CPSC eFiling CSV Checker & Builder — Pricing, Limits & Retention Schedule

Version: 2.1
Last updated: August 11, 2026
Applies to: Global B2B and B2C; all country, subdivision, and purchaser-type routes disabled by default until approved
Currency: USD

This Pricing, Limits & Retention Schedule (the “Schedule”) applies to the CPSC eFiling CSV Checker & Builder (the “Application”), a distinct product of Registry Intelligence. Registry Intelligence is a U.S.-focused commercial intelligence platform and editorial publication operated by Natallia Vasilyeva, trading as NATALLIA VASILYEVA – Poland Documents, a sole proprietorship registered in Poland (“Poland Documents,” “we,” “us,” or “our”). Poland Documents is the Application’s legal operator, seller, service provider and contracting party. Registry Intelligence is a public brand and platform name, not a separate legal person or contracting party.

Poland Documents provides the technical, operational, commercial and administrative infrastructure for Registry Intelligence and supports the development, publication, licensing, sale and delivery of Registry Intelligence Content, products and services, primarily to clients and users in the United States. The word “primarily” describes the commercial focus and does not limit the approved global B2B and B2C purchaser model.

This Schedule supplements the CPSC eFiling CSV Checker & Builder Application Terms and License (the “Application Terms”), the CPSC Refund & Delivery Policy made available with the Application (the “Refund & Delivery Policy”), the Data Processing Addendum made available with the Application where applicable (the “DPA”), the Terms of Use, the Privacy Policy, and the Data Security notice. Where Customer Data includes personal data that Poland Documents processes on behalf of a Business User, the applicable DPA forms part of the agreement. Capitalized terms not defined here have the meanings given in the Application Terms.

For a Consumer or other Protected Customer purchase, this Schedule also supplements the Consumer Checkout & Immediate Performance Notice and any mandatory pre-contract information supplied for that Job. The DPA and U.S. State Privacy Law Addendum apply only where their stated business-controller or processor conditions are met; they are not imposed on a Consumer merely because the Consumer uses the Application.

For matters expressly covered by these documents: (a) this Schedule controls pricing, operational limits, batching, and retention; (b) the Refund & Delivery Policy controls delivery, correction, renewed access, and refunds; (c) the Consumer Checkout & Immediate Performance Notice controls any request to begin paid performance during an applicable withdrawal period and the related acknowledgement; and (d) the Application Terms control all other Application matters. The general Terms of Use apply only where the product-specific documents do not address the issue.

Where the DPA applies, it controls over this Schedule and the Application Terms solely for personal data that Poland Documents processes on behalf of a Business User acting as a controller or processor. Transaction, tax, fraud-prevention, security, contract-evidence and direct-support data that Poland Documents processes as an independent controller remain governed by applicable law, the Privacy Policy and this Schedule.

The transaction-specific confirmation shown immediately before payment controls only the factual details confirmed for that Job, including the Selected Ready Record count, pricing version, currency, subtotal, applicable tax, total charge, Output Package, processing estimate, Displayed Availability Period and scheduled deletion time. It may not reduce a right, remedy or protection granted by a product-specific document or mandatory law. Security, fraud, legal or integrity controls may suspend access or require earlier isolation or deletion of unsafe content, but they do not eliminate an applicable replacement or refund remedy where conforming delivery cannot be provided.

The Application may be purchased for business or professional use or by an individual for personal, family or household purposes. No general Registry Intelligence account is required. A user must be at least 18 years old and legally capable of entering the transaction. Consumer or protected status is determined by the actual purpose and circumstances and mandatory law, not solely by a company field, invoice label, tax number or checkout selection.

Before email verification, Job creation or any document upload, the Application displays this required radio group with no choice preselected:

Who is creating this Job?

  • An individual for personal, family or household use
  • An individual or sole proprietor for business, trade or professional use
  • An organization or other legal entity

This selection is used only to display the correct notices and contract documents. It does not determine or waive any rights that apply by law.

The choice is mandatory and cannot be inferred solely from a company field, tax number, business email, payment method or the fact that the output is intended for CPSC. A conflicting fact requires correction or review; it does not silently remove a mandatory purchaser protection.

The Application also requires:

  • Purchaser country or territory
  • For personal use, select your country of habitual residence. For business use, select the purchaser’s principal place of business.
  • State or territory, province or other subdivision where required by the active route.

A route is activated only after its tax, consumer, invoice or receipt, payment, privacy, contract, language and dispute-handling controls have been approved and tested. B2B and B2C eligibility is global; the absence of an active route means only that checkout for that country and purchaser type is temporarily unavailable.

