Privacy Policy

EPRINTIT USA, LLC
Corporate Privacy Policy & Data Protection Framework
Document ID: ePI-PP-2026-v4.0 Effective Date: May 20, 2026
Version: 4.0 Classification: Customer-Facing Evidence
Technical Owner: Cloud Data Protection &
Compliance Board
Audit Scope: ISO/IEC 27001:2022
Certified Scope

1. Commitment to Privacy

ePRINTit™ USA, LLC (“ePRINTit”) is strictly committed to respecting and safeguarding your privacy through the
rigorous technical protection of your personal information. When we collect, process, or store your personal data,
you can be completely confident that it is managed using industry-leading security controls designed to prevent
unauthorized access, alteration, or disclosure. ePRINTit collects personal information solely for the explicit
operational purposes specified within this Privacy Policy. ePRINTit does not sell, rent, lease, or trade your
personal information or customer lists to third parties under any circumstances.

2. Corporate Contact Matrix

For any inquiries regarding this policy, data privacy controls, or to exercise your individual data rights, you can reach
our corporate offices through the following channels:
Postal Address: ePRINTit™ USA, LLC, 7820 S Quincy Street, Willowbrook, IL 60527
Central Inbound Support Gateway: support@eprintit.com
Dedicated Data Protection Team Intake: support@eprintit.com (Please mark the subject line as: “Attention:
Cloud Data Protection”)
North American Toll-Free Telephone: (877) 494-0443

3. User Consent & Right to Opt-Out

By explicitly submitting personal information to ePRINTit via our mobile applications, web portals, or corporate
website, you consent to our collection, processing, use, and disclosure of that data for the operational purposes
described herein and as permitted or required by law.

Subject to local legal or contractual parameters, you retain the complete right to govern your data preferences:
Communication Preferences: You can opt out of receiving promotional or non-transactional communications
from ePRINTit Representatives at any time by updating your communication preferences within the “Your
Profile” section of the web portal, or by calling (877) 494-0443 for direct assistance.

Baseline Record Retention: Minimum personal information may be temporarily retained in our secure
database for record-keeping purposes, internal research, or to ensure we continue to honor your explicit
communication opt-out requests.

Complete Data Erasure Request: To be permanently removed from all marketing, administrative, and user
tracking databases, please submit an email from your registered email address to support@eprintit.com with a
clear request for complete information removal.

If you provide ePRINTit with personal information concerning another individual, you represent and warrant that you
possess the full legal authority and have obtained all necessary consents from that individual to authorize ePRINTit
to process that data under this policy.

4. Data Categories Collected by ePRINTit

To maintain high availability and deliver secure cloud printing services, ePRINTit collects both anonymous system
metrics and identifiable personal attributes:

4.1 Automated Infrastructure & Telemetry Metrics

When interacting with our cloud-based delivery systems, our servers capture basic technical data transmitted by
your hardware client, including:
Internet Protocol (IP) addresses of the devices accessing the platform.
Operating system types, browser versions, and device identifier tokens.
Internet Service Providers (ISPs) utilized by visitors.
Immutable timestamps marking the exact dates and times of system utilization.
Specific system application pages visited, along with the names and sizes of files requested.

4.2 Identifiable Personal Information

When registering an account, purchasing print credits, or modifying account preferences, you choose to provide
specific personal attributes that identify who you are, including your name, email address, physical mailing
address, and phone number. Visitors can navigate the public pages of our corporate website without disclosing
any personal data.

4.3 Children’s Online Privacy Protection Act (COPPA) Compliance

The ePRINTit ecosystem is a general audience platform. It is neither designed nor intended to collect personal
information from children under the age of 13. In strict compliance with COPPA regulations, children under 13 must
not submit any personal data to this platform. We request that parents and guardians actively supervise their
children’s online activities to guarantee compliance.

5. Ephemeral Data Architecture & Document Processing Security

The strongest data protection mechanism implemented by ePRINTit is our automated data destruction workflow:
AUTOMATED ENCRYPTED PURGE VECTOR: All documents, print payloads, and files sent to the ePRINTit service
for processing are handled strictly as temporary transit assets. All uploaded files are automatically, permanently,
and irreversibly destroyed in their encrypted form within a maximum window of eight (8) days from
submission.

User Control & Visibility: Customers retain the power to manually delete their uploaded data objects at any
time prior to the automated sweep. Users are provided with clear data-expiry notices and an active countdown
clock indicating the precise time of destruction across their mobile applications and private web portals.
Forums and Community Interactions: ePRINTit operates isolated online communication forums. Any
information or interaction you transmit within these spaces is treated as strictly private by ePRINTit and is never
disclosed to external third parties.

6. Operational Usage of Personal Data

ePRINTit utilizes your personal information strictly for core business operations and fulfillment purposes, including:
Enhancing customer service delivery and addressing your support needs.
Processing secure financial transactions for print services.

Delivering purchased products and fulfilling the specific print capabilities you request.
Sending order confirmations, technical updates, and occasional company announcements. Note: You can
instantly unsubscribe from company news emails at any time by following the detailed instructions provided at
the bottom of each communication.

