Skip to main content

GDPR and data protection at Certify

How Certify handles personal data for the organisations that issue credentials: controller and processor roles, storage, sub-processors and DPAs.

This article is for organisations that issue credentials through Certify. If you are a recipient, see My data privacy & "right to be forgotten".

Who is responsible for what

When you issue credentials through Certify, you decide whose data is used and why. That makes your organisation the data controller for your recipients' personal data. Certify processes that data on your behalf and on your instructions, which makes us the data processor.

We comply with UK GDPR and the Data Protection Act 2018, EU GDPR, and Brazil's LGPD.

Where your data is stored

Certify's data is hosted by Digital Ocean in SOC2-certified data centres, with servers in the EU and the US. Where personal data is transferred internationally, we rely on recognised safeguards such as standard contractual clauses.

Who else handles your data

We use a small number of trusted suppliers (sub-processors) to run our service: for hosting and backups, and for the tools we use to email customers and recipients and to answer support requests. Each one is under contract to protect personal data to the same standard we do, and we never sell personal data.

Data Processing Agreement

If your organisation needs a Data Processing Agreement, for example as part of a procurement process, please contact us.

Supporting your own GDPR obligations

  • Access and portability: you can export your credential data from your account.

  • Deletion: you can delete credentials, and you can ask us to remove data at any time.

  • Recipient requests: if a recipient asks for their data to be deleted, they will be directed to you first, as the data controller.

More information

Did this answer your question?