# 1. Executive Overview
Certifada (operated by CuspForge Ltd.) provides enterprise-grade digital credential issuance and verification infrastructure. We are committed to processing personal data transparently, securely, and in strict adherence to applicable privacy laws globally, including the UAE Personal Data Protection Law (PDPL - Federal Decree-Law No. 45/2021), the EU General Data Protection Regulation (GDPR), and GCC data sovereignty regulations.
# 2. Information We Collect
We collect personal data strictly necessary to provide and secure our credential services:
- Organization Account Data: Administrator name, professional email, company domain, organization registration number, and billing information.
- Credential Recipient Data: Full name, recipient email, credential title, issue date, metadata fields, and cryptographic signature logs provided by issuing organizations.
- Technical & System Log Data: IP address, browser user-agent, authentication timestamp, API request logs, and verification activity analytics.
# 3. Lawful Basis for Processing (UAE PDPL & GDPR)
We process personal data based on the following legal grounds under Article 4 of UAE PDPL and Article 6 of EU GDPR:
- Contractual Performance: Processing required to issue, store, and verify digital credentials on behalf of subscribing organizations.
- Legal & Regulatory Compliance: Retaining audit trails and financial transaction records as mandated by UAE commercial and tax laws.
- Legitimate Interests: Protecting platform security, detecting fraudulent credentials, and ensuring high-availability system operations.
# 4. Cookies & Local Storage
Certifada uses essential session cookies, local storage authentication tokens, and privacy-first security cookies. For full details on cookie categories and consent controls, please visit our dedicated Cookie Policy.
# 5. Cross-Border International Data Transfers
Certifada primary infrastructure is hosted within Microsoft Azure UAE Datacenters (Abu Dhabi & Dubai). Cross-border transfers to secondary global nodes occur strictly under Standard Contractual Clauses (SCCs) and encrypted channels complying with UAE PDPL Article 22 requirements for adequate data protection levels.
# 6. Data Retention & Destruction Policy
Personal data is retained only for the duration necessary to fulfill credential verification contracts. Cryptographic verification hashes remain permanently stored unless an issuing organization explicitly revokes and deletes the underlying credential record via the Admin API.
# 7. AI Processing & Layout Automation
AI Ethics Commitment: Certifada utilizes Azure OpenAI Service for automated certificate template generation and layout optimization. Customer recipient data and certificate text are NEVER used to train or fine-tune public AI models. All AI processing stays isolated within enterprise tenant boundaries.
# 8. Your Data Subject Rights
Under UAE PDPL and EU GDPR, data subjects have the right to request access, rectification, erasure ('right to be forgotten'), restriction of processing, and data portability. To exercise your rights, email privacy@certifada.com.