For route design, see the European Commission’s official place-of-taxation guidance and One Stop Shop (OSS) portal. These sources support route-specific analysis; they do not activate any country route by themselves.

Unavailable route message: Purchases for this customer type are not yet available in {COUNTRY}. No file can be uploaded and no payment will be taken.

The following four controls must be separate and unchecked by default before upload:

  • “I agree to the Application Terms and License and this Pricing, Limits & Retention Schedule, and acknowledge that I have reviewed the Privacy Policy.”
  • “I am at least 18 years old and legally capable of entering into this transaction. I am acting for myself or am authorized to act for the person or organization using this Job.”
  • “I have the legal right and all required permissions to upload these files and have their contents, including any personal data, processed to provide this Job.”

Immediately above the fourth control, the Application must display this unavoidable notice: Do not upload Social Security numbers, government identification numbers, payment-card or bank-account data, passwords or login credentials, health, genetic or biometric data, precise location data, personal data about children, or other sensitive personal data that the Application does not expressly request.

  • “I understand that the Application is not designed for prohibited sensitive data, and I will not upload data identified in the prohibited-data notice above.”

A Business User that uploads personal data as a controller or processor must complete the separate role selection and acceptance required by the applicable DPA, Subprocessor List and U.S. State Privacy Law Addendum before upload. Those business-processing controls are not presented as a consumer consent.

The server-side evidence record must retain the Job ID, verified email reference, exact purchaser choice, country or territory and subdivision, exact order snapshot, each control’s rendered text and initial unchecked state, affirmative event, UTC timestamp, UI and document versions and hashes, pricing inputs, subtotal, tax, total, currency, ruleset, package, payment reference, Delivery, access and deletion events. Browser local storage alone is not sufficient evidence.

1. Definitions used in this Schedule

“Business User” means a person or organization using the Application mainly for trade, business, craft or professional purposes.

“Consumer” means a natural person purchasing mainly for personal, family or household purposes, or otherwise treated as a consumer under non-waivable applicable law.

“Protected Sole Trader” means an individual or sole proprietor entitled to mandatory consumer or consumer-like protections under applicable law for the particular transaction. This is a legal classification, not a fourth checkout choice.

“Protected Customer” means a Consumer or, to the extent the relevant mandatory provisions apply, a Protected Sole Trader.

“Purchaser” means the person or organization legally responsible for a Job, whether a Business User, Consumer or Protected Sole Trader.

“Output Package” means the protected ZIP for a paid Job containing the CPSC CSV file or files, Validation Summary, Correction Ledger, Ruleset & Provenance Receipt and README. Section 7 governs direct CSV access and batching.

“Source Record” means a submitted row or record, whether or not it becomes Ready. A technical header, instruction, blank or non-record row is excluded where the Application identifies it as such.

“Ready Record” means a record that has passed the Application’s implemented checks and all required user confirmations. Ready does not mean approved by CPSC or legally compliant.

“Selected Ready Record” means a Ready Record selected and confirmed for paid generation. Each Selected Ready Record counts once even if technical batching creates more than one output file.

“Large Job” means a Job containing 50,001 to 1,000,000 Source Records and processed asynchronously after successful automatic preflight.

“Standard Job” means a Job containing no more than 50,000 Source Records.

“Product Collection” means a product grouping identified for the relevant CPSC Product Registry workflow. The Application does not create or manage a Product Collection for the Purchaser.

“Output Batch” means one separately generated CPSC-formatted CSV within an Output Package.

“Working Period” means the period during which a Job remains available for validation, correction, checkout, generation, delivery, or a confirmed support hold, subject to the expiry rules in Section 9.

“Inactivity Period” means a continuous period during which no server-accepted upload, replacement, mapping, confirmation, correction, revalidation, payment, support hold, or other state-changing action is recorded for the Job. Merely opening or refreshing a page does not restart the Inactivity Period.

“Delivery Time” means the timestamp recorded when a complete Output Package materially conforming to the checkout confirmation is first made available to the authorized Purchaser through a functional protected download and the availability is displayed or notified.

“Displayed Availability Period” means the no-additional-charge protected retrieval period beginning at Delivery Time. Under this version it is seven calendar days unless mandatory law requires more favorable access.

“Business Day” means Monday through Friday, excluding public holidays in the Republic of Poland. Where mandatory law assigns a different meaning or a shorter deadline, that law controls.

