Policy
Privacy policy
What this site holds about you, who can see it, and how long it is kept.
This policy applies to Medical Device Manufacturing, the site at this address, and to nothing else: not to the publisher’s own website, and not to the websites this site links to. It describes what the software and the server actually do. Where a sentence states a period, the number is read from the code that keeps it, so the page and the software cannot say different things.
Who is responsible for this site
Medical Device Manufacturing is published by Life Science Outsourcing, Inc., 830 Challenger St, Brea, CA 92821. Everything described on this page is held by the publisher. How to reach the publisher about anything here is under your rights below.
The short version
- Reading this site needs no account and sets no cookie.
- There is no analytics tag, no advertising tag and no third party script, font or image on any page. You can confirm that by viewing the source of any page here.
- The web server keeps ordinary access logs, which include your IP address, for about two weeks. No database table on this platform stores an IP address, and nothing you type is ever joined to one.
- Each of these collects something from you, and only when you use it: the request form at /rfq, the newsletter signup, the claim of a company page and posting a job. So does the form for sending us news. So does writing to us by email. What each holds, who sees it and for how long is set out in full below. Nothing at all is held about the people who answer a job posting: applications never come through this site.
- Requests to this site pass through Cloudflare on their way to the server, and every email this site sends, and every message sent to it, goes through one delivery provider, Resend. Nothing is sold, rented or shared with anyone else.
Reading the site
The news, the FDA data pages, the company pages, the directory and the policy pages are public and need no account. An ordinary visit sets no cookie. Fonts, scripts and images are served from this domain and from no other. Requests pass through Cloudflare on their way to the server, as set out under who else handles your data.
The web server writes a line for every request, in the way web servers do: your IP address, the time, the page you asked for, the page you came from if your browser sends it, and your browser string. It does not record anything after the question mark in a page’s address, because that is where the one-time links this site emails carry their token. It also records the address of a request it refuses. Those logs are rotated daily and kept for about two weeks, for operations and for defending the server against abuse. They are not used to build a profile of you, and no other record on this platform holds your IP address or is joined to those logs.
The request form
- What it holds
- What you type about the project: the categories you pick, your description, the stage, quantity bands, a timeline, any hard requirements and the three optional regulatory questions if you answer them. Then your name, work email, company and location, and a phone number if you choose to give one. It also records whether you asked to stay anonymous, the moment you ticked the consent box, and, if you reached the form through a supplier’s referral link, which supplier that was.
- What it will not take
- Files. There is no upload control and there is not going to be one. The form asks you to include nothing confidential, and specifications and drawings are meant to change hands after an introduction under your own agreements, so that we never hold them.
- Who sees it, and when
- No supplier and no queue here sees it until you open the link we email you. Until then it sits in our database, and the confirmation email, which names your categories and quotes the first line of what you wrote, is delivered through Resend. After you confirm, no supplier sees it except those matched to the categories you picked, and never more than five of them. In the service categories the publisher serves itself, the publisher is the only match; those categories are listed on network rules. The people who run the desk here can also read it, and every read they make is logged. It is never published on this site, never listed anywhere and never sold. If you ask to stay anonymous, a person here reads the request first to remove anything in it that would identify you, so an anonymous request waits until one has read it, and no supplier sees who you are unless you accept an introduction.
- What a supplier sees about you
- Unless you asked to stay anonymous, the card a matched supplier sees carries your name, company and location from the start, with the project details. If the company name you typed exactly matches a company in FDA’s registration records, the card also shows that company’s public FDA record counts: listings, clearances and enforcement records in a window, each linking to the public record. Nothing is looked up about you anywhere else. An anonymous card carries none of this.
- When your contact details move
- Your email address and phone number move only after a supplier says they are interested AND you say yes to being introduced to them. Two separate answers, and the second is yours. You give it on a page we link from the message we send you, which has a Yes and a No and changes nothing until one is pressed; the link works for fourteen days and once. If you write to us in words instead, a person records the same answer the same way.
- Who else reads it
- The people who run the desk here, and our automated routing and retention jobs. Every one of those reads is recorded with who or what did it, in a permanent log that holds the request’s number and not your details. That is a rule we hold ourselves to on network rules rather than a courtesy.
- How long we keep it
- If you never open the confirmation link, the whole request is deleted when the link expires after seven days. If you do, we keep it for at least ninety days from the day you sent it, and longer only while a supplier’s answer or your own decision on an introduction is still open. We then remove your name, email, company, location, phone number and everything you wrote in free text, and keep the anonymised shape of the request: the categories, the stage, quantity and timeline bands, the hard requirements, the regulatory answers, whether it was anonymous, which supplier referred it, and the dates. That shape cannot identify you and is what tells us which categories buyers ask for. You can ask us to remove a request sooner; see your rights.
