Environmental readings, validation records, documentation Deliver monitoring services, maintain audit trail
Business contacts Name, email, phone, title at client or prospect organization CRM, sales, account management
“We collect only what we need for the purpose stated — no speculative collection, no selling.”

We don't collect special-category data (health, biometric, political, religious) and we don't knowingly collect data from anyone under 16. If you believe we have, contact us at Support@QualifiedControls.com and we'll delete it.

03

How we share it

We share personal data with a limited set of service providers who help us run the business — including cloud hosting and infrastructure, email delivery, CRM and marketing automation, and website analytics. Each provider is selected for its security posture and operates under a data protection agreement that requires them to handle personal data with the same standards we apply.

Regulators and lawful requests: we may disclose data when legally required — for example, a valid subpoena, court order, or FDA inspection request. We don't volunteer data to regulators.

Business transfers: if our business is merged or acquired, personal data may transfer as part of the transaction. We would notify affected individuals before the transfer.

We don't sell personal data. We don't rent it. We don't share it with advertisers or data brokers. Ever.

We do not transfer personal data to third countries except through our service providers, and only under the appropriate safeguards (EU Standard Contractual Clauses or equivalent).

04

How long we keep it

We retain personal data only as long as necessary for the purpose we collected it, plus any legally required period.

Data Retention period
Website access logs90 days
Contact form submissions24 months after last contact
Newsletter subscribersUntil unsubscribe + 30 days
Risk / ROI Assessment submissions12 months
MySirius Portal accountsDuration of active account + 90 days
Client monitoring recordsPer contract (typically 7+ years, as required under 21 CFR Part 11)
Business relationship contactsDuration of relationship + 24 months
Financial / billing records7 years (tax and audit obligations)

When the retention period ends, data is deleted or anonymized so it can no longer be linked to an individual.

05

Your rights

Under GDPR and applicable US state privacy laws, you have the following rights regarding the personal data we hold about you:

  • Access — request a copy of what we hold about you.
  • Correction — ask us to fix anything that's inaccurate.
  • Deletion — ask us to delete your data. Subject to legal retention obligations — some regulated monitoring records must be preserved by law.
  • Portability — receive your data in a structured, machine-readable format you can take to another provider.
  • Objection — object to processing based on legitimate interest, especially for marketing.
  • Withdraw consent — at any time, without affecting lawful processing that occurred while consent was valid.
  • Complain — lodge a complaint with a supervisory authority. EU residents: your national data protection authority. US residents: your state Attorney General or the Federal Trade Commission.

To exercise any of these rights, email us at Support@QualifiedControls.com or write to us at the address in section 08. We'll respond within 30 days. If your request requires verification or extended time, we'll let you know why.

06

Cookies & tracking

We use a small set of cookies, grouped by purpose:

  • Essential cookies. Session, authentication, and CSRF protection. The site can't function without these — they can't be disabled without breaking basic functionality.
  • Analytics cookies. Anonymous usage statistics via our web analytics service, with IP anonymization enabled. Helps us understand which content is useful. You can decline on your first visit or disable them via your browser settings.
  • Marketing cookies. None. We don't run retargeting campaigns or third-party ad tracking on our site.

Most browsers let you block or delete cookies via their settings. Doing so may reduce site functionality — for example, you may need to re-authenticate on each visit.

07

Security & policy updates

We treat personal data with the same engineering rigor we apply to regulated monitoring infrastructure.

  • Encryption in transit — TLS 1.2+ on every connection to our systems.
  • Encryption at rest — AES-256 on sensitive stores.
  • Access control — role-based. Team members access client data only when necessary to deliver services.
  • Regular security reviews — vulnerability scans and penetration testing on customer-facing systems. Our controls operate under ISO 27001 principles.
  • Breach notification — if a personal data breach affects you, we will notify you and the relevant supervisory authorities within 72 hours of becoming aware of it.

Policy changes. We'll post updates to this page with a revised "Last updated" date at the top. Material changes that affect how we handle your data will trigger an email notice if we have your address on file.

08

Contact us

For privacy questions, rights requests, or anything else related to this policy:

We respond to privacy requests within 30 days. For general business inquiries, please use info@qualifiedcontrols.com.