Who this notice covers
This notice applies to Certifiedge direct users and explains how roles change when Certifiedge processes information for a school, organization, employer or partner. The exact operator/controller identity is provided by the Legal Identity Registry.
Data we process
Depending on the service, Certifiedge may process account/contact data, learning activity, child/family relationships, submitted evidence, assessment/review records, credential/verification records, organization membership, support communications, security logs, billing records and optional AI/analytics information.
Why and on what basis
Each processing activity must have a documented purpose and lawful basis before processing. Certifiedge does not use consent as a blanket basis where another basis is actually relied on. Optional features that depend on consent must remain usable without coercive bundling where the processing is not necessary for the service.
Controller and processor roles
For direct individual services Certifiedge generally determines the purposes of its own processing. For institution/organization-directed records Certifiedge may act as processor while separately acting as controller for its own security, billing, support, legal compliance and platform integrity.
Children
Child data receives heightened protection, guardian/institution relationship controls, privacy by default, no public Proof Passport, no durable child AI memory and no advertising profiling. Child processing must protect and advance the child’s rights and best interests.
AI and automated processing
AI assistance is governed by access, source, memory and authority controls. Certifiedge does not design AI to make the reserved consequential decisions identified in the AI policies. Where significant automated processing would apply, applicable notice and human-review rights are preserved.
Sharing and recipients
Data is disclosed only for defined service, contractual, legal, security or user-authorized purposes. Provider and recipient categories are maintained in the Subprocessor/Third-Party Register. Public sharing is not the default for learner evidence.
International transfers
Cross-border transfers require a documented transfer basis and safeguards appropriate to the data/context. Deployment configuration must identify actual hosting, email, AI, analytics and other providers before public effective status.
Retention
Certifiedge maintains a retention schedule by data class and purpose. Data is not retained merely because storage is available. Legal holds, financial duties, safeguarding, assessment integrity and audit needs may justify retention after optional profile data is erased.
Your rights
Depending on the context and law, users can request information, access, correction, objection/restriction, erasure, withdrawal of consent and review of significant automated decisions. Child rights are exercised through appropriate guardian/authorized processes while respecting the child’s best interests.
Security and breach response
Certifiedge applies technical and organizational controls, access restrictions, audit logging and incident workflows. Breach notification follows the statutory trigger and timelines that apply; the policy does not promise notification where the law does not require it.
Complaints
Users can raise privacy concerns through the Certifiedge data-rights/complaints routes and retain the right to complain to the Office of the Data Protection Commissioner where applicable.
Questions or requests
Use the Certifiedge contact, complaints or data-rights route appropriate to the issue. Internal policies do not remove rights or remedies available under applicable law.