Data Processing Agreement

Effective date: July 1, 2026


1. Introduction

This Data Processing Agreement ("DPA") forms part of the agreement between Certifable, Inc. ("Processor," "we," "us") and the certification agency using our platform ("Controller," "you," "your") for the provision of the Certifable service.

This DPA sets out the terms under which we process personal data on your behalf when you use our platform to manage your certification operations.

2. Definitions

  • Personal Data: Any information relating to an identified or identifiable natural person processed through the Certifable platform.
  • Processing: Any operation performed on Personal Data, including collection, storage, retrieval, use, disclosure, or deletion.
  • Sub-processor: Any third party engaged by us to process Personal Data on your behalf.

3. Scope of Processing

We process Personal Data solely to provide the Certifable service, including:

  • Storing client company contact information and user accounts
  • Managing document submissions and review workflows
  • Facilitating audit scheduling and reporting
  • Generating and delivering certificates
  • Sending automated email notifications on your behalf
  • Providing analytics and reporting dashboards

4. Categories of Data Subjects

  • Your employees and team members (agency staff)
  • Your clients' employees and representatives
  • Auditors and reviewers

5. Types of Personal Data

  • Names and contact details (email, phone, address)
  • Job titles and organizational roles
  • Account credentials (hashed passwords, session tokens)
  • Audit and inspection records
  • Document metadata and uploaded files
  • Communication logs (email delivery records)

6. Our Obligations

  • Process Personal Data only on your documented instructions
  • Ensure persons authorized to process data are bound by confidentiality
  • Implement appropriate technical and organizational security measures
  • Assist you in responding to data subject access requests
  • Delete or return all Personal Data upon termination of the service
  • Make available information necessary to demonstrate compliance
  • Notify you without undue delay of any Personal Data breach

7. Sub-processors

We use the following categories of sub-processors to deliver the service:

  • Cloud infrastructure: Hosting and compute services
  • Database services: Managed database hosting
  • Email delivery: Transactional email sending
  • File storage: Encrypted object storage for documents
  • Payment processing: Subscription billing (Stripe)

We will notify you of any intended changes to sub-processors and provide you with the opportunity to object.

8. Data Transfers

Where Personal Data is transferred outside your jurisdiction, we ensure appropriate safeguards are in place, including Standard Contractual Clauses where applicable.

9. Data Retention

We retain Personal Data for the duration of your subscription. Upon termination, we will delete all Personal Data within 30 days, unless retention is required by law. You may request data export at any time during your subscription.

10. Security Measures

We implement and maintain appropriate technical and organizational measures as described in our Security page, including encryption, access controls, and regular security assessments.

11. Breach Notification

In the event of a Personal Data breach, we will notify you without undue delay (and in any event within 72 hours of becoming aware) and provide sufficient information to enable you to meet your own notification obligations.

12. Contact

For questions about this DPA or to exercise your rights, contact us at privacy@certifable.com.