Certify Skills Limited t/a Certify ("Certify", "we", "us" or "our") is committed to respecting your privacy. This policy explains what personal data we collect, why we use it, who we share it with, and the rights you have. It applies to our website at https://www.certify.one and the services we provide.

1. Who we are

Certify Skills Limited t/a Certify is the organisation responsible for the personal data described in this policy. We are a company registered in England and Wales, company number 11369436, with our registered office at 7 Bell Yard, London, WC2A 2JR. We are registered with the Information Commissioner's Office under registration number ZB949024.

We process personal data in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Where we process the personal data of people in the European Union, the EU General Data Protection Regulation (EU GDPR) also applies.

2. Controller and processor

In the course of providing our services, we deal with two types of user:

  • Issuers, our customers, such as training organisations, associations and schools, who use our services to issue digital badges, certificates and credentials ("Credentials").
  • Recipients, the people who receive, manage and display those Credentials.

When an Issuer uses our services to issue a Credential to a Recipient, we process the Recipient data the Issuer provides solely on the Issuer's behalf and on their instructions. For that data we act as the Issuer's processor, and our processing is governed by our contract with the Issuer, not by this policy. Questions about that data should be directed to the relevant Issuer.

We act as controller for the data we collect from Issuers, and for the profile data of Recipients who choose to create a credential profile with us.

3. Information we collect

We collect information you provide to us and information collected automatically when you use the site.

Log and device data. When you visit the site, our servers may log standard technical data such as your IP address, browser type and version, the pages you visit, the time and date of your visit, and details about your device, operating system, settings and approximate location. If you encounter an error, we may collect technical data about that error.

Account creation (Issuers). When you create an Issuer account we may collect your username, first and last name, email address and password, contact phone number, the name and URL of your organisation, how many Recipients you expect to issue Credentials to in a year, your job title, and referral information.

Issuing credentials. To issue Credentials, an Issuer uploads the name and email address of each Recipient and the issue date for each Credential. An Issuer may also add an expiry date or, in Brazil, a CPF number as part of a Credential.

Your credential account and wallet (Recipients). When you receive a Credential, we create an account using the email address and name provided by the Issuer. You can edit these fields, or add a password, avatar image, LinkedIn Profile URL, and X (Twitter) URL. In your account settings you can choose whether to make your credential wallet public and adjust the privacy settings of each Credential.

Sharing credentials. If you add a Credential to LinkedIn, you log in to LinkedIn using your own credentials, which we do not store. You can also share a Credential to other networks or send it to someone by email, in which case we collect the recipient's email address.

Purchases (Issuers). We collect details associated with your purchases, including billing details. Card payments are handled by our payment processors. We do not collect or store full payment card details entered through our services.

Your communications with us. We collect the personal data you give us when you request information, sign up to our newsletter, ask for support, apply for a job, or otherwise contact us.

Surveys, events and business development. We may collect personal data when you take part in a survey, when we meet you at an event, and when we assess potential business opportunities.

Website and platform analytics. On our website we use GoSquared to count visits and see which pages people use, as described in the Cookies section and our Cookie Policy. The Certify platform uses the analytics and support tools listed in section 5.

4. Why we use your data and our lawful basis

We only use your personal data where we have a lawful basis to do so. The table below sets out the main purposes, the data involved, and the lawful basis for each.

Purpose Data Lawful basis
Providing the services to Issuers Issuer account and usage data Performance of a contract
Processing Recipient data for Issuers Recipient data an Issuer uploads Processed as the Issuer's processor, on the Issuer's instructions (the Issuer determines the lawful basis)
Running Recipient credential profiles Recipient profile and wallet data Performance of a contract, and our legitimate interests in operating the credential wallet
Billing and payments Issuer billing and payment details Performance of a contract, and legal obligation (tax and accounting)
Customer support Your contact details and correspondence Our legitimate interests in helping users and improving the services
B2B marketing emails Business contact details Our legitimate interests, with an opt-out in every message
Website usage statistics on www.certify.one (GoSquared) Cookie and usage data, with IP addresses anonymised Visitors outside the EU and EEA: legitimate interests, relying on the PECR exemption for statistical cookies; you can switch it off at any time via Cookie settings. Visitors in the EU or EEA: consent, given through the cookie banner or Cookie settings
Applying the right cookie rules for where you are, on www.certify.one The country detected from your IP address when you visit; only whether you are inside or outside the EU and EEA is kept Our legitimate interests in following the cookie rules that apply to you
Analytics and marketing tools on the Certify platform (app.certify.one) Cookie and usage data Consent, where these tools use cookies that are not strictly necessary
Security and fraud prevention Account, device and log data Our legitimate interests in keeping the services secure
Legal compliance Relevant personal data Legal obligation

Where we rely on legitimate interests, we have considered your interests, rights and freedoms, and you can object at any time (see Your rights). Where we rely on consent, you can withdraw it at any time without affecting processing that has already taken place.

