CEMarque Privacy Notice
Effective date: 19 September 2026
Draft revision: 16 September 2026 — implementation reconciliation
Controller: Ronald D. Coburn, a sole proprietor trading as CEMarque, operating the CEMarque service
Place of establishment: North Carolina, United States
Postal address: 2608 Erwin Rd, Unit 402, Durham, NC 27705, United States
Privacy contact: privacy@cemarque.com
1. Scope and key points
This notice explains how we handle personal information when you visit cemarque.com, use its checker, contact us, join a waitlist, buy an Attestation Pack, or subscribe to CEMarque Watch. Sections about a paid service apply when you use that service; they do not mean every described service is currently available.
- You can use the public checker without creating an account or giving us your name or email address.
- Checker verdicts and the answers displayed on their pages are public. They are separate from private Pack submissions. If you request updates for a verdict or include its reference in a signup, we can link that verdict to your email address in our private subscription records.
- Website delivery and security involve automatically processed technical information. No account does not mean no personal-data processing.
- We use purchase and contact information to supply services, communicate with you, maintain appropriate records, and address security or legal issues.
- We do not sell or rent personal information, or share it for cross-context behavioural advertising. We do not operate advertising profiles or cross-site advertising tracking.
- Stripe processes payments. We do not request or store full card numbers or card security codes.
The Terms of Service describe the service contract. This notice is information about our processing, not a request for blanket consent.
This notice covers the CEMarque services identified here. A different website or service is not covered merely because it has a common owner; its own notice explains its processing. An external page you choose to visit may receive request information directly from your browser under that site's own notice.
2. Who is responsible
The controller identified above decides why and how personal information is processed for our website, customer administration, communications, billing records, and security.
For an engagement in which we process personal information solely on a business customer's documented instructions, that customer is the controller and we act as its processor under a separate data-processing agreement. This notice does not replace that agreement or the customer's own notice. Contact that customer first about information it controls; we will assist as required.
EU/EEA and UK representatives: none appointed. Our processing of EU and UK personal information is occasional, involves no special-category data and is unlikely to result in a risk to the rights of individuals, so we rely on the exemption in Article 27(2)(a) of the GDPR and the UK GDPR; the assessment is documented and reviewed whenever our EU or UK customer base changes materially.
Data protection officer: not required and not appointed; the privacy contact above handles every request.
You can contact us at privacy@cemarque.com whether or not a representative or data protection officer is appointed.
3. Information we process and its sources
3.1 Website visits and security
When your browser requests a page, the systems delivering it process network and request information. Depending on the component involved, this includes an IP address, request time, requested path, response status, browser or user-agent information, and security or error events. We use technical records to deliver pages, diagnose problems, understand aggregate usage, and prevent abuse.
We use an IP-derived hash for abuse prevention. Hashing reduces direct exposure of the address; it does not automatically make the record anonymous. Logs or other technical records may still permit association with a visitor. We do not promise that discarding one value makes every related record permanently unidentifiable.
The implemented hash rotation and deletion schedule is a SHA-256 hash of the address under a salt that changes every UTC day; each salt is discarded 7 days after its day, after which the hashes computed with it can no longer be matched to an address; the raw address itself is never written to storage. The access-log scope, including whether raw IP addresses, request URLs, and referrers are stored, is a standard web-server access log on our own server holding the raw IP address, the time, the requested path and query string, the response status and size, the referrer and the user-agent string; no other party receives it. Retention is described in Section 9. We do not intentionally use URLs or logs to collect customer secrets.
3.2 Checker answers and public verdicts
We process your checker selections to generate a result and a reference URL. The page displays the selected answers included in the result, the assessment, relevant assumptions and citations, the generation date, and the applicable rules or facts version. The standard checker does not ask for a name, email address, or customer account identifier.
However, information may be personal data if it identifies a sole trader or another individual, or can reasonably be linked to them through other records. A waitlist signup or request for verdict updates can connect your email address with a saved verdict. We do not treat the absence of a name field in the checker as proof that every verdict is anonymous.
3.3 Waitlists, subscriptions, and communications
We receive the email address you submit, the list or service you request, your subscription and preference status, and records needed to administer those choices. A waitlist record can also contain the product type, saved-verdict reference, and note you provide, together with its creation time, an IP-derived abuse-prevention hash, and a coarse browser or device category.