Member accounts
A member is a company that has claimed its own page here. There is no registration and no password: a company proves control of a mailbox on its own domain, and signs in afterwards with a link sent to that mailbox.
- Claiming a page
- The claim form takes an email address on the company’s domain and one FDA identifier already on the company’s public record. We store the address, its domain and which kind of identifier matched, never the identifier you typed. The claim link works for seven days; a claim that is never finished is deleted when its link expires. Opening the link does not hand over the page: it tells us the mailbox is yours, and a person here then reviews the claim. A notice that a claim is waiting is sent to a mailbox at the publisher, outside this site; it carries the company, the domain the address is on and which kind of identifier matched, and not the address itself. The record says who decided and, on a refusal, why; that reason is for us and is never published, and you are told the outcome by email either way. A claim that is confirmed and not yet decided is kept until a person decides it, and then follows whichever of the next two applies. A claim that was approved is kept as the record of how the company came to hold its page; a claim that was refused, or that was closed because another claim on the same page was approved first, is deleted 30 days after the decision. A company with no FDA identifier on its record cannot use the form; a person here mints the same link for it on request, and the claim record says so, so the review has already happened by the time the link is opened.
- Signing in
- A sign-in link goes only to the account address on the page, works for one hour and once, and is sent at most once every five minutes. The record of the link is deleted once it is used or has expired. Signing in sets two cookies: a signed session, and one holding a single character so the page can show the account link instead of the sign-in link. Both last 14 days, both go when you sign out, and neither can be read as a name.
- Changing the account address
- The account address is the address a page is reached at, the one sign-in links go to, and it starts as the address that claimed the page. A signed-in member can move it. We hold the new address on a record of its own, unproved, until a link we send to it is opened, and nothing on the profile changes before that. The link works for 60 minutes and once, and the record of the request is deleted once it is used or has expired. When the address moves we write to the address it moved from and name the new one. The quality contact does not move with it, and the claim record is not rewritten, because that is the record of how the company came to hold its page. A member who has lost the mailbox asks a person here, who sends the same link to the new address.
- What a profile holds
- The account address, the categories the company lists itself in, and the fields the company fills in about itself: a description, a website, a founded year, an employee band and a minimum order. Those fields are published on the company page as the company’s own words and never carry a verified mark. The profile also holds a quality contact, a name and an address for notices about verification, which is never published, and a random referral code.
- What is public
- The self-reported fields and categories above, and the company’s verification record once one exists: its status, each check’s outcome and the record relied on, on the company page and at the badge’s verify address. What verification checks is published in full.
- Asking for verification
- A member asks for the checks from its own account, and we record which wing it asked on and the day it asked. A notice that a member has asked is sent to a mailbox at the publisher, outside this site; it carries the company and the wing, and not the address of the person who asked.
- When membership ends
- A member can release its page from its own profile screen, and we release a claim that turns out not to have been the company’s own. Either way the page goes back to the generated one at once: the company’s own statements, its categories and any badge come off it, and any verification is marked revoked. What the company entered is kept for 90 days, so a page claimed again in that time comes back with its own words, and is then deleted along with the account address, the quality contact and the claim record. The verification record is kept past that, because it is the record of what we checked, and the badge’s verify address keeps resolving to it as revoked, because the badge may still be printed on other websites.
- Desk activity
- A member’s answers to the requests routed to it, the time taken to answer, the reason given for passing, and the one-tap ratings members give after an introduction are kept and used internally to order routing. They are never published, never shown to any other member and never shown as a score to the member itself. A member sees its own cards and its own answers, and nothing that compares it with anyone.
- Passing on a buyer
- A member can give us the name and email of a buyer it cannot help. We send that person one message, naming the member, and keep nothing unless they then use the request form themselves.
The newsletter
- What it holds
- Your email address, which page and signup box you used, a dated record of each step (asked, confirmed, unsubscribed), and a dated record of each edition sent to you with the delivery provider’s answer. No name, no company, no location. Every reader confirms by email before receiving anything, not only readers in the EU, because telling the two apart would mean recording where each signup came from, and no record on this platform holds that.