2. Free validation and the unit used for pricing

Before payment, the Purchaser receives at no charge:

  • Readiness Report;
  • detected errors and warnings;
  • missing confirmations;
  • the number of Ready Records;
  • the selected records, mappings and corrections; and
  • the exact final price for the frozen paid scope.

Pricing is based only on the number of Selected Ready Records confirmed for the paid Output Package. Source Records that remain missing, invalid, blocked, unconfirmed or otherwise ineligible for paid generation are not charged. If the selection, mapping, correction, ruleset, tax or scope changes, the count and price must be recalculated and reconfirmed before payment.

If a Job contains no Selected Ready Records, paid generation is unavailable and no generation charge is due. File, row, security, rate, processing-time, and retention limits nevertheless apply to every Job, including a free Job and a Job containing no Ready Records.

3. Progressive pricing schedule

The price is calculated progressively. A lower rate applies only to the Selected Ready Records within that rate band; it does not retroactively reprice records in an earlier band.

Selected Ready Records in one Job — Marginal charge for that band

  • 1–25: $15.00 fixed total
  • 26–1,000: +$0.10 for each record in this band
  • 1,001–10,000: +$0.03 for each record in this band
  • 10,001–100,000: +$0.008 for each record in this band
  • 100,001–1,000,000: +$0.0015 for each record in this band

The resulting pre-tax totals at representative volumes are:

  • 25 records: $15.00;
  • 100 records: $22.50;
  • 500 records: $62.50;
  • 1,000 records: $112.50;
  • 5,000 records: $232.50;
  • 10,000 records: $382.50;
  • 25,000 records: $502.50;
  • 50,000 records: $702.50;
  • 100,000 records: $1,102.50;
  • 250,000 records: $1,327.50;
  • 500,000 records: $1,702.50; and
  • 1,000,000 records: $2,452.50.

The maximum calculated pre-tax price under this published formula is $2,452.50 for 1,000,000 Selected Ready Records. For example, 1,000 Selected Ready Records cost $15.00 + (975 × $0.10) = $112.50. Standard and Large Jobs use the same public formula; a Large Job does not require a product account, sales-team contact, manual commercial review or a hidden custom quote.

4. Price calculation, rounding, and confirmation

All Selected Ready Records across all accepted source files, Product Collections, Output Batches, and other components of the same Job are aggregated for pricing. Separate Jobs are priced separately.

Rates may contain fractions of one cent. The Application calculates the aggregate subtotal across all applicable bands and rounds the final subtotal once to the nearest U.S. cent using decimal half-up rounding. It does not round each record or each fractional-cent rate separately.

On the same checkout screen and before payment, the Application must display directly and conspicuously:

  • the Job ID and purchase route;
  • the Selected Ready Record count and a statement that Ready means passing implemented checks, not CPSC approval;
  • the pricing version, full marginal-tier calculation, subtotal and currency;
  • any applicable tax and the final total payable, inclusive of mandatory charges;
  • the one-time nature of the charge and that no subscription or recurring charge is created;
  • the direct CPSC CSV download and protected Output Package ZIP: CPSC CSV, Validation Summary, Correction Ledger, Ruleset & Provenance Receipt and README;
  • the applicable ruleset or official-source version and material compatibility or technical limits;
  • the processing and delivery estimate, Displayed Availability Period and exact scheduled deletion time in UTC;
  • the legal seller name, actual street address and contact details;
  • a concise delivery and refund summary with a conspicuous link to the Refund & Delivery Policy; and
  • a statement that the Application does not file with CPSC, determine compliance, issue a certificate or guarantee acceptance.

Seller: Natallia Vasilyeva, carrying on business as NATALLIA VASILYEVA – Poland Documents, ul. Ogrodowa 58, lok. 29, 00-876 Warszawa, Poland. This legal and public correspondence address is confirmed by the owner and verified through Business Plus. A fixed order confirmation and the applicable Refund & Delivery Policy are made available through the protected Job page and sent to the verified order email.

Immediately before the final payment action, checkout must present the following four separate controls for every Purchaser, each unchecked by default:

  • “I confirm the order summary: {COUNT} Selected Ready Records, a final total of {TOTAL} {CURRENCY} including applicable taxes, and the deliverables, delivery estimate, download-access period and deletion time shown above. I agree that this Pricing, Limits & Retention Schedule applies to this Job.”
  • “I have reviewed and approve the selected records, column mappings and corrections (if any) shown in the final preview for this Job.”
  • “I have reviewed the Refund & Delivery Policy, including the rules for delivery, download access, corrections and refunds.”
  • “I understand that the Application does not submit files to CPSC, determine product compliance, issue a certificate or guarantee acceptance by CPSC or any third party. I am responsible for reviewing the output and making any required submission.”

