CPA Attest Inc. logo CPA ATTEST INC. PORTAL LOGIN
CPA ATTEST / PRIVACY POLICY

Privacy, handled with confidence.

This Privacy Policy explains how CPA Attest Inc. collects, uses, discloses, protects and retains information through its website, client portal, consultation process and professional services.

Effective Date · August 26, 2026
Important: This Privacy Policy is designed to address GDPR, HIPAA and CCPA/CPRA considerations where they are legally applicable. Applicability depends on the company, client relationship, information processed, jurisdiction and actual data practices. This document should be reviewed by qualified legal counsel before publication as the company's final legal policy.
GDPREuropean data protection, transparency, lawful processing and data-subject rights where applicable.
CCPA / CPRACalifornia privacy disclosures and consumer rights where applicable.
HIPAAProtected health information safeguards where CPA Attest acts in a qualifying HIPAA role.

1. Scope

This Privacy Policy applies to personal information processed through the CPA Attest website, contact and consultation forms, client portal, engagement communications and related services.

It should be read together with applicable engagement letters, confidentiality provisions, data-processing agreements and, where applicable, a HIPAA Business Associate Agreement (BAA).

2. Information We Collect

Depending on how you interact with CPA Attest, we may collect:

3. How We Use Information

We may use information to provide and administer professional services; respond to inquiries; manage engagements and evidence; authenticate users; communicate about projects and billing; maintain security; prevent fraud; troubleshoot and improve the website; comply with legal obligations; enforce agreements; and protect our rights and the rights of users.

4. GDPR and European Data Protection

4.1 Applicability

Where the General Data Protection Regulation (GDPR) applies to CPA Attest's processing of personal data, CPA Attest will process personal data in accordance with applicable GDPR requirements.

4.2 Lawful Bases

Depending on the circumstances, lawful bases may include performance of a contract, taking steps at an individual's request before entering a contract, compliance with a legal obligation, legitimate interests, or consent where consent is required.

4.3 Data Minimization and Purpose Limitation

CPA Attest seeks to collect information that is reasonably relevant to the purpose for which it is processed and will not intentionally use personal data for materially incompatible purposes without an appropriate legal basis.

4.4 GDPR Rights

Where GDPR applies, individuals may have rights including access, rectification, erasure, restriction of processing, data portability and objection to certain processing. Individuals may also withdraw consent where consent is the applicable legal basis.

Requests may be submitted using the contact information in this policy. CPA Attest may request information reasonably necessary to verify the identity of the requester and may apply lawful exceptions or limitations.

5. Privacy Rights and Requests

Depending on applicable law, you may have rights to access, correct, delete, restrict or object to processing, receive a portable copy of certain data, withdraw consent, or submit a complaint to a relevant supervisory authority.

To submit a privacy request, email [email protected] with the subject line “Privacy Request.” Please identify the jurisdiction and type of request where possible.

CPA Attest may need to verify your identity before completing a request. Certain rights may be subject to statutory exceptions, legal obligations, security requirements, legal privilege or the rights of other individuals.

6. California Privacy — CCPA / CPRA

6.1 California Privacy Rights

Where the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), applies, California residents may have rights concerning the categories and purposes of personal information collected, access/know, deletion, correction, and certain rights concerning the sale or sharing of personal information.

6.2 Sensitive Personal Information

Where applicable, California law provides additional protections concerning certain categories of sensitive personal information. CPA Attest will handle qualifying requests and limitations in accordance with applicable law.

6.3 No Discrimination

Where the CCPA applies, CPA Attest will not unlawfully discriminate against a consumer for exercising rights provided by applicable California privacy law.

6.4 California Requests

California residents may submit a request by emailing [email protected] with “California Privacy Request” in the subject line.

CPA Attest may use reasonable verification procedures and may deny or limit a request where an exception permitted by law applies.

The CCPA applies only when its statutory applicability requirements and thresholds are met. This Privacy Policy does not by itself state that CPA Attest is a covered California “business” for every CCPA obligation.

7. HIPAA and Protected Health Information

7.1 When HIPAA Applies

The Health Insurance Portability and Accountability Act (HIPAA) applies to covered entities and business associates in qualifying circumstances. Not all health-related information is automatically subject to HIPAA.

7.2 Business Associate Relationships

If CPA Attest acts as a business associate for a HIPAA covered entity, the parties may enter into a Business Associate Agreement governing permitted uses and disclosures, safeguards, breach reporting and other applicable HIPAA requirements.

7.3 Protected Health Information

Where HIPAA applies, protected health information (PHI) will be handled only for permitted purposes and subject to applicable contractual, administrative, technical and physical safeguards.

7.4 Secure Submission

Do not submit PHI through a general public website form unless CPA Attest has specifically instructed you to do so through an approved secure channel. Use the designated client portal or other secure transfer method provided for your engagement.

A public privacy policy does not replace a HIPAA Business Associate Agreement, security documentation, breach-notification procedures or any Notice of Privacy Practices applicable to a covered entity.

8. Disclosure and Service Providers

CPA Attest may disclose information to personnel and professional advisers who need it to perform services; hosting, security, authentication, communications, payment and other service providers; auditors or professional advisers; regulators or law enforcement where legally required; and parties involved in a corporate transaction, subject to applicable confidentiality and legal requirements.

Service providers are expected to process information only for authorized purposes and under appropriate contractual, organizational or technical controls.

9. Security

CPA Attest uses administrative, technical and physical safeguards appropriate to the nature of information handled. Depending on the system, controls may include access controls, authentication, encryption in transit, logging, least-privilege practices, secure configuration and incident-response processes.

No internet transmission or storage system can be guaranteed to be completely secure. Clients should use the secure portal or specifically approved transfer mechanisms for engagement evidence.

10. Data Retention

CPA Attest retains information for as long as reasonably necessary for the purpose collected, to perform services, maintain professional and business records, satisfy contractual and legal obligations, resolve disputes, enforce agreements and protect legitimate interests.

Retention periods may vary according to the type of information, engagement, contractual requirements and applicable law.

11. International Data Transfers

Because CPA Attest may serve clients internationally, information may be processed in jurisdictions outside an individual's home country.

Where GDPR or another data-transfer regime applies, CPA Attest will use an applicable lawful transfer mechanism and appropriate safeguards as required by law.

12. Cookies and Analytics

The website may use cookies or similar technologies for essential operation, security, preferences, analytics and other permitted purposes. Where required by applicable law, consent mechanisms may be used before deploying non-essential technologies.

Specific cookies and third-party analytics tools may change as the website and technology stack evolves. Users should review any cookie preference controls presented on the website.

13. Children

The CPA Attest website and professional services are intended for businesses and professional users and are not directed to children. CPA Attest does not knowingly collect personal information from children in violation of applicable law.

14. Changes to This Privacy Policy

CPA Attest may update this Privacy Policy when services, technology, legal obligations or privacy practices change. The Effective Date above identifies the current version.

Material changes may be communicated through the website or other appropriate channels where required by applicable law.

15. Contact

For privacy questions, data-subject requests or California privacy requests:

CPA Attest Inc.
New York, NY
Email: [email protected]
Phone: +1 (917) 590-4334

Regulatory Resources

Last updated: August 26, 2026