REGULATORY PATHWAYS INC.
1. INFORMATION COLLECTION IN THE ALCOHOL BEVERAGE SECTOR
Regulatory Pathways Inc. collects and processes non-public commercial data to operate the RegPath regulatory intelligence platform. We collect contact details, brewery and distillery operating numbers, federal basic permit data, and billing information processed securely through Stripe. Additionally, we collect proprietary beverage formulation notes, government warning layouts, and graphic label files uploaded directly by users for automated compliance analysis.
2. ALCOHOL INDUSTRY AGE RESTRICTION AND COPPA COMPLIANCE
2.1 Strict Twenty-One and Older Commercial Requirement. Because the RegPath software platform analyzes regulations governing beer, wine, and distilled spirits, access is restricted strictly to commercial beverage professionals who are at least twenty-one years of age or older. The organization does not knowingly solicit, collect, store, or process personal identifiable information from minors under the age of eighteen, nor from individuals under the legal drinking age of twenty-one. If the company discovers that an underage individual has created an account or submitted product data, the corresponding digital records will be purged and destroyed immediately.
3. CATEGORICAL SUBPROCESSOR DISCLOSURE AND ARTIFICIAL INTELLIGENCE ROUTING
3.1 Confidential Software Stack Routing. To deliver automated Certificate of Label Approval prechecks and real-time regulatory answers, Regulatory Pathways Inc. routes uploaded text and graphic data through specialized third-party technology subprocessors. In accordance with enterprise software privacy standards, we disclose our subprocessor architecture by operational category rather than specific brand names to protect our proprietary routing pipeline.
3.2 Third-Party Processing Categories. Uploaded customer data is processed utilizing three distinct subprocessor tiers: secure cloud infrastructure hosting vendors for database archiving, optical character recognition partners for text extraction from graphic labels, and automated artificial intelligence processing engines for regulatory rule comparison. We contractually require our artificial intelligence processing partners to operate under zero data retention frameworks, ensuring that proprietary customer beverage formulas and label graphics are never retained by external subprocessors to train public machine learning models.
4. COOKIES, LOCAL STORAGE, AND ANALYTICS TRACKING
4.1 Digital Tracking Technologies. The platform utilizes digital tracking tools, including analytical web beacons, session cookies, local browser storage, and Stripe payment tracking tokens, to optimize platform functionality and authenticate user sessions. These assistive tools automatically gather non-identifiable system information, including browser types, device screen resolutions, referring web domains, and individual page viewing durations.
4.2 Payment Processor Tokens. Financial transactions are executed strictly through our integrated payment processor, Stripe. The platform does not directly store credit card numbers or banking credentials on our primary servers; instead, we utilize secure billing tokens generated by Stripe to manage recurring subscriptions and one-time review checkouts.
4.3 User Tracking Control. Users maintain complete administrative control over cookie execution and may disable non-essential analytical cookies by modifying individual browser security settings, though disabling core session cookies may impair automated label scanning functionality.
5. TECHNICAL SECURITY STANDARDS AND ENCRYPTION PROTOCOLS
5.1 Data Encryption Standards. To safeguard sensitive commercial trade secrets, including craft beer mash bills and unreleased graphic labels, the company implements enterprise-grade technical encryption protocols. All digital transmissions between the browser of the user and our primary servers are insulated utilizing Transport Layer Security encryption in transit. Furthermore, stored label files and compliance workpapers are secured utilizing Advanced Encryption Standard protocols at rest within Amazon S3 cloud arrays.
5.2 Incident Notification Protocol. In the event of a confirmed cyber interception or security breach impacting our cloud infrastructure storage arrays, Regulatory Pathways Inc. will notify affected commercial users and relevant regulatory authorities in accordance with applicable statutory timelines. Because the company exercises reasonable administrative care in selecting reputable software subprocessors, the organization shall not be held liable for third-party security breaches occurring outside our direct physical and administrative control.
6. DATA RETENTION AND DELETION TIMETABLE
6.1 Active Subscription Storage. All label files, compliance reports, and formula documentation belonging to active subscribers are maintained securely in cloud storage arrays to facilitate ongoing library management and product line auditing.
6.2 Post-Termination Purge Cadence. When a user terminates an active subscription or requests account deletion, Regulatory Pathways Inc. initiates a thirty-day grace period to allow the user to export historical compliance documentation. Upon the expiration of the thirty-day window, all proprietary label graphics, uploaded formulas, and account workpapers are permanently and irreversibly purged from our primary servers and Amazon S3 storage arrays.
7. ITEMIZED SCHEDULE OF USER PRIVACY RIGHTS
7.1 Schedule of Commercial Rights. Regardless of the geographic location of the brewery or distillery, Regulatory Pathways Inc. grants all active platform users an explicit schedule of digital privacy rights regarding stored commercial records:
The Right to Access: Users may request a comprehensive digital copy of all account records, billing logs, and historical compliance reports currently hosted on our servers.
The Right to Rectification: Users maintain the right to correct inaccurate account details, update brewery operating numbers, or modify administrative contact information directly through their digital dashboard.
The Right to Data Portability: Users may export archived label graphics and Certificate of Label Approval precheck workflows in standard machine-readable formats prior to subscription termination.
The Right to Erasure: Users may submit a formal request for immediate account erasure, which accelerates our standard thirty-day post-termination purge timeline and permanently destroys all associated cloud storage files.
8. CROSS-BORDER DATA TRANSMISSION DISCLAIMER
8.1 United States Governing Framework. The RegPath software platform is engineered, hosted, and operated strictly within the United States to support domestic federal Alcohol and Tobacco Tax and Trade Bureau and state alcoholic beverage control compliance. If an enterprise user, international compliance consultant, or traveling brewery executive accesses the platform from locations outside the United States, all transmitted information is routed directly to domestic cloud servers. By utilizing the software from international jurisdictions, the user explicitly consents to the transmission, processing, and storage of commercial data within the United States under domestic privacy frameworks.
9. REGIONAL STATE PRIVACY NOTICES
9.1 Regulatory Pathways Inc. complies with applicable United States privacy laws. Residents of certain states may have rights to request access to, correction of, deletion of, or a copy of personal information, subject to applicable law. Requests may be submitted to support@regpath.io, and RegPath will respond in accordance with applicable legal requirements.