Legal
Privacy Policy
Effective July 9, 2026
This Privacy Policy describes how Verisaf LLC (“Verisaf,” “we,” “our,” “us”) collects, uses, and protects personal information when you use our website and services.
1. Information we collect
To issue certificates and operate our service, we collect:
- Information you provide: company name, address, industry, scope of operations, chosen ISO standard(s), full name, email address, phone number, and any other details you enter into the certification flow.
- Verification data: your electronic signature on the declaration, email verification (one-time code), and the reference number of any certificate we issue to you.
- Technical data: IP address, approximate region derived from IP, device and browser information, referral source, UTM parameters, and timestamps of your activity on the site.
- Communications: messages you send us and our responses.
2. How we use your information
- To issue, verify, and manage your certificate(s).
- To communicate with you about your certificate, account, and requests.
- To operate, secure, and improve our services.
- To detect and prevent fraud or misuse of certificates.
- To comply with legal obligations.
We do not sell your personal information. We do not use your data for third-party advertising.
3. Nature of certificates and public verification
Verisaf issues three types of certificates, with different public visibility:
- Provisional certificate: self-declared, issued instantly after you complete the intake and sign the declaration. Valid for 7 days. Not accredited.
- Issued certificate: reviewed and issued by Verisaf.
- Accredited certificate: independently reviewed and issued under our accreditation processes.
When we issue a certificate, we make limited information publicly available at our verification page so anyone with your reference number can confirm the certificate: company name, standard(s), scope, country and city, reference number, and issue date. We do not expose your email address, phone number, or other private data via verification.
4. Legal bases for processing
Where applicable law (such as GDPR) requires a legal basis, we rely on:
- Performance of a contract — to provide the certification service you request.
- Legitimate interests — to secure, improve, and operate our service and to prevent misuse.
- Legal obligation — where required by law.
- Consent — where you have given it (for example, optional communications).
5. Sharing your information
We share personal information only with:
- Service providers that operate our infrastructure (hosting, database, transactional email delivery) under confidentiality obligations.
- Regulators, accreditation bodies, or authorities where required by law.
- Successors in interest in the event of a merger, acquisition, or reorganization.
6. Cookies and similar technologies
We use only strictly necessary cookies and local storage required to run the certification flow (for example, to preserve your progress between steps and keep you signed in). We do not currently use third-party advertising, marketing, or cross-site tracking cookies. If this changes, we will update this page and, where required, ask for your consent before setting any non-essential cookies.
7. Data retention
We retain your information for as long as your certificate is active and thereafter for a reasonable period consistent with our legal, accounting, and audit obligations. You can request deletion of your data by contacting us; where a certificate has been issued, some records may need to be retained to preserve the integrity of the verification record.
8. Your rights
Depending on where you live, you may have rights to access, correct, delete, export, or restrict the processing of your personal information, and to object to certain processing. To exercise these rights, contact us at the address below. We will respond within the timeframes required by applicable law.
9. Security
We use industry-standard measures — encryption in transit, restricted access controls, and secure infrastructure — to protect your information. No method of transmission or storage is entirely secure, and we cannot guarantee absolute security.
10. International transfers
Our infrastructure may process data outside your country of residence. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for international transfers.
11. Children
Our services are intended for businesses and are not directed to children under 16. We do not knowingly collect personal information from children.
12. Changes to this policy
We may update this policy from time to time. The “Effective” date at the top reflects the latest version. Material changes will be announced on the site.
13. Contact
Questions or privacy requests: hello@verisaf.com.
Verisaf LLC. This document is a baseline template and does not constitute legal advice. Please have counsel review before reliance on it in production.