Loading…
Version 1.0 Effective Date: April 2026
Operated by GIBQ Operations LLC under license from Global Institute for Biomedical Quality.
This Privacy Policy describes how GIBQ Operations LLC, a Delaware limited liability company ("we," "us," "our," or "GIBQ Operations"), collects, uses, discloses, and safeguards information when you visit gibq.org, submit a vendor application, communicate with us, or otherwise interact with services we operate (collectively, the "Services").
GIBQ Operations is the data controller for personal information processed in connection with the Services. The Services operate under license from Global Institute for Biomedical Quality, a Delaware nonprofit corporation that owns the GIBQ™ and GIBQ Verified™ certification marks and the standards underlying them. Global Institute for Biomedical Quality does not collect, store, or process personal information in the operation of the Services.
By accessing the Services, you acknowledge that you have read and understood this Policy. If you do not agree with this Policy, do not use the Services.
This Policy applies to all visitors to gibq.org, all vendors submitting an application for verification under the GIBQ Verified standard, and all persons who otherwise communicate with us in connection with the Services.
During Phase 1, vendor applications for GIBQ Verified status are accepted only from entities legally formed and operating in the United States. Vendor applications submitted from outside the United States will not be processed during Phase 1. We may expand vendor eligibility to additional jurisdictions in subsequent phases; if we do, this Policy will be updated accordingly.
Notwithstanding the Phase 1 vendor restriction above, gibq.org is accessible globally. Visitors from outside the United States, including the European Economic Area ("EEA"), the United Kingdom, and Canada, may browse the website, read about the GIBQ Verified standard, and contact us. Such visitors are entitled to the rights described in Section 9 below.
We collect only information that is reasonably necessary to evaluate vendor applications, operate the Services, communicate with you, and meet our legal obligations. We do not sell personal information.
We do not knowingly collect personal information from minors under the age of sixteen (16). The Services are intended for business and professional use only. If you believe a minor has provided personal information to us, please contact us using the address in Section 12 and we will delete it.
We do not collect or process special categories of data (such as health, biometric, racial or ethnic, religious, or political data) in the ordinary course of operating the Services.
We use the information described in Section 3 only for the purposes set out in the table below. The legal bases identified are those applicable under the European Union General Data Protection Regulation ("GDPR") and the United Kingdom General Data Protection Regulation ("UK GDPR"). For United States residents, the equivalent purposes are described in Section 9.2.
| Purpose | Categories of Data | Legal Basis (GDPR/UK GDPR) |
|---|---|---|
| Evaluate vendor applications and conduct the GIBQ Verified audit | Vendor application and audit submission data | Pre-contractual measures (Art. 6(1)(b)) |
| Issue, maintain, suspend, or revoke GIBQ Verified status; maintain the public registry | Vendor application data; audit results; communications | Performance of contract (Art. 6(1)(b)) |
| Operate, secure, and improve the website and Services | Technical data; aggregated analytics | Legitimate interests (Art. 6(1)(f)) |
| Communicate with you and respond to inquiries | Contact information; communications | Legitimate interests (Art. 6(1)(f)) |
| Comply with legal, regulatory, accounting, audit, and tax obligations | All categories as required | Legal obligation (Art. 6(1)(c)) |
| Protect, establish, exercise, or defend legal claims | All categories as required | Legitimate interests (Art. 6(1)(f)) |
| Process payments (Phase 2 onward) | Billing and payment information | Performance of contract (Art. 6(1)(b)) |
We do not engage in automated decision-making that produces legal or similarly significant effects on individuals. Vendor audit determinations are reviewed and approved by qualified human reviewers.
We share personal information only as described below. We do not sell personal information, and we do not share personal information for cross-context behavioral advertising.
We engage third-party service providers to perform functions on our behalf, including website hosting, email delivery, document storage, payment processing (Phase 2 onward), and analytics. These providers process information only as instructed by us and under written agreements that require confidentiality and appropriate safeguards. Categories of providers include:
Pursuant to the trademark license agreement between GIBQ Operations LLC and Global Institute for Biomedical Quality, we provide the nonprofit with summary, aggregated, and anonymized information regarding the operation of the Services and the certification program. We also disclose vendor identity and audit outcome information as necessary to enable the nonprofit to exercise its quality-control rights and to maintain the integrity of the GIBQ Verified certification mark.
Vendors who pass the GIBQ Verified audit are listed in a publicly available registry on gibq.org. The registry displays the vendor's legal entity name, the date of certification, the certification status, and any product categories covered. The public registry does not include personal information about individual employees of the vendor unless the vendor expressly authorizes such disclosure.
We may disclose information when we believe in good faith that disclosure is required by law, court order, or governmental request; necessary to enforce our agreements or this Policy; or appropriate to protect the rights, property, or safety of GIBQ Operations, its affiliates, vendors, users, or the public.
If GIBQ Operations is involved in a merger, acquisition, financing, reorganization, sale of assets, or insolvency proceeding, personal information may be transferred to the relevant counterparty as part of that transaction. Any such transfer will remain subject to the protections set out in this Policy or a successor policy that provides equivalent protections.