5. Who we share it with

We share personal data with service providers who help us run the services. We require them to protect the data and to use it only for the purposes we specify. Our main processors are listed below, by where they are used.

Our website (www.certify.one)

  • Website usage statistics: GoSquared. Lawful basis: for visitors outside the EU and EEA, legitimate interests, relying on the PECR exemption for statistical cookies, and you can switch it off at any time via Cookie settings; for visitors in the EU or EEA, consent.

The website is hosted by Vercel, with DNS by Cloudflare. Enquiries you send through the Book a Demo form go to HubSpot, our CRM; the website does not load any HubSpot tracking.

The Certify platform (app.certify.one)

  • Hosting and infrastructure: Cloudflare (DNS and content delivery) and Digital Ocean (application hosting, in the United Kingdom).
  • Transactional email: Postmark.
  • Payments: Stripe and Chargebee.
  • Analytics, marketing and support: Google Analytics, HubSpot, Intercom, and the LinkedIn Insight Tag.

We may also share data with our professional advisers, with a party that acquires our business, and with courts, regulators or law enforcement where we are legally required to do so.

6. International transfers

Some of our processors are located outside the United Kingdom, including in the United States. Where personal data is transferred outside the UK, we rely on one of the following safeguards: UK adequacy regulations; the UK Extension to the EU-US Data Privacy Framework (the UK-US data bridge) where the receiving organisation is certified under it; or the ICO's International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses. Where personal data is transferred out of the European Economic Area (EEA), equivalent safeguards under the EU GDPR apply.

7. How long we keep it

We keep personal data only for as long as we need it. Our standard retention periods are set out below. Where a longer period is required by law, or a shorter period is appropriate, we adjust accordingly.

Data Retention period
Issuer account data 6 years
Recipient profile data after account deletion 6 years
Issued credential records 6 years
Marketing and CRM contacts 6 years
Support conversations 6 years
Billing records 6 years

Deleting a Recipient profile removes that profile within the period above. However, a Credential that an Issuer has issued may remain live and verifiable on the Issuer's instruction, because the Issuer, not Certify, controls whether an issued Credential stays valid. This is explained further in our Terms of Use.

8. Children

Our services are not aimed at children. In the United Kingdom, the age at which a child can consent to online services is 13. Where an Issuer issues Credentials to people under 18, the Issuer is responsible for having a lawful basis for that processing and for obtaining any parental or guardian consent that is required.

9. Your rights

Under UK GDPR you have the right to:

  • Access the personal data we hold about you.
  • Rectification of inaccurate or incomplete data.
  • Erasure of your data in certain circumstances.
  • Restriction of our processing in certain circumstances.
  • Objection to processing based on our legitimate interests, and to direct marketing at any time.
  • Portability of data you have provided to us, in a machine-readable format.
  • Withdraw consent at any time, where we rely on consent.

We do not make decisions that produce legal effects, or similarly significant effects, based solely on automated processing.

To exercise any of these rights, contact us using the details in the Data Protection Enquiries section. We will respond within one month. If your request is complex, we may extend this by up to a further two months, and we will let you know if we need to.

10. Complaints

If you are unhappy with how we have handled your personal data, please contact us at credential@certify.one. We will acknowledge your complaint within 30 days, investigate it, and reply without undue delay.

You also have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection, at ico.org.uk or on 0303 123 1113.

11. Cookies

Our website (www.certify.one). The website uses strictly necessary cookies and, for site statistics, GoSquared. Site statistics are on by default for visitors outside the EU and EEA, and off until you allow them if you are in the EU or EEA. To tell which applies, the website uses the country detected from your IP address and keeps only whether you are inside or outside the EU and EEA; it does not store your IP address or your country. You can change your choice at any time using the "Cookie settings" link in the footer. Our Cookie Policy lists every cookie the website sets.

The Certify platform (app.certify.one). The platform sets its own cookies, including cookies that keep you signed in and secure, and cookies used by the platform tools listed in section 5.

12. Security

We protect personal data using measures including encryption of data in transit (HTTPS and TLS), access controls granted on a need-to-know basis, and hosting with reputable providers that maintain recognised security certifications. Certify holds Cyber Essentials Plus certification. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, and you are responsible for keeping your account password confidential.

13. Changes to this policy

We may update this policy to reflect changes to our practices or to the law. We will post any changes on this page, and where changes are significant we will take reasonable steps to tell you.

14. Data Protection Enquiries

For any question about this policy or your personal data, or to exercise your rights, please contact us:

Certify Skills Limited 7 Bell Yard, London, WC2A 2JR Email: credential@certify.one