Privacy policy
What happens to anything you send us.
This is a small, plain site run by one person. You read pages, and if you want to talk to us you fill in one form. Section 3 is the complete, dated list of everything the site actually does, in tables you can check against your own browser's developer tools in about a minute. We would rather you did.
Effective 6 August 2026. Version 2.4. Section 3 is the part that changes, and it carries the same date.
Version and date
| Effective | Last updated | Version | What changed |
|---|---|---|---|
| Effective6 August 2026 | Last updated6 August 2026 | Version2.4 | What changedTwo things were switched on. Google Analytics 4 now runs for every visitor, so 3.1 lists two Google origins, 3.2 lists two cookies, 3.3 names the product and 3.6 explains that Google receives your IP address as our processor. And the GoHighLevel inquiry records in 3.5 are now connected, so a submission creates a contact record there. See section 10.3, the change log. |
Section 3 of this page describes what this site does as at the date above. Every other section is a set of commitments that do not change with the code. That split is deliberate, and section 10 explains how it is kept honest.
0The short version
This site is small and says exactly what it does. It uses Google Analytics to count visits and see which pages get read, which sets two cookies and sends Google some information about your visit. Section 3 lists precisely what. Beyond that, almost nothing happens: you read pages, and if you want to talk to us you fill in one form. Section 3 is the complete, dated list of everything the site actually does.
The personal information we get from you directly is what you type into that form, or what you put in an email you send us. Google Analytics also collects some information about your visit automatically, including your IP address, which it processes on our behalf: sections 3.3 and 3.6 explain what and why. This page explains what happens to all of it, who else sees it, what you are agreeing to when you send it, how long we keep it, and how to get a copy or get it deleted.
If anything here is unclear, email info@probitysciences.com and we will explain it in plain terms.
1Who runs this site
This site is probitysciences.com. It is operated by Probity Sciences, an independent packaging validation practice based in the Greater Seattle Area, Washington, United States. Probity Sciences is responsible for the information described on this page, and a person here reads everything sent through this site. In this policy, "we", "us" and "our" mean Probity Sciences.
There is no separate company behind the name today. If that changes, this page will name the company and will be re-dated.
Contact for anything on this page, including any request about your own information: info@probitysciences.com
We publish no street address and no phone number for the practice. Email is the way to reach us.
2What you can ask for, and how
This section is first because it is the part people actually need, and because it never goes out of date. Whatever state or country you are in, you can ask us to:
- Tell you what we hold about you.
- Give you a copy of it.
- Correct anything that is wrong.
- Delete it. We will delete every copy we control, unless we have a specific legal reason to keep it, and we will tell you if that is the case. Section 6 explains the copies we cannot reach and why one kind of record is deliberately kept.
- Stop contacting you. By any route, in any words. Section 5.5 explains how that works and how fast.
- How
Email info@probitysciences.com and say what you want. One sentence is enough. You do not need to cite a statute or fill in a form.
- Stopping and deleting are different requests, and we will ask which you mean
Stopping keeps the record and marks it, so we can show that we stopped. Deleting removes it, which also removes the evidence that you ever asked us to stop. If a request could be either, we will ask rather than guess.
- Verification
We may need to be reasonably sure you are the person the information is about, so that we do not hand somebody's inquiry to a stranger. In practice that means we reply to the email address on the inquiry itself. If we cannot match a request to an inquiry, we will say so rather than guess.
- Timing
We aim to reply within 30 days, and in practice much sooner: the same person who answers a technical question answers this one. If a request needs longer, we will tell you so within those 30 days and tell you why.
- Limits
These are things we do as a matter of practice, in addition to anything a law where you live requires of us. We may decline a request that is repeated without good reason, that is manifestly excessive, or that we cannot verify. If we decline, we will say why.
- No penalty
We will not treat you differently, refuse to work with you, or change what we would charge you, because you exercised any of these rights.
- What we cannot do
We cannot remove an individual line from our hosting provider's platform logs, and we cannot alter records held by a third party outside our control. If your request touches something we cannot reach, we will say so directly rather than implying it was handled. Section 6 sets out exactly which copies those are.
3What this site does today
This is the section that changes. Everything in it describes the site as at the date at the top of this page, and nothing anywhere else on this page restates a fact from here. If you want to know what this site does, this is the list, and it is the whole list.