If you request updates for a particular saved verdict, we associate your subscription with that verdict's reference so we can identify the updates you requested. The same association can arise when you include a verdict reference in a waitlist signup. We do not add your subscription email address to the public verdict page. The public page remains accessible as described in Section 4; the private association means that the result may be identifiable to us.
To confirm subscriptions, honour unsubscribe requests, and prevent misuse, we process confirmation and unsubscribe token records, request and confirmation times, and subscription status. Confirmation and unsubscribe links can authorise an action, so avoid forwarding them or posting them publicly. Free verdict updates, promotional messages, and the paid Watch Bulletin have different purposes and controls; subscribing to one does not by itself authorise the others or create a payment obligation.
We also process messages and attachments you send when requesting help, a correction, a refund, or a privacy action.
Where we rely on consent, we retain evidence of the consent, including its time, source, and the wording presented. Email-delivery systems process delivery, bounce, and complaint information needed to operate the service. Our use or non-use of message-open and link-click tracking is described in Section 5.
3.4 Payments and order administration
Stripe receives payment details directly. We receive and maintain the order and transaction information needed to fulfil the purchase, identify payments, administer subscriptions, issue invoices or refunds, and meet recordkeeping obligations. Depending on your purchase and the checkout configuration, that includes email, customer or business name, billing address, country, tax identifier, purchase description, amounts, currency, payment status, transaction identifiers, and limited payment-method information such as card brand and last four digits.
We do not receive or store your complete card number or card security code. Stripe may process information for its own fraud prevention, compliance, and other purposes as described in its Privacy Policy. Its role varies by processing activity; it is not solely a processor acting on our instructions.
3.5 Attestation Pack inputs and documents
You may send product details, technical descriptions, inventories, evidence, proposed support commitments, security contacts, and other information needed to prepare your Pack. These materials may include the names and business contact details of employees, suppliers, or other people.
We use this material to prepare and deliver the purchased documents, perform included regeneration, correct problems, provide related support, and maintain necessary transaction or dispute records. We do not publish Pack inputs or deliverables as public verdicts. Materials intended for your own public security page remain private with us unless publication is separately and expressly agreed.
Send only information needed for the engagement. Do not submit passwords, private keys, unrelated personal records, or unnecessary sensitive information. If your intended engagement requires personal information to be handled on your organisation's behalf, arrange the appropriate data-processing agreement first.
3.6 Information from others
We may receive order and payment updates from Stripe; delivery and security information from our service providers; and business contact information from a colleague or organisation arranging a service for you. We use that information for the corresponding purposes described here. Where EU GDPR Article 14 applies to information obtained indirectly, we provide the required notice within a reasonable period and no later than one month after obtaining it, or earlier at our first communication with the person or first disclosure to another recipient, as applicable. A lawful exception may apply. Other applicable notice deadlines remain effective.
Regulatory source material and customer records serve different purposes. Monitoring public regulatory developments does not give us permission to add a named person to a marketing list or reuse their personal information for an unrelated purpose. Where publication of a regulatory source itself involves personal information, we assess the appropriate basis and transparency requirements.
4. Public verdicts: publication, access, and removal
Submitting the checker creates a public result as explained at the point of submission. Anyone who obtains its URL can view it. A difficult-to-guess link is not authentication. Others may share or copy it, and it may be indexed or archived by search engines or other third parties.
The current search-engine indexing configuration is indexing permitted: verdict pages are served with a robots directive of "index, follow" and the /v/ path is allowed in robots.txt for every crawler, including the named AI crawlers; verdict pages are not listed in the sitemap. A request not to index a page is not a guarantee that it remains private. Do not put confidential or unnecessary personal information into a public result or share a link that you do not want others to view.
To request correction or removal, contact privacy@cemarque.com and identify the page and your concern. A public URL alone is not proof that the requester created the page or is entitled to confidential information. We use proportionate verification where needed. We do not collect additional identity information solely to create an identification capability that the service otherwise does not need.
Where applicable law requires correction, restriction, or erasure, we act accordingly, including required steps regarding recipients. For copies we control, removal covers the stored record, any application-memory copy, affected public HTML, JSON, Markdown, print and derived responses, and relevant proxy or other caches. The backup rules in Section 9 govern backup expiry and restoration without reintroducing removed information. Copies independently held by third parties may be outside our direct control. We will not claim that deleting our page erases every copy on the internet.
