Sertifier INC. (“Sertifier”, “us”, “we”, or “our”) is committed to protecting the privacy of its customers and end-users.
This page summarizes the data we collect from the Sertifier website (“Site”) or software application, including API (“app”), and how we help ensure excellent privacy standards. When you use our site or app you agree to the data practices as per this policy.
Our approach to data security and privacy includes but is not limited to:
Sertifier collects data about customers and processes data on behalf of customers, about their end-users. Sertifier does not sell any data to third parties and makes clear its responsibilities as a Data Controller and Data Processor under the GDPR.
Since Sertifier is a B2B SaaS, we never target end-users or customers as a potential subscriber. When we say “customer” or “user”, we mean someone working for a startup, corporate company, or any kind of organization looking for a business solution like Sertifier. While using our Service, we may ask you to provide us with certain personally identifiable information that can be used to contact or identify you (“Personal Data”).
Personally, identifiable information may include, but is not limited to:
We may use your Personal Data to contact you with newsletters, marketing or promotional materials, and other information that may be of interest to you. You may opt-out of receiving any, or all, of these communications from us by following the unsubscribe link or instructions provided in any email we send or by contacting us via email at email@example.com.
Sertifier may also collect email addresses when someone subscribes to our blog and newsletter, and we fulfill this request by sending product updates and relevant content.
Sertifier does not store financial data about customers (e.g., credit card information), choosing instead to employ a dedicated payment processor.
Sertifier is GDPR compliant and offers customers their individual rights to access, delete, and modify their data, etc.
We may also collect information about how the Service is accessed and used (“Usage Data”). This Usage Data may include information such as your computer’s Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our Service that you visit, the time and date of your visit, the time spent on those pages, unique device identifiers and other diagnostic data.
We may also collect customer-wide statistics such as the number of times certificates and badges are opened/clicked, the number of certificate and badge verification, how many certificates and badges are shared on social media platforms, etc.
We may use and store information about your location if you give us permission to do so (“Location Data”). We use this data to provide features of our Service, to improve and customize our Service.
You can enable or disable location services when you use our Service at any time, through your device settings.
Customers can share data about their receivers of the certificates or the badges, to help deliver the related assets, and to assess which users engaged with the certificates and badges. The legal basis for Sertifier processing this data is a legitimate interest (to help provide Sertifier’s service).
Data in this category is used to help and support the aims of customers through their educational pathways. The aforementioned data is displayed only in the Sertifier customer dashboard.
We accept that our customers/users collect their end user’s data in a way that complied with GDPR. We do not take any responsibility for how our own customers/users collect or process their end user’s data. We also provide a range of methods to support customers in providing their end-users with their individual rights under GDPR, including erasure, restriction, etc.
Cookies are files with a small amount of data which may include an anonymous unique identifier. Cookies are sent to your browser from a website and stored on your device. Tracking technologies also used are beacons, tags, and scripts to collect and track information and to improve and analyze our Service.
You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our Service.
Sertifier uses the collected data for various purposes:
Sertifier will also retain Usage Data for internal analysis purposes. Usage Data is generally retained for a shorter period of time, except when this data is used to strengthen the security or to improve the functionality of our Service, or we are legally obligated to retain this data for longer time periods.
In the case that customers or individuals request the deletion of their data, Sertifier will perform this deletion within seven working days.
Requests for data deletion may be addressed to firstname.lastname@example.org
Sertifier leverages best-in-class practices around data security including serving over 256 bit SSL and controls to prevent data access between customers. We backup data daily and all backups are encrypted.
Sertifier is committed to the privacy of the information as it passes over the network, as well as to preventing unauthorized access to customer or end-user data. We use industry-leading encryption to protect all external traffic in transit (via HTTPS/TLS) and at rest (using AES-256 and an automated key rotation system).
Sertifier does not handle customer payment data directly, instead using a fully PCI DSS compliant payments processor. Sertifier is not intended for the handling of end-user payment information.
If you are a resident of the European Economic Area (EEA), you have certain data protection rights. Sertifier aims to take reasonable steps to allow you to correct, amend, delete, or limit the use of your Personal Data.
If you wish to be informed of what Personal Data we hold about you and if you want it to be removed from our systems, please contact us.
In certain circumstances, you have the following data protection rights:
Please note that we may ask you to verify your identity before responding to such requests.
You have the right to complain to a Data Protection Authority about our collection and use of your Personal Data. For more information, please contact your local data protection authority in the European Economic Area (EEA).
We use the information you provide about yourself when placing an order only to complete that order and to provide excellent customer service during the term of your service.
Although Sertifier owns the data storage, databases, and the Sertifier site, you retain all rights to your content. We will also not utilize your content in our databases to compete with you, to advertise, or to market to your clients.
Under the following circumstances, we may have to share your personally identifiable information provided to us online.
Sertifier will collect End-User Customer Data necessary to provide the service to you. “End User Customer Data” means information about your customers, which includes any information you elect to send to Sertifier in your implementation as well as general information including but not limited to browser and device information.
We do not sell, share, or disclose any End User Customer Data with any third party, except if Sertifier is acquired by or merged with another company.
Services offered by Sertifier are not directed at children under the age of 13. Sertifier does not allow anyone to register and use the tools under the age of 13 as a user.
Sertifier’s collection of personal data on Services and contents that are directed to children under 13 is intended to follow the principles of the Children's Online Privacy Protection Act ("COPPA"), a U.S. law designed to protect the online privacy of children under the age of 13.
In matters and cases as being a direct Service provided via Sertifier to a customer which allows the data infrastructure to reach and collect end-user customer data that belongs to children under the age of 13, Sertifier knowingly approves that:
We use vendors to help us deliver the best functionality and user experience for our customers. This part gives an overview of what we use and where you can find more information about the GDPR compliance of these vendors.
We use AWS as our static file storage (S3) and infrastructure provider.
Mailgun is an email distribution service that we use to distribute certificates and badges to the receivers of our customers.
Google Analytics, Amplitude, Woopra
Google Analytics is an analytics platform that helps us understand what parts of our product users are engaging with. We also track overall tour data by account (e.g. how many tours were started on a certain domain). We don't collect or see any user attribute data you are sending to Sertifier here.
Google Tag Manager
Google Tag Manager is a tag management platform that helps us to manage the tags or scripts needed on this site in a centralized fashion.
Intercom helps us manage our communication (emails and in-app messages) and support (tickets and help articles) with our customers. Intercom also supplements our customer data from other sources, and you can read more about this here.
Slack is our internal communications platform (instead of email) and also contains a stream of events that our customers are taking, such as payments, errors, usage, and tickets.
Iyzico and Stripe
İyzico and Stripe are our credit card and payment processing platforms. Stripe handles all sensitive credit card and account information on our behalf so we can rely on their super-secure system and keep your data safe.
Zoom is our video conferencing platform. We also use it for hosting webinars or group calls, and this sometimes requires registration.
© 2022 Sertifier Inc., All rights reserved.