3.1Requests your browser makes
When you load a page here, your browser is asked to contact the following origins, other than probitysciences.com itself.
| Origin | Whose it is | What it is for | What it receives |
|---|---|---|---|
| Originwww.googletagmanager.com | Whose it isGoogle | What it is forLoads Google Analytics 4 (the gtag.js script) | What it receivesThe request for the script, carrying your IP address and the page you are on |
| Originwww.google-analytics.com | Whose it isGoogle | What it is forReceives the measurements gtag.js sends | What it receivesEach page view: your IP address, the page URL, the referring page, and general device and browser information |
Two origins, both Google's, both part of Google Analytics 4, which we turned on 6 August 2026. They are the only third-party requests your browser makes on this site. There is nothing else embedded: no other script, no stylesheet, no font, no image, no iframe, no video, no map, no chat widget, no social button, no scheduling widget. Sections 3.2, 3.3 and 3.6 set out exactly what Google Analytics collects, and any browser setting or extension that blocks Google Analytics stops both requests without breaking the site.
The typefaces are the part people usually assume is an exception, so: they are downloaded, subsetted and bundled when the site is built, and served from this site's own domain. Your browser does not ask Google, or anyone else, for them.
Our server contacts the following origins.
| Origin | Whose it is | What it is for | Active today |
|---|---|---|---|
| Originservices.leadconnectorhq.com | Whose it isHighLevel (GoHighLevel) | What it is forReceives your submission and creates a contact record, described in 3.5 | Active todayYes, when you submit the contact form |
One origin. When you submit the contact form, our server sends the submission to GoHighLevel to create a contact record. Nothing else on this site makes a server-to-server request to another company, and no server request is made until you submit the form.
One technical note for anyone reading our HTTP headers
This site sends a report-only content security policy. It authorizes this site's own origin, inline image and typeface data that reaches no network, and the two Google Analytics origins named in the table above: a tag manager domain, www.googletagmanager.com, from which the analytics script loads, and www.google-analytics.com, which receives the measurements. No other company's domain appears in it. The header and the table say the same thing, in the two places a scanner and a reader each look.
If a future change adds an origin to that header, it appears in the table above in the same change, and this page carries a new date. If you run a header scanner against us and want to compare notes, email us.
3.2What is stored in your browser
| Mechanism | What this site stores | Names |
|---|---|---|
| MechanismCookies | What this site storesTwo, set by Google Analytics 4 to tell one visit from another and count returning visitors | Names_ga and _ga_NFMEQRTSSF |
| MechanismLocal storage | What this site storesOne entry, and only if you tick a box or type a note in the transition checklist | Namesprobity.transition-checklist.v1 |
| MechanismSession storage | What this site storesNothing | Namesnone |
| MechanismIndexedDB | What this site storesNothing | Namesnone |
| MechanismAnything else | What this site storesNothing | Namesnone |
The two cookies are set by Google Analytics, described in 3.3. We do not show a cookie banner: United States law does not require one for analytics cookies, and we would rather this page tell you plainly what is set than make you dismiss a box. There is no login, no password, no account, no session and no profile, and any browser setting or extension that blocks Google Analytics stops the cookies without breaking the site.
Your answers to the contact form live in your browser's memory while you are filling the form in, and are gone when you close the tab. Nothing is saved on your device, so a half-finished form is not recoverable and closing the tab discards it.
The one exception on this site is the self-check on the ISO 11607 transition page. If you tick an item or type a note there, your ticks and your notes are saved in your own browser under the name in the table above, so that they survive the page being closed. They stay on your device: they are never sent to us, never sent to anybody else, and we cannot read them. The page carries a control that erases them, and clearing your browser's site data does the same thing. Section 3.9 describes the tools themselves.
3.3Measurement, and protection against automated submissions
Usage measurement in use: Google Analytics 4, turned on 6 August 2026. It counts page views and tells us which pages are read, roughly where in the world visitors are, and what kind of device and browser they use. It sets the two cookies listed in 3.2, loads from the two Google origins listed in 3.1, and sends each page view to Google, which acts as our processor and receives your IP address (see 3.6). We do not enable Google Signals, advertising features or cross-site tracking, so the data is not used to build an advertising profile of you or to follow you to other sites. We use it only to see which of our pages are useful.
Bot protection in use: two things, on the contact form only, neither of which identifies you.
