Privacy Policy
How we process personal data in SmartCerts. September 2026 version.
Who processes the data
For the data of recipients (name and email), the issuer is the controller and SmartCerts is the processor, using data to issue, deliver and enable credential verification. For dashboard users' data (name, email, organization), SmartCerts is the controller.
What appears publicly
Each credential page shows the recipient's name, issuer, certified achievement, dates and status. The recipient's email is not displayed. The page is only found by those with the link or code, and we ask search engines not to index it (noindex).
How we use it
- Issue and deliver credentials by email
- Display the verification page and PDF
- Resend links to those requesting them using their email
- Count views and downloads without identifying viewers
Data subject rights
Recipients may request access, correction or deletion from the credential issuer or from us at ola@smartcerts.co, and we will forward the request to the issuer when appropriate.
Cookies
Dashboard users receive a session cookie needed to stay signed in. Google Analytics only loads after you accept the cookie notice; you can change your choice using the "Cookies" link in the footer.
Retention
We retain credentials while the issuer's account exists so they remain verifiable. Technical records are retained as needed for service security.
Draft text, not yet reviewed by legal counsel.