Legal

Privacy Policy

Last updated: June 17, 2026

1. Who we are

CertControl ("we", "us", "our") provides a certificate and document validity tracking platform for maritime seafarers and other regulated professionals. This policy explains how we process your personal data in accordance with the EU General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018.

2. Data we collect

  • Account data: name, email, password hash, profession, industry.
  • Certificate data: licence titles, issue & expiry dates, issuing authority, uploaded documents.
  • Usage data: log-in events, device and browser metadata, IP address.

3. How we use your data

We process your data to deliver the service (Art. 6(1)(b) GDPR — contract), to send expiry reminders you have configured (Art. 6(1)(a) — consent), and to keep our platform secure and lawful (Art. 6(1)(f) — legitimate interests).

4. Sharing

We do not sell your data. We share it only with the sub-processors needed to run the service (hosting, transactional email, analytics) under written DPAs.

5. Your rights

You may access, rectify, export, restrict, or erase your personal data at any time from your account settings or by emailing privacy@certcontrol.cloud. You may also lodge a complaint with your local supervisory authority.

6. Retention

Account and certificate data are retained while your account is active and for up to 90 days after deletion to satisfy backup and audit requirements.

7. Contact

Questions about this policy? Write to privacy@certcontrol.cloud.

See also our Terms of Service.