A privacy correction or removal is distinct from creating a new assessment of an updated product. We do not silently replace a dated result with a different conclusion while representing it as the original assessment. Where necessary, we remove or restrict exposed personal information without making the individual pay for a new Pack or subscribe to a service.
5. Cookies, browser storage, analytics, and email tracking
The current public-site cookie and browser-storage configuration is none: the public site sets no cookies, uses no browser storage and serves no JavaScript, so no third-party script runs on it and nothing is collected across websites; checker progress is carried in the page URL you are on; because nothing optional is set, the site does not read Do Not Track or Global Privacy Control signals. This covers the technologies used, their purposes and duration, your choices, any third-party collection across websites, and our actual response to browser Do Not Track signals where relevant. Do Not Track and Global Privacy Control are distinct signals; this notice does not assume that one describes the other. A cookie-free public page does not mean that every payment, email, or linked third-party service is cookie-free.
The checker and site use aggregate usage information, such as counts of checks started or completed, to understand use and reliability. The analytics implementation, technical information processed before aggregation, any outside recipient, and retention are server-side only: a named event (check started, check completed, facts page viewed, waitlist signup, Watch page viewed and the Watch subscription events) is appended to a log file on our own server with an allow-listed set of properties — the page or preset, the checker outcome, a classification of the referrer (search, social, direct, AI assistant) and of the user-agent (browser, crawler, AI agent) — and no IP address, cookie, email address or other direct identifier; no outside recipient; retention is stated in Section 9. Truly anonymous totals do not identify an individual; information is not treated as anonymous merely because it will later be aggregated.
Payment and other third-party services may use their own security and session technologies when you interact with them. Relevant providers and their notices appear in Section 7. Where consent is required for optional storage, access, or tracking, we obtain it before activating that technology and provide a way to withdraw it. Essential service delivery is not made conditional on accepting optional advertising or analytics.
Our email open and click tracking practice is none: our emails are plain text and contain no open-tracking image and no per-recipient tracked links; confirmation and unsubscribe links carry a token that identifies the subscription so that the request can be honoured, and nothing else. Basic delivery, bounce, unsubscribe, and complaint handling is separate from optional engagement tracking.
6. Purposes and legal bases
Where the EU GDPR, UK GDPR, or another law requiring a legal basis applies, our processing is organised as follows.
| Purpose | Information involved | Basis where applicable |
|---|---|---|
| Take steps you request before a purchase and perform a contract directly with you | Contact details, order records, necessary Pack inputs, paid-delivery information | Contract and requested pre-contractual steps. |
| Provide a service purchased by your employer or another organisation | Business contact details, necessary messages and product materials | Legitimate interests in administering that business relationship, unless we act as the customer's processor under its instructions. |
| Deliver pages, prevent abuse, investigate faults, and protect users | Network/request records, IP-derived identifiers, security events | Legitimate interests in secure and reliable operation; consent separately where a technology requires it. |
| Generate and maintain public checker results | Checker answers, resulting pages, related technical records | Legitimate interests in providing the requested public reference service, subject to necessity, reasonable expectations, and users' rights. |
| Understand aggregate service use | Usage events and aggregate counts | Legitimate interests where permitted; consent for any processing requiring it. |
| Send requested waitlist communications, free verdict-update emails, and promotional communications | Email, the requested list or verdict reference, signup and consent records, preferences | Consent, with withdrawal available at any time. Each signup must clearly identify the communications requested. |
| Deliver the purchased Watch bulletin and essential order communications | Subscription details, email and delivery records | Contract when you are the contracting individual; legitimate interests in serving the customer organisation for its representatives. |
| Keep required financial or other compliance records | Necessary billing and transaction records | Legal obligation where grounded in law qualifying under the applicable data-protection regime; otherwise, where lawful, legitimate interests in meeting applicable business obligations. |
| Handle complaints, refunds, legal claims, and objections to marketing | Necessary transaction, communication, and preference records | Contract, applicable legal obligations, or legitimate interests in resolving disputes and respecting preferences, according to the activity. |
When relying on legitimate interests, we assess the purpose, necessity, and impact on individuals. You may object as explained in Section 11. A legal basis for security does not automatically justify every analytics or advertising use.
