Effective 14 July 2026

Privacy Policy

Roles and data

CertKit is controller for customer account, security, support, and billing-contact data. For certificate-recipient data, the issuing customer is controller and CertKit is processor. Public verification pages never display recipient email addresses.

Purposes

We process data to provide and secure the service, perform contracts, prevent abuse, meet legal obligations, and communicate essential account information. We use self-hosted, cookie-free product analytics and do not sell personal data or use advertising trackers.

Retention

Deleted workspaces enter a 30-day deletion process; encrypted backup copies age out within the published backup-retention window. Billing records may be retained where tax or accounting law requires it.

Rights

Customers can access, correct, export, revoke, or delete data through the product. Recipient requests should normally be sent to the issuer. Contact [email protected] for access, deletion, objection, restriction, portability, or complaint questions.

Grievance and data-protection contact

The service is operated by Logicues, a sole proprietorship based in India, which is responsible for the personal data described here. Under India's Digital Personal Data Protection Act, 2023 and applicable information-technology rules, you may raise a privacy grievance or exercise your rights by writing to the Grievance Officer at [email protected]. We aim to acknowledge within a reasonable period and to respond within the timelines required by law.

International processing

Hosting and sub-processor locations are disclosed on the Sub-processors page. Payment data is processed by Razorpay under its own privacy terms; CertKit does not store card details.