A Consumer must also complete the separate express request or consent required by the enabled consumer route through the Consumer Checkout & Immediate Performance Notice before immediate paid performance begins. That control must explain the applicable effect on any withdrawal or cancellation right and must not waive a right that cannot lawfully be waived. It is separate from the Terms, Privacy Policy, Refund & Delivery Policy, marketing choices and payment control, and is unchecked by default. If the route does not permit immediate performance without that control, paid processing does not begin until the condition is satisfied.

The final payment control states “Pay {TOTAL} {CURRENCY} now,” or an equally unambiguous localized Pay or Buy label showing the same total. The server verifies the signed Stripe payment event, amount, currency, Job ID and frozen order snapshot before accepting the order. A browser redirect or payment-success page is not proof of payment or Delivery.

The server-side checkout record must retain the Job ID, verified email reference, exact purchaser choice, country or territory and subdivision, exact order snapshot, each control’s rendered text and initial unchecked state, affirmative event, UTC timestamp, UI and document versions and hashes, pricing inputs, subtotal, tax, total, currency, ruleset, package, payment reference, Delivery, access and deletion events. Browser local storage alone is not sufficient evidence.

Paid checkout requires a verified email address. After payment verification, a fixed, downloadable order confirmation must be displayed and sent to that address. It must identify the seller, Job, purchase route, Selected Ready Record count, pricing version, subtotal, tax, total, currency, paid deliverables, delivery estimate, access and deletion periods, accepted controls and document versions. For a Protected Customer, the confirmation must also include the applicable withdrawal information and model form and the exact immediate-performance statement accepted. Paid generation must pause if the required durable confirmation cannot be issued; a link to a changeable webpage alone is not sufficient.

The calculated price remains valid only for the frozen Job snapshot shown at checkout. If the Job data, selection, scope, pricing version, tax information or checkout eligibility changes, the price expires and must be recalculated and reconfirmed before payment.

Changing source data, selected records, mappings, confirmations, corrections, ruleset, tax, currency, purchase route or other Job scope before payment invalidates the earlier order snapshot and controls. The Application must recalculate and collect fresh confirmation. After payment, scope cannot be expanded without a new price confirmation and, where applicable, a new Job and payment. A remedy for the same paid scope does not create a second charge.

If a clearly erroneous price is detected before Delivery, we may cancel the affected generation and refund the full amount charged, including collected tax, to the original payment method. We will not collect a higher amount without a new price calculation and the Purchaser’s separate express authorization.

5. Payment, taxes, and third-party charges

Each Application charge is a one-time charge. The Application does not create a subscription or recurring Registry Intelligence charge.

The published price includes validation, Large-Job preflight, generation, batching, packaging and protected delivery for the confirmed paid scope. Government-imposed tax, if applicable, is calculated separately and displayed before payment.

Tax treatment is determined by the enabled country or territory, subdivision and purchaser-type route. Business status does not by itself create an exemption. VAT ID, exemption evidence, customer-location evidence, registration status, invoice or receipt treatment and any reverse-charge or sales-tax rule must be handled by the active route. If that route is not approved, upload and payment remain unavailable.

Business or professional status does not by itself create a tax exemption. An exemption will be applied only where valid exemption documentation is provided and accepted before payment.

Every paid checkout collects only the Purchaser’s name, verified email, country and billing or location information reasonably necessary for contract formation, payment, fraud prevention, delivery and tax. Business name, professional role, registration or tax identifier, DPA details and exemption evidence are collected only for the applicable business, invoice, DPA or tax-exemption branch. A Consumer is not required to provide evidence of business activity.

The Application price is a charge for Poland Documents data-preparation, validation and generation functions. It is not a CPSC, CBP, ACE, Product Registry, customs-entry, testing-laboratory, certification, marketplace, brokerage or other government or third-party fee. The Purchaser remains responsible for any separate third-party charge.

A bank, card issuer, or payment provider may apply its own currency-conversion, international-payment, or other charge. Such a provider charge is not part of the Application price unless expressly included in checkout.

6. Job and processing limits

6.1 Standard Jobs

A Standard Job contains no more than 50,000 Source Records across all accepted source files. It may use the ordinary automated checkout after all file, security, route and validation controls pass. No Job may contain more than 1,000,000 Selected Ready Records.

Standard Jobs may be processed through the ordinary self-service workflow, subject to the published limits in Section 6.3 and the security, rate, concurrency and processing-time controls stated in this Schedule. A Job is not accepted for paid generation until the applicable checks pass.