We do not use consent as the basis for processing that you cannot meaningfully decline. Withdrawing optional marketing consent does not affect the lawful processing needed to fulfil an existing purchase, and refusing optional tracking does not require you to accept a different privacy notice. Where a new purpose needs fresh information or consent, we address that before the new use starts.
Information needed to identify and fulfil a purchase is a contractual requirement. If you do not provide it, we may be unable to accept or deliver that order. Marketing signup is optional and is not a condition of purchasing. The public checker does not require an email address. Any legally required billing fields are identified at checkout.
7. Recipients and service providers
We restrict sharing to what is needed for the purposes described in this notice. Service providers acting as processors are subject to appropriate instructions, confidentiality, and data-protection obligations. Providers acting as independent controllers are responsible for their own processing under applicable law.
| Recipient | Purpose and role |
|---|---|
| Stripe and relevant payment participants | Payment processing, subscription administration, refunds, fraud prevention, and compliance. Stripe acts as controller and/or processor depending on the activity. See Stripe's Privacy Policy. |
| Hosting and email-delivery infrastructure | The actual providers, services, contracting entities, and regions, including AWS only if used, are Amazon Web Services: an EC2 virtual server in the eu-central-1 (Frankfurt) region hosts the website, the verdict store, server logs and the Watch data, and Amazon SES in the same region sends Watch email; no other AWS service holds personal information. |
| Other operational providers | The provider list for support email, analytics, monitoring, backup, file handling, and any AI processing, including purposes, information involved, and relevant processing countries, is Titan, which hosts and forwards the @cemarque.com mailboxes used for support and correspondence; Stripe, listed above; and GitHub, Inc., which hosts the source code and no customer information. We use no analytics, monitoring, file-handling or marketing vendor; AI assistance is described in Section 10. |
| Authorised personnel and contractors | Preparation, delivery, support, and security work that requires access, subject to confidentiality and appropriate access restrictions. Relevant contractor locations are included in the transfer assessment. |
| Professional advisers and authorities | Information reasonably necessary for advice, legal obligations, or establishment, exercise, or defence of legal claims. We assess legal requests and limit disclosures appropriately. |
Public verdict information is also disclosed to anyone who accesses the page, as explained in Section 4.
If the business is reorganised or sold, necessary information may be disclosed under confidentiality during the transaction and transferred to a successor responsible for the service. Applicable notice, purpose-limitation, and data-protection requirements continue to apply. This does not authorise unrelated marketing use of customer information.
8. International access and transfers
The operator’s place of establishment is identified above. The countries in which information is actually processed or remotely accessed, including provider and authorised-personnel access, are identified in the transfer details below. Hosting in an EU region does not, by itself, mean all processing or access remains in the EEA.
For processing that constitutes a restricted international transfer under the applicable law, the actual destination, recipient, and safeguard are:
[TRANSFER_DETAILS: identify each relevant transfer or recipient category, the countries, the applicable adequacy decision or executed safeguards, and how a copy or information about those safeguards can be obtained.]
We do not rely on a provider's general compliance statement as proof that it covers every transfer involving our service. Where standard contractual clauses or another contractual mechanism is used, it must cover the actual parties and activity, with required assessments and supplementary measures. Where an adequacy framework is used, it must apply to the recipient and processing in question. UK transfers require the mechanism applicable under UK law.
You may request information or a copy of relevant safeguards at privacy@cemarque.com, subject to appropriate redaction of confidential information. We do not treat acceptance of the Terms as general consent to otherwise unlawful transfers.
9. Retention and deletion
We retain personal information only for as long as needed for its stated purpose and applicable obligations. The schedule below applies to our operational copies, subject to a documented legal hold or other lawful exception. Different copies serving genuinely different purposes may have different retention periods.
