Who is responsible
For records an organization creates, such as participant lists and certificates, the organization decides why the data is processed and Atharix processes it on its behalf. For accounts, website enquiries and security logs, the operator of Atharix is responsible: [Operating legal entity — to be confirmed].
What we process
Staff account details (email, name, sign-in and two-step verification data); participant names, contact details and certificate details entered by organizations; verification page requests; and messages sent through the website contact form.
Why
To provide the service an organization uses, to deliver certificates to people who agreed to receive them, to keep public verification accurate, to protect the service against misuse and to answer enquiries.
What is public
A verification page shows only the certificate details needed to check it. Organizations can keep a record private, in which case no personal details are shown. Verification pages are not listed by search engines.
How long we keep data
Certificate records are kept so that verification keeps working after issuing; the proposed period is five years, to be confirmed. Export files are deleted after seven days. Final retention periods will be published before launch.
Your choices
Certificate holders can ask the issuing organization to correct their name or details. Anyone can ask us about data we hold about them through the contact form. Contact: [Contact address — to be confirmed].