Effective 14 July 2026
Privacy Policy
Roles and data
CertKit is controller for customer account, security, support, and billing-contact data. For certificate-recipient data, the issuing customer is controller and CertKit is processor. Public verification pages never display recipient email addresses.
Purposes
We process data to provide and secure the service, perform contracts, prevent abuse, meet legal obligations, and communicate essential account information. We use self-hosted, cookie-free product analytics and do not sell personal data or use advertising trackers.
Retention
Deleted workspaces enter a 30-day deletion process; encrypted backup copies age out within the published backup-retention window. Billing records may be retained where tax or accounting law requires it.
Rights
Customers can access, correct, export, revoke, or delete data through the product. Recipient requests should normally be sent to the issuer. Contact [email protected] for access, deletion, objection, restriction, portability, or complaint questions.
Grievance and data-protection contact
The service is operated by Logicues, a sole proprietorship based in India, which is responsible for the personal data described here. Under India's Digital Personal Data Protection Act, 2023 and applicable information-technology rules, you may raise a privacy grievance or exercise your rights by writing to the Grievance Officer at [email protected]. We aim to acknowledge within a reasonable period and to respond within the timelines required by law.
International processing
Hosting and sub-processor locations are disclosed on the Sub-processors page. Payment data is processed by Razorpay under its own privacy terms; CertKit does not store card details.