1. Scope of this プライバシー Policy
This プライバシー Policy explains how DigiTrustly processes personal data when you visit our websites, use public verification, submit a certification application, communicate with us, use the クライアントポータル, purchase assessment or certification services, or otherwise interact with DigiTrustly.
It applies to DigiTrustly-operated services including the main certification website, the クライアントポータル, public certificate pages and the DigiTrustly payment environment.
2. Who is responsible for your data
DigiTrustly is responsible for the personal data it decides to collect and use for its own certification, verification, account, support and business operations.
Where third-party services such as payment processors, hosting providers or email providers process data under their own purposes and terms, they may also act as independent controllers or processors depending on the service and applicable law.
3. Personal data we may process
Account and contact data
This may include your name, business or organisation name, email address, billing details, account identifiers and information needed to operate the クライアントポータル.
Certification application data
This may include information about the website, organisation, digital service, release or other subject submitted for certification; application answers; uploaded evidence; correspondence; reviewer notes; review outcomes; status history; certificate identifiers; validity dates; and information relating to suspension, revocation, expiry or renewal.
Technical and security data
This may include IP addresses, timestamps, browser/device information, authentication events, server logs, failed login attempts, session data and other information used to operate and secure DigiTrustly services.
Payment and order data
This may include order numbers, selected service, assessment or certification period, transaction status, billing information, currency and payment provider references. Full payment-card details are normally handled by the payment provider rather than stored by DigiTrustly.
Communications
We may retain emails, support requests, reviewer correspondence and other communications necessary to provide services, resolve disputes, maintain audit records or meet legal obligations.
4. Why we use personal data
- to receive and evaluate certification applications;
- to conduct technical checks and human review;
- to make and document certification decisions;
- to create and maintain public certificates and verification records;
- to operate the クライアントポータル and account authentication;
- to process assessment and certification payments;
- to send service, status, renewal and support communications;
- to detect misuse, impersonation, fraud and unauthorised access;
- to maintain business, accounting, audit and security records;
- to comply with applicable legal obligations;
- to enforce DigiTrustly terms and certification rules.
5. Legal bases for processing
Where the GDPR or similar privacy laws apply, DigiTrustly may rely on one or more of the following legal bases depending on the activity:
- Contract: processing necessary to provide services you request or take steps before entering into a service relationship.
- Legal obligation: processing required by law, for example certain accounting, tax or compliance records.
- Legitimate interests: activities such as service security, fraud prevention, maintaining certification integrity, defending legal claims and operating our business, where those interests are not overridden by your rights.
- Consent: where we specifically ask for consent for a processing activity that requires it.
6. Public certificate and verification data
DigiTrustly certification is designed to be 検証できるべきです。 For that reason, approved certificates may have a public record that displays information such as certificate ID, certified subject or organisation, certified website or relevant asset, issue information, current status and verification links.
Expired, suspended or revoked records may remain publicly accessible where maintaining historical verification status is necessary to prevent confusion, misuse or false claims of active certification.
7. Payments and the DigiTrustly payment environment
DigiTrustly may use a separate payment environment to process assessment and certification fees. Order data may be linked to the relevant application or client account so that DigiTrustly can identify whether an assessment fee or certification-period fee has been paid.
Payment processors may collect and process payment-card, banking or transaction information under their own terms and privacy notices. DigiTrustly generally receives payment confirmation and transaction references rather than full card credentials.
9. International data transfers
DigiTrustly is intended for international use and some service providers or infrastructure may operate in multiple countries. Where applicable law requires safeguards for international transfers, DigiTrustly aims to use appropriate mechanisms such as contractual safeguards or providers offering legally recognised transfer protections.
10. How long we keep information
Retention depends on the type of data and why it is needed. DigiTrustly may retain data for certification administration, audit history, accounting, security, fraud prevention, dispute handling and legal compliance.
| Category | Typical reason for retention |
|---|---|
| Application and decision records | Certification history, audit trail and dispute handling |
| Order and payment records | Accounting, tax and transaction history |
| Public certificate records | Verification and historical status |
| Security logs | Fraud prevention and incident investigation |
| Support correspondence | Customer support and dispute history |
Specific retention periods may vary depending on law, risk, service type and whether a dispute or investigation is ongoing.
11. Security
DigiTrustly uses technical and organisational measures designed to protect personal data and service integrity. Depending on the service, these may include encrypted network connections, restricted reviewer and administrative access, separate client functions, authentication controls, one-time security codes, backups and security logging.
No online system can guarantee absolute security. Users are responsible for protecting their credentials and should promptly report suspected unauthorised access.
13. Your privacy rights
Depending on your location and applicable law, you may have rights to request access, correction, deletion, restriction, portability or objection, and to withdraw consent where processing is based on consent.
These rights may be subject to lawful exceptions. For example, DigiTrustly may need to retain certain accounting, anti-fraud, contractual or certification audit records even after a deletion request.
Where GDPR applies, you may also have the right to complain to a competent data protection supervisory authority.
14. Children
DigiTrustly certification services are primarily intended for organisations, professionals and persons legally able to enter into the relevant service relationship. DigiTrustly does not seek to collect unnecessary personal data from children.
15. Changes to this プライバシー Policy
We may update this プライバシー Policy when our services, technology, providers or legal obligations change. The current version applies from the “Last updated” date shown at the top of this page.
16. お問い合わせ and privacy requests
certification@digitrustly.com
Use the same contact address for questions about certificate data or public verification records.
We may request reasonable information to verify the identity of a person making a privacy request before taking action.
