Legal
Last updated: September 2026
This policy covers three kinds of people: applicants and issuers (businesses and individual trainers who apply to issue certificates), trainees (people certified by an issuer, whose profile may appear in the public directory), and visitors (anyone browsing or verifying a certificate without an account).
A trainee's public profile is created by the issuer that certified them, and only with the issuer's confirmation that the trainee consented to it. Once created:
To review and approve issuer applications; to generate, sign, and host verifiable certificate records; to operate the public directory and its contact-relay feature; to prevent abuse (rate limiting, fraud/spam detection); and to meet our own recordkeeping and legal obligations.
Certificate records are kept indefinitely once issued, a certificate needs to remain verifiable for as long as someone might reasonably rely on it, including after a trainee hides their directory profile. Application documents and account data are kept for as long as the account is active, plus a reasonable period afterward for legal and audit purposes.
Depending on the data-protection law that applies to you (for example Nigeria's NDPA 2023, or the equivalent law in your own country of operation), you may have rights to access, correct, or request deletion of your personal data, and to object to or restrict certain processing. A trainee can already exercise most of this directly through their claimed profile; for anything else, or if you don't have a claimed profile, contact us.
Uploaded images are re-encoded server-side before storage rather than served back as the original file. Certificate signing happens server-side only, using a secret that is never exposed to any client or returned in an API response. See our Security & trust page for more detail on how certificate integrity itself is protected.
Questions about this policy, or a request relating to your data, can be sent via our contact page.