Agency Connect Policy
Effective Date: July 13, 2026
CPR Enroll Agency Connect
A Product of ResQWare LLC
Last Updated: July 23, 2026
Contents
- 1. Introduction & Scope
- 2. Definitions & Roles
- 3. Information the Extension Accesses
- 4. How Information Is Used
- 5. Browser Permissions & Why They Are Needed
- 6. Human Review Before Irreversible Actions
- 7. Data Security
- 8. Data Retention & Device Removal
- 9. Sharing & Disclosure
- 10. Your Privacy Rights
- 11. Children's Privacy
- 12. Changes to This Policy
- 13. Contact Us
Scope: This policy covers the CPR Enroll Agency Connect Chrome extension only. Data held in your CPR Enroll account is governed by our main Privacy Policy, and should be read alongside our Terms of Service at https://cprenroll.com/terms/.
1. Introduction & Scope
ResQWare LLC ("We", "Us", "Our") publishes CPR Enroll Agency Connect ("the extension"), a Chrome extension provided to CPR Enroll customers. It helps you enter your own class and roster data into your certification body's web portal — HSI/OTIS today, with the American Heart Association and American Red Cross planned.
The extension is a conduit. It moves data you already hold in your CPR Enroll account into a portal you are already logged in to. It does not originate, enrich, or retain that data.
- Source
Your CPR Enroll account
You start a run. Only the class and roster details needed for that step are sent to your browser, and only when you ask for them.
- This extension
Agency Connect, in your browser
Fills the portal form with real keystrokes and clicks. Nothing here is uploaded anywhere else.
- Kept on this device: device token, API address, run status.
- Never stored: student names, emails, or any roster field.
- Destination
Your certification portal
The data lands in the portal account you already hold. What happens to it there is governed by that provider's own privacy policy.
2. Definitions & Roles
You / the customer — the CPR Enroll account holder, usually a training centre or instructor, who installs and runs the extension.
Roster data — the class and student details you already maintain in CPR Enroll: names, email addresses, course and session details, and similar enrolment fields.
Portal — the third-party certification body website the extension fills in on your behalf, such as HSI/OTIS at *.osmanager4.com.
A run — one operator-initiated task: the extension opens or attaches to a portal tab, fills a defined set of fields, and stops.
For roster data, you are the controller and we act as your processor. You decide what is submitted, to which portal, and when. We do not use roster data for any purpose of our own.
3. Information the Extension Accesses
| Category | What it is and where it goes |
|---|---|
| Device token | Issued once when you pair the extension with a one-time code. Stored on your device. Our server keeps only a one-way hash of it, never the token itself. |
| Run status | Which step of a run is in progress, so the extension can resume if the browser suspends it. Field values are not included. |
| API address | The CPR Enroll endpoint the extension polls for pending work. |
| Roster data | Held in memory only for the duration of a run, then discarded. Never written to browser storage, never sent to us, never sent anywhere except the portal you targeted. |
| Portal credentials | Not accessed. You log in to the portal yourself, in your own browser session. The extension neither reads nor stores your username or password. |
| Browsing activity | Not collected. The extension activates only on the portal domains listed in its manifest, and only during a run you started. |
We do not sell data, and we do not use any of the above for advertising, profiling, or resale.
4. How Information Is Used
Each category above is used for one purpose and no other:
- The device token authenticates this browser to your CPR Enroll account so the extension can collect work assigned to you.
- Run status lets an interrupted run pick up where it left off instead of restarting.
- Roster data is typed into the portal form fields you asked it to fill, then released from memory.
There is no analytics SDK, no telemetry beacon, and no third-party script inside the extension.
5. Browser Permissions & Why They Are Needed
Chrome asks you to approve a permission list at install time. Here is what each one is for, in plain terms.
| Permission | Why it is requested |
|---|---|
storage | To keep the device token, API address, and run status on your machine. Roster data is never written here. |
alarms | To check CPR Enroll on an interval for work you have queued. This is a pull on a timer, not a live connection. |
tabs | To find or open the portal tab a run applies to. |
scripting | To read the portal form's structure so the right value goes in the right field. |
debugger | The most sensitive permission on this list, so it deserves a direct explanation. Portal form controls ignore synthetic events, so ordinary scripted input silently fails or saves blank records. The extension uses the debugger interface to dispatch genuine keyboard and mouse input instead. Chrome displays a visible banner across the top of the tab for the entire time it is attached, and the extension detaches as soon as the run ends. |
| Host access | Limited to the certification portal domains and your CPR Enroll instance. The extension does not run on other sites. |
6. Human Review Before Irreversible Actions
The extension fills forms. It does not finish them.
Before any button that commits, charges, or notifies — Submit, Create, Assign, Pay — the run stops and hands control back to you. You read what was entered and you click it yourself, or you correct it first, or you close the tab and nothing happens at all.
This is deliberate. It keeps a person accountable for every record that reaches a certification body, and it means a mistake in the data is caught before it becomes a certificate.
7. Data Security
- All communication between the extension and CPR Enroll runs over HTTPS.
- The device token is stored on your device; our servers retain only a one-way hash, so a breach of our database does not yield working tokens.
- Roster data exists only in browser memory during a run and is never persisted to disk by the extension.
- The debugger session is scoped to the single portal tab in use and is detached when the run finishes.
No system is perfectly secure. If a breach affects your data, we will notify you and any authority required by applicable law, without undue delay.
8. Data Retention & Device Removal
Roster data is retained for the length of a run — seconds to minutes — and then discarded. It is never archived.
The device token and run status stay on your device until you revoke or uninstall. To remove the extension's access:
- Revoke the device from your CPR Enroll account settings. The token stops working immediately, on that device only.
- Uninstall the extension from
chrome://extensions. Chrome deletes its local storage, including the token, run status, and API address.
Records already submitted to a certification portal are held by that provider and are subject to their retention policy, not ours. Removing the extension does not withdraw them.
9. Sharing & Disclosure
We do not sell, rent, or trade personal information, and we do not share it with advertisers or data brokers.
Roster data goes to exactly one destination: the certification portal you directed the run at. That transfer is initiated by you and the portal's own privacy policy governs the data once it arrives.
We may disclose information where required by law, valid legal process, or to protect the rights and safety of our users. If we are ever acquired or merged, any information involved would remain subject to this policy or a successor giving equivalent protection, and we would tell you before that change takes effect.
10. Your Privacy Rights
Depending on where you live, you may have the right to access, correct, delete, or export personal information we hold, to object to or restrict certain processing, and to be free from discrimination for exercising any of these rights.
Because the extension retains almost nothing, most requests concern data in your CPR Enroll account rather than the extension itself. Write to support@cprenroll.com and we will respond within the period the applicable law requires.
Where you are the controller of the roster data and a student contacts us directly, we will refer that person to you and support you in responding.
11. Children's Privacy
The extension is a business tool. It is not directed at children, and we do not knowingly collect personal information directly from anyone under 13.
Rosters you process may include minors enrolled in a course. That data is yours as the controller: you are responsible for holding the consent required to enter a minor's details into a certification portal. The extension passes those fields through without storing them.
12. Changes to This Policy
We may revise this policy as the extension adds portals or capabilities. When we do, the revised version is posted at this address with an updated effective date. Material changes will also be announced inside your CPR Enroll account before they take effect.
This policy is effective as of July 23, 2026. Continuing to use the extension after a revision takes effect means you accept the updated terms.
13. Contact Us
Questions about this policy, or about how the extension handles data, go to:
- Entity
- ResQWare LLC
- Product
- CPR Enroll Agency Connect
- Support
- support@cprenroll.com
- General
- hello@cprenroll.com