Independent Private Consulting Disclaimer
Suru Compliance LLC is an independent private food safety and regulatory compliance consulting company and is not affiliated with, endorsed by, or acting on behalf of the U.S. Food and Drug Administration (FDA), Centers for Disease Control and Prevention (CDC), USDA, any state or local health department, or any other government agency. Regulatory, inspection, recall, warning letter, outbreak, advisory, and enforcement information displayed through this platform is obtained from publicly available government sources. Suru Compliance organizes and may summarize this information for convenience and educational/business-compliance purposes. The original government source remains the authoritative record. Users should review the original government record before making regulatory, legal, compliance, or business decisions.
1. Who we are
Suru Compliance LLC (“SURU”, “we”, “us”) is an independent, privately owned food safety and regulatory compliance consulting company. We operate surucompliance.com and the SURU Compliance Intelligence Portal (together, the “Service”). We are not a government agency and are not affiliated with, endorsed by, or acting on behalf of the FDA, CDC, USDA, or any state or local health department.
This policy explains what personal information we collect when you use the Service, why we collect it, how long we keep it, and the choices you have. Contact us about anything in it at info@surucompliance.com.
2. What we collect when you create an account
Registration for the portal asks for exactly four things:
- Full name (required) — so we can address you and so SURU staff know who has registered.
- Company or organization name (optional) — to understand what kinds of operations use the portal. Leave it blank if you prefer.
- Email address (required) — your sign-in identifier and the only channel we use to verify your account and to send security messages.
- Age (required, a whole number) — see the next section. We do not ask for or store a date of birth.
You also choose a password. We store only a one-way bcrypt hash of it. Nobody at SURU can see your password, it is never written to a log, and it is never included in any email.
We do not collect a postal address, phone number, payment details, government identifiers, or any profile information beyond the four fields above through the account system. If you separately contact us through the consulting enquiry form, the information you type there is handled as a consulting enquiry and is described on that form.
3. Why we ask for your age
The portal presents regulatory and enforcement records intended for business and professional use. We ask for your age at registration solely to confirm that you are old enough to hold an account (you must be at least 13) and to comply with laws that restrict the collection of personal information from children. Age is stored as a single integer, is never used for advertising or profiling, and is not shared with anyone outside SURU except as described under “Who sees your information”.
4. How we use account information
- To create, secure and administer your account and sign-in sessions.
- To send transactional email: a verification link when you register, a reset link when you ask to change a forgotten password, a notice if someone attempts to register with your address, and security notices about your account. These messages are necessary to run the Service and cannot be opted out of while you hold an account.
- To notify SURU staff that a new member has verified an account, so we can understand who is using the portal and, where appropriate, offer consulting support. This internal notification contains your name, company (if given), email, age and registration time — never your password.
- To respond when you contact us.
- To detect and prevent abuse (rate limiting, bot detection, audit logging).
We do not sell personal information, and we do not send marketing email to portal members without separate, explicit consent.
5. Government data shown in the portal
The inspection results, FDA warning letters, FDA recall and enforcement records, and CDC advisories and outbreak reports shown in the portal are public records published by government agencies. SURU retrieves them from those agencies’ public data sources, organizes them, labels each with its official source and the time SURU retrieved it, and may summarize them. They are not personal information about you and are not covered by the account-data provisions of this policy.
The original government record remains the authoritative version. SURU does not conduct inspections, issue letters, or declare recalls, and SURU’s analytics, scores, comparisons and summaries are its own independent work — not government determinations.
6. AI-assisted summaries
Some records in the portal are accompanied by a plain-language summary generated by SURU using artificial intelligence. These summaries are labelled as such wherever they appear. They are produced from the public government record only — your account information is never sent to an AI model and is never used to train one. AI summaries can omit or mischaracterise detail; always read the original record before making a regulatory, legal, compliance or business decision.
8. How we protect your information
- Passwords are stored only as bcrypt hashes and are checked against a list of commonly breached passwords.
- Verification and reset links use single-use, time-limited tokens; only a cryptographic hash of each token is stored.
- Sign-up, sign-in and reset requests are rate limited and protected against automated submission.
- Account-related actions are written to an internal audit log that records what happened and when — never a password.
- Data is transmitted over HTTPS and stored with a managed database provider in the United States.
No system is perfectly secure. If you believe your account has been accessed without your permission, change your password immediately (which signs out every other device) and tell us at info@surucompliance.com.
9. Who sees your information
- SURU staff with administrative access, for account support and to know who has registered.
- Service providers that host the Service and deliver our email (currently a managed Postgres database provider, a hosting platform, and a transactional email provider). They process data only on our instructions.
- Authorities, if we are legally required to disclose information, or to protect the rights, safety or property of SURU or others.
We do not sell, rent or trade personal information.
10. How long we keep it
- Account data is kept while your account is active. When you delete your account from the Account page it is deactivated immediately and you are signed out everywhere; the record is retained in a deactivated state so the email address cannot be re-registered by someone else and so audit history remains intact. Write to info@surucompliance.com from your registered address to have the record erased.
- Verification and reset tokens expire after 24 hours and 1 hour respectively and are useless once consumed.
- Rate-limit counters hold an IP address or a hashed email for at most a few hours.
- Audit log entries are retained for security and legal purposes.
11. Your choices and rights
- See the account data we hold at any time on your Account page.
- Change your password there; ask us by email to correct your name, company or email address.
- Delete your account there, or ask us to erase the record entirely.
- Ask us what personal information we hold about you and to receive a copy.
Depending on where you live you may have additional rights under laws such as the California Consumer Privacy Act or similar state laws. Contact us and we will honour them.
12. Children
The Service is not directed to children under 13 and we do not knowingly collect personal information from them. Registration requires an age of at least 13. If you believe a child has registered, tell us and we will remove the account.
13. Changes to this policy
We will update this page when our practices change and revise the effective date at the top. Material changes affecting account holders will also be announced by email to the address on the account.
14. Contact
Suru Compliance LLC · info@surucompliance.com
Questions about this document: info@surucompliance.com. We respond to every message directly.