# 1. Executive Overview
Certifada (operated by CuspForge Technologies) provides enterprise-grade digital credential issuance and verification infrastructure. We are committed to processing personal data transparently, securely, and in strict adherence to applicable privacy laws globally, including the UAE Personal Data Protection Law (PDPL - Federal Decree-Law No. 45/2021), the EU General Data Protection Regulation (GDPR), and GCC data sovereignty regulations.
# 2. Information We Collect
We collect personal data strictly necessary to provide and secure our credential services:
- Account Data (at sign-up): First name, last name, email address, and a password which is stored only as a salted hash — never in readable form. Organization name, address, branding and billing details are collected later, only if and when you provide them.
- Social Sign-In Data: If you register using Google, Microsoft, Facebook or LinkedIn, we receive your name, email address and profile identifier from that provider. We never receive your password with them, and we do not post anything on your behalf.
- Credential Recipient Data: Full name, email address, and — where an issuer chooses to notify by WhatsApp — mobile number, together with the credential title, issue date, metadata fields and signature logs supplied by the issuing organization.
- Delivery Data: Whether each credential email was accepted, delivered, bounced or failed, and the provider's reason for any failure. Open and click tracking is disabled by default and only occurs where an issuing organization explicitly enables it.
- Technical & System Log Data: IP address, approximate country derived from it, browser user-agent, authentication timestamps, API request logs, and verification activity analytics.
# 3. Lawful Basis for Processing (UAE PDPL & GDPR)
We process personal data based on the following legal grounds under Article 4 of UAE PDPL and Article 6 of EU GDPR:
- Contractual Performance: Processing required to issue, store, and verify digital credentials on behalf of subscribing organizations.
- Legal & Regulatory Compliance: Retaining audit trails and financial transaction records as mandated by UAE commercial and tax laws.
- Legitimate Interests: Protecting platform security, detecting fraudulent credentials, and ensuring high-availability system operations.
# 4. Cookies & Local Storage
Certifada uses essential session cookies, local storage authentication tokens, and privacy-first security cookies. For full details on cookie categories and consent controls, please visit our dedicated Cookie Policy.
# 5. Service Providers We Share Data With
Certifada does not sell personal data and does not share it for advertising. We use a small number of processors, each limited to a single purpose:
- Microsoft Azure — hosting, database and file storage (UAE datacentres).
- ZeptoMail (Zoho Corporation) — transactional email delivery. Recipient name, email address and the credential message pass through this service so it can be sent, and it reports delivery outcomes back to us.
- Meta Platforms (WhatsApp Business Cloud API) — only where an issuing organization enables WhatsApp notifications. The recipient's mobile number and credential details are sent to Meta to deliver that message.
- Stripe — subscription payments. Card details are entered directly with Stripe and are never received or stored by Certifada.
- Azure OpenAI Service — template layout assistance, within the isolated tenant boundary described in section 8.
Each processor is bound by a data processing agreement and may use the data only to perform the service on our behalf.
# 6. Cross-Border International Data Transfers
Certifada primary infrastructure is hosted within Microsoft Azure UAE Datacenters (Abu Dhabi & Dubai). Cross-border transfers to secondary global nodes occur strictly under Standard Contractual Clauses (SCCs) and encrypted channels complying with UAE PDPL Article 22 requirements for adequate data protection levels.
# 7. Data Retention & Destruction Policy
Personal data is retained only for the duration necessary to fulfill credential verification contracts. Cryptographic verification hashes remain permanently stored unless an issuing organization explicitly revokes and deletes the underlying credential record via the Admin API.
# 8. AI Processing & Layout Automation
AI Ethics Commitment: Certifada utilizes Azure OpenAI Service for automated certificate template generation and layout optimization. Customer recipient data and certificate text are NEVER used to train or fine-tune public AI models. All AI processing stays isolated within enterprise tenant boundaries.
# 9. Your Data Subject Rights
Under UAE PDPL and EU GDPR, data subjects have the right to request access, rectification, erasure ('right to be forgotten'), restriction of processing, and data portability. To exercise your rights, email privacy@certifada.com.