Trust

Privacy Policy

Version 2.2 · Effective August 14, 2026 · Last updated August 14, 2026

This Privacy Policy explains how CertAttestor ("we", "us" or "our"), a service operated by CertAttestor, collects, uses, discloses and safeguards personal information when you visit our website, verify a credential, or use the service as a registered issuer. It also explains the roles we play under data-protection law and the choices and rights available to you.

Privacy at a glance

  • We are the controller of your issuer-account and website data. When an organization issues credentials, that organization is the controller of the credential data and we act as its processor.
  • We never store identity-document numbers, and we never sell personal information.
  • Public verification is by design: the credential details an issuer publishes are shown to anyone who looks them up.
  • Only non-personal cryptographic hashes are written to the public blockchain — never names or credential contents.
  • We use only strictly necessary cookies. We do not run advertising cookies or third-party tracking.
  • If you are in Europe, the EU and UK GDPR apply and give you additional rights — see the dedicated GDPR section below.

This summary is for convenience only; the full policy below governs.

1. Who we are and how this policy applies

CertAttestor is a credential-verification service operated by CertAttestor. This policy applies to our website, our public verification pages, and the issuer dashboard and related tools.

Controller and processor

For your issuer account and your use of our website, we act as the data controller. For the credential data an organization submits when it issues credentials, that organization is the controller and decides what data to include; we process that data on its behalf, under its instructions, as a processor.

We are not a certificate authority or a notary. The issuing organization, not us, is responsible for the accuracy of the identity claims in the credentials it issues. Questions about a specific credential should be directed to the organization that issued it.

2. Information we collect

We collect the following categories of information, depending on how you interact with the service.

Information you or your organization provide

  • Issuer account details: the account holder’s name and email address, and the organization’s name, contact details, website and logo.
  • Vetting information: during registration review we record the verification method used and the type of evidence relied upon. We do not store identity-document numbers.
  • Credential data submitted by issuers: a holder’s name, credential type and number, issue and expiry dates, an optional holder email address, and optional line-item detail such as a transcript.
  • Uploaded documents: where an issuer uploads a source document (for example a PDF) to certify, we store that file and a cryptographic hash of it so the document can be shown and verified.
  • Account security data: a hashed password, and — if you enable two-factor authentication — an encrypted authenticator secret and hashed one-time recovery codes.
  • Billing data: where prepaid on-chain credit ("Coin") is used, the account balance and a ledger of top-ups and charges. We do not store full payment-card numbers.
  • Communications: the content of messages you send us and our replies.

Information we collect automatically

  • Technical data: IP address, browser and device type, referring pages, pages viewed and timestamps.
  • Cookies and local storage used for sessions, form security and bot protection (see “Cookies” below).
  • Verification activity: the credential number entered when a credential is looked up, together with the technical data above. No account is needed to verify.

Information from third parties

  • If you sign in through a third-party identity provider (for example, Google), we receive basic profile information such as your name and email address from that provider.

3. Data we hold, why, and for how long

The table below summarises the main categories of personal data, why we process them, the legal basis we rely on, and how long we keep them.

CategoryExamplesPurposeLegal basisRetention
Issuer accountName, email, organization detailsOperate accounts, authenticate usersContract; legitimate interestsWhile the account is active, then as required by law
Vetting recordVerification method and evidence type (no ID numbers)Confirm an issuer is legitimateLegitimate interests; legal obligationWhile the account is active, then archived per policy
Credential dataHolder name, credential type/number, dates, optional email/transcriptIssue and publicly verify credentials on the issuer’s behalfProcessed for the issuer (controller)While the credential must remain verifiable, per the issuer’s instructions
Verification activityCredential number looked up, technical dataReturn a result; prevent abuseLegitimate interestsShort-term logs only
Technical and usage dataIP address, browser, timestampsSecurity, fraud prevention, operationLegitimate interests; legal obligationA limited period
Blockchain anchorNon-personal Merkle-root hashIndependent, tamper-evident proof of existenceLegitimate interestsPermanent (cannot be deleted)

4. How we use information

We use personal information to:

  • operate the service — creating, issuing and publicly verifying credentials, and maintaining issuer accounts;
  • vet issuers and prevent fraudulent or abusive use;
  • communicate with you — issuance notifications and expiry reminders where an issuer has enabled them and a holder email is on file, and responses to your enquiries;
  • secure the service, diagnose problems and protect against misuse; and
  • comply with legal obligations and establish, exercise or defend legal claims.