- A hidden field
The form contains one field positioned off-screen that a person never sees and never fills in. Automated scripts fill it in. If it comes back filled, the submission is discarded immediately and nothing about it is recorded: not the answers, not the email address, nothing. Only a fixed warning line goes into the log, with no content in it.
- A timing token
When the form loads, our server issues a short signed timestamp. It contains a time and a signature and nothing else: no identifier, no IP address, no fingerprint, no data about you. It is not a cookie and is not stored on your device. On submit we check it, which lets us reject submissions made faster than a human can type, and submissions whose token does not carry a valid signature. If that check fails, the submission is discarded and nothing about it is recorded. If the token is instead missing or out of date, the submission is accepted and a one-word note recording that fact is kept beside it. It is not a score, and it changes nothing about how we treat you or your inquiry.
No bot-detection service is called, from your browser or from our server. A challenge service is wired into the form and is switched off: no key is set, so no script loads in your browser and no call is made from our server. If it is ever switched on, it appears in the table in 3.1 and in this subsection first.
We do not use any of this to build a picture of you, and none of it produces an automated decision about you.
These checks are automatic and they are not perfect
If a submission is discarded by one of them, then so that automated senders do not learn they were caught, the page may still show you a confirmation. This is unlikely to happen to a person filling the form in normally, but it is possible.
If you send us something and do not hear back within a couple of working days, email info@probitysciences.com directly. That address reaches the same person and passes through none of these checks.
3.4The forms on this site, field by field
There is one form on this site, in the sense of something that sends what you type to us. It is on the contact page, it has nine questions in two steps, and this is the complete list. Four other pages carry controls that look like a form and are not one: two calculators, a self-check and a readiness questionnaire, all of which run entirely in your browser and send nothing anywhere. Section 3.9 describes them.
Step 1, about your device and program
| Question | What it is | Required | Limit |
|---|---|---|---|
| QuestionDevice or product | What it isFree text | RequiredYes | Limit500 characters |
| QuestionDevice class | What it isA choice from a fixed list | RequiredYes | Limit |
| QuestionSterilization method | What it isA choice from a fixed list | RequiredYes | Limit |
| QuestionPackaging system | What it isA choice from a fixed list | RequiredYes | Limit |
| QuestionSealing process validation status | What it isA choice from a fixed list | RequiredYes | Limit |
| QuestionTarget submission date | What it isA month, or no date set yet | RequiredYes | Limit |
Step 2, about you
| Question | What it is | Required | Limit |
|---|---|---|---|
| QuestionName | What it isFree text | RequiredYes | Limit200 characters |
| QuestionWork email | What it isFree text | RequiredYes | Limit200 characters |
| QuestionAnything else we should know | What it isFree text | RequiredNo | Limit4,000 characters |
Those character limits are applied when the submission reaches us, not by your browser. If you write more than the number shown, we keep the first part and the rest is discarded, and nothing on screen tells you so. If you have a lot to say, email it instead.
What the form does not have, today
- No phone number field. We do not ask for one, and we do not have one for you unless you give it to us for a call you arranged. Section 5.4 explains what would change if that ever alters, and what would have to be true first.
- No company name field. If we know where you work, it is because you told us in one of the free-text answers or it is visible from your email domain.
- No job title, no address, no file upload, no payment field.
The one checkbox on this form
Step 2 carries a single checkbox, above the send button, asking whether you want occasional email about ISO 11607 and packaging validation practice. It loads unticked, it is never a condition of sending the form, and the form sends with it untouched. What arrives is described next to the box rather than behind a link. Section 5.2 is the commitment behind it, and section 5.6 is what we record when somebody ticks it.
There is no text message consent on this form and no phone number field for one to attach to. Section 5.4 sets out what would have to be true before either existed.
Two smaller things about the form that are worth knowing
- When the form loads, your browser makes one request back to this same site to fetch the anti-spam token described in 3.3. It goes nowhere else.
- The work-email field may show you a gentle note if you enter a personal address such as a Gmail or Outlook one. That check is a plain string comparison against a short list built into the page itself. Nothing is sent anywhere, and no lookup is performed on your address.
Please do not put sensitive information in the free-text boxes
The "anything else we should know" box is deliberately wide, and we cannot control what somebody types into it. Do not send health information about yourself or anyone else, and do not send anything you would not want recorded in an ordinary business inquiry record.
