Privacy Policy
What we collect, why we hold it, who processes it on our behalf, and what you can ask us to do with it.
Last updated: 4 October 2026
What we collect
- Account details — name, email address, and the company you represent
- Company profile — legal name, licence number, address and website, where you supply them
- Certification request data — the standards selected, the accreditation body, and the scope of your request
- Documents you upload in support of a certification request
- Payment records — the amount, currency, term and status of a subscription. Card details are handled by Stripe and never reach our systems
- Support correspondence and training enquiries you send us
- Usage data — pages visited and interactions, through the analytics tools listed below
Why we hold it
To assess and process your certification request, to issue and maintain a certificate, to carry out the surveillance audits that keep it valid, to take payment and manage your subscription, to respond to support and training enquiries, and to meet the record-keeping obligations that apply to an accredited certification body.
A certification body is expected to retain audit and certification records so that a certificate it has issued can be substantiated. That obligation outlives the commercial relationship.
Who processes it on our behalf
We use the following processors. Each receives only what it needs for its function.
- Supabase — hosting of the application database and user authentication
- Stripe — payment processing. Card details are entered directly with Stripe and are never stored on our systems
- Resend — transactional and notification email
- Cloudflare — content delivery, performance and protection against abuse
- Google Analytics and Google Tag Manager — usage measurement
- Meta Pixel — advertising measurement, where enabled
Certificate information that is published
Certification is a public assertion. Certificates issued through an accredited body are listed on the IAF CertSearch global registry so that anyone can confirm them, and that listing typically includes the certified organisation, the standard, the scope and the certificate status.
This is the point of accredited certification rather than an incidental disclosure. If you do not want a certificate to be publicly verifiable, accredited certification is not what you are looking for.
Your choices
- Ask for a copy of the personal data we hold about you
- Ask us to correct anything inaccurate
- Ask us to delete data we are not obliged to retain as a certification body
- Object to analytics tracking by using your browser or device controls
- Withdraw from marketing email at any time, without affecting service email about your certification
To exercise any of these, email [email protected] from the address on your account.
Security
The site is served over HTTPS with HSTS, a content security policy, and protections against clickjacking and content-type sniffing. Access to client data in the application database is governed by row-level security policies, so an account can reach its own records and not another organisation's.
No system is beyond compromise. If a breach affects your data we will tell you what happened, what it affected, and what we are doing about it.
Changes and contact
If this policy changes materially we will say so on this page. For any question about it, write to [email protected], or to ISO Order Portal, Al Garhoud, Dubai, United Arab Emirates.