CertGuard

Data Processing Agreement (DPA)

You are the controller of your employees' personal data; CertGuard is the processor.

DRAFT — this legal text must be reviewed by a lawyer before publication. Do not rely on it as a final agreement.

1. Parties

Controller: [customer name, address, registration number]. Processor: [CertGuard legal entity, address, registration number]. VERIFY: fill in the legal details.

2. Subject matter and duration

The processor processes personal data solely to maintain training and examination records and to send reminders, for the duration of the subscription. VERIFY.

3. Types of personal data

Name, work email, job role, completion and validity dates, and uploaded certificates. Medical results, diagnoses and reasons are not processed.

4. Categories of data subjects

The customer's employees and contractors whose obligations the customer tracks.

5. Sub-processors

Hosting and database: Supabase (EU, Frankfurt). Email: Resend. Payments: Stripe. Application hosting: Vercel. VERIFY: confirm and complete before publishing.

6. Security measures

Encrypted transport (TLS), per-organisation isolation enforced at the database level (RLS), private file storage with scoped access, access limited to signed-in members.

7. Deletion and return of data

The customer may export all data at any time. On a deletion request, data is permanently deleted after a 30-day grace period. Reminder records are kept for 24 months.

8. Place of processing

Data is processed on servers within the European Union.

Where is my data?

On servers in the European Union (Frankfurt). Each organisation sees only its own records — isolation is enforced at the database level, not just in the application.

What we store

Names, work emails, job roles, completion and validity dates, and uploaded certificates.

What we never store

Medical results, diagnoses or reasons. For a medical examination we store only the date and its validity.