Privacy Policy
We engineered Credinberg for organizations and enterprises that hold recipient trust to the highest standard. This policy provides full transparency into the data we process, our cryptographic safeguards, and your rights.
Overview & Scope
Credinberg (“Credinberg,” “we,” “our,” or “us”) operates the digital credential issuance, management, and verification platform available at credinberg.com. This Privacy Policy governs our collection, processing, storage, and transfer of personal data when you interact with our website, application workspaces, public verification portals, and badge APIs.
In the context of international data protection frameworks, including the European Union General Data Protection Regulation (GDPR Art. 28) and the California Consumer Privacy Act (CCPA/CPRA):
- Data Processor Role: When organizations, universities, and issuers upload recipient lists or issue badges, the customer is the Data Controller, and Credinberg acts strictly as the Data Processor carrying out verifiable credential baking and delivery under organization instruction.
- Data Controller Role: For direct account holders (issuers, administrators, earner passport holders), Credinberg acts as the Data Controller solely for authentication, billing, account security, and service delivery records.
Information We Collect
We strictly enforce the principle of Data Minimization (GDPR Art. 5(1)(c)). We only gather personal data directly necessary to deliver cryptographically verifiable credentials and maintain service integrity.
- Account & Identity Credentials: Legal name, business email address, job title, encrypted password hashes, and federated OAuth profile details.
- Organization Profile: Organization name, website domain, custom handle, public contact email, and official branding logos.
- Credential & Recipient Data: Recipient names, recipient email addresses, issue dates, expiration dates, achievement narratives, criteria rubrics, and skills tags uploaded by issuing organizations.
- Billing Information: Payment transactions are handled securely by Stripe, Inc. We do not store full credit card numbers or banking secrets. We retain only Stripe Customer IDs and invoicing history.
How We Process Data
We process data solely to execute the core functionalities of the Credinberg platform:
- Credential Minting & Baking: Injecting Open Badges 2.0 / 3.0 cryptographic metadata assertions directly into image files (PNG chunk injection / SVG metadata tags).
- Public Verification Portals: Serving instant validation requests when third-party verifiers, employers, or organizations scan badge QR codes or open verification links.
- Transactional Notifications: Transmitting credential claim invitations, credential expiry reminders, and security alerts via Resend.
- Platform Security & Rate Limiting: Monitoring request volumes against Cloudflare WAF to prevent credential farming, brute force attacks, and system tampering.
Credinberg never sells, rents, or brokers your personal data to advertisers or third parties, and never trains public AI models on your organization’s recipient rosters, certificates, or educational records.
Cryptographic Identity Protection & Open Badges
In traditional credential platforms, publishing a certificate publicly on the web exposes the recipient’s plain-text email address to web scrapers and spammers. Credinberg eliminates this risk by implementing the open Open Badges Specification for cryptographic recipient hashing.
By applying a random 128-bit cryptographic salt and a one-way SHA-256 hash, relying third-party employers can mathematically prove that a given email matches the credential without the plain-text email ever being stored in public JSON-LD assertions.
Authorized Subprocessors & Cloud Infrastructure
To ensure zero-trust security and high availability, Credinberg partners with enterprise-tier infrastructure providers bound by strict Data Processing Addendums (DPAs):
| Subprocessor | Purpose | Region | Certifications |
|---|---|---|---|
| Supabase, Inc. (AWS) | Database hosting & Row-Level Security isolation | United States | SOC 2 Type II, ISO 27001 |
| Cloudflare, Inc. | R2 object storage for badge assets, edge caching & WAF | Global Edge Network | SOC 2 Type II, PCI-DSS |
| Vercel, Inc. | Serverless compute runtime & edge delivery | Global Edge | SOC 2 Type II, ISO 27001 |
| Stripe, Inc. | Subscription billing and merchant payment settlement | United States | PCI-DSS Level 1 |
| Resend, Inc. | Transactional email delivery for badge claims & alerts | United States | SOC 2 Type II |
| PostHog, Inc. | Product usage analytics & feature adoption (session recording disabled) | United States / EU | SOC 2 Type II, EU-US DPF |
| Microsoft Corporation | Microsoft Clarity UX telemetry & heatmaps with masked sensitive data | United States | ISO 27001, SOC 2 Type II |
| Google LLC | Google Tag Manager script orchestration & telemetry containerization | United States | ISO 27001, SOC 2 Type II |
Data Retention, Purging & Lifecycle
We store personal data strictly for as long as necessary to maintain active digital credentials or fulfill legal obligations:
- Active Accounts: Credentials remain publicly verifiable while the issuing organization or earner account remains in good standing.