What sending an inquiry does and does not do
Sending this form starts a conversation. It does not create a consulting engagement, and it does not by itself put a confidentiality agreement in place between us. We treat what you send as commercially sensitive and we do not pass it to anyone.
If your material needs formal protection before it changes hands, say so in one line and we will agree how to handle it in writing first. Please do not send drawings, specifications, test data, or anything you hold under an obligation of confidentiality to somebody else, through this form.
3.5Where a submission goes
| Who | What they do | Do they receive a submission today? |
|---|---|---|
| WhoVercel | What they doBuilds and serves the site, terminates the encrypted connection, runs the code that receives your submission, and keeps the platform logs described below | Do they receive a submission today?Yes. In full. |
| WhoHighLevel (GoHighLevel) | What they doCustomer relationship management. Holds our inquiry records. | Do they receive a submission today?Yes. Your submission creates a contact record. |
| WhoGoogle | What they doGoogle Analytics, described in 3.3. Receives measurements about your visit, not your form submission. | Do they receive a submission today?Analytics only, never your inquiry. |
| WhoAnyone else | What they do | Do they receive a submission today?No |
When you submit the contact form, two things happen. Our code sends the submission to GoHighLevel, which creates a contact record holding your name, your work email, your six answers about the device and program, your free-text note if you wrote one, and the time of submission. Our code also writes the complete submission to a Vercel log line: all nine answers, including your name, your work email and the full text of anything you wrote in the free-text box, plus the time of submission, the one-word anti-spam note described in 3.3, and the consent record set out in 5.6, whether the box was ticked or not.
The log line is there deliberately, as a backstop. If a submission ever failed to reach GoHighLevel, the log is the thing standing between an inquiry and being lost. It is not analyzed and it is not used for anything except recovering an inquiry that did not arrive any other way.
Everything else our code writes to a log contains no personal information at all: a fixed warning when the hidden field is filled, a short reason code when a token fails a check, and nothing else. Our code never logs an IP address, a browser user-agent string or a referring page. The one URL path it ever writes is the page a consent was given on, which is part of the consent record in 5.6 and is written only when a form is submitted.
Two kinds of log are involved in running this site, and this page keeps them apart
- The submission log line
The one described above. It is written by our code, only when somebody submits the form, and it is the one place your information rests today.
- Platform request logs
These are made by Vercel for every request to every page, whether or not you ever send us anything. They typically contain an IP address, the page requested, a timestamp and a browser user-agent string. That happens at the platform level, under Vercel's own terms, not because of anything this site does. We do not read the platform request logs to work out who visited or what they read.
About the customer relationship management service
GoHighLevel, operated by HighLevel, holds our inquiry records. When you submit the form, it creates a contact record with your name, your work email, your six answers about the device and program, your free-text note if you wrote one, and the time of submission. It does not receive the anti-spam note or the consent wording, which stay in the Vercel log line described above.
Creating a contact record is not the same as being emailed: see section 5. If you ask us to delete your inquiry, the GoHighLevel record is one of the copies we control, and we will delete it.
3.6Your IP address
This site's own code never stores, logs or transmits your IP address. There is one point in the submission handler where the address is read from the request and passed to the bot-check function described in 3.3, which is switched off and returns before making any outside call. The value is discarded without being used. It is not written to any log or record we keep.
As noted in 3.5, Vercel sees IP addresses at the network layer, as every host does, and they appear in the platform request logs. That is outside this site's code and is governed by Vercel's own terms.
Google Analytics also receives your IP address, because your browser sends each page view directly to www.google-analytics.com, as described in 3.3. Google uses it to estimate the rough location of a visit and does not expose it to us: we never receive your IP address from Google and we never store it ourselves. If you would rather Google did not receive it, blocking Google Analytics in your browser stops the page view being sent at all.
One narrow exception exists in the design and is not in use today
If we ever run the text message program described in 5.4, the IP address of somebody who gives express written consent to be texted would be stored with that consent record and for no other purpose, because a record of consent has to be evidence of it. No text message program is running, no consent is being collected, and no IP address is being stored. When and if that changes, this subsection changes first.
3.7Email you send us
If you email info@probitysciences.com, we receive your message, your email address, your name as your mail client presents it, and anything you attach. The message is delivered and stored by a third-party email provider in the ordinary way that any business mailbox works, and we keep it so we can reply and so there is a record of the exchange.