- How long
- A signup that is never confirmed is deleted when its link expires, seven days after you signed up. A confirmed address is kept for as long as it is subscribed. An address that unsubscribes is kept for 30 days marked unsubscribed, so that nothing can be sent to it in the meantime, and is then deleted along with its records. An address the delivery provider reports as bouncing or as having complained is kept marked that way and is never mailed again, because deleting it would let the form put it back on the list.
- Sending
- Editions send from an authenticated sending subdomain, carry the publisher’s postal address and a one click unsubscribe, and an unsubscribe is honoured without asking for a reason. The list is never sold or rented.
Staff accounts
The newsroom and the desk sign in to an administration area. Those accounts hold a name, an email address, a password hash, the roles granted, a count of sign-in attempts with a lock after too many, and the sessions that are open. Signing in sets one cookie that lasts two hours. Accounts are created by an account administrator, never by registration, and every administrative read of a request is logged as described above.
FDA records, and the people in them
The company pages and the FDA data pages are built from openFDA’s public registration, listing, clearance and recall files. Those files are about companies, but they include the names and business contact details of registration correspondents and US agents. We hold those fields as part of the file, refresh them when FDA does, and publish none of them. A company that finds an error on its page can tell us through the route under your rights.
Writing to us
The site has one address of its own, [email protected]. This is what happens to a message sent to it.
- What it holds
- A message to that address is received by Resend and handed to this site, which stores the address it came from, the addresses it was sent to, the subject, the text of the message, and the names, types and sizes of any attachments. The attachments themselves are not stored here. The message’s technical headers are not stored either, because they carry the addresses of the mail servers a message passed through.
- Who reads it
- Each message is forwarded, as it stands, to a mailbox at the publisher and read by a person. A reply to that forward goes to you directly. Nothing answers automatically.
- How long
- The copy this site holds is deleted 90 days after the message arrived. The forwarded copy is in the publisher’s mailbox, outside this site, and is not covered by that period. Resend keeps its own copy for a period set on its side, as described under who else handles your data.
Sending news
The form on submit news takes a release, and a message to [email protected] is handled as a message to the address above.
- What it holds
- The contact’s name and email address, the organisation, the headline, the text of the release and a link to its source if one was given. No attachments: the form has no upload control.
- Who reads it, and when
- Nobody until the contact opens the link we send to that address. Then the release is forwarded, as it stands, to a mailbox at the publisher, with the contact’s address as the reply address, and read by a person. A submission is not a commitment to publish.
- How long
- A submission whose link is never opened is deleted when the link expires, seven days after it was sent. One that was confirmed is deleted 90 days after it was sent. The forwarded copy is in the publisher’s mailbox, outside this site, and is not covered by that period.
Posting a job
The form on post a position takes a job posting from an employer, and a member posts the same thing from its own company page. Reading the board needs no account and collects nothing.
- What it holds
- The posting itself, which is public by design: the position, the employer’s name, the function, the type, the place, the description, any pay the employer typed, and where applicants go. Beside it, and never published: the name and email address of the person who posted it, and the domain of that address, which is what the application link is checked against. No IP address, no message headers, no attachment and no file of any kind.
- Nothing about applicants, ever
- Applications go to the employer’s own page or mailbox and never through this site. There is no candidate account, no CV, no application form and no record that anybody followed an apply link. This site does not know who applied for anything.
- Who reads it, and when
- The posting is public from the moment the confirmation link is opened, or immediately when a member posts it from its own page. The poster’s name and address are read by the people who run the site, on the operator screen, and are used to send the posting’s own management link and to tell the poster if a posting is held.
- How long
- A posting whose confirmation link is never opened is public nowhere and is deleted when that link expires, 7 days after it was sent. A posting that closes, whether the employer closed it, its close date passed or we took it down, is kept 90 days and then deleted with its tags. A member’s postings are closed when it releases its page and are deleted with its profile.
Cookies
An ordinary visit sets no cookie. Four exist, each set only by an action you take:
| Name | Set when | Holds | Lasts |
|---|---|---|---|
mdm_ref | You arrive through a supplier’s referral link | That supplier’s public code, so a request you send is credited to them | Thirty days |
mdm_member | A member signs in, or completes a claim a person has already reviewed | A signed session naming the company and its account address as that address stood when you signed in | 14 days |
mdm_signed_in | A member signs in, completes a claim a person has already reviewed, or opens the member area; it is deleted there when the account manages no page | A single character, so the page can show the account link instead of the sign-in link. It names nobody and nothing can be read from it. | 14 days |
payload-token | A staff account signs in to the administration area | A signed staff session | Two hours |
Who else handles your data
- Resend
- Delivers every email this site sends, including the request confirmation, the messages the desk sends, staff password resets, claim links, sign-in links and the newsletter. It receives the recipient address, the subject and the message body, which for a request confirmation includes your categories and the first line of your description. It also receives every message sent to the address above, holds it on its side, and hands it to this site. Resend keeps its own logs of the messages it delivers, and its own copy of the messages it receives for us, for periods set on its side, under its own privacy policy.
