Privacy Policy
Version 2.1Effective October 5, 2026Current policy
On this page
ChemCal Pro Privacy Notice
Version 2.1 | Effective date: October 5, 2026
Application of this version. This version is made available from its first publication. The effective date above does not imply earlier publication, retroactive consent or a change to rights that have already accrued.
---
1. About this notice
1.1 This notice explains how ChemCal Pro LLC ("ChemCal Pro," "we," "us," "our") handles personal information across the places where people meet us: the ChemCal Pro application, our marketing website, our meeting-scheduling page, and our support email.
1.2 This is a transparency notice, not a consent form. Reading it, browsing our website or using the Service is not treated by us as your agreement to anything. Where the law requires consent for a specific activity, we will ask for it separately and will not begin that activity in your jurisdiction until we can obtain and honour that consent properly.
1.3 This notice describes our current practices, the information we process, and the choices and rights available to you.
---
2. Who we are and how to reach us
2.1 ChemCal Pro LLC is a limited liability company formed in Texas, United States.
2.2 Contact us about privacy by emailing `support@chemcalpro.com` with the subject line Privacy Request or Privacy Complaint. That mailbox is monitored and requests are routed internally to the person responsible for them.
2.3 Our postal address for privacy correspondence is 63 Marino Drive, Missouri City, Texas 77459, United States. Use the email route in Section 2.2 where possible so that we can route and acknowledge the request promptly.
---
3. Two different roles — and why it matters to you
3.1 Information inside a customer's account. Most information in the ChemCal Pro application belongs to a customer organization — a pest-management company or similar business. That organization decides who is invited, what is uploaded and how the account is used. For that information the organization is the controller (or business), and ChemCal Pro acts as its processor (or service provider), under our Data Processing Addendum.
3.2 What this means if you are a technician or an administrator at a customer organization. If you want to see, correct or delete information your employer put into its ChemCal Pro account, the fastest route is usually to ask your employer. We will help your employer respond, and we will respond directly where the law requires us to.
3.3 Information we handle for ourselves. For some information we decide the purposes ourselves and act as a controller in our own right — for example contracting and account administration, billing, security and fraud prevention, support correspondence, meeting bookings, marketing enquiries from our website, and establishing or defending legal claims. Sections 5 to 14 apply to both, and each entry says which role we hold.
---
4. The four places we collect information
| Channel | What it is | Who runs it |
|---|---|---|
| The application | `app.chemcalpro.com` — the administrator and technician application | ChemCal Pro, on hosting and database services described in Section 10 |
| The marketing website | `chemcalpro.com` — our public pages and enquiry forms | A third-party website and lead-capture platform |
| The scheduling page | `meet.chemcalpro.com/consultation` — booking a consultation or support call | A third-party customer-relationship and scheduling platform |
| Support email | `support@chemcalpro.com` | Delivered to our monitored business mailbox |
The rest of this notice tells you which channel each practice belongs to.
---
5. What we collect in the application
Unless a row says otherwise, the customer organization is the controller and we are its processor.
5.1 Account and identity
| Category | Examples | Where it comes from |
|---|---|---|
| Contact and identity | Name, email address, organization name, job title, start date | You, a Company Admin who invited you, or account creation |
| Authentication and session | Authentication identifier, sign-in method, session token, sign-in and access times, the single-active-session state | You, your browser or device, and our authentication provider |
| Membership and role | Role, membership status, invited email address, who invited you, invitation and acceptance dates, last-seen time | Company Admins and ordinary use of the Service |
| Preferences | Favourites, and small interface settings such as which tool category was last open and which measurement units you last used | You |
Where an invited user chooses Google sign-in, our authentication provider receives Google's sign-in result, identity identifier, email address and associated basic profile information, which can include a name and profile image. This sign-in does not give ChemCal Pro access to the user's Google mailbox, contacts or calendar.
