Last updated: February 2026
This Data Protection Notice applies to the processing of personal data by Certifyd Inc. ("Certifyd," "we," "us," or "our") in connection with our digital certificate and badge management platform, website at certifyd.cloud, and all related services (the "Service"). This notice is intended to provide transparency about our data protection practices and to inform individuals of their rights under the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK General Data Protection Regulation ("UK GDPR"), and other applicable data protection legislation.
This notice applies to the personal data of all individuals whose data we process, including:
This notice should be read in conjunction with our Privacy Policy, Terms of Service, and Cookie Policy.
For the purposes of the GDPR and applicable data protection laws, the data controller responsible for the processing of your personal data is:
Company: Certifyd Inc.
Address: 123 Innovation Drive, Suite 400, San Francisco, CA 94105, United States
Email: support@certifyd.cloud
When organizations use Certifyd to issue digital certificates and badges, the organization acts as the data controller with respect to the personal data of their certificate recipients, and Certifyd acts as a data processor processing data on behalf of the organization. In this capacity, Certifyd processes personal data only in accordance with the organization's instructions and the terms of our Data Processing Agreement.
Certifyd acts as a data controller for data collected directly from individuals, such as account registration data, website visitor data, and data collected through direct communications with our support team.
We process personal data only when we have a valid legal basis to do so under the GDPR. The legal bases we rely on include:
We process personal data when it is necessary to perform our contractual obligations to you, including providing the Service, managing your account, processing subscription payments, issuing and delivering digital certificates and badges, and providing customer support. This legal basis applies to account holders and organizational administrators who have agreed to our Terms of Service.
We process personal data when it is necessary for our legitimate interests or the legitimate interests of a third party, provided that such interests are not overridden by your fundamental rights and freedoms. Our legitimate interests include: improving and optimizing the Service; ensuring the security and integrity of the platform; detecting and preventing fraud and abuse; conducting analytics to understand user behavior and improve user experience; and communicating with users about service updates and relevant information.
In certain cases, we process personal data based on your freely given, specific, informed, and unambiguous consent. This includes the use of non-essential cookies (analytics, performance, and preference cookies), sending marketing communications, and processing data for specific purposes that go beyond what is necessary for the performance of the contract. You have the right to withdraw your consent at any time without affecting the lawfulness of processing carried out before the withdrawal.
We process personal data when it is necessary to comply with a legal obligation to which Certifyd is subject, such as tax and accounting requirements, responding to lawful requests from law enforcement or regulatory authorities, and fulfilling data protection obligations.
We process the following categories of personal data in connection with the Service:
We carry out the following data processing activities in connection with the Service:
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law. The specific retention periods for different categories of data are as follows:
| Data Category | Retention Period | Justification |
|---|---|---|
| Account & Identity Data | Duration of account + 12 months | Contractual obligation; transition period for data export |
| Certificate & Badge Data | Duration of issuer account + 24 months | Ongoing verification needs; contractual obligation to issuers |
| Financial & Billing Data | 7 years from transaction date | Tax and accounting legal requirements |
| Usage & Analytics Data | 26 months from collection | Legitimate interest in service improvement; anonymized thereafter |
| Technical & Log Data | 90 days from collection | Security monitoring and incident investigation |
| Support Communications | 36 months from last interaction | Service quality; dispute resolution |
| Cookie Consent Records | 12 months from consent date | GDPR compliance; proof of consent |
| Marketing Consent Records | Duration of consent + 36 months | Regulatory compliance; proof of consent and withdrawal |
After the applicable retention period expires, personal data is either securely deleted or irreversibly anonymized so that it can no longer be used to identify an individual. Anonymized data may be retained indefinitely for statistical and analytical purposes.
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, you have the following rights under the GDPR and applicable data protection laws with respect to your personal data:
You have the right to obtain confirmation as to whether we are processing your personal data and, if so, to access that data along with information about the purposes of processing, the categories of data concerned, the recipients or categories of recipients, the retention period, and the existence of your other rights. You may request a copy of the personal data we hold about you, which will be provided free of charge. Additional copies may be subject to a reasonable fee.
You have the right to request the correction of inaccurate personal data we hold about you and to have incomplete personal data completed. We will take reasonable steps to verify the accuracy of the corrected data and update our records accordingly.
You have the right to request the deletion of your personal data in certain circumstances, including when the data is no longer necessary for the purposes for which it was collected, when you withdraw consent and there is no other legal basis for processing, when you object to processing and there are no overriding legitimate grounds, when the data has been unlawfully processed, or when erasure is required for compliance with a legal obligation. Please note that this right is not absolute, and we may be required to retain certain data for legal, contractual, or legitimate business reasons.
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data, when processing is unlawful and you oppose erasure, when we no longer need the data but you require it for legal claims, or when you have objected to processing pending verification of whether our legitimate grounds override your interests.
You have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, and to transmit that data to another controller without hindrance from us, where the processing is based on consent or the performance of a contract and is carried out by automated means. Upon request, we will provide your data in JSON or CSV format.
You have the right to object to the processing of your personal data where processing is based on our legitimate interests or is carried out for direct marketing purposes. Where you object to processing for direct marketing, we will cease such processing immediately. Where you object to processing based on legitimate interests, we will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defense of legal claims.
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. Certifyd does not currently engage in solely automated decision-making that produces legal or similarly significant effects on individuals. If this changes in the future, we will update this notice and provide appropriate safeguards, including the right to obtain human intervention, to express your point of view, and to contest the decision.