- Cloudflare
- Requests to this site pass through Cloudflare on their way to the server. The encrypted connection your browser makes ends at Cloudflare, which passes the request on, so Cloudflare handles each request as the server does: your IP address, the full address you asked for, what your browser sends with it, and anything you submit in a form. Any record it keeps of that traffic is kept for periods set on its side, under its own privacy policy.
- Nobody else
- No analytics service, no advertising network, no data broker and no firmographic lookup receives anything about you. The FDA data comes from openFDA, and nothing about you is sent there.
Backups
A copy of the whole database, and a copy of the uploaded images, is taken nightly and kept for fourteen days, so that we can recover from a failure. A record we have deleted or anonymised can remain in those copies for up to two weeks after it was deleted. Backups are not used for anything else and are not read in the ordinary course.
Where it is held, and the basis for holding it
Everything this page describes is held in the United States. If you are reading from the EU, the UK or anywhere else, what you send is processed there. The publisher is the controller of it, in the sense the GDPR and the UK GDPR use that word.
We hold each thing on one basis, and the basis is the one the surface itself makes plain. A sourcing request, a claim, a job posting and a news submission are held to do the thing you asked for, which is the performance of what you and we agreed when you sent it. The newsletter is held on your consent, given twice, and withdrawn with the unsubscribe link in every edition. The access log and the staff accounts are held in our legitimate interest in running and defending the server. Nothing is held on any other basis, and nothing is used for a purpose other than the one stated beside it on this page. No decision about you is made by automated means alone.
How it is protected
Every connection to this site is encrypted. Staff sign in with a password that is stored only as a hash, under roles that separate the people who work the verification queue from the people who work the request queue, and every administrative read of a request is logged with who made it. Every link this site emails is a one-time token with an expiry, and the web server never writes a token to its log. No security measure is perfect; if we learn of a breach that affects you, we will tell you and any authority the law requires, within the period the law requires.
Your rights, and how to reach us
Whoever you are and wherever you are reading from, you can ask us what we hold about you, ask us to correct it, ask us to delete it, and ask us to remove a request, a claim, a posting or a subscription sooner than the periods above. We do not sell or share personal information, we do not use it for advertising, and we do not profile anyone, so there is nothing to opt out of; we say so here because some laws require the sentence.
- Readers in the EU, the EEA and the UK have the rights of access, rectification, erasure, restriction, portability and objection under the GDPR and the UK GDPR, and the right to withdraw consent to the newsletter at any time, which the unsubscribe link in every edition does without asking why. You also have the right to complain to the supervisory authority where you live; we would rather hear from you first.
- Readers in California have the rights the California Consumer Privacy Act gives them: to know what is collected and why, to delete it, to correct it, to opt out of a sale or sharing (there is none), and not to be treated differently for exercising any of them. This page is the notice at collection for every form on the site.
- Readers elsewhere have whatever comparable rights their own law gives them, and we handle a request from anyone the same way.
A request is read by a person and handled by hand. We may ask you to confirm you are the person the record is about, usually by writing from the address on the record, and we answer within the period the applicable law allows. An authorised agent may ask on your behalf with your written permission. A record that has already been anonymised or deleted cannot be retrieved, and a record we are keeping as the record of a decision, such as an approved claim or a verification, is kept with the identifying fields removed rather than destroyed, and this page says so where that applies.
Write to [email protected] and say which address, request or subscription you mean, or by post to the publisher at 830 Challenger St, Brea, CA 92821, marked for Medical Device Manufacturing.
Children
This is a trade publication for people at work. It is not directed at anyone under sixteen, and we do not knowingly collect anything from them. If you believe a child has sent us something, tell us through the route above and we will delete it.
Changes
The date at the top of this page is the date of the version you are reading, and it moves whenever the text does, so that you can tell whether the page has changed since you last read it. A change that narrows what we hold, or shortens how long we hold it, takes effect when it is published. A change that would widen either is published here before it takes effect, and anything already collected is handled under the version that was in force when it was collected. Earlier versions are kept and can be had on request.
