Privacy Policy

Last updated: April 11, 2026 · Effective for all users of certify.ma

certify SAS ("we", "us", "our") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and protect information when you use the certify.ma platform. We comply with Morocco's Law 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data, administered by the CNDP, as well as the EU General Data Protection Regulation (GDPR) where applicable.

Legal professional reviewing data protection documents

1Information We Collect

  • Account Information: When you register, we collect your name, email address, institution affiliation, and role (student, administrator).
  • Credential Data: For institutions, we store the credential metadata you submit (degree names, dates, student identifiers). For students, we store credentials issued to your account.
  • Usage Data: We automatically collect device type, browser version, IP address (anonymized), and page interaction data to improve our service.
  • Communication Data: If you contact support or use the feedback widget, we store your message content and contact details.

2How We Use Your Data

  • Service Delivery: To issue, store, verify, and share academic credentials as requested by institutions and students.
  • Security: To detect and prevent unauthorized access, brute force attacks, and fraudulent credential submissions.
  • Analytics: To understand platform usage patterns and improve the user experience (aggregated, anonymized data only).
  • Communication: To send transactional emails (credential notifications, password resets) and, with consent, product updates.

3Data Sharing

  • We never sell your personal data to third parties.
  • Credential data is only shared when you explicitly generate a share link with a defined expiry date.
  • We may share anonymized, aggregated statistics with institutional partners (e.g., total verifications by country).
  • We may disclose data if required by Moroccan law or a valid court order.

4Data Retention

  • Active accounts: Data is retained for the duration of your account plus 2 years after account deletion.
  • Credentials: Credential metadata is retained indefinitely for verification integrity, even after account deletion.
  • Audit logs: Security and compliance logs are retained for 7 years as required by Moroccan financial regulations.
  • Share links: Expired share links are permanently invalidated but the link metadata is retained in audit logs.

5Your Rights

  • Access: You can request a complete copy of all personal data we hold about you.
  • Rectification: You can request correction of inaccurate personal data.
  • Erasure: You can request deletion of your account and personal data (credential hashes are retained for verification integrity).
  • Portability: You can export your credentials in W3C Verifiable Credential JSON format.
  • Objection: You can object to processing of your data for marketing purposes at any time.

6Security Measures

  • All data is encrypted at rest using AES-256 and in transit using TLS 1.3.
  • Passwords are hashed using bcrypt with a cost factor of 10.
  • API keys are hashed and never stored in plaintext.
  • We conduct regular security audits and penetration testing.
  • Access to production systems is restricted via role-based access control with multi-factor authentication.

7Contact

  • Data Protection Officer: [email protected]
  • Postal Address: certify SAS, Technopark, Casablanca 20000, Morocco
  • CNDP Registration Number: D-XXXX/2026 (pending)
Business partnership agreement in Moroccan office