5.2 Member profile and credential records
This is information the Service is specifically designed to hold, and we want to be plain about it.
| Category | Examples |
|---|---|
| Member photograph | A profile photograph of a member of a customer organization, stored in a private location |
| Credential records | Licence, certification and course records — the type of credential, identifying details recorded by the member or their administrator, the issuing body where recorded, and expiry dates. Expiry dates are used to show renewal reminders |
| Credential proof documents | Images or PDF documents a member uploads as evidence of a credential, including photographs of the front and back of a licence card, stored in a private location |
Access to this material is restricted: a technician can see their own; an administrator of the same organization can see their organization's members'; nobody at another organization can see it. ChemCal Pro staff do not access it as part of routine operations.
A licence number or a photograph of a licence card is sensitive information. Customer organizations should collect only what they actually need for their own workforce management, and should not use these fields for unrelated personal data.
5.3 Product, document and calculation records
| Category | Examples |
|---|---|
| Product and company content | Product records, internal names, company guidance and notes, supporting files, images and links, and who authored or reviewed them |
| Label and safety data sheet records | Uploaded or adopted documents, versions, storage references, file fingerprints, sources, verification status, who verified and when |
| Calculator records | Calculator definitions, the structured values and units configured, source references, version history, verification, locking and publication history |
| Publication records | Which document revisions were present when a product was published to technicians, and who published it |
How a calculation is processed, and what is not kept. When someone runs a product-bound calculator, the values they enter are sent to our servers and processed there: our server loads the locked calculator definition from the organization's own records, evaluates it under that user's session, and returns the result. The definition is never taken from the browser.
That processing is transient. We do not keep a history of individual calculation runs, their inputs or their results, and we would change this notice before doing so. General measurement and conversion tools that are not bound to a product may run entirely in the browser; that is a different thing from a product-bound calculator.
5.4 Commercial, legal and operational records — we are the controller for these
| Category | Examples |
|---|---|
| Subscription and billing metadata | Plan, seat counts, subscription status, payment-provider customer and subscription identifiers, billing period, transaction status, payment-provider event metadata, and records of billing operations such as a scheduled cancellation or a refund |
| Legal acceptance records | Which document version was accepted, its content fingerprint, the on-screen authority confirmation, the accepting person and their verified email address, their role at the time, the organization, and the date and time |
| Audit records | Who did what, to which record, in which organization, and when |
| Technical and security records | IP address, browser and device information, request and error metadata, security events, and hosting and database logs |
Payment details. Payments are taken on pages hosted by our payment provider. We do not see, enter or store complete card or bank-account numbers.
---
6. What we collect on the marketing website, the scheduling page, and by email
6.1 Marketing website enquiry forms. Our enquiry and early-access forms collect the first name, last name, email address and state you enter. We use that to respond to you and to tell you about ChemCal Pro. We are the controller for this information.
6.2 Our website platform. The marketing website runs on a third-party website and lead-capture platform. That platform sets its own browser storage and runs its own script on our pages, and it offers optional visitor-identification features that can involve sharing visitor identifiers with third-party identity-resolution services for those services' own purposes.
Optional visitor-identification and identity-resolution sharing are disabled on our marketing website. Ordinary website-platform scripts and browser storage remain as described here and in Section 7. We do not sell personal information for money.
6.3 Scheduling a call. Booking through `meet.chemcalpro.com/consultation` uses a third-party customer-relationship and scheduling platform.
The booking form asks for:
- your name and email address;
- your company (required);
- the reason for the meeting — Demo, Setup Assistance, Configuration Support, or Other;
- free text describing the reason, where you choose Other;
- your phone number (optional); and
- the number of technicians you expect to have (optional).
Booking creates a calendar event and a video-meeting link, and the platform sets its own browser storage on that page, which can include analytics and visitor-tracking storage operated by that platform. We are the controller for the booking information. We use it to hold the meeting, to prepare for it, and to follow up.
6.4 Support email. When you write to `support@chemcalpro.com`, we receive your message, any attachments, and the ordinary technical metadata of an email. We use it to answer you and to keep a record of the request. We are the controller for this correspondence. Please do not send passwords, sign-in links, complete card numbers, or personal information we have not asked for.
