Privacy
This page describes how the Certalyn platform handles personal data. It is a description of the software’s behaviour, not legal advice, and it is pending review before commercial launch.
Two different responsibilities
Certalyn is used by organisations to issue credentials to people. That creates two separate roles, and it matters which one you are dealing with.
The issuing organisation decides who receives a credential, what it records, and how long it is kept. Questions about a particular credential — why it was issued, why it was withdrawn, or a request to correct or remove it — are for that organisation, whose name appears on the verification page.
Techvora operates the platform that stores and serves those records. Questions about the service itself can be sent to support@techvora.net.
What is stored about a recipient
Only what the issuing organisation enters: a name, and optionally an email address, an employer and its own internal reference. A recipient does not need a Certalyn account and is never asked for a password.
A credential also stores what was issued — its name, the issue and expiry dates, and any fields the organisation configured.
What a verifier can see
Verification pages default to the minimum: the credential name, the issuer, the issue and expiry dates, the reference, the current status, and the holder’s name in whichever form the issuer chose — in full, as initials, or withheld entirely.
An email address, a phone number, an employer, an internal reference, a private note and the reason a credential was withdrawn are never shown to a verifier. Additional fields appear only where the issuing organisation has explicitly published them.
Verification pages are not indexed by search engines, and credential references carry enough randomness that they cannot be worked through to discover other credentials.
Verification activity
When a credential is checked, Certalyn records that a check happened, when, and what the answer was, so an issuer can see how often its credentials are being verified.
It does not record the IP address, the device, the browser or the location of the person doing the checking. Network addresses are used only, in a hashed form that is never written down, to limit abuse of the public verification page.
Retention
An issued credential is a historical record. Expiry and withdrawal change what a verifier is told; they do not delete the record, because a credential that quietly vanished would be indistinguishable from one that had never existed — which would make verification worthless.
Removing an organisation’s account is deliberately separate from deleting the credentials it issued, and is handled as a described process rather than a single irreversible click.
What Certalyn does not claim
Certalyn confirms its own record of what an organisation issued. It has not checked that the holder attended a course, passed an assessment or earned a qualification, and no status shown on a verification page should be read as saying so.
Using Certalyn does not by itself make an organisation compliant with data protection law. The features here are intended to help a responsible organisation operate well; the obligations remain that organisation’s own.
Contact
About the platform: support@techvora.net. About a specific credential: the organisation named on its verification page.
Back to Certalyn · A Techvora Product