Privacy Policy

Privacy Policy for the certification portal

Last updated: 2026-08-26

This Privacy Policy is issued by VIVO Group BV, a limited liability company under Belgian law with its registered office at Kasteelstraat 62, 3360 Korbeek-Lo, Belgium, registered under company number 0778.676.507 (RLE Leuven) and trading under the name “certN” (hereinafter: “certN,” “certN.global,” “us,” “we,” or “our”). certN operates the Website reachable through the certN.global domain and its sub-domains. This Privacy Policy applies to all services and products offered on certN.global and its sub-domains. It does not apply to other websites or sources, even where we link to them; certN is not responsible for the privacy practices of those websites and sources. Purchases of digital products through the VDS portal are covered by the separate [Privacy Policy for the Voucher Distribution System (VDS) below, and examiners and invigilators working with certN are also covered by a separate privacy policy.

certN respects the privacy of all its users and treats the personal data you provide as confidential, unless stated otherwise in this Privacy Policy. On this page, we explain which data we collect when you use our Website, why we collect it, how long we keep it, and with whom we share it. We provide this information so that you understand exactly how we work.

When you create an account, we ask you to confirm that you have read this Privacy Policy. Reading it is not what permits us to process your data: most of what we do with your data is necessary in order to provide the exam and certification services you have asked for, or rests on one of the other legal grounds set out in Section II.

You need to be at least 18 years old to create an account on certN.

I. Which data do we collect?

There are three sources of personal data at certN:

  1. Data we receive from you
  2. Data we receive automatically
  3. Data we receive from third parties

For each source, the following three sections explain what triggers the collection, exactly which data we collect, and how long we keep them.

1. Data we receive from you

2. Data we receive automatically

3. Data we receive from third parties

II. Why do we collect these data?

This section sets out what we use your data for and which legal ground applies in each case. The legal grounds are those listed in Article 6 of the General Data Protection Regulation (“GDPR”).

Automated decisions and artificial intelligence

We do not use artificial intelligence in our own handling of your personal data. No decision we take about you — your exam result, your certification, the outcome of an invigilation review — is made or prepared by an AI system.

For invigilation in particular, we can be categorical: exams that are invigilated remotely are reviewed by people, and only by people. A human invigilator watches the session, live or afterwards from the recording. We do not use automated behaviour analysis, gaze or emotion detection, facial recognition, or any other automated system to decide, or to help decide, whether something went wrong during your exam. Where a session is questioned, a person looks at it and a person decides.

Like every company, we use software from other vendors — for example to host our servers or run our support channels — and we cannot rule out that such a tool uses machine learning internally for routine functions such as filtering spam or securing systems. What we can say is that no vendor tool analyses your data to make or influence any decision about you, and that we do not permit our processors to use your data for their own purposes, including training AI models.

We do not carry out automated individual decision-making, including profiling, within the meaning of Article 22 of the GDPR.

III. Data retention periods

Your personal data are processed for no longer than the retention periods listed in Section I.

When a retention period comes to an end, we delete your personal data: your name, your email address, your exam results and your contact history with us all go. The one exception is a sanction that is still in effect: we keep the record of that sanction for as long as it lasts, because we could not enforce it otherwise (see Section I).

You may choose to show your downloaded certificate to someone after your data have been deleted, and for that reason we keep the initials of your name, which still allows the certificate to be checked with an acceptable degree of confidence.

From then on, entering the certification code returns:

Someone who you decide to share your certificate code with can therefore still confirm that an achievement of that description was issued at that time, that it has not been withdrawn, and that the initials correspond to the name on the document in front of them.

We should be straightforward that this is a good check rather than a perfect one. Matching initials is less precise than matching a full name, and we accept that limitation deliberately: keeping a named record of you indefinitely would be a greater intrusion into your privacy than the additional certainty would justify. We would rather hold less about you.

IV. Your rights

You can access your personal data and have them rectified or erased, free of charge. You also have the right to restrict the processing of your personal data.

You have the right to object, on grounds relating to your particular situation, to any processing we base on our legitimate interests (Article 6(1)(f) — see Section II). If you object, we will stop that processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed for legal claims.

Where we process data based on your consent, such as Accommodation Data, you can withdraw that consent at any time. Withdrawing consent does not affect the lawfulness of what was done before you withdrew it.

Moreover, you have the right to data portability for the personal data you have provided to certN, to the extent that certN still retains them. If you want more information on your rights, you can always contact us or consult the website of the Belgian Data Protection Authority: https://www.dataprotectionauthority.be/en

To exercise these rights, please send a request to the address mentioned below, stating clearly what it is you want to access, rectify or erase.

Normally, a request sent from the email address on your account is enough. If we have a genuine reason to doubt that a request comes from you, we may ask for additional information to confirm your identity — but only where that is necessary, and we will ask for the least we can.

We will respond to your request within one month of receiving it. If your request is complex, or if you have made several, we may extend this by up to two further months; if we do, we will tell you within the first month and explain why.