---
7. Browser storage and similar technologies
7.1 In the application, we and our authentication provider use:
| What | Purpose | Notes |
|---|---|---|
| Authentication cookies set by our authentication provider | Keeping you signed in and completing a sign-in exchange | Necessary for the Service to work at all |
| An organization-selection cookie | Remembering which organization an administrator is currently working in | Set for one year; contains only an organization identifier, which the server re-checks against your real memberships |
| Small browser-storage entries | Remembering an open tool category, a conversion selection, recently used measurement units, and recently used colours in the platform content editor | Convenience only; stored on your device |
7.2 What the application does not use. We do not use advertising cookies, cross-context behavioural advertising, or a third-party analytics product in the application. There is no service worker, no offline cache and no offline mode. The application does not collect GPS or continuous location.
7.3 On the marketing website and the scheduling page, the third-party platforms described in Section 6 set their own storage, which can include analytics and visitor-tracking storage that is not necessary to display the page.
7.4 We do not claim that all of this storage is strictly necessary. Authentication and organization selection are necessary to provide what you asked for. Error monitoring, session replay and the marketing and scheduling platforms' analytics storage serve our purposes, and in some jurisdictions that means consent is required before they may be used. We do not currently operate a consent banner or a preference centre. Before we offer the Service to customers in a jurisdiction that requires prior consent for that storage, we will put a compliant consent mechanism in place, or we will disable the optional processing for those visitors.
---
8. Error monitoring, performance monitoring, and session replay
We use a third-party error and performance monitoring service so that we can find and fix faults. This section describes it plainly because it is the least visible thing we do.
8.1 Error and performance events. When something goes wrong, or on a small sample of ordinary page transactions, the monitoring service receives a report. Our configuration turns off the collection of user identity, cookies, request and response headers, request and response bodies, URL query parameters, database query values and local variable values, and it removes free-text content such as error messages and descriptions before the report is sent. What remains is technical: the type of error, the code path, the HTTP method and status, a general route family, the runtime, the environment, correlation identifiers and the release.
8.2 Session replay — error-triggered only, and masked. The monitoring service keeps a short rolling recording of the page in your browser's memory. In the error-triggered mode we have configured, no replay recording is uploaded unless an error is captured. If an error is captured, the buffered period immediately before the error, and a short period after it, is uploaded.
This statement is about replay recordings specifically. It does not mean nothing else is ever sent: as Section 8.1 describes, a small sample of ordinary page transactions is reported for performance monitoring even when nothing has gone wrong.
Because a rolling buffer exists, a period before an error can be uploaded even though you took no action after the error. In the absence of a captured error, the configured mode does not upload a replay recording, but a buffer does exist in memory. Ordinary error and performance telemetry is separate from replay recordings.
8.3 What is masked, and what is not. In a replay, all text is masked, all form input values are masked, and images, video and other media are blocked. Network request and response detail, request and response bodies and headers are not captured. Masking applies to page content, not to every technical field. Page addresses (URLs) and comparable technical metadata associated with the recorded period can be included in the recording and replay data.
8.4 Sampling and retention. Ordinary session recording is switched off entirely; only error-triggered replay is enabled. Performance transaction sampling is a small percentage. Monitoring data is retained under the terms and configuration of our account with the monitoring provider. Retention depends on the type of monitoring data and the provider account configuration. You may request information about the applicable retention period through the privacy contact in Section 2.2.
8.5 What masking does and does not achieve. Masking substantially reduces what a replay shows. We do not claim that replay or telemetry data is completely anonymised. Technical metadata that is not masked — page addresses, timing, route and environment identifiers, correlation identifiers and similar fields — remains, and we cannot guarantee that such metadata could never, alone or combined with other information, be associated with a person. Masking is also not a substitute for a consent requirement where one applies.
8.6 If you would rather not be recorded. Write to `support@chemcalpro.com` with the subject line Privacy Request and tell us. Where we are the controller, we will consider your objection and tell you what we can do.