To exercise any of the rights described above, you may submit a request by contacting us at support@certifyd.cloud with the subject line "Data Protection Rights Request." Please include the following information in your request:
We will acknowledge receipt of your request within 5 business days and will respond substantively within 30 days of receipt. In complex cases, or where we receive a high volume of requests, we may extend the response period by an additional 60 days, in which case we will inform you of the extension and the reasons for it within the initial 30-day period.
We may need to verify your identity before processing your request to prevent unauthorized access to personal data. We will not charge a fee for processing your request unless it is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to act on the request.
Certifyd is headquartered in the United States, and our primary data processing infrastructure is located in the United States. When personal data is transferred from the EEA, the United Kingdom, or Switzerland to the United States or other countries outside those regions, we ensure that appropriate safeguards are in place to protect your data in compliance with the GDPR.
The safeguards we rely on for international data transfers include:
You may request a copy of the appropriate safeguards we have implemented for international data transfers by contacting us at support@certifyd.cloud.
When Certifyd processes personal data on behalf of organizations (our customers) as a data processor, we enter into Data Processing Agreements ("DPAs") that comply with the requirements of Article 28 of the GDPR. Our DPAs set forth the subject matter and duration of the processing, the nature and purpose of the processing, the types of personal data processed, and the categories of data subjects.
Our standard DPA includes commitments to:
Organizations that require a DPA may request one by contacting us at support@certifyd.cloud.
Certifyd engages third-party sub-processors to assist in providing the Service. Each sub-processor is bound by contractual obligations that are consistent with the GDPR and our Data Processing Agreements. We conduct due diligence on all sub-processors to ensure they provide sufficient guarantees regarding data protection.
Our current sub-processors include:
| Sub-processor | Purpose | Location |
|---|---|---|
| Microsoft Azure | Cloud infrastructure and hosting | United States |
| Stripe | Payment processing | United States |
| SendGrid | Email delivery (certificate notifications) | United States |
| Google Analytics | Website analytics | United States |
We will notify customers of any intended changes to our sub-processors (additions or replacements) by providing at least 30 days' advance notice. If you have concerns about a new sub-processor, you may object by contacting us within the notice period. We will work with you in good faith to address your concerns or, if the concerns cannot be resolved, provide you with the option to terminate the affected services.
Certifyd maintains comprehensive incident response procedures to detect, investigate, and respond to personal data breaches. In the event of a personal data breach, we will comply with the notification requirements under the GDPR and other applicable data protection laws.
Notification to Supervisory Authorities: Where a personal data breach is likely to result in a risk to the rights and freedoms of natural persons, Certifyd will notify the relevant supervisory authority without undue delay, and where feasible, within 72 hours of becoming aware of the breach, in accordance with Article 33 of the GDPR.
Notification to Data Subjects: Where a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, Certifyd will communicate the breach to affected individuals without undue delay, in accordance with Article 34 of the GDPR, unless appropriate technical or organizational protective measures have been applied that render the personal data unintelligible to unauthorized persons.
Notification to Data Controllers: Where Certifyd is acting as a data processor on behalf of an organization, we will notify the organization (data controller) of a personal data breach without undue delay after becoming aware of it, and will provide sufficient information to enable the organization to meet its own breach notification obligations.
The Service is not directed to children under the age of 16, and we do not knowingly collect personal data from children under 16. Where the Service is used by organizations to issue certificates to individuals under the age of 16 (for example, in an educational context), the organization is responsible for ensuring that parental or guardian consent has been obtained in accordance with Article 8 of the GDPR and applicable national laws.
If we become aware that personal data has been collected from a child under the age of 16 without appropriate parental or guardian consent, we will take steps to delete the data as soon as possible. If you believe that a child under 16 has provided us with personal data without appropriate consent, please contact us at support@certifyd.cloud.
Certifyd has designated a Data Protection Officer (DPO) to oversee our data protection practices and ensure compliance with the GDPR and other applicable data protection laws. You may contact our DPO for any inquiries related to data protection, privacy, or the exercise of your rights.
Data Protection Officer
Email: support@certifyd.cloud
Company: Certifyd Inc.
Address: 123 Innovation Drive, Suite 400, San Francisco, CA 94105, United States
If you are located in the European Economic Area or the United Kingdom, you have the right to lodge a complaint with a supervisory authority if you believe that our processing of your personal data violates the GDPR or other applicable data protection legislation.
You may lodge a complaint with the supervisory authority in the EU Member State of your habitual residence, your place of work, or the place of the alleged infringement. A list of EU Data Protection Authorities and their contact information can be found on the European Data Protection Board website.
For complaints from the United Kingdom, you may contact the Information Commissioner's Office (ICO) at ico.org.uk. While you have the right to lodge a complaint with a supervisory authority at any time, we encourage you to contact us first so that we may address your concerns directly.
We may update this Data Protection Notice from time to time to reflect changes in our data processing practices, changes in applicable law, or other factors. When we make material changes to this notice, we will update the "Last updated" date at the top of this page and, where required by the GDPR, notify affected individuals by email or through a prominent notice on the Service.
We encourage you to review this notice periodically to stay informed about our data protection practices. Your continued use of the Service after the publication of any changes to this notice constitutes your acknowledgment of those changes.
If you have any questions about this Data Protection Notice, our data processing practices, or if you wish to exercise your data protection rights, please contact us:
Email: support@certifyd.cloud
Sales: sales@certifyd.cloud
Company: Certifyd Inc.
Address: 123 Innovation Drive, Suite 400, San Francisco, CA 94105, United States
We aim to respond to all data protection inquiries within 30 days of receipt. For urgent data protection matters, please include "URGENT" in the subject line of your email.
Join thousands of organizations using Certifyd
Get Started Free