Legal

Privacy Policy

Last updated: August 3, 2026 · Applies to certyze.com and the Certyze platform

1. Scope & who this applies to

Certyze is a workflow platform built for Certification Bodies (CBs), their franchise and representative networks, and the Accreditation Bodies that oversee them. This policy covers two categories of people: CAB personnel who administer Certyze on behalf of their organization (Head Office staff, franchise representatives, auditors), and end clients whose applications, audits, non-conformities, and certificates are processed inside a customer's Certyze instance. In most cases, the Certification Body or Accreditation Body is the data controller and Certyze acts as data processor on their behalf under a data processing agreement.

2. Data we collect

Depending on how a CAB configures its instance, Certyze may process:

  • Account & identity data — name, work email, role, and organization for CAB staff, franchise reps, auditors, and client contacts.
  • Certification workflow data — client applications, scope of certification, standards and schemes applied for, questionnaires, audit plans, man-day calculations, auditor assignments, resource-matrix and competency records, non-conformities, audit reports, and issued certificates.
  • Auditor data — qualifications, approved standards/IAF codes, calendar availability, and conflict-of-interest (COI) declarations, used solely to validate assignment eligibility.
  • Usage & audit-trail data — who changed what, when, and on which record, captured automatically to support Accreditation-grade traceability.
  • Technical data — IP address, browser/device type, and log data collected automatically when you use certyze.com or the platform.

3. How we use data

We use the data above to operate the certification lifecycle inside Certyze: routing applications, calculating audit duration, validating and assigning auditors, managing non-conformities and certificate issuance, sending notifications and reminders, and giving Head Office visibility across franchise locations. We also use technical data to secure, maintain, and improve the platform and certyze.com, and to respond to support requests.

Where applicable data protection law requires a legal basis (for example under the GDPR), Certyze processes personal data under one or more of: performance of a contract with the CAB customer, the CAB customer's legitimate interests in running its certification program, compliance with a legal or accreditation-scheme obligation, or consent where explicitly requested (for example, marketing communications).

5. Who we share data with

We do not sell personal data. We share data only as needed to operate the service:

  • With the CAB customer that owns the relevant instance, and the franchise locations, auditors, or clients they authorize within it.
  • With sub-processors that provide hosting, infrastructure, email delivery, and analytics on our behalf, bound by contractual confidentiality and data-protection terms.
  • With Accreditation Bodies, where a CAB customer configures oversight access as part of its own accreditation reporting.
  • Where required by law, regulation, or a valid legal process.

6. Data security

We apply industry-standard technical and organizational measures — encryption in transit, role-based access control, and audit logging of record-level changes — to protect data processed within Certyze. No system is completely immune to risk, and we continually review our safeguards as the platform evolves.

7. Data retention

Certification and audit records are retained for as long as the CAB customer's contract with Certyze is active, and for any additional period required by the standards or accreditation scheme the CAB operates under (for example, ISO/IEC 17021-1 record-retention requirements). Account data for individuals is retained only as long as needed for the purposes described in this policy, or as required by law.

8. Your rights

Depending on your location, you may have the right to access, correct, export, or request deletion of your personal data, and to object to or restrict certain processing. Because most workflow data in Certyze is controlled by the CAB customer, requests relating to certification or audit records are typically directed to that CAB in the first instance; we support them in responding. To make a request directly to us, use the contact details below.

9. International data transfers

Certyze serves CABs, franchise networks, and Accreditation Bodies across multiple countries. Where data is transferred across borders, we rely on appropriate safeguards such as standard contractual clauses or equivalent mechanisms recognized under applicable law.

10. Cookies & tracking

certyze.com uses essential cookies required for the site and platform to function, along with limited analytics cookies to understand how visitors use our marketing pages. We do not use cookies to sell personal data to third parties.

11. Children's data

Certyze is a B2B platform intended for use by certification, accreditation, and audit professionals. It is not directed at children, and we do not knowingly collect personal data from children.

12. Changes to this policy

We may update this policy as Certyze's platform and services evolve. Material changes will be reflected by an updated "Last updated" date at the top of this page.

13. Contact us

Questions about this Privacy Policy, or requests relating to your personal data, can be sent to us — contact here.