If you are not satisfied, you can lodge a complaint with a data protection supervisory authority. Our lead authority is the Belgian Data Protection Authority (https://www.dataprotectionauthority.be/en), because certN is established in Belgium. You may also complain to the supervisory authority in the country where you live or work, or where you believe the problem occurred. You are welcome to raise the matter with us first, but you are not required to.

V. Cookies

We only use a limited number of first-party cookies that are strictly necessary for saving session information (e.g., your preferred colour scheme) and for keeping you logged in to the platform. These are kept for maximum one year.

We measure the use of our Website with Matomo, an analytics tool that we host on our own servers in Germany: no analytics data is shared with, or accessible to, any third party. Matomo is configured to work without cookies.

VI. Security measures

certN has taken appropriate technical and organizational measures to ensure that your personal data are processed securely. If you have any questions about these security measures, feel free to contact us at the address mentioned below. Within certN, personal data are only available to people who need access to them for their job.

We will never sell or rent out your personal data to third parties. We may occasionally use an external processor. If we do, we always ensure that your data are handled confidentially and securely, and we always conclude a data processing agreement with the processor, as required by Article 28 of the GDPR. This means the processor may only use your data on our documented instructions, never on its own initiative, and must erase your data as soon as the assignment has been completed.

VII. Who has access to your data?

Certification Partners

Each certification program is created and offered in cooperation with a small number of Certification Partners that cover various aspects of the program, such as content and accreditation services.

We may share some of your personal data related to a specific certification with the Certification Partners of that program, to the extent necessary to provide you the certification services (e.g., recording your achievement in related directories). We require every Certification Partner to comply with data protection law. Where a Certification Partner processes your data for its own purposes, it does so as a separate controller under its own privacy policy; for information on those practices, please refer to the privacy policies of the Certification Partners.

These Certification Partners receive access to the following:

Certification Partners never receive Invigilation Data: the recordings are not shared with them. Where an appeal or an investigation requires it, they may receive a written report of what the invigilator observed, but not the footage itself.

The organization that provided your voucher

Exam vouchers are distributed by trainers, training organizations, and exam distributors, who order them through our Voucher Distribution System (VDS). The organization that ordered your voucher can see, in its VDS account, the data resulting from that voucher:

An organization that holds your voucher code because it supplied the voucher to you, but did not order it through its own VDS account, can also retrieve the same data. An organization with a managed account can enter the code in its account and is given access automatically; we know who these organizations are, because managed accounts are only created manually by certN for accredited trainers, training organizations, and exam distributors. A trainer without a managed account can request the data by email; in that case, we first verify that the requester is indeed a known trainer before providing anything.

In every case, this works by possession of the voucher code: an organization only sees or receives the data belonging to voucher codes it ordered itself or supplied to you, and it cannot look up any other candidate. Treat your voucher code as confidential once it is yours: whoever holds it can ask us about that voucher. If you obtained your voucher directly from us and have shared the code with no one, no organization sees your data. Organizations process this data as independent controllers, bound by the Provisions specific to managed accounts in our Terms and Conditions, for following up on the vouchers they distributed and on the training they provided.

Individuals verifying your achievement

When an achievement is issued for you, it is included in the certification verification directory with the following information:

This information is accessible to anyone who knows the unique certification code of the achievement. This is a 32-character code that belongs to that certificate and to no other. The code is the key, and you hold it. Our verification page cannot be searched by name: there is no list of certified people to browse, and typing someone’s name into it will not find them. The only way to retrieve a certificate is to have its code, and the code appears on your certificate and on your social badge. Your details can therefore only be looked up by someone you have chosen to share your certificate or badge with.

Once you have shared your certificate or badge with someone, we cannot control whether they pass the code on, and we cannot see who has used a code to run a check.

Why we do it this way

A certificate is only worth something if the person you show it to can confirm that it is real. The check also protects you: if someone alters a certificate, or copies your code onto a document carrying their own name, the details shown when the code is checked will not match the document they are holding.

If you would rather not be listed

You can ask us at any time to remove your details from the verification directory by emailing support@certN.global. Keep in mind that this means we can no longer definitively verify your achievement for third parties.

VIII. Where your data are processed

All personal data are stored on servers located in Germany, within the European Economic Area, with one exception: our email provider, Fastmail, stores email on its servers in the United States. This concerns the content of email conversations you have with us and the messages we send you (such as login codes); everything else — your account, exam data, recordings, and support chat — stays in Germany. We have a data processing agreement with Fastmail that includes the European Commission’s Standard Contractual Clauses for this transfer.

Some of the people who work for us do so from outside the EEA: part of our invigilation team and part of our support team are based ouside the EEA. When they view invigilation recordings or handle your support request, they access the data remotely on our German servers, through our portal. Under the GDPR, this remote access counts as a transfer of your data to those countries.

The invigilators and support agents based there work for us as independent contractors, and we have concluded the European Commission’s Standard Contractual Clauses (Article 46(2)(c) GDPR), together with a data processing agreement, with each of them individually. These are supplemented by technical and organizational measures: access is remote and view-only, encrypted in transit, logged, limited to what the specific task requires, and no personal data is stored locally in those countries.