7. Tracking & Cookie Policy

A cookie is a small text file containing a unique identification number transferred to your device’s hard drive to
identify your browser configuration, but not you as an individual. Cookies are text-only files; they cannot run
programs, execute code, or search your device for data. You can reset your browser preferences to refuse cookies
or alert you when a cookie is sent. To optimize platform availability, ePRINTit utilizes two types of cookies:
Session Cookies (Temporary): Used to support active forms, portal registration paths, and payment cart
structures. These cookies exist strictly during your active online session and expire automatically when you
close your browser window.

Persistent Cookies (Long-Term): Stored on your device for an extended duration to remember specialized
browser preferences, such as default language settings.

8. Reseller and Partner Boundary Restraints

If a corporate client purchases ePRINTit cloud services through an authorized external Reseller, that Reseller may
maintain administrative visibility over the corporate client’s account dashboards and associated end-user metadata
configurations.

No Document Access: Resellers have absolutely zero technical visibility or access to the customer
documents, processed print data, or raw credit/debit card financial data.

Data Boundary Limitation: Resellers are provided strictly with aggregated metadata necessary to monitor
sales metrics and fulfill their direct customer service and partner support obligations. The customer remains
solely responsible for outlining data access governance within their individual Reseller Agreement.

9. Technical & Organizational Security Measures

ePRINTit deploys multi-layered technical, physical, and administrative safeguards to protect user data from loss,
unauthorized modification, or exploitation:

Centralized Identity and Access Control: Personnel access to cloud production environments is regulated via
a centralized access management framework restricted to a minimal number of highly vetted engineers based
on a documented business-need-to-know. Identity validation enforces unique user IDs, strong password
constraints, and multi-factor authentication (MFA) parameters at registration. Technical access layers leverage
LDAP, Kerberos, and secure SSH certificate models to ensure complete audit trails for all system modifications.
Cryptographic Protections and Network Security: All user metrics and system data are stored within
geographically distributed data center nodes in a fully encrypted form, utilizing military-grade 256-bit SHA2
(AES-256) encryption keys. Data transfers execute strictly via secure HTTPS or TLS 1.2 / TLS 1.3 protocols.
Server cryptographic handshakes support 256-bit SHA2 key exchanges signed with RSA and ECDSA, enforcing
Perfect Forward Secrecy (PFS) to defend communication channels against key exploitation. The external attack
surface is defended by multiple inline network layers, including intelligent perimeter web application firewalls and
active intrusion detection mechanisms.

Physical Microsoft Azure Data Center Safeguards: ePRINTit production infrastructure is hosted across
secure, geographically distributed cloud data centers managed natively within the Microsoft® Azure Network.
These facilities maintain 24/7/365 on-site security operations teams that monitor closed-circuit television (CCTV)
loops, manage environmental alarms, and conduct regular physical facility patrols. Data center computing
infrastructure features complete hardware redundancy (including dual network circuits, switches, and automated
backup UPS battery systems paired with emergency diesel generators) to eliminate single points of failure and
guarantee high availability.

10. Specific EU-GDPR Privacy Provisions

For data transfers originating from the European Union (EU) and the United Kingdom (UK), ePRINTit formally acts
in compliance with the General Data Protection Regulation (GDPR):
Lawful Basis and Instructions: Personal data is processed solely on behalf of the client (Data Exporter) in
strict accordance with the documented instructions outlined within our primary Services Agreement and Data
Processing Terms.

Sub-Processor Governance: Before onboarding any sub-processors to fulfill service layers, ePRINTit
conducts a security and privacy audit of their operational systems. Sub-processors are bound via formal
contract terms to maintain identical data safeguards and are strictly prohibited from utilizing data for any
unapproved purpose.

Post-Termination Data Obligation: Upon formal termination of personal data processing services, ePRINTit
and its sub-processors will permanently delete or return all personal data transferred, certifying compliance to
the Data Subject, unless prevailing local statutory legislation prevents data destruction. In such instances,
ePRINTit guarantees the permanent confidentiality of the data and halts active processing.

Third-Party Integrations (Google API Compliance): ePRINTit’s utilization, processing, and transfer of
information received from Google APIs back to the downstream application hooks adheres fully to the official
Google API Services User Data Policy, including all defined Limited Use requirements.

11. Regulatory Oversight and Certifications

The validity of ePRINTit’s data protection workflows, identity management pipelines, encryption keys, and
ephemeral data lifecycles are evaluated and certified annually by an accredited third-party external compliance
entities. Our operational security and privacy postures maintain active compliance verification under **Prescient
Security Certificate Number: 122705**, validating complete technical alignment with the international control
objectives mandated within the **ISO/IEC 27001:2022 Certified ISMS standard**.

Global Privacy Framework Authorization: Issued and authorized for compliance mapping during the active 2026 calendar cycle.
Corporate Data Protection Ledger Token: ISO-PRIVACY-POLICY-2026-v4.