Data Protection (GDPR)

Protecting Your Data Rights

Our commitment to GDPR compliance and data protection standards

Legal Basis for Processing

We process personal data only when we have a valid legal basis under GDPR:

  • Contractual Necessity: Processing required to deliver our certification services
  • Legal Obligation: Compliance with certification and regulatory requirements
  • Legitimate Interest: For platform security, fraud prevention, and service improvement
  • Consent: When you explicitly provide consent for specific processing activities
  • Vital Interests: To protect essential interests in emergency situations
Your Data Subject Rights

Right to Information

You have the right to know what personal data we collect, why we collect it, how we use it, and who we share it with.

Right to Access

You can request a copy of all personal data we hold about you, including the source of the data and the purposes of processing.

Right to Rectification

You can request correction of inaccurate or incomplete personal data we hold about you.

Right to Erasure

You can request deletion of your personal data when it's no longer necessary for the purposes it was collected, or if you withdraw consent.

Right to Restrict Processing

You can request restriction of processing your personal data in certain circumstances.

Right to Data Portability

You can request your data in a structured, machine-readable format for transfer to another service provider.

Right to Object

You can object to processing based on legitimate interests or direct marketing.

Data Retention Policies

We retain personal data only as long as necessary for the purposes it was collected:

  • Account Data: Retained for the duration of your account plus 7 years
  • Certification Records: Retained for 10 years as required by certification standards
  • Financial Data: Retained for 7 years to comply with tax and accounting regulations
  • Support Tickets: Retained for 3 years for quality assurance purposes
  • Analytics Data: Anonymized after 26 months
  • Marketing Data: Retained until you unsubscribe or withdraw consent
International Data Transfers

Your data may be transferred outside the European Economic Area (EEA) only with appropriate safeguards in place:

  • Adequacy Decisions: Transfers to countries with EU-approved adequacy decisions
  • Standard Contractual Clauses: EU-approved contracts with data importers
  • Binding Corporate Rules: Internal rules for intra-organizational transfers
  • Explicit Consent: When you provide specific consent for international transfers
Data Breach Procedures

In the event of a personal data breach, we follow established procedures:

  • Immediate Assessment: Evaluate the breach scope and potential impact
  • Containment: Take immediate steps to prevent further data loss
  • Notification: Inform affected individuals within 72 hours when required
  • Regulatory Reporting: Report to relevant data protection authorities
  • Remediation: Implement measures to prevent future breaches
Exercise Your Rights

To exercise your GDPR rights or ask questions about our data protection practices, please contact our Data Protection Officer.