Skip to main content
Atharix

LegalDraft version 0.1

Privacy notice

How Atharix handles personal data for organizations, their staff, certificate holders and people who verify certificates.

Draft — pending legal review

This text is a working draft for the pilot. It is not yet binding and will change before launch. The operating legal entity, contact address and final retention periods are still to be confirmed.

Who is responsible

For records an organization creates, such as participant lists and certificates, the organization decides why the data is processed and Atharix processes it on its behalf. For accounts, website enquiries and security logs, the operator of Atharix is responsible: [Operating legal entity — to be confirmed].

What we process

Staff account details (email, name, sign-in and two-step verification data); participant names, contact details and certificate details entered by organizations; verification page requests; and messages sent through the website contact form.

Why

To provide the service an organization uses, to deliver certificates to people who agreed to receive them, to keep public verification accurate, to protect the service against misuse and to answer enquiries.

What is public

A verification page shows only the certificate details needed to check it. Organizations can keep a record private, in which case no personal details are shown. Verification pages are not listed by search engines.

How long we keep data

Certificate records are kept so that verification keeps working after issuing; the proposed period is five years, to be confirmed. Export files are deleted after seven days. Final retention periods will be published before launch.

Your choices

Certificate holders can ask the issuing organization to correct their name or details. Anyone can ask us about data we hold about them through the contact form. Contact: [Contact address — to be confirmed].