Only the data needed for the task is accessible this way:

You can request a copy of the Standard Contractual Clauses by writing to data-protection@certN.global.

IX. Contact information of the data controller

For all questions or complaints regarding this Privacy Policy, you can contact us at the following email address: data-protection@certN.global

If you have a complaint regarding the processing of your personal data, you can also address it by registered mail to:

VIVO Group BV
Data Protection Desk
Kasteelstraat 62
3360 Korbeek-Lo
Belgium

You can also contact the Belgian Data Protection Authority (https://www.dataprotectionauthority.be/en) to assist you or to file a complaint.

Privacy Policy for the Voucher Distribution System (VDS)

Last updated: 2026-08-26

This Privacy Policy is issued by VIVO Group BV, a limited liability company under Belgian law with its registered office at Kasteelstraat 62, 3360 Korbeek-Lo, Belgium, registered under company number 0778.676.507 (RLE Leuven) and trading under the name “certN” (hereinafter: “certN,” “us,” “we,” or “our”).

This Privacy Policy applies only to the purchase of digital products (such as exam vouchers) through the VDS portal (vds.certn.global). Everything that happens after your purchase — creating an account on the exam portal, redeeming your voucher, taking an exam, receiving a certificate — is covered by our main Privacy Policy above, not this one. This document is deliberately short, because the VDS portal does one thing: it sells you a digital product and delivers it by email.

I. Which data do we collect?

What we do not collect: your payment details. Payments are handled by PayPal and Stripe (see Section III). Your card number, bank details, or PayPal credentials are entered directly with them and never reach our systems. We only receive confirmation that the payment succeeded, together with a payment reference and, where relevant, the country in which your payment method was issued.

II. Why do we collect these data?

We do not use your data for marketing, we do not build profiles of you, and we do not make automated decisions about you within the meaning of Article 22 of the GDPR.

III. Payment providers

We use PayPal and Stripe to process payments. When you pay, you provide your payment details directly to them. For the processing of your payment they act as independent controllers under their own privacy policies, which we encourage you to read:

Both providers may process your data outside the European Economic Area under safeguards they are themselves responsible for; their privacy policies describe these.

IV. Where your data are processed

All Order Data and Support Data are stored on servers located in Germany, within the European Economic Area, with one exception: our email provider, Fastmail, stores email on its servers in the United States. This concerns the content of email conversations you have with us and the messages we send you (such as your voucher delivery); we have a data processing agreement with Fastmail that includes the European Commission’s Standard Contractual Clauses for this transfer.

Part of our support team is based outside the EEA. When they handle your question about an order, they access Order Data and Support Data remotely on our German servers, through our portal. Under the GDPR, this remote access counts as a transfer of your data to those countries. We have concluded the European Commission’s Standard Contractual Clauses (Article 46(2)(c) GDPR), together with a data processing agreement, with each of these independent contractors individually, supplemented by technical and organizational measures: access is remote and view-only, encrypted in transit, logged, limited to what the specific task requires, and no personal data is stored locally in those countries. You can request a copy of the Standard Contractual Clauses by writing to data-protection@certN.global.

V. Who has access to your data?

We will never sell or rent out your personal data. Beyond the payment providers described in Section III and the support arrangement described in Section IV, your data is only accessible to the people at certN who need it for their job, and to processors (such as our hosting provider) bound by a data processing agreement under Article 28 of the GDPR.

If you redeem your voucher on the exam portal, the data processed there — including the link between your voucher and your exam — is governed by our main Privacy Policy above.

Managed accounts and candidate data. Managed accounts show their holders the status of the vouchers they ordered, including who redeemed them and, after the exam, the candidate’s result and score. An organization can also retrieve the same data for a voucher it supplied to a candidate outside its own VDS orders, by entering the voucher code in its managed account, or — for verified accredited trainers without a managed account — by requesting it from us by email. This candidate data is processed and disclosed under Section VII of our main Privacy Policy (“The organization that provided your voucher”), not under this document. Users of a managed account may only access it for the certification purposes of their organization.

VI. Your rights

You have the same rights over your data as under our main Privacy Policy: access, rectification, erasure, restriction, data portability, and the right to object to processing based on our legitimate interests — all free of charge. Note that we cannot erase invoice data that the law requires us to keep; in that case we will tell you so and delete whatever we are not obliged to retain.

To exercise these rights, email data-protection@certN.global, stating clearly what you want. A request sent from the email address used for your order is normally enough. We will respond within one month; for complex or multiple requests we may extend this by up to two further months, in which case we will tell you within the first month and explain why.

If you are not satisfied, you can lodge a complaint with the Belgian Data Protection Authority (https://www.dataprotectionauthority.be/en) or with the supervisory authority in the country where you live or work. You are welcome to raise the matter with us first, but you are not required to.

VII. Contact information of the data controller

For all questions or complaints regarding this Privacy Policy: data-protection@certN.global

Or by registered mail:

VIVO Group BV
Data Protection Desk
Kasteelstraat 62
3360 Korbeek-Lo
Belgium