6.2 Large Jobs

A Large Job contains 50,001 to 1,000,000 Source Records. It is processed asynchronously after an automatic, free generation-capacity and security preflight.

Large Jobs require successful preflight and capacity approval by the Application before checkout. Preflight may consider total byte size, format, file count, archive expansion, row and column structure, Product Collection structure, processing complexity, ruleset availability, regulatory freshness, security status, and current system capacity.

Large-Job preflight does not require a general Registry Intelligence account and does not by itself create a charge. If the Application cannot safely accept, validate, generate, protect, or deliver a Large Job under the displayed conditions, checkout will remain unavailable and no generation payment will be requested.

Large Jobs may be queued and processed asynchronously. A displayed processing estimate is an estimate, not a guaranteed completion time, unless checkout expressly states otherwise.

6.3 Format-specific and security limits

Version 1 accepts CSV (.csv), XLSX (.xlsx), PDF (.pdf) and ZIP (.zip). MB means 1,000,000 bytes and GB means 1,000,000,000 bytes. The limits below are internal Application safeguards, not published CPSC limits.

Control — Version 1 limit

  • Standard Job: Up to 50,000 Source Records
  • Large Job: 50,001–1,000,000 Source Records; asynchronous after automatic preflight
  • CSV: Up to 250 MB per file
  • XLSX: Up to 100 MB per file; maximum 20 worksheets
  • PDF: Up to 50 MB and 200 pages per file
  • OCR: Maximum 1,000 pages in one Job
  • ZIP — uploaded: Up to 250 MB compressed
  • ZIP — expanded: Up to 1 GB total extracted data
  • Files inside ZIP: Maximum 100
  • ZIP expansion ratio: Maximum 20:1
  • Output CPSC CSV: Maximum 10,000 Selected Ready Records in one CSV; larger results are batched

ZIP may contain only CSV, XLSX and PDF. Nested ZIP files, encrypted or password-protected archives, .xlsm files, macros, executable files, external links, symbolic links, absolute or unsafe paths, path traversal and damaged archives are rejected automatically.

Text in a text-based PDF is extracted directly. A scanned PDF is processed by OCR. OCR is included in Version 1 product scope, but production OCR remains disabled until the actual provider or a verified local processing route, data locations, retention, security controls and Subprocessor disclosures have been approved. If OCR is unavailable for a Job, a scanned PDF is rejected before paid checkout rather than silently omitted.

For every value extracted from a PDF or OCR process:

  • the value is displayed to the user for confirmation or correction;
  • the affected record is not Ready until every required value is confirmed or corrected;
  • the source document, page and source fragment are retained with the value during the Job period;
  • confidence and review status are recorded, and uncertain recognition is marked as requiring review; and
  • the Application does not guess certificate type, citation code, requirement applicability, manufacturer or testing laboratory.

A supported filename extension does not guarantee acceptance. The Application may reject malformed, encrypted, password-protected, macro-enabled, executable, malicious, unexpectedly complex, decompression-bomb, formula-injection, external-reference, unsupported or otherwise unsafe content. Exact fraud and abuse thresholds need not be published where disclosure could weaken the control. A paid Job may not be accepted unless the Job passes the applicable checks.

A Job exceeding 1,000,000 Source Records, 1,000,000 Selected Ready Records or another published ceiling is outside this Schedule and is not accepted through the self-service workflow. A different ordinary limit may not be substituted only in the interface. Any separately agreed processing requires written terms accepted before payment.

7. Output batching and package structure

After payment and successful generation, the protected Job page displays these exact controls:

  • Download CPSC CSV
  • Download Complete Output Package (ZIP)

The standard paid Output Package consists of:

  • CPSC CSV — CPSC_Upload_001.csv: Selected Ready Records; additional CSV files are numbered sequentially
  • Validation Summary — Validation_Summary.pdf: Validation results, excluded records, warnings and ruleset version
  • Correction Ledger — Correction_Ledger.xlsx: Corrections, normalizations and user confirmations with source provenance
  • Ruleset & Provenance Receipt — Ruleset_and_Provenance_Receipt.json: Job ID, dates, schema and ruleset versions, file names, counts and integrity hashes
  • README — README.pdf: Package contents, file order, limitations and next actions

The paid product is the complete Output Package, not only a CSV. “Protected” describes the access channel and does not represent that the ZIP itself is encrypted unless checkout expressly states that it is.

A separate protected control provides direct access to the CPSC CSV. Where batching creates more than one CSV, that control provides clearly identified per-batch CSV files or a CSV-only ZIP.