---
9. Why we use personal information
9.1 We use personal information to:
- create, authenticate, secure and administer accounts and organizations;
- provide the product, document, calculator, measurement-tool and guidance functions of the Service;
- manage roles, invitations, seats, subscription status, access state and legal acceptance;
- take payment and handle taxes, accounting, refunds and billing questions;
- send service, security, legal, billing and support messages;
- diagnose faults, monitor, maintain, protect and improve the Service;
- detect and prevent fraud, abuse and unauthorized access;
- keep audit, contract, verification and security evidence;
- respond to enquiries and hold meetings you book with us;
- comply with legal obligations and lawful requests; and
- establish, exercise or defend legal claims.
9.2 Lawful bases, where your law requires one. Where a law such as UK data-protection law requires us to identify a lawful basis, we rely on the following.
| Activity | Basis |
|---|---|
| Providing the Service under our agreement with a customer organization | Contract, where you are the individual contracting with us; otherwise our legitimate interests in performing that agreement with your organization |
| Pre-contract steps you ask for — an enquiry, a demonstration, a booking | Contract (steps at your request), or legitimate interests where you are acting for an organization |
| Account administration, authentication and access control | Legitimate interests in operating a controlled, individually attributable business service |
| Security, fraud prevention, error diagnosis and service integrity | Legitimate interests in protecting the Service, its customers and their people |
| Billing, tax and accounting records | Legal obligation, and legitimate interests in keeping accurate commercial records |
| Marketing to business contacts who have asked to hear from us | Consent where required, otherwise legitimate interests |
| Non-essential storage and error-triggered replay, where the applicable law requires prior permission | Consent — obtained properly before we enable it in that jurisdiction |
| Establishing, exercising or defending legal claims | Legitimate interests in protecting our legal position, and legal obligation where a specific duty applies |
An individual who uses the Service under their employer's account is not a party to their employer's subscription agreement, and we do not treat them as one. Where we rely on legitimate interests we consider the effect on people, use information proportionately, and you may object as described in Section 14. If information falls within a legally defined sensitive or special category, additional conditions may apply. An occupational licence image is not automatically special-category data under UK law; its contents and the applicable law determine the classification. The customer organization is responsible for the lawful collection it directs, and ChemCal Pro remains responsible for its own applicable duties.
9.3 What we do not do. We do not sell personal information for money. We do not use personal information in the application for cross-context behavioural advertising. We do not use it to make automated decisions that produce legal or similarly significant effects.
---
10. Who we share personal information with
10.1 Service providers. We share information with the providers listed in our Subprocessors and Service Providers registry, which names each provider — except providers used only for our internal review of manufacturer reference material, which it identifies by category — and states what each does for us, what categories of information it handles, and whether it acts as our processor or in its own right. Categories include application hosting, database and storage, authentication, transactional email, payment processing, error and performance monitoring, backup storage, backup automation, internal document review, business email and meetings, customer-relationship and scheduling, and our marketing website platform.
10.2 A provider's role is not always the same. Some providers act only on our instructions. Others — our payment provider is the clearest example — also act in their own right for their own legal, fraud-prevention and product purposes. The registry says which is which.
10.3 The customer organization. Where information sits in a customer's account, we make it available to that organization and its administrators, because it is their account.
10.4 Professional advisers and transactions. We may share information with professional advisers, auditors and financing or transaction advisers under confidentiality obligations, and in connection with a merger, acquisition, financing, reorganization, insolvency or sale of relevant assets, subject to appropriate protections.
10.5 Law and safety. We may disclose information where reasonably necessary to comply with law, legal process or a lawful government request, or to protect the rights, safety, security and integrity of people, our customers, ChemCal Pro or the Service. Where we act as a processor, the Data Processing Addendum governs how we handle such a request.
---
11. International processing
11.1 ChemCal Pro operates from the United States. Our providers' processing locations are described in the Subprocessors and Service Providers registry to the extent verified. Providers operate globally for support, delivery and resilience, so information may be processed in other countries where those providers operate. Those countries may have different privacy laws. This is not an exclusive data-residency commitment.
