PRIVACY & DATA PROTECTION

Privacidad Policy

How DigiTrustly handles personal data across certification, verification, accounts, public records and payments.

Last updated: 14 September 2026

1. Scope of this Privacidad Policy

This Privacidad Policy explains how DigiTrustly processes personal data when you visit our websites, use public verification, submit a certification application, communicate with us, use the Portal del cliente, purchase assessment or certification services, or otherwise interact with DigiTrustly.

It applies to DigiTrustly-operated services including the main certification website, the Portal del cliente, public certificate pages and the DigiTrustly payment environment.

2. Who is responsible for your data

DigiTrustly is responsible for the personal data it decides to collect and use for its own certification, verification, account, support and business operations.

Contacto for privacy matters: certification@digitrustly.com

Where third-party services such as payment processors, hosting providers or email providers process data under their own purposes and terms, they may also act as independent controllers or processors depending on the service and applicable law.

3. Personal data we may process

Account and contact data

This may include your name, business or organisation name, email address, billing details, account identifiers and information needed to operate the Portal del cliente.

Certification application data

This may include information about the website, organisation, digital service, release or other subject submitted for certification; application answers; uploaded evidence; correspondence; reviewer notes; review outcomes; status history; certificate identifiers; validity dates; and information relating to suspension, revocation, expiry or renewal.

Technical and security data

This may include IP addresses, timestamps, browser/device information, authentication events, server logs, failed login attempts, session data and other information used to operate and secure DigiTrustly services.

Payment and order data

This may include order numbers, selected service, assessment or certification period, transaction status, billing information, currency and payment provider references. Full payment-card details are normally handled by the payment provider rather than stored by DigiTrustly.

Communications

We may retain emails, support requests, reviewer correspondence and other communications necessary to provide services, resolve disputes, maintain audit records or meet legal obligations.

4. Why we use personal data

  • to receive and evaluate certification applications;
  • to conduct technical checks and human review;
  • to make and document certification decisions;
  • to create and maintain public certificates and verification records;
  • to operate the Portal del cliente and account authentication;
  • to process assessment and certification payments;
  • to send service, status, renewal and support communications;
  • to detect misuse, impersonation, fraud and unauthorised access;
  • to maintain business, accounting, audit and security records;
  • to comply with applicable legal obligations;
  • to enforce DigiTrustly terms and certification rules.

6. Public certificate and verification data

DigiTrustly certification is designed to be verificable. For that reason, approved certificates may have a public record that displays information such as certificate ID, certified subject or organisation, certified website or relevant asset, issue information, current status and verification links.

Important: public certificate records are intentionally public. Applicants should not provide unnecessary personal data for public display.

Expired, suspended or revoked records may remain publicly accessible where maintaining historical verification status is necessary to prevent confusion, misuse or false claims of active certification.

7. Payments and the DigiTrustly payment environment

DigiTrustly may use a separate payment environment to process assessment and certification fees. Order data may be linked to the relevant application or client account so that DigiTrustly can identify whether an assessment fee or certification-period fee has been paid.

Payment processors may collect and process payment-card, banking or transaction information under their own terms and privacy notices. DigiTrustly generally receives payment confirmation and transaction references rather than full card credentials.

8. Service providers and disclosures

We may use providers for hosting, infrastructure, email delivery, security, backups, payment processing, website operation, analytics or other business functions. They may receive personal data only where reasonably necessary for those services.

We may also disclose information where reasonably necessary to comply with law, respond to valid legal requests, protect DigiTrustly or others from fraud or abuse, investigate security incidents, enforce agreements or establish, exercise or defend legal claims.

DigiTrustly does not sell personal data as a business model.

9. International data transfers

DigiTrustly is intended for international use and some service providers or infrastructure may operate in multiple countries. Where applicable law requires safeguards for international transfers, DigiTrustly aims to use appropriate mechanisms such as contractual safeguards or providers offering legally recognised transfer protections.

10. How long we keep information

Retention depends on the type of data and why it is needed. DigiTrustly may retain data for certification administration, audit history, accounting, security, fraud prevention, dispute handling and legal compliance.

CategoryTypical reason for retention
Application and decision recordsCertification history, audit trail and dispute handling
Order and payment recordsAccounting, tax and transaction history
Public certificate recordsVerification and historical status
Security logsFraud prevention and incident investigation
Support correspondenceCustomer support and dispute history

Specific retention periods may vary depending on law, risk, service type and whether a dispute or investigation is ongoing.

11. Security

DigiTrustly uses technical and organisational measures designed to protect personal data and service integrity. Depending on the service, these may include encrypted network connections, restricted reviewer and administrative access, separate client functions, authentication controls, one-time security codes, backups and security logging.

No online system can guarantee absolute security. Users are responsible for protecting their credentials and should promptly report suspected unauthorised access.

12. Cookies and similar technologies

DigiTrustly may use cookies or similar technologies necessary for authentication, session management, security, language or interface preferences, checkout functions and essential service operation.

If DigiTrustly introduces non-essential analytics, advertising or marketing technologies, they should be handled in accordance with applicable consent requirements.

13. Your privacy rights

Depending on your location and applicable law, you may have rights to request access, correction, deletion, restriction, portability or objection, and to withdraw consent where processing is based on consent.

These rights may be subject to lawful exceptions. For example, DigiTrustly may need to retain certain accounting, anti-fraud, contractual or certification audit records even after a deletion request.

Where GDPR applies, you may also have the right to complain to a competent data protection supervisory authority.

14. Children

DigiTrustly certification services are primarily intended for organisations, professionals and persons legally able to enter into the relevant service relationship. DigiTrustly does not seek to collect unnecessary personal data from children.

15. Changes to this Privacidad Policy

We may update this Privacidad Policy when our services, technology, providers or legal obligations change. The current version applies from the “Last updated” date shown at the top of this page.

16. Contacto and privacy requests

Privacidad contact

certification@digitrustly.com

Verification and certification

Use the same contact address for questions about certificate data or public verification records.

We may request reasonable information to verify the identity of a person making a privacy request before taking action.

EnglishENNederlandsNLDeutschDEFrançaisFREspañolESItalianoITPortuguêsPTPolskiPL日本語JA한국어KOالعربيةAR