Email is also how the supplier qualification pack is requested, and how a call is arranged. Anything you send us that way is covered by this subsection.
We have not named the email provider here because we would rather leave it out than name the wrong one. Ask us and we will tell you which one it is.
3.8Things we are told rather than things we can prove
Everything else in section 3 is a fact about code we control and can show you. The following are not. They are set inside other companies' systems, and the honest thing to do is say who confirmed them and when, rather than present them with the same confidence as the rest.
| Statement | Confirmed by | On |
|---|---|---|
| StatementNo analytics or performance-monitoring product is enabled in our hosting platform's own dashboard. This is separate from the Google Analytics we run ourselves, described in 3.3. | Confirmed byProbity Sciences | On4 August 2026 |
| StatementNo open tracking, click tracking or tracking pixel is enabled on any message sent from our customer relationship management system. | Confirmed byProbity Sciences | On4 August 2026 |
Section 10.2 explains why these are separated out and what the limit of our own checking is.
3.9The calculators, the self-check and the questionnaire
Four pages carry controls you can type into. None of them is a form, none of them sends anything anywhere, and none of them is watched.
| Where | What it does | What leaves your browser |
|---|---|---|
| WhereThe accelerated aging calculator | What it doesTurns a shelf life claim, two temperatures and a Q10 into chamber days and a pull point schedule | What leaves your browserNothing |
| WhereThe sample size tool | What it doesRuns the arithmetic published on the same page, in four directions | What leaves your browserNothing |
| WhereThe ISO 11607 transition self-check | What it doesTicks and notes against thirteen items already published on the page | What leaves your browserNothing |
| WhereThe packaging validation readiness questionnaire | What it doesScores fifteen answers you give it into a count and one of four bands published on the same page, and builds a summary your browser saves to your machine | What leaves your browserNothing |
All four compute in your browser, using code that arrived with the page. There is no request to us and no request to anybody else while you type or when a result appears, nothing is computed on our servers, and no event is recorded anywhere. We do not know that you used one, what you entered, or what came out.
The transition self-check is the only one of the four that keeps anything, and it keeps it on your own device: your ticks and your notes, under the name given in 3.2, so they are still there if you come back. Its own page says so beside the controls, it carries a control that erases them, and nothing about them ever reaches us. The readiness questionnaire keeps nothing: close the tab and the answers are gone.
The printable and downloadable output these tools offer is generated in your browser. The calculators and the self-check hand the page to your browser's own print function; the questionnaire builds a plain text summary your browser saves to your machine. No file is generated by us, nothing is uploaded, and neither printing nor downloading tells us anything.
4What we may add, and what we never will
Section 3 describes what the site does today. It will change. When it does, the change is published here before it goes live, not after.
4.1What we may add
Within the boundaries below, adding something is an update to this page and not a departure from it:
- a challenge on a form, if the form starts attracting automated submissions;
- typefaces, diagrams or other assets served by another company;
- a way to book a call directly on the contact page;
- further forms, collecting the same kinds of business contact detail already listed in 3.4;
- the optional phone field and text message consent described in 5.4.
Each of those would appear in section 3, with the company involved named, before it went live.
4.2What we will never add
These are not descriptions of our current setup. They are rules, and they do not change.
- We do not sell personal information.
- We do not share personal information for cross-context behavioral advertising. Because we do neither, a Global Privacy Control signal has nothing here to switch off. That stays true whatever else we add, because sale and sharing are on this list.
- No advertising, no retargeting, no conversion pixels.
- No session recording and no keystroke capture.
- We do not buy personal information from data brokers, and we do not use bought, rented or shared contact lists.
- No third party will be allowed to collect information about your activity on other websites through this site. That is a rule we hold ourselves to, not a description of a current configuration.
- Nobody is cold-called, and nobody is sent a text message who has not asked to be.
- Nothing goes to a testing laboratory unless you engage us and we have agreed together which laboratory, and what is being sent.
5What you are agreeing to when you send us something
There are three separable things here, and this practice keeps them separate on purpose.
