Privacy Policy
Effective date: 9 June 2025
CertAlert (“we”, “us”, or “our”) is committed to protecting your personal data and respecting your privacy. This policy explains what data we collect, why we collect it, and your rights under the General Data Protection Regulation (GDPR) and the Data Protection Acts 1988–2018 (Ireland).
1. Data Controller
CertAlert is the data controller for personal data relating to account holders (Training Providers and their administrators). For personal data relating to learners and client contacts entered into the platform by a Training Provider, the Training Provider is the data controller and CertAlert acts as a data processor.
To contact us about data protection matters, please email hello@cert-alert.ie.
2. Data We Collect
Account Data
When you create an account, we collect:
- Your name and email address (via Clerk authentication)
- Your company name, contact phone number, and company logo (if provided)
- Your account role and the date your account was created
Learner and Certification Data
Training Providers may enter the following data about their clients’ employees:
- First name, last name, and email address
- Course enrolment records, attendance, and pass/fail results
- Certificate issue dates and expiry dates
- Certificate documents (PDF or image files)
This data is entered by the Training Provider and processed by CertAlert on their behalf. If you are a learner and have questions about your data, please contact your Training Provider in the first instance.
Usage and Technical Data
- Log data (IP addresses, browser type, pages visited, timestamps) for security and debugging purposes
- Error and performance data collected via Sentry
- Authentication tokens and session data managed by Clerk
3. Legal Basis for Processing
We process personal data on the following legal bases:
- Contract — to provide the Service you have signed up for (account data, billing information).
- Legitimate interests — to operate, secure, and improve the Service (usage logs, error monitoring).
- Legal obligation — to comply with applicable Irish and EU law.
- Processor — for learner and certification data, we act on the instructions of the Training Provider (data controller).
4. How We Use Your Data
- To create and manage your account
- To provide the certification management features of the Service
- To send transactional emails (e.g., certification expiry reminders, course confirmations) on behalf of Training Providers
- To respond to support requests
- To monitor, secure, and improve the Service
- To comply with our legal obligations
We will not use your personal data for marketing without your explicit consent.
5. Sharing Your Data
We do not sell your personal data. We share data only with:
- Supabase — our database and storage provider (servers located in the EU).
- Clerk — our authentication provider.
- Resend — our transactional email provider.
- Sentry — our error monitoring service.
- Vercel — our hosting provider.
- Law enforcement or regulatory bodies where required by law.
All third-party providers are selected on the basis of their data protection commitments and, where applicable, are subject to Data Processing Agreements.
6. Data Retention
We retain account data for as long as your account is active plus 30 days after closure, to allow for data export. Learner and certification records are retained for as long as the Training Provider’s account is active, unless the Training Provider requests earlier deletion.
Technical logs are retained for up to 90 days. Error reports may be retained for up to 12 months for debugging purposes.
7. Your Rights
Under GDPR, you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — request correction of inaccurate data.
- Erasure — request deletion of your data (“right to be forgotten”), subject to our legal obligations.
- Restriction — request that we limit how we process your data in certain circumstances.
- Portability — receive a copy of your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interests.
To exercise any of these rights, please email hello@cert-alert.ie. We will respond within 30 days.
If you are not satisfied with our response, you have the right to lodge a complaint with the Data Protection Commission (DPC) at dataprotection.ie.
8. Cookies
We use cookies to operate the Service. Please see our Cookie Policy for details.
9. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure. These include TLS encryption in transit, encrypted storage, access controls, and regular security monitoring.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by a notice in the platform. The current version is always available at cert-alert.ie/privacy.
11. Contact
For any data protection queries, please contact us at hello@cert-alert.ie.