This policy applies to:
• Institutions (colleges and universities) that onboard to use CertiOwn.
• Users (students, faculty, coordinators, HODs, principals, admins) whose accounts are created within an Institution's CertiOwn instance.
If you are a student or staff member, your Institution creates your account and controls your academic records. CertiOwn acts as a processor for that data under the direction of the Institution, and a controller for direct account management data.
• Account & Identity Data: Name, email address, role (student/faculty/HOD/admin), institutional affiliation, and securely hashed login credentials.
• Academic & Event Data: Certificates issued, event registrations, attendance records, roll/enrollment numbers, departments, and other academic details provided by your Institution.
• Usage Data: Log-in activity, session data, browser/device information, IP address, and general usage patterns to help us maintain and improve platform security and performance.
• Payment Data: When our fees payment feature launches, processing will be handled directly by a secure third-party gateway. CertiOwn does not store card or bank details.
We use collected data to: operate the platform (issue certificates, manage events, and run ERP workflows); authenticate and secure user accounts; communicate critical updates (password resets, OTPs, certificate issuance confirmations via Resend); improve services; and comply with legal requirements. We do not sell your personal data to third parties, and we do not use your data for advertising.
4. Where Your Data Is Stored
Your data is stored on secure cloud servers hosted via Supabase in Singapore, with Redis utilized for caching and session management. By using the Service, users in India acknowledge this cross-border transfer of personal data. We take all necessary technical and organizational measures to protect your data in line with India's Digital Personal Data Protection Act (DPDP Act, 2023).
5. Third-Party Services We Use
We rely on the following industry-standard providers to run CertiOwn:
• Supabase: Database hosting (Singapore)
• Redis: Caching and session management
• Resend: Transactional email delivery
• NextAuth: Secure authentication
As we scale (e.g., adding Google Sign-In or analytics), we will update this list accordingly.
We retain your data as long as your account is active or as required by your Institution. If your Institution terminates its relationship with us, or you request account deletion, we will delete or anonymize your personal data within 30 days, except where we are required to retain it for legal, security, or verification purposes (e.g. issued certificates must remain verifiable).
Depending on your location and role, you have the right to: access the personal data we hold about you; request correction of inaccurate data; request deletion of your data (subject to legal/record-keeping exceptions, such as public verification of certificates); and withdraw consent where processing is based on consent. To exercise these rights, please email campus@certiown.in.
We employ industry-standard security safeguards, including HTTPS encryption for all data in transit, AES-256 database encryption at rest, secure password hashing, and strict role-based access control (RBAC). While no system is 100% secure, we take reasonable steps to prevent data breaches and will notify affected parties as required by law.
CertiOwn is used in educational contexts and may process data of students under 18. We only collect minors' data provided or authorized by the Institution for legitimate academic/administrative purposes, and we do not use this data for marketing or profiling.
10. Changes to This Policy
We may update this Privacy Policy as our services evolve (e.g. when launching the fees module or adding social logins). We will update the "Last updated" date and notify institutions directly of any material changes.