- Deleted Workspaces: When an organization initiates deletion via account settings, associated templates, badges, and rosters are permanently removed in accordance with data lifecycle policies.
- Disaster Backups: Encrypted database snapshots and transaction archives are retained on standard automated rolling backup schedules for disaster recovery.
Global Privacy Frameworks & Statutory Rights
Credinberg operates as a globally compliant verifiable credential infrastructure. We enforce universal privacy rights across all jurisdictions, ensuring sovereign data ownership regardless of where you reside.
European Union & United Kingdom (GDPR)EU / UK
Full compliance with EU Regulation 2016/679 and UK Data Protection Act 2018. Includes rights of access, rectification, erasure (“Right to be Forgotten”), data portability, and restriction of processing under lawful bases (Contract, Legitimate Interest, Consent).
California (CCPA / CPRA)USA
Notice at Collection & No Sale of Data: Credinberg does not sell personal information for monetary consideration. Under the California Consumer Privacy Act (CCPA/CPRA), the deployment of third-party performance analytics may be classified as a “share” of data. California consumers have the statutory right to opt out at any time by selecting “Do Not Sell or Share My Info” in our website footer or through our on-demand Cookie Preferences modal.
India (DPDP Act 2023)INDIA
Under the Digital Personal Data Protection Act, 2023, data principals have the right to access summaries of digital personal data, seek correction, easily withdraw consent at any time via cookie settings, and access grievance redressal mechanisms.
Brazil (LGPD - Law No. 13.709/2018)BRAZIL
Brazilian holders of personal data maintain sovereign rights under Article 18, including confirmation of processing, anonymization, blocking or elimination of unnecessary data, and information on shared entities.
Canada (PIPEDA)CANADA
Complies with fair information principles governing collection, use, disclosure, accuracy, and safeguards for commercial electronic transactions across Canadian provinces.
Asia-Pacific (PDPA Singapore & Sri Lanka No. 9/2022)APAC / LK
Adheres to Singapore Personal Data Protection Act and Sri Lanka's Personal Data Protection Act No. 9 of 2022. Legitimate processing standards, retention limitations, and transparent data subject access rights are enforced across all regional accounts.
Universal Self-Service Rights:
- Right to Access & Portability: Download a machine-readable JSON-LD or CSV copy of all credentials and profile records directly from your Passport or Dashboard.
- Right to Rectification: Correct inaccurate profile records or organization metadata through workspace settings.
- Right to Erasure: Permanently delete your account and records via self-service account settings or by emailing privacy@credinberg.com.
- Right to Restrict Processing: Badge earners may toggle credentials to “Private” inside their Passport, instantly delisting the assertion from public search.
Educational Records & Student Privacy
When educational organizations utilize Credinberg to issue credentials to students, Credinberg acts as a service provider processing records solely on behalf of the issuing organization to provide verifiable digital credentials. We do not sell or reuse student data for commercial advertising or marketing.
Direct account registration requires individuals to be at least 18 years of age. Organizations issuing badges to students under the age of majority must secure requisite student or parental consent in accordance with applicable education and child privacy laws.
Contact & Policy Updates
We review and update this Privacy Policy periodically. When material amendments occur, we provide notification via registered email or a banner in the dashboard.
Privacy Office & DPO: privacy@credinberg.com
General Legal Inquiries: legal@credinberg.com
Terms of Service
Examine terms governing account registration, acceptable use, billing, and platform verification.
Credinberg Global Governance & Compliance Office
Authoritative legal and privacy policy repository. Inquiries may be directed to legal@credinberg.com.