| Category | Retention period or criterion |
|---|---|
| Raw technical and access logs | 14 days, measured from creation, with restricted retention of relevant incident evidence where necessary. |
| IP hashes, salts or keys, and rate-limiting records | Salts exist only in the server's memory, are never written to disk or to a backup, and are discarded 7 days after their day; rate-limiting counters likewise exist only in memory and are lost on restart. The hash stored with a verdict record stays in that record but cannot be matched to an address once its salt is gone, which is the point at which it stops being personal information in our hands. |
| Individual analytics events | 12 months from the event, then deleted; genuinely anonymous aggregate totals may be retained longer. |
| Public verdicts | Intended availability of at least 12 months from creation, subject to privacy, security, lawful-removal, and service-closure exceptions. Longer retention is reviewed under an annual review after the first 12 months, keeping a verdict while the checker and the facts and rules versions it cites remain online to determine whether keeping the public reference remains necessary and appropriate. This is not a promise of perpetual retention. |
| Waitlist and marketing records | While the requested list remains active and you remain subscribed, with review under deletion 24 months after signup if no corresponding plan has opened and no contact has taken place. We stop promotional use when you unsubscribe. Limited consent and suppression records may remain as described below. |
| Watch subscriber, confirmation, and delivery records | While needed to confirm, deliver, and administer the requested subscription, then unconfirmed signups are deleted after 7 days and confirmation tokens expire after 24 hours; ended subscriptions, their verdict associations and their delivery records are deleted 30 days after the end of the last paid period. This schedule specifies expiry and deletion for unconfirmed signups, confirmation tokens, ended subscriptions, verdict associations, and delivery records. Financial records and suppression records follow their separate rules. |
| Pack working inputs and operational copies of documents | During preparation and the included 12-month regeneration period, and as reasonably necessary to complete a regeneration or correction request still in progress, then 30 days after the 12-month regeneration period ends, unless a regeneration or correction request is still open, in which case 30 days after it closes. We retain only the material needed for that outstanding work, not every input indefinitely. Valid earlier deletion requests and separate processing-agreement requirements still apply. Necessary transaction or claim evidence follows its separate schedule. |
| Purchase, invoice, tax, and refund records | 7 years from the end of the tax year in which the transaction occurred, reflecting the obligations applicable to our actual legal entity. |
| Support, complaint, consent-evidence, and privacy-request records | 3 years from the closure of the request or complaint, limited to what is needed to resolve the matter and demonstrate appropriate handling. |
| Marketing suppression records | A minimal record while necessary to honour the objection or withdrawal and prevent reintroduction into active marketing lists. We restrict its use to that purpose and review necessity. |
| Backups | Watch data is backed up once a day on the same server with a 30-day rolling expiry, after which the backup is deleted; no other copies are kept and no off-site or disk-image backups are taken. Data awaiting backup expiry is not returned to ordinary use merely because a backup exists; restoration procedures reapply relevant deletion and suppression actions. |
Unsubscribing does not require deletion of records that must remain for billing, disputes, or respecting your preferences. A suppression record may use an email-derived hash to recognise an address that should not be contacted. We treat that hash as personal information where it can still be linked to an individual; replacing an email address with a hash is not, by itself, anonymisation. We explain any applicable exception when responding to an erasure request.
A legal hold or dispute exception is limited to the relevant records and duration. It is not a blanket reason to retain every customer's material indefinitely. We restrict held records to the necessary purpose, review whether the exception still applies, and delete or anonymise information when no valid retention purpose remains. If our role is processor, deletion and return follow the customer's lawful instructions and the applicable processing agreement, subject to any binding retention duty.
Deleting Pack inputs may prevent further regeneration. We explain that consequence without using it to refuse a valid privacy right. You should maintain your own regulatory records: our retention schedule does not establish how long you must retain your technical documentation.
10. Security and AI processing
We use organisational and technical safeguards appropriate to the information and processing, including limiting access to authorised people and providers. The specific controls must be maintained in our operational security procedures. No internet service can promise absolute security.
Do not email credentials or private keys. Contact privacy@cemarque.com if you believe information has been exposed or incorrectly published. Where a personal-data breach triggers notification duties, we notify the appropriate authority and affected people as required.
The checker uses submitted answers and encoded regulatory rules to produce an informational product assessment. Its output does not itself grant or remove an individual's legal rights, and we do not represent it as an official decision. We do not use the checker to make solely automated decisions about individuals with legal or similarly significant effects.
Payment and security providers may use automated fraud or abuse screening for their own activities. Their notices describe that processing; the statement about the checker does not describe every decision made by an independent provider. If a payment or access restriction appears incorrect, contact privacy@cemarque.com so we can review matters within our control and explain the appropriate provider route where needed. Any CEMarque use of personal information for legally significant automated decisions would require a separate assessment and the disclosures and safeguards required by the applicable law before use.