Under this version of the Schedule, the Application limits each Output Batch to no more than 10,000 Selected Ready Records. It may create smaller batches where required by Product Collection boundaries, data structure, file integrity, technical controls, or the active workflow. Records spanning different Product Collections will be separated into different Output Batches where the Application workflow requires that separation.

CPSC public materials identify CSV bulk upload, but do not publish a one-million-row or other universal per-import ceiling. The 10,000-record batch limit is therefore an internal safety limit and is not attributed to CPSC. See the CPSC eFiling FAQ and CPSC Product Registry information. The output is a “CPSC-formatted CSV,” never an “official CPSC CSV.”

Output partitioning does not increase the Selected Ready Record count or price. The Application does not upload an Output Batch to CPSC, CBP, ACE, the CPSC Product Registry, or another third-party system and does not guarantee acceptance.

7.1 No-account access and recovery

No general product account or password is required. A purchase is associated with the Job ID, verified email and Stripe payment record. A Stripe payment reference is billing and transaction evidence only and is never an authentication factor. Email verification is required before any document upload.

Primary method — email magic link

  • The link is one-time and bound to one Job and access purpose.
  • It expires 30 minutes after issue and becomes invalid after successful use.
  • A new link may be requested until the Job is automatically deleted.
  • Issue, resend and validation attempts are rate-limited.

Fallback method — Job ID and Recovery Code

  • The Recovery Code contains at least 128 bits of cryptographic entropy.
  • It is displayed once when the Job is created, and the Purchaser must save it.
  • Only a keyed hash is stored server-side.
  • It remains valid until automatic Job deletion and is never sent in the same message as an email magic link.

In the browser where the Job is created, the Purchaser continues through a protected Secure, HttpOnly session without repeated authentication. From a new device, access to a paid result requires a new email magic link or the Job ID and Recovery Code. All issue, resend and validation attempts are rate-limited.

If the Purchaser has lost access to both the verified email account and the Recovery Code and has no still-valid authorized browser session, Job access and paid-output access cannot be recovered. Support must not reset either factor, change the verified email, disclose Job data, issue a replacement credential or restore downloads on the basis of a Stripe payment reference, billing details, purchaser or business facts, or identity documents. Support may handle a complaint, billing issue or refund without granting Job access. Loss of both factors does not extend retention or restore expired or deleted content.

30 minutes is not 7 days: The 30-minute period applies only to one authentication magic link. Authentication credentials do not extend the seven-calendar-day paid output entitlement. After output expiry, a magic link, Recovery Code or surviving browser session may authenticate only Job-status information that remains lawfully retained; none can restore access to expired or deleted source or output content.

7.2 Delivery and Full Performance

Delivery Time is the UTC timestamp of one atomic transition after all purchased processing is complete and all of the following conditions have been satisfied:

  • the complete conforming paid result exists and has passed required integrity checks;
  • Download CPSC CSV is functional and genuinely accessible to the authorized Purchaser;
  • Download Complete Output Package (ZIP) is functional and genuinely accessible to the authorized Purchaser;
  • the exact seven-calendar-day access expiry and scheduled deletion time are recorded and displayed; and
  • the ready-for-download notice has been sent to the verified email without a known hard delivery failure.

Actual download or opening of a file is not required for Delivery or Full Performance. Payment, a payment receipt, browser redirect, queue entry, processing start, file creation, partial output, link creation, email dispatch without accessible files, link expiry or scheduled deletion is not by itself Delivery or Full Performance.

Full Performance occurs only after every purchased validation, transformation, generation, integrity-checking, packaging and Delivery obligation for the paid scope has been completed and every promised component is available in usable form.

8. Regulatory-freshness and technical safety stops

8.1 Production gates

The Subprocessor List is intentionally pre-production. It must identify actual providers and data routes, not assumed or invented providers. Until the production providers and routes for hosting, storage or database, backup, transactional email, OCR, malware scanning, monitoring or logging and support are confirmed, no live customer upload and no public paid sale may be enabled for any country or purchaser type.

OCR remains included in Version 1 product scope, but production OCR is enabled only after its actual provider or verified local route, processing locations, safeguards, retention and disclosures are approved. The same provider gate applies globally to business and consumer Jobs.

A country or subdivision and purchaser-type route is enabled only after its tax calculation, invoice or receipt, payment, privacy, contract and consumer controls have passed end-to-end testing.

Before payment, the Application may pause validation, require revalidation, lower the currently available operational limit, or disable checkout if an official-source change, unverified rule, unavailable specification, security event, system-integrity concern, or provider failure prevents safe processing. No generation charge is imposed while checkout remains disabled.