5.1Answering your inquiry
Sending the form, or emailing us, is asking to be contacted back. Replying to you, and following up about the same subject, is not marketing and does not need a marketing consent. It is the thing you asked for. Concretely, sending the form means:
- we read it and reply to the email address you gave;
- a record of the inquiry is created in the systems named in 3.5;
- we may follow up about that inquiry if you go quiet. The boundary is a number, not a mood: at most three follow-ups, within 90 days of the last message you sent us, about the subject you raised and nothing else. Any new message from you restarts that window. Every follow-up carries one line telling you how to make it stop;
- nothing else. No list, no sequence, no text message, no call unless you ask for one.
Sending the form does not sign you up for anything, and submitting a form is never treated as consent to marketing. The checkbox described in 3.4 is the only way to ask us for anything beyond a reply, and leaving it alone costs you nothing.
5.2Occasional email about standards work
This is a separate checkbox, unticked when the page loads, that you have to tick, with the description of what arrives written next to it. It is never a condition of getting a reply, of getting a document, or of anything else. Every message will carry a working way to stop it, and stopping takes effect immediately.
As at the date at the top of this page the checkbox is on step 2 of the contact form, and no such email has been sent to anyone. See 3.4.
5.3Text messages
As at the date at the top of this page, this site collects no phone number and we send no text messages. We are not registered to send business text messages in the United States and we do not send any. Nothing on this site should be read as saying otherwise.
The rest of 5.3 describes the rules we have set for that program if it ever runs, so that you can see them before rather than after. Section 5.4 sets out what would have to be true first.
- Scope, deliberately narrow
Text messages would be for two things only: a short reply about your own inquiry, and messages about a call you have arranged, such as a confirmation, a change of time or a reminder. No promotional or marketing text messages, at all.
- How consent would be given
By ticking a checkbox that is unticked when the page loads, next to a phone number you typed in yourself. The description sits next to the box, not behind a link, and it names us, says what the messages are about, says that frequency varies, says that message and data rates may apply, says how to stop and how to get help, and says in the same breath that consent is not required to contact us or to get a reply. The box is never pre-ticked, never bundled with anything else, and never a condition of anything. Leaving it alone costs you nothing.
- How you would stop it
Reply STOP to any message. You can also just say so, in any words, by any route that reaches us, including email. STOP is not the only way out, and a reply like "please take me off this" is treated exactly the same as the word STOP. We would stop as soon as we saw it, and in any case within ten business days. You would get one plain confirmation message and nothing else.
Mobile information is not shared or sold
This one matters enough to state exactly. We do not sell, rent or share your mobile phone number or your text messaging consent with anyone for their own marketing or promotional purposes. No mobile information is shared with third parties or affiliates for marketing or promotional purposes. We do not share either with affiliates, lead generators or list brokers for any purpose. The only parties who would ever receive your number are the service providers that carry a message for us, named in section 3.5, and only so that the message reaches you.
That is true unconditionally, today and if the program ever runs.
5.4What would have to be true before any of that happened
We are setting this out because a page that describes a program should say plainly whether the program exists. This one does not.
| Step | Status today |
|---|---|
| StepA phone field on the form, optional | Status todayNot present |
| StepA text message consent checkbox | Status todayNot present |
| StepPublished messaging terms | Status todaySee section 11 of our terms of use |
| StepA registered legal entity and a federal tax identification number | Status todayNeither exists. There is no company. |
| StepRegistration of the business and the messaging program with the United States mobile carriers' registry | Status todayNot done, and cannot start until the entity exists |
| StepA business phone line to send from | Status todayDoes not exist |
| StepAny text message sent | Status todayNone, ever |
Every one of those steps would appear in section 3 and in the change log in 10.3 as it happened. Nothing on this site claims that any of it is done.
Terms of use, including the messaging terms5.5Stopping, and what a consent never covers
Tell us to stop, in any words, by any route, and we stop. Reply STOP to a text if you ever get one, click the unsubscribe link in any email that carries one, or just email info@probitysciences.com and say so. We do not require a particular form of words and we do not require you to use a particular channel.
A consent never carries over
Stated once, so it does not have to be repeated.
- Consent to be replied to is not consent to be added to a list.
- Consent to email updates is not consent to be texted.
- Consent to be texted is not consent to be called.
- No consent given here permits sale, sharing for advertising, or transfer to anyone else for their own purposes. Those are in section 4.2 and no checkbox unlocks them.