11.2 We state each provider's processing geography in the registry to the extent we have verified it. A regional account URL, a domain prefix or a storage location hint is not a residency guarantee, and we do not present one as if it were.
11.3 Transfers into the Service from outside the United States. Where applicable law restricts a transfer, a lawful route must be established before the transfer. Depending on the law and the facts, that route may be an applicable adequacy mechanism, an appropriate safeguard or a recognised exception. Where a contractual instrument is required, it must be properly completed and executed. This notice does not establish any such route or execute an instrument.
---
12. How long we keep information
12.1 We keep information for as long as we reasonably need it for the purpose we collected it for, and then for any additional period the law requires or permits — for tax, accounting, security, dispute or evidential reasons. How long that is depends on the record type, the account's status, the customer's instructions, our providers' capabilities and applicable law.
12.2 Records that persist by design.
- Legal acceptance records are kept as evidence that a contract was formed and by whom. They are not deleted as part of ordinary account clean-up.
- Audit records are append-only and are kept as evidence of what happened in an account.
- Billing and subscription records are kept for tax, accounting and dispute purposes.
12.3 Backups — stated accurately. Two different kinds of copy exist:
- Our providers' own backups, which follow the provider's operating cycle; and
- ChemCal Pro's own snapshot copies, which we create on a regular schedule and store with a backup storage provider.
Our own snapshot copies do not currently rotate or expire on an automated schedule. We are establishing a retention and disposal schedule for them. Until it is in place and operating, a deletion inside the live Service does not immediately remove that information from existing snapshot copies. Those copies are access-restricted, are not used for ordinary business purposes, and are used only for restoring service, investigating a security incident, or meeting a legal obligation.
12.4 We may keep information that has been irreversibly de-identified and can no longer reasonably be linked to a person or an organization.
---
13. Deletion — what actually happens
13.1 These are different operations with different effects.
| Operation | What it does |
|---|---|
| Cancelling a subscription | Ends billing. Does not delete anything |
| Suspension | Ends access. Does not delete anything |
| Archiving | A reversible lifecycle state within an account |
| Deleting a customer organization's records | Permanently removes that organization's records and its stored files from the live Service, and reduces the organization to a minimal shell |
| Deleting an individual's identity | Permanently removes that person's sign-in identity and profile from the live Service. It is available only for a person who no longer belongs to any organization, and it does not delete an organization's records |
13.2 What survives a deletion, and why. When an organization's records or an individual's identity are deleted, we keep a limited set of records because we need them to show that a contract was formed, to meet tax and accounting obligations, to keep audit integrity, or to preserve evidence for a dispute. In particular:
The legal acceptance record survives, and it includes the email address of the administrator who accepted the agreement, together with the organization's name at the time, a reference to the organization, that person's role at the time, the document version and fingerprint, and the date and time.
We are telling you this specifically because "your identity has been deleted" would otherwise leave you with the impression that no record of you remains. Your sign-in identity, password, sessions, linked sign-in providers and profile are removed. The acceptance record is not, and it contains an email address.
13.3 Retention of that evidence is not unlimited in principle. We keep it for as long as it is necessary for the purposes in Section 13.2. We do not treat it as a record that must be kept forever, and we will review it against those purposes as our retention schedule is established.
13.4 Backups. Deletion in the live Service does not immediately remove information from existing backup copies. See Section 12.3.
13.5 Stored files. Removing a record and removing the underlying stored file can be separate steps. Where a file cannot be removed at the same time as its record, we retry until it is removed.
---
14. Your rights and how to use them
14.1 Depending on where you are and the circumstances, you may have the right to:
- ask what personal information we hold about you and get a copy;
- have inaccurate information corrected;
- ask for information to be deleted;
- receive information in a portable form;
- restrict or object to certain processing;
- withdraw consent where an activity depends on consent;
- opt out of marketing messages; and
- complain to a privacy regulator.