After payment but before Delivery, the Application will recheck the payment event, Job scope, price, authorization state, ruleset, regulatory freshness and integrity conditions. If a correctable problem occurs, we may rerun generation or provide a replacement. If a paid Job cannot be delivered conformingly, the Refund & Delivery Policy controls replacement, renewed access or refund. A request for reasonably necessary information will not be used to defer a refund indefinitely. Any shorter or immediate mandatory Consumer remedy controls.

The applicable correction, renewed-download, duplicate-payment, non-delivery, inaccessible-result, and refund procedures are governed by the Application Terms and the CPSC Refund & Delivery Policy made available for the Application. A later change to official requirements after conforming delivery does not, by itself, make the earlier Output Package defective.

9. Retention schedule

The Application is a temporary processing service, not a permanent archive or certificate-management system. The periods below are fixed for this version. The seven-day Displayed Availability Period is the minimum promised protected access period for a conformingly delivered paid Job. Other periods are maximum retention periods and may be shortened at the Purchaser’s verified deletion request or where a documented security or legal requirement demands earlier isolation or deletion. A longer period requires a documented support hold, preservation duty or expressly agreed delivery-resolution period; it may not arise from a silent policy or interface change.

Data or Job state — Exact retention or action

  • Failed upload; no Job created: Delete within 24 hours
  • Free or unpaid Job: Delete after 7 days of inactivity; absolute maximum 30 days from Job creation
  • Paid Job before Delivery: Retain until Delivery, cancellation or refund resolution
  • Paid Job not delivered: Within 14 days after verified payment: deliver, obtain a documented written extension, or initiate a full refund
  • Source CSV, XLSX, PDF and ZIP: 7 calendar days from Delivery Time
  • Extracted files, OCR text, mappings, confirmations, corrections and intermediate data: 7 calendar days from Delivery Time
  • CPSC CSV, Complete Output Package and protected output access: 7 calendar days from Delivery Time
  • Deletion from active systems: Complete no later than 24 hours after the applicable period expires
  • Ordinary technical, access, rate-limit and security logs without file content: Exactly 90 days from creation
  • Backup remnants of deleted active data: Delete or overwrite no later than 30 days after active-system deletion
  • Delivery or refund case: Retain only necessary data for 30 days; any extension must be documented in an additional 30-day period
  • Fraud, chargeback or security-incident evidence: 12 months after the case closes
  • Ordinary support correspondence: 3 years after the matter closes
  • Terms, price, payment, Delivery and deletion evidence without source files: 6 years after the later of payment, Delivery, cancellation or refund
  • Invoices and Polish tax records: Applicable Polish statutory tax period
  • Structured invoice in KSeF: 10 years from the end of the year in which the invoice was issued

For the KSeF entry above, the official Polish Ministry of Finance source states that a structured invoice is stored in KSeF for 10 years from the end of the year in which it was issued: KSeF — Zasady obowiązywania KSeF i przepisy prawne.

The exact expiry timestamp applicable to an active Job will be displayed in the Application. Unless stated otherwise, timestamps are calculated in Coordinated Universal Time (UTC).

10. Deletion, backups, and preservation exceptions

When an active period expires, protected access ends and credentials are invalidated. The Application automatically deletes the relevant source files, temporary payloads, mappings, intermediate files, generated files, ZIPs and other temporary Job content from the active environment within the 24-hour deletion window stated above. Merely hiding content is not deletion. Where a valid preservation exception applies, only the necessary data remains under restricted processing until the purpose ends, after which deletion resumes. A deletion event may be recorded without retaining the deleted content.

Deletion from active systems does not remove every encrypted backup remnant at the same moment. Backup remnants are not used for ordinary customer recovery. If a backup is restored for disaster recovery, the applicable deletion markers, access restrictions and expiry controls must be reapplied.

We may preserve a limited, relevant portion of data beyond the ordinary period where reasonably necessary to comply with law or binding legal process, investigate fraud or a security incident, handle a chargeback or documented dispute, establish or defend a legal claim, or enforce the Application Terms. Preserved data will be restricted from ordinary processing, retained only for the applicable purpose, and deleted when that purpose and any mandatory period end.

Expiry or deletion does not waive, shorten or condition a statutory withdrawal, conformity, refund, complaint or chargeback right. If a timely claim remains available after temporary content was deleted, Poland Documents will not reject it solely because of that deletion. Reasonable and lawful resubmission may be requested; if a conforming remedy cannot be supplied, the applicable price-reduction or refund remedy remains available. Following a valid consumer withdrawal, qualifying non-personal content will be handled and, on request, made available as required by mandatory law before final deletion.

