# 1. Executive Overview
Certifada is operated by CuspForge Technologies L.L.C., Sharjah Media City, Sharjah, United Arab Emirates. We determine how account, billing, support, and service-security data is used. Issuing organizations determine the purpose and content of recipient credentials; we process that data on their behalf. This policy explains both roles. Contact hello@certifada.com.
# 2. Information We Collect
We collect personal data strictly necessary to provide and secure our credential services:
- Account Data (at sign-up): First name, last name, email address, and a password which is stored only as a salted hash — never in readable form. Organization name, address, branding and billing details are collected later, only if and when you provide them.
- Social Sign-In Data: If you register using Google, Microsoft, Facebook or LinkedIn, we receive your name, email address and profile identifier from that provider. We never receive your password with them, and we do not post anything on your behalf.
- Credential Recipient Data: Full name, email address, and — where an issuer chooses to notify by WhatsApp — mobile number, together with the credential title, issue date, metadata fields and signature logs supplied by the issuing organization.
- Delivery Data: Whether each credential email was accepted, delivered, bounced or failed, and the provider's reason for any failure. Open and click tracking is disabled by default and only occurs where an issuing organization explicitly enables it.
- Technical & System Log Data: IP address, approximate country derived from it, browser user-agent, authentication timestamps, API request logs, and verification activity analytics.
# 3. Lawful Basis for Processing (UAE PDPL & GDPR)
We use account and payment data to provide the service and administer subscriptions, records required by law to meet legal obligations, and technical data to protect the service. The lawful basis depends on the activity and applicable law; where consent is required, we seek it. Optional website analytics use your consent. Issuers are responsible for a lawful basis for recipient data and making credential information public.
# 4. Cookies & Local Storage
Certifada uses essential session cookies, local storage authentication tokens, and privacy-first security cookies. For full details on cookie categories and consent controls, please visit our dedicated Cookie Policy.
# 5. Service Providers We Share Data With
We use service providers for hosting, delivery, payments, and optional features. The provider list describes their roles, including Cloudflare, Microsoft Azure, ZeptoMail, Stripe, and optional Google or Meta services. Customer-selected AI and sign-in providers also process information when used. Public credential pages disclose the information selected by the issuer to visitors with the link and may be shared further. We do not sell personal data. We may disclose information where required by law or necessary to protect lawful rights.
# 6. Cross-Border International Data Transfers
Our company address is Sharjah Media City, Sharjah, United Arab Emirates. This is not a guarantee that all processing occurs at that location. Primary application hosting is in the UAE; delivery, edge, payment, and optional providers may process data internationally. Transfers must meet the safeguards required by the applicable law and relevant processing agreement. An EU transfer mechanism does not by itself satisfy every jurisdiction. Contact us before uploading data subject to specific residency restrictions.
# 7. Data Retention & Destruction Policy
Retention depends on the purpose: account administration, credential verification, security, support, legal obligations, and dispute handling. Cancelling a subscription does not automatically delete issued credentials or their verification records. Erasure requests are assessed separately with the issuer and applicable law; expiry or revocation is not the same as erasure. Backups may retain data until their retention cycle ends. Ask support@certifada.com for help with export or deletion.
# 8. AI Processing & Layout Automation
AI design assistance is optional. When you use it, your prompt and design instructions are sent to the provider you configure, such as OpenAI, Anthropic, or a custom endpoint. That provider’s terms, retention rules, and account settings apply. Do not include recipient personal data or confidential material without authorization and suitable provider terms. Review generated designs before issuing credentials. This feature does not imply Azure-only processing or a dedicated tenant boundary.
# 9. Your Data Subject Rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or object to processing, and withdraw consent where processing relies on it. You may complain to the competent data protection authority. For issuer-controlled credential data, contact the issuer or ask us to route your request. Send requests to hello@certifada.com; we may verify identity and will respond within applicable legal time limits. These rights are subject to lawful exceptions.