5.6What we record to show you agreed
If you ever tick a consent box on this site, we record what you agreed to and when, so that in two years it is possible to say exactly what you saw. That record is:
- the fact of the consent, and which one it was;
- the date and time;
- the exact wording that was on the screen at the moment you ticked it, saved word for word rather than as a pointer to whatever the page says now;
- a version identifier for that wording;
- which page you were on;
- how it was given, which for this site means a checkbox on a web form;
- the phone number a text message consent attaches to, if it is that one;
- your IP address, only if it is a text message consent, for the reason given in 3.6;
- if you later stop it: the date and time you did, and how you told us.
No consent record is ever deleted when you withdraw. Withdrawal marks the record; it does not remove it. The record is the evidence that we contacted you because you asked us to, and that we stopped when you told us to. Section 6 says how long we keep it and is honest about the fact that this is longer than we keep most things.
As at the date at the top of this page no consent record exists for anyone, and the checkbox described in 3.4 is the only one that could create one.
6How long we keep it
There is no automated retention or deletion schedule, and no code that expires or purges anything. We are not going to publish a retention period that nothing enforces. What is actually true:
- Inquiry records
We keep an inquiry for as long as it is useful: while we are talking, and afterwards as a record of who asked what and when. There is no automated deletion; it is done by hand. If you ask us to delete your inquiry, we will delete every copy we control and tell you when it is done.
- One copy is outside our control
As 3.5 explains, a copy of your submission is written to the submission log line held by Vercel. We cannot remove an individual line from that log. It ages out on Vercel's schedule and we will not pretend otherwise.
- The submission log line and the platform request logs
Their retention is set by the hosting platform and by the plan we are on, not by us. We do not control it and we are not going to invent a number for it.
Email you send us stays in our mailbox until it is deleted by hand.
- Consent records are different, and this is the one place we do publish a number
If you ever give a consent under section 5, we keep the record of what you agreed to, and of when you told us to stop, for at least five years after the later of the consent or the last message we sent you. That is longer than we keep most things. The reason is that this record is the proof that we only contacted you because you asked us to, and that we stopped when you said so. Keeping it protects you as much as it protects us, and deleting it would destroy the only evidence that you ever said stop.
One clarification, because the number appears elsewhere on this site
Other pages state that records are retained for seven years. That figure is about project records for engaged clients, kept under our own quality procedures. It is not a retention period for website inquiries, and this page does not extend it to anyone who fills in the contact form.
7Where you sit
The rights in section 2 are offered to everybody who asks, on the same terms, by the same email address. That is the simple version and it is the operative one. This section covers what is specific to a few places.
7.1California
California law gives residents rights over their personal information, including rights to know, to access, to correct, to delete, and to opt out of the sale or sharing of personal information. Some of those rights sit in statutes that apply only to businesses above certain size thresholds. Rather than argue about where this practice sits, we offer the rights in section 2 to everyone. The rest of what you would want to know:
- We do not sell your personal information, and we do not share it for cross-context behavioral advertising. That is in section 4.2 and it does not change, so there is nothing here for you to opt out of.
- No third party collects information about your activity across other websites through this site. Section 3.1 is the evidence and section 4.2 is the rule.
- The categories we collect are: identifiers (your name, your work email, and a phone number if you give us one for a call you arranged); commercial or professional information (your answers about a device and its packaging, and anything you volunteer in the free-text box or in an email, including attachments); and internet or other electronic network activity information (an IP address, the pages you view, timestamps, and general device and browser information), collected through Google Analytics as described in 3.3 and present in the platform request logs kept by Vercel rather than by us. We collect all of it directly from you, and only from you: Google Analytics gathers the network-activity information on our behalf as a processor, and even so it comes from your visit and from no other source. We do not buy personal information from data brokers or obtain it from any other source.
- We use it to reply to you and to run the work, and nothing else.
7.2Washington
Washington's My Health My Data Act regulates consumer health data. This site does not collect consumer health data. Every field on every form on this site is listed in 3.4, and none of them asks about anyone's health. They ask what the product is, its class, how it is sterilized, how it is packaged, whether the sealing process is validated, and when you plan to submit.
The free-text box is the one place where we cannot control what arrives. We ask you in 3.4 not to put health information in it. If health information about you or anyone else reaches us anyway, we do not want it, we will not use it for any purpose, and we will delete it from the records we control as soon as we notice it.
