Effective 14 July 2026

CertKit Data Processing Addendum

1. Parties and operator identity

The customer identified by the accepting workspace and acceptance receipt is the Controller. The CertKit operator is the Processor. Operator legal name: Logicues (sole proprietorship, established under the laws of India). Registered address: Tapadia Nagar, Akola, Maharashtra 444005, India. Registration and tax identifiers: Sole proprietorship; not registered for GST at present (below the registration threshold). PAN and any tax identifiers available to competent authorities and to customers on reasonable request.. These published details identify the contracting processor and must match the operator's public imprint and merchant records.

2. Scope, subject matter, and duration

This DPA forms part of the CertKit Terms whenever the customer submits personal data for CertKit to process on its behalf. Processing covers certificate creation, delivery, verification, support, security, backup, and deletion for the duration of the customer's use of the service and the documented deletion period.

3. Data subjects and personal data

Data subjects may include certificate recipients, customer personnel, and people represented in customer-provided certificate fields. Personal data may include names, email addresses, certificate fields, delivery records, identifiers, verification metadata, and customer-supplied content. The customer is responsible for lawful instructions, data accuracy, notices, consents, and its authority to issue each credential.

4. Documented instructions and confidentiality

CertKit processes personal data only to provide, secure, support, and delete the service under the customer's documented instructions, unless applicable law requires otherwise. People authorised to process the data are bound by confidentiality obligations.

5. Security measures

CertKit maintains tenant-scoped access controls, encrypted secrets, isolated rendering, authenticated administration, logging, backups, vulnerability management, incident procedures, and deletion controls appropriate to the service and processing risk.

6. Sub-processors and transfers

The customer gives general authorisation for the sub-processors listed on the CertKit Sub-processors page. CertKit remains responsible for imposing appropriate data-protection obligations and will provide notice of material additions where required. Processing locations and transfer safeguards follow the published Sub-processors and Privacy pages.

7. Assistance, requests, and incidents

Taking account of the nature of processing, CertKit will reasonably assist the customer with data-subject requests, security enquiries, impact assessments, and regulator consultations. Confirmed incidents affecting customer-controlled personal data are reported without undue delay, with an operational target of 48 hours after confirmation.

8. Return, deletion, and audit information

On termination or a valid customer instruction, personal data is returned or deleted through the service's export and deletion processes unless law requires retention. Backup copies expire under the published backup-retention schedule. CertKit will provide information reasonably necessary to demonstrate compliance, subject to confidentiality, security, and proportionality safeguards.

9. Electronic acceptance and countersignature

The accepting signatory represents that they are authorised to bind the customer. Acceptance records the exact version and SHA-256 content hash shown on the receipt. CertKit countersigns electronically as: “Logicues (sole proprietorship, established under the laws of India) — electronically countersigned by CertKit”. Self-service acceptance and countersigning are enabled for this version because the published operator identity is configured. Any later identity or term change requires an intentional DPA version update and produces a new canonical content hash.

10. Self-service execution

Authenticated workspace owners and administrators can review and accept this exact version at /app/settings/dpa. The service records the canonical content hash and provides a printable countersigned HTML receipt. Emailing signatory details is not required for self-service acceptance.