We share information with third parties when you direct us to do so or otherwise consent to the disclosure.
GIBQ Operations LLC is established in the United States, and the Services and supporting infrastructure are hosted in the United States. If you access the Services from outside the United States, the information we collect about you will be transferred to, stored in, and processed in the United States.
The United States may not provide the same level of legal protection for personal information as your country of residence. For transfers of personal information from the EEA, the United Kingdom, or Switzerland to the United States, we rely on the Standard Contractual Clauses approved by the European Commission (and, as applicable, the UK International Data Transfer Addendum) as the legal mechanism for the transfer. A copy of the relevant clauses is available on request using the contact information in Section 12.
We retain personal information only for as long as necessary for the purposes for which it was collected, to comply with our legal, accounting, or reporting obligations, or to establish, exercise, or defend legal claims. The retention periods below are guidelines; specific periods may be longer where required by applicable law or where the information is the subject of a legal hold.
| Category | Retention Period |
|---|---|
| Vendor application and audit records (certified vendors) | Duration of certification plus seven (7) years |
| Vendor application records (declined or withdrawn applicants) | Twenty-four (24) months from final decision or withdrawal |
| Communications and contact-form submissions | Thirty-six (36) months from last interaction |
| Billing and payment records (Phase 2 onward) | Seven (7) years for tax and accounting compliance |
| Server logs and security event records | Up to twelve (12) months |
| Aggregated and anonymized analytics | No fixed period (no longer constitutes personal information) |
When the applicable retention period expires, we will delete or irreversibly anonymize the personal information.
We implement administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. These safeguards include access controls, encryption of data in transit, secure cloud infrastructure, and ongoing review of our information-security practices.
No method of electronic transmission or storage is completely secure, and we cannot guarantee the absolute security of personal information. You are responsible for maintaining the confidentiality of any account credentials you receive in connection with the Services. If you suspect that your interaction with us has been compromised, contact us immediately using the information in Section 12.
If you are located in the EEA, the United Kingdom, or Switzerland, you have the following rights with respect to your personal information, subject to the conditions and limitations set out in the GDPR and UK GDPR:
To exercise any of these rights, contact us using the information in Section 12. We will respond within the period required by applicable law (generally one month, extendable by up to two further months for complex requests). We do not currently maintain a representative in the European Union under Article 27 of the GDPR; this Policy will be updated if we appoint one.
Depending on your state of residence, you may have rights under United States state privacy laws, including the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), and the comprehensive privacy statutes of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Tennessee, Indiana, Iowa, Delaware, New Jersey, New Hampshire, and other states with similar laws. Subject to the conditions and limitations of the applicable statute, those rights generally include:
California residents may designate an authorized agent to make a request on their behalf. We may require verification of the agent's authority and your identity before responding.
You may submit a privacy rights request by emailing privacy@gibq.org. We will need to verify your identity before responding to certain requests. Verification will be proportionate to the sensitivity of the data and the nature of the request. We will not charge a fee for responding to a request unless it is manifestly unfounded, excessive, or repetitive, in which case we may charge a reasonable fee or decline to act, as permitted by applicable law.
We use a small number of strictly-necessary cookies for site functionality and security (for example, session and CSRF cookies). We also use privacy-friendly analytics that do not set tracking cookies, do not collect personally identifying information, and do not perform cross-site tracking.
We may, in the future, use additional cookies and similar technologies for advertising, conversion measurement, or behavioral analytics. If we do, we will update this Policy and deploy a consent management tool that permits you to accept or reject those non-essential categories before they are activated. Until that time, no advertising or cross-site tracking technologies are loaded on the Services.
You can configure your browser to refuse all cookies or to alert you when cookies are being sent. If you reject strictly-necessary cookies, parts of the Services may not function correctly.
For full details, see our Cookie Policy.
We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes, we will revise the "Effective Date" at the top of this Policy and, if the changes are material, provide additional notice through the Services or by other reasonable means. Your continued use of the Services after the Effective Date of an updated Policy constitutes your acknowledgment of the updated Policy.
Questions, concerns, and privacy rights requests may be directed to:
GIBQ Operations LLC Attn: Privacy Officer Email: privacy@gibq.org General inquiries: info@gibq.org Website: gibq.org
This Privacy Policy and any disputes arising under or in connection with it shall be governed by and construed in accordance with the laws of the State of Delaware, without regard to its conflict-of-laws principles. Any action, suit, or proceeding arising under or in connection with this Policy shall be brought exclusively in the state or federal courts located in Wilmington, Delaware, and the parties consent to the personal jurisdiction of such courts and waive any objection based on inconvenient forum.
Nothing in this Section 13 limits any non-waivable rights you may have under the consumer protection or privacy laws of your state, country, or region of residence.
GIBQ Operations LLC · Privacy Policy v1.0 · April 2026 Operated under license from Global Institute for Biomedical Quality.