Any AI assistance used in preparing or supporting paid deliverables, including the provider, purpose, information submitted, relevant human review, and provider retention, is as follows: the operator may use Anthropic's Claude to draft Pack documents from the inputs a customer supplies, under Anthropic's commercial terms, which do not permit training on that material; every draft is reviewed and edited by the operator before delivery; Anthropic retains API inputs only for the period stated in its published retention policy. No customer information is submitted to any other AI service. We do not use confidential customer inputs or deliverables to train general-purpose AI models or authorise providers to do so under the service. AI processing, if used, remains subject to this notice, the service confidentiality commitment, and appropriate provider terms.
11. Your choices and rights
Depending on the law that applies, you may have rights to access personal information, obtain a copy, correct inaccuracies, request deletion, restrict processing, receive eligible information in a portable format, or object to processing. These rights are subject to their legal conditions and exceptions.
Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal. You can unsubscribe from marketing through the email link or contact us. Where applicable, you may object to processing based on legitimate interests, including on grounds relating to your particular situation. You may object to direct marketing at any time.
To exercise a right, email privacy@cemarque.com. We use reasonable, proportionate identity checks and do not ask for more information than necessary. Possession of a public verdict URL is not sufficient verification for disclosure of other records. Where we cannot identify the relevant person or record, we explain that and consider additional information you choose to provide.
For requests governed by the EU GDPR, we respond without undue delay and within one month of receipt, subject to applicable calculation rules. A necessary extension for complexity or the number of requests may add up to two months; we explain the extension within the initial month. Requests are free unless the law permits a reasonable fee, such as for manifestly unfounded or excessive requests or additional access copies. We explain any refusal and the available complaint and judicial remedies. Other regimes' deadlines and procedures remain applicable.
You may complain to the competent data-protection authority without first contacting us. In the EEA, this may be the authority in your habitual residence, workplace, or the place of the alleged infringement. The EDPB member directory lists EEA authorities. For UK matters, see the Information Commissioner's Office.
Where a US state or another jurisdiction grants applicable access, deletion, correction, portability, opt-out, authorised-agent, or appeal rights, we honour those rights under the relevant conditions. Contact privacy@cemarque.com to submit a request or appeal a denial; we provide the applicable procedure in our response. We do not penalise you for exercising a protected privacy right. Our statement that we do not sell data or use cross-context behavioural advertising is not a claim that every US state privacy law necessarily applies to us.
An authorised agent may contact the same address. We request evidence of authority and any identity verification allowed by the applicable law, proportionate to the request. Where a legally recognised browser or universal opt-out signal applies to our processing, we honour it as required. A signal concerning advertising or sale of data does not by itself cancel a paid subscription or request erasure of all order records.
12. Paid-service cancellation and communication choices
Marketing preferences and paid-service cancellation are different actions. Unsubscribing from promotional messages does not cancel an order, stop essential billing notices, or by itself cancel Watch. Use the control clearly labelled to cancel the paid subscription or email privacy@cemarque.com. A control labelled to stop the paid Watch bulletin also cancels future renewal, as explained in the Refund and Cancellation Policy.
If a privacy request indicates that you also want a paid service to stop, we address both aspects rather than requiring you to restart the request. Where your intention is unclear, we explain the choices. We do not keep using unnecessary information merely because a subscription is active, or erase a payment record while leaving an unwanted renewal running.
You can use the public checker without joining a mailing list or buying a service. We do not use a privacy-rights request as consent to marketing.
13. Children
The service is designed for business and professional users and is not directed at children under 16. Paid purchases require an adult with contractual capacity under the Terms. We do not knowingly solicit children's personal information. If you believe a child has supplied personal information, contact us so we can assess and take appropriate action. These statements do not override a different age or protection required by applicable law.
14. Changes to this notice
We update this notice when processing changes and show the effective date above. Where a change materially affects how existing customer information is used, we provide an appropriate direct or prominent notice before the new processing begins, unless law requires a different approach. We obtain fresh consent where required. Posting a revised notice does not itself make an incompatible new use lawful.
15. Contact
Ronald D. Coburn, a sole proprietor trading as CEMarque, operating the CEMarque service
2608 Erwin Rd, Unit 402, Durham, NC 27705, United States
Privacy requests: privacy@cemarque.com