We do not use your personal information for advertising, and we do not sell it.

Where data-protection law requires a legal basis, we rely on one or more of the following, depending on the processing and your location:

  • Performance of a contract — to provide the service you or your organization signed up for;
  • Consent — for example, where you choose to sign in with a third-party provider; you may withdraw consent at any time;
  • Legitimate interests — operating, securing and improving the service, where these interests are not overridden by your rights; and
  • Legal obligation — where we must process data to comply with applicable law.

6. Public verification

Public verification is a core purpose of the service. When an issuer publishes a credential, the credential details that issuer chooses to include are displayed to anyone who verifies it — this is by design, so recipients can confirm authenticity. Issuers should not include information in a credential that must not be public. Requests to change or remove published credential data should be directed to the issuing organization.

7. Notarization and the blockchain

To make credentials independently verifiable, we combine cryptographic fingerprints (hashes) of issued credentials into a single Merkle-tree root and may anchor that root on the Base public blockchain (an Ethereum layer-2 network operated using Coinbase infrastructure).

Only hashes are published — never names, credential contents or any other personal data. Hashes are one-way and cannot be reversed to recover the underlying information.

Information written to a public blockchain is permanent and cannot be altered or deleted. Because only non-personal hashes are anchored, this does not place your personal data on-chain; you should nonetheless be aware that the existence of a root at a given time becomes a permanent public record.

8. Cookies and similar technologies

We use strictly necessary cookies and local storage to keep you signed in, secure forms, and operate bot-protection. We do not use advertising cookies or third-party tracking cookies.

You can control or delete cookies through your browser settings, but disabling essential cookies may prevent parts of the service from working.

9. How we share information

We do not sell personal information. We share it only in the following circumstances.

Service providers (sub-processors)

We use the trusted providers below, who process personal data on our behalf under appropriate contractual safeguards. This list may change as our infrastructure evolves; the current version is always reflected here.

ProviderRoleData involved
HostingerWeb hosting and databaseAll application and account data
CloudflareCDN, DNS, security and bot-protection (Turnstile)Technical data, IP address
Amazon Web Services (KMS)Hardware-backed custody of signing keysNo personal data — cryptographic keys only
Base (Coinbase)Public blockchain used to anchor hashesNo personal data — non-personal hashes only
Google / MicrosoftOptional social sign-inName and email, only if you use it
Email (SMTP) providerSending transactional emailRecipient email address, message content

Public verification and legal disclosures

  • As part of public verification, which by design displays the credential information an issuer has published;
  • Where required by law, regulation or valid legal process, or to protect rights, property and safety; and
  • In connection with a merger, acquisition or asset sale, subject to this policy.

10. International data transfers

Some of our service providers operate globally, so your information may be processed in countries other than your own, including outside the Philippines. Where this happens, we take steps intended to keep it protected in line with this policy and applicable law.

11. Data retention

We keep personal information only as long as necessary for the purposes described in this policy, as summarised in the table above. Issuer account and credential records are retained while the account is active and the credentials need to remain verifiable, and thereafter as required for legal, accounting or security purposes. Technical logs are kept for a limited period. Non-personal hashes anchored on the blockchain cannot be deleted.

12. Your rights and choices

Subject to applicable law — including the Philippine Data Privacy Act of 2012 and, for individuals in Europe, the EU and UK GDPR (see the dedicated section below) — you may:

  • access the personal information we hold about you and ask for a copy;
  • ask us to correct inaccurate or incomplete information;
  • ask us to delete information, where there is no overriding legal or operational reason to keep it;
  • object to or ask us to restrict certain processing;
  • request portability of information you provided; and
  • withdraw consent where processing is based on consent.