14.2 How to ask. Email `support@chemcalpro.com` with the subject line Privacy Request. Tell us what you want, your relationship to ChemCal Pro, the organization involved and the account email address. We may ask for proportionate information to confirm who you are and, where you are acting for someone else, that you are authorized.
14.3 When the information belongs to a customer's account, we will usually direct the request to that organization, tell you we have done so, and help the organization respond. Where the law places the duty directly on us, we will respond ourselves.
14.4 How quickly. We will acknowledge your request and respond within the period the applicable law requires. If the law allows more time and we reasonably need it, we will tell you.
14.5 No penalty. We will not treat you less favourably for exercising a privacy right.
---
15. Regional information
The Service is currently offered to business customers in the United States. The sections below apply where the relevant law applies to us in your circumstances. Whether it does depends on facts about you, about the processing and about us — not simply on where you live.
15.1 United States
Residents of states with consumer privacy laws may have rights under those laws, subject to their thresholds, scope, and exemptions — including exemptions that can apply to information handled in a business-to-business or employment context. We do not sell personal information for money and we do not use personal information in the application for targeted or cross-context behavioural advertising. Where you have a right under your state's law and it applies to us, use the contact route in Section 14.2 and tell us which state you are in.
15.2 Canada
If you are in Canada, you may ask for access to your personal information and for correction, and you may challenge our compliance. We will investigate and explain our response. You may also contact the Office of the Privacy Commissioner of Canada or the applicable provincial regulator. Information about our use of providers outside Canada is in Section 11 and in our Subprocessors and Service Providers registry.
15.3 United Kingdom
If you are in the United Kingdom and UK data-protection law applies to our processing of your information, you may have rights of access, rectification, erasure, restriction, objection and portability, and you may complain to the Information Commissioner's Office.
Our purposes and the basis for each are set out in the table at Section 9.2 rather than as a general list. In summary: contract where you are the individual contracting with us or requesting pre-contract steps; legitimate interests in providing the Service where you act for a customer organization; legal obligation for billing, tax and accounting records; legitimate interests for account administration and authentication, for security, fraud prevention and error diagnosis, for business-contact communication, and for establishing or defending legal claims; and consent for non-essential storage and error-triggered replay, which we will obtain before enabling that processing for United Kingdom users, or else disable it for them.
Whether we are required to appoint a UK representative, whether the UK data-protection fee applies to us, and the arrangements for any restricted transfer are matters we settle before offering the Service in the United Kingdom.
15.4 Australia
If you are in Australia and the Privacy Act applies to our handling of your information, you may ask for access and correction and may complain to us. We will acknowledge a privacy complaint and explain how we will handle it. If you are not satisfied, you may contact the Office of the Australian Information Commissioner. Overseas recipients are described in Section 11 and in the registry.
---
16. Children
The Service is a business tool for adults. It is not directed to children, and we do not knowingly collect personal information from children through it.
---
17. Messages we send
17.1 We send account, security, legal, billing and service messages. These are necessary to operate an account and are not marketing.
17.2 We may send marketing messages to business contacts who have asked to hear from us. You can opt out at any time using the unsubscribe route in the message or by writing to `support@chemcalpro.com` with the subject line Unsubscribe. Opting out of marketing does not stop necessary service messages while your account is active.
---
18. Changes to this notice
18.1 We may update this notice as the Service, the law, our providers or our practices change.
18.2 Each version carries a version identifier and an effective date. We will give reasonable notice of a material change. Where a change materially affects processing we carry out on a customer's instructions, we will handle it under the Data Processing Addendum.
18.3 We will not make a change retroactive, and we will not treat continued use of the Service as agreement to a change that requires your consent.
---
19. Complaints
If you are not satisfied with how we have handled your information or your request, tell us at `support@chemcalpro.com` with the subject line Privacy Complaint. We will review it, investigate where appropriate, and tell you the outcome or the next step. You may also complain to the privacy regulator available where you are.