Service providers acting as our processors retain and delete personal data under our documented instructions and applicable data-processing terms, except where law requires otherwise. Stripe, banks, card networks, KSeF, and public authorities may also process particular records as independent controllers under their own legal obligations and retention periods. This Schedule does not control records retained independently by those recipients.

Payment-card data is processed by the identified payment provider. Poland Documents does not receive or store complete payment-card numbers or card security codes.

11. Purchaser responsibilities

The Purchaser must:

  • download and open the paid results before the displayed expiry;
  • verify that every promised file is present, readable and appropriate for the intended submission;
  • report a delivery or access problem promptly while the Job still exists;
  • maintain independent authoritative source records, certificates, reports and other supporting evidence;
  • store required downloaded results securely;
  • avoid prohibited sensitive data that the Application does not expressly request; and
  • for a business or professional Job, apply the Purchaser’s own legal and business retention requirements.

Expiration or deletion of a Job does not remove any legal duty that applies to a Business User to retain certificates, test records, source evidence, customs records or other required business documentation. A Protected Customer is responsible only to the extent required by applicable law and the stated use of the Output Package. Failure to download promptly does not remove a non-waivable remedy where access, delivery or conformity failed. Once temporary Job content has been deleted, recovery or regeneration may require lawful resubmission or a new Job.

12. Changes to pricing, limits, and retention periods

We may change this Schedule prospectively to reflect changes in the Application, infrastructure, security risks, official requirements, law, providers, taxes, or operational costs. The current version and date will be posted with the Application.

The pricing version and transaction-specific conditions accepted for a paid Job govern that Job. We will not retroactively increase its confirmed charge, shorten its Displayed Availability Period, extend retention of uploaded content or reduce a Consumer right merely by posting a revised Schedule. A new or materially changed Job may require acceptance of a later version.

Posting a revised Schedule will not retroactively shorten an active Working Period, Displayed Availability Period or deletion deadline. Immediate isolation or deletion may occur where reasonably necessary for a security, fraud, legal or integrity reason. If that prevents conforming Delivery after payment, the Refund & Delivery Policy applies. Extending retention of existing uploaded content requires a documented lawful basis and, where applicable, the Purchaser’s express agreement or instruction.

For transaction evidence, we may retain a reproducible record of the purchase route, accepted document versions, exact control text and hashes, affirmative events, Job ID, verified email, UTC timestamps, selected count, tier calculation, ruleset, currency, subtotal, tax, total, payment reference, durable-confirmation hash and send or bounce status, Delivery, access, withdrawal, complaint, refund and deletion events. This evidence is retained without keeping complete uploaded files, active tokens or the Output Package beyond their temporary periods.

Where an urgent security, legal, regulatory, or integrity issue requires immediate action, we may suspend processing or protected access as permitted by the Application Terms. If that action prevents conforming delivery after payment, the applicable replacement or refund remedy remains available.

The controlled companion machine-readable file is DOCUMENT_AUTHORITY_CONFIG_CPSC_R2.json, version R2, SHA-256 607e3b0ab0dff75fc4505d9e94a00567bf1bf044edf2330e4b205853d727aaf7. The DOCX and JSON must carry the same authority version. Any mismatch blocks release and implementation pending reconciliation; neither file may silently override the other.

13. Operator and contact

Legal operator, seller, contracting party and service provider:
Natallia Vasilyeva, carrying on business as
NATALLIA VASILYEVA – Poland Documents

Business form: Sole proprietor registered in the Republic of Poland; active VAT payer
Public brand and client-facing platform: Registry Intelligence
Product relationship: CPSC eFiling CSV Checker & Builder is a distinct Registry Intelligence product; the Application may use the Registry Intelligence brand and is technically isolated from city modules and unrelated application runtimes
NIP: 9512533744
REGON: 521062093
Business and correspondence address: ul. Ogrodowa 58, lok. 29, 00-876 Warszawa, Poland — owner-confirmed and Business Plus verified
Email: inbox@polandoc.com
Telephone: +48 501 335 073
Website: https://polandoc.com/

For a pricing, billing, limit, retention, deletion or delivery request, include the Job ID and a factual description. A payment reference may be provided for a billing or refund inquiry only. It cannot authenticate the Purchaser, authorize a change of verified email, restore access or authorize disclosure or delivery of Job files. Do not send complete payment-card details, passwords, authentication secrets or unnecessary sensitive information.