This article is for organisations that issue credentials through Certify. If you are a recipient, see My data privacy & "right to be forgotten".
Who is responsible for what
When you issue credentials through Certify, you decide whose data is used and why. That makes your organisation the data controller for your recipients' personal data. Certify processes that data on your behalf and on your instructions, which makes us the data processor.
We comply with UK GDPR and the Data Protection Act 2018, EU GDPR, and Brazil's LGPD.
Where your data is stored
Certify's data is hosted by Digital Ocean in SOC2-certified data centres, with servers in the EU and the US. Where personal data is transferred internationally, we rely on recognised safeguards such as standard contractual clauses.
Who else handles your data
We use a small number of trusted suppliers (sub-processors) to run our service: for hosting and backups, and for the tools we use to email customers and recipients and to answer support requests. Each one is under contract to protect personal data to the same standard we do, and we never sell personal data.
Data Processing Agreement
If your organisation needs a Data Processing Agreement, for example as part of a procurement process, please contact us.
Supporting your own GDPR obligations
Access and portability: you can export your credential data from your account.
Deletion: you can delete credentials, and you can ask us to remove data at any time.
Recipient requests: if a recipient asks for their data to be deleted, they will be directed to you first, as the data controller.
More information
The UK Information Commissioner's Office has guidance on data protection for organisations.