7.3Outside the United States
This practice is based in Washington State and operates in the United States. Vercel and our customer relationship management provider are United States companies, and we have not asked either to process your information outside the United States. Where their infrastructure physically sits is governed by their own terms, not by us.
We do not target visitors in the European Economic Area or the United Kingdom, and this page is written to United States law. We do not claim compliance with the GDPR or the UK GDPR, because claiming a compliance program we have not built would be exactly the kind of statement this page exists to avoid.
If you are outside the United States and you have a question about information you have sent us, email info@probitysciences.com. The rights in section 2 are offered to you the same as to anyone else.
8Children
This site is for quality and regulatory professionals at medical device manufacturers. It is not directed at children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has sent us something, email info@probitysciences.com and we will delete what we hold, subject to the limits in section 2.
9Security
Proportionately, and without overstating it:
- The site is served over an encrypted connection, and it tells your browser to refuse an unencrypted one in future.
- We run no database and no server of our own. Where a submission actually rests is in 3.5, under Vercel's access controls rather than ours.
- There is no account system and no password on this site, so there are no credentials of yours for anyone to steal.
- The form collects no payment details, no files and no passwords, so none of those can be exposed.
- Keys used by the site are held in the hosting platform's environment and are not in the site's code.
Two honest limits
We do not hold, and do not claim, any security certification such as SOC 2 or ISO 27001. And no method of transmitting or storing information is completely secure, so we cannot promise absolute security.
If something happened that exposed information you sent us, we would tell you. That is a commitment we are choosing to make: the law does not require notification for every kind of information, and we would rather you heard it from us.
10How this page is kept true
10.1The commitments
- 1
This page is updated before something is switched on, not after. That is how Google Analytics arrived: the cookies, the Google scripts and the measurement in section 3 were disclosed in the same change that turned them on, on 6 August 2026. The same rule holds for whatever is next: a challenge on the form, a second form, a phone field, a single text message.
- 2
If the inquiry records described in 3.5 are connected, this page is updated on the same day.
- 3
If we ever start sending email that is not a reply to your own inquiry, this page will say so, and you will have had to tick a box first.
- 4
The date at the top moves whenever section 3 moves, and the change is listed in 10.3.
10.2Where the limit of our own checking is
Some things are set in our hosting platform and in the systems we use rather than in our code, and a check that reads our code cannot see those. Section 3.8 lists them, says who confirmed them, and says when. We would rather draw that line clearly than imply a machine is checking something it cannot see.
Everything else in section 3 is a fact about our own code, in a repository one person controls, and the same person writes both the code and this page in the same change.
10.3Change log
| Version | Date | What changed |
|---|---|---|
| Version2.0 | Date4 August 2026 | What changedFirst publication. |
| Version2.1 | Date4 August 2026 | What changedThe consent record described in 5.6 is now kept. Section 3.5 states that the submission log line carries it, and that the page a consent was given on is the one URL path our code writes. |
| Version2.2 | Date5 August 2026 | What changedTwo calculators and a self-check now run on this site. New section 3.9 describes all three and states that they compute in your browser and send nothing. Section 3.2 names the one local storage entry the self-check writes, and 3.4 draws the line between the one form and three sets of controls that are not one. |
| Version2.3 | Date5 August 2026 | What changedA packaging validation readiness questionnaire now runs on this site, a fourth set of browser-only controls. Section 3.9 adds it, states it computes in your browser and keeps nothing, and section 3.4 counts it among the controls that are not the one form. Its answers are scored in the browser and reach no server; the optional route that would email a result to yourself is not built yet, and this page moves before it is. |
| Version2.4 | Date6 August 2026 | What changedTwo things were switched on in this release. Google Analytics 4 now runs for every visitor: sections 3.1, 3.2, 3.3 and 3.6 describe the two Google origins, the two cookies, what is measured, and that Google receives your IP address as our processor, and there is no cookie banner. And the GoHighLevel inquiry records described in 3.5 are now connected: a submission creates a contact record there, in addition to the Vercel log line. The short version, section 4.1, section 7.1 and section 10.1 were updated to match. |
11How to contact us
Probity Sciences, Greater Seattle Area, Washington, United States. info@probitysciences.com
This page is published at probitysciences.com/privacy.
Email is the way to reach us about anything on this page, including a request about your own information. There is no separate privacy inbox and no web form for it: the address above reaches the person who runs the practice.