If an issuing organization submitted your credential data, please direct requests about that data to that organization; as processor, we will assist the organization where appropriate.

To exercise your rights, contact us at [email protected]. You also have the right to lodge a complaint with your data-protection authority — in the Philippines, the National Privacy Commission.

13. European Economic Area, United Kingdom and Switzerland (GDPR)

If you are located in the European Economic Area (EEA), the United Kingdom or Switzerland, this section applies to you and supplements the rest of this policy. The EU General Data Protection Regulation (GDPR) and the UK GDPR govern the processing of your personal data, and in case of any conflict this section prevails for you.

Controller and legal bases

The controller of your issuer-account and website data is CertAttestor. We rely on the legal bases set out in the “Data we hold” table above: performance of a contract with you, our legitimate interests in operating, securing and improving the service (balanced against your rights), compliance with legal obligations, and, where applicable, your consent. When an organization issues credentials, that organization is the controller of the credential data and we act as its processor under a data-processing agreement.

Your GDPR rights

In addition to the rights listed above, you have the right to:

  • obtain access to, and rectification or erasure of, your personal data;
  • restrict or object to processing carried out on the basis of our legitimate interests;
  • receive the personal data you provided in a portable, machine-readable format where processing is based on consent or contract;
  • withdraw consent at any time, without affecting processing carried out before withdrawal; and
  • not be subject to a decision based solely on automated processing that produces legal or similarly significant effects — which we do not carry out.

International transfers

We and some of our sub-processors operate outside the EEA and the UK. Where personal data is transferred to a country without an adequacy decision, we rely on appropriate safeguards — such as the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum — to keep it protected, and a copy of the relevant safeguards is available on request.

Complaints

You have the right to lodge a complaint with your local data-protection supervisory authority (for example, your national Data Protection Authority in the EEA, or the Information Commissioner’s Office in the UK). We would appreciate the opportunity to address your concerns first, so please consider contacting us using the details below before doing so.

14. How we protect information

We protect information using measures appropriate to its sensitivity, including encrypted connections (HTTPS), signing keys held in a hardware-backed key-management service or encrypted at rest, an append-only tamper-evident audit trail, role-based access controls, and login-abuse protections. No system can be guaranteed perfectly secure, and we cannot warrant absolute security.

15. Data breach notification

If a security incident affecting personal data occurs, we will assess it and, where the law requires, notify the relevant supervisory authority — in the Philippines, the National Privacy Commission — and affected individuals within the timeframes prescribed by applicable law.

16. Automated decision-making

A verification result is a factual lookup against the registry, not a profiling decision about you. We do not use your personal information to make solely automated decisions that produce legal or similarly significant effects.

17. Children’s privacy

The service is intended for organizations and adults. We do not knowingly collect personal information directly from children under the age of majority. Credential data about a minor may be submitted by an issuing organization acting as controller; questions about such data should be directed to that organization. If you believe a child has provided us information directly, contact us and we will take appropriate steps.

18. Third-party links

Our site and verification pages may link to third-party websites, including issuers’ own sites. We are not responsible for the privacy practices of those sites and encourage you to review their policies.

19. Changes to this policy

We may update this policy as our practices or the law change. Material changes will be reflected in the version and effective date shown above, and where appropriate we will provide additional notice. Your continued use of the service after an update indicates acceptance of the revised policy.

20. Contact us

For questions, concerns or requests regarding this policy or your personal information, contact CertAttestor at [email protected], or by post at Prk. 1, San Agustin, Iba, Zambales, Philippines 2201.

If your question concerns credential data that an organization issued to you, please also contact that organization directly, as it controls that data.

CertAttestor Privacy Policy — version 2.2, effective August 14, 2026. This document is an operational draft provided for transparency and is not legal advice.