Privacy Policy
1. Data Controller and Contact
The data controller within the meaning of the General Data Protection Regulation (GDPR) is:
EUCERTA AG Email: support@eucerta.eu Website: www.eucerta.eu
For questions regarding data protection or to exercise your data subject rights, please contact us at the email address above.
2. General Information on Data Processing
We process personal data of our users only to the extent necessary to provide our website, our SaaS platform (EUCERTA Management System), and our certification services. The processing of personal data generally takes place only with the user's consent or in cases where prior consent cannot be obtained for practical reasons and the processing is permitted by law.
3. Legal Bases for Processing
The processing of personal data is based on the following legal grounds:
Art. 6(1)(a) GDPR – Consent: Where we obtain the consent of the data subject for processing activities, e.g., for sending marketing emails or the use of certain cookies.
Art. 6(1)(b) GDPR – Performance of contract: Processing is necessary for the performance of a contract, in particular for the provision of the SaaS platform, conducting audits, issuing certificates, and payment processing.
Art. 6(1)(c) GDPR – Legal obligation: Processing is necessary to comply with a legal obligation, e.g., tax retention requirements.
Art. 6(1)(f) GDPR – Legitimate interest: Processing is necessary for the purposes of legitimate interests pursued by EUCERTA, e.g., improving the platform, fraud prevention, or IT security.
4. What Data We Process
4.1 Account Data (Registration and Platform Use)
When creating a customer account and using our SaaS platform, we process the following data:
First name and last name, company name (for business customers), email address, telephone number (optional), postal or business address, username and encrypted password, IP address and device information upon login.
Legal basis: Art. 6(1)(b) GDPR (performance of contract) Retention period: For the duration of the contractual relationship, thereafter in accordance with statutory retention periods (generally 6 to 10 years)
4.2 Payment and Transaction Data
Payment processing is handled by our payment service provider Digistore24 GmbH. EUCERTA itself does not store complete payment data (e.g., credit card numbers). The following data is processed in the context of payment processing:
Payment method (type, e.g., credit card, PayPal, SEPA), transaction ID and payment status, billing address, payment date and amount.
Legal basis: Art. 6(1)(b) GDPR (performance of contract) Retention period: In accordance with tax retention periods (10 years for invoices and accounting records)
4.3 Audit and Certification Data
In the context of our certification services, we process the following data:
Documents and evidence uploaded by the customer as part of the audit process, answers to audit questions within the platform, results and assessments of audit procedures, issued certificates including certificate number, scope, date of issue, and expiry date.
Legal basis: Art. 6(1)(b) GDPR (performance of contract) Retention period: Certificate data is stored for the duration of the certificate's validity (24 months) plus statutory retention periods. Audit documentation is retained in accordance with the requirements of the respective ISO standards.
4.4 Platform Usage Data
When using our SaaS platform, the following technical data is automatically collected:
IP address, browser type and version, operating system, date and time of access, pages and functions accessed within the platform, time spent and interactions, referrer URL.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in ensuring IT security and improving the platform) Retention period: Server log files are automatically deleted after 30 days
4.5 Communication Data
When you communicate with us via email, contact form, or through the platform, we process:
Name and email address, content of the message, time of communication, any attachments.
Legal basis: Art. 6(1)(b) GDPR (for contract-related inquiries) or Art. 6(1)(f) GDPR (legitimate interest for general inquiries) Retention period: For the duration of processing the inquiry, thereafter in accordance with statutory retention periods
5. Recipients and Disclosure of Data
5.1 Digistore24 GmbH (Payment Processing)
EUCERTA uses Digistore24 GmbH, St.-Godehard-Straße 32, 31139 Hildesheim, Germany, as a reseller and payment processor. During the ordering process, your payment data is transmitted directly to Digistore24 and processed there. The privacy policy of Digistore24 can be found at: https://www.digistore24.com/page/privacy
5.2 Hosting and Infrastructure
Our SaaS platform is hosted on servers within the European Union (EU) or the European Economic Area (EEA). We employ technical and organizational measures to ensure the security of your data.
5.3 Other Recipients
Your personal data will only be disclosed to third parties to the extent that this is necessary for the performance of the contract (e.g., to payment service providers), you have expressly consented, there is a legal obligation to disclose, or the disclosure is permissible to protect legitimate interests and is compatible with your data protection interests.
Transfer of personal data to third countries (outside the EU/EEA) does not generally take place. Should such a transfer be necessary in individual cases, we ensure an adequate level of data protection through appropriate safeguards (e.g., EU Standard Contractual Clauses, adequacy decisions of the EU Commission).
6. Cookies and Tracking
6.1 Technically Necessary Cookies
Our website and platform use technically necessary cookies that are required for the operation of the site and the provision of our services. These cookies include session cookies to maintain your login, authentication cookies for account security, and preference cookies to store your language preference and platform settings.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in operating the website)
6.2 Analytics and Marketing Cookies
To the extent that we use analytics or marketing cookies (e.g., Google Analytics, Meta Pixel, or comparable services), we obtain your express consent via a cookie banner before their activation. You may withdraw your consent at any time with effect for the future.
Legal basis: Art. 6(1)(a) GDPR (consent)
7. Your Rights as a Data Subject
Under the GDPR, you have the following rights:
Right of access (Art. 15 GDPR): You have the right to request information about the personal data we process about you.
Right to rectification (Art. 16 GDPR): You have the right to request the correction of inaccurate or the completion of incomplete personal data.
Right to erasure (Art. 17 GDPR): You have the right to request the deletion of your personal data, provided no statutory retention obligations apply.
Right to restriction of processing (Art. 18 GDPR): You have the right to request the restriction of the processing of your data.
Right to data portability (Art. 20 GDPR): You have the right to receive the personal data concerning you in a structured, commonly used, and machine-readable format.
Right to object (Art. 21 GDPR): You have the right to object at any time, on grounds relating to your particular situation, to the processing of your data where the processing is based on Art. 6(1)(f) GDPR.
Right to withdraw consent (Art. 7(3) GDPR): You have the right to withdraw consent at any time with effect for the future.
Right to lodge a complaint (Art. 77 GDPR): You have the right to lodge a complaint with a competent data protection supervisory authority.
To exercise your rights, please contact: support@eucerta.eu
8. Data Security
EUCERTA employs extensive technical and organizational measures pursuant to Art. 32 GDPR to protect your personal data against accidental or intentional manipulation, loss, destruction, or access by unauthorized persons. Our security measures include, among others:
Encryption of data transmission via TLS/SSL, encrypted storage of sensitive data, access control and authorization management, regular security updates and vulnerability assessments, backup systems and disaster recovery procedures.
Our security measures are continuously adapted to the current state of technology.
9. Retention and Deletion
Personal data is deleted or blocked as soon as the purpose of storage no longer applies and no statutory retention obligations exist. The following specific retention periods apply:
Contract data: For the duration of the contractual relationship, thereafter 10 years in accordance with commercial and tax law retention periods.
Certificate data: For the duration of the certificate's validity (24 months) plus a verification period of at least 3 years.
Invoicing data: 10 years from the end of the calendar year in which the invoice was issued.
Server log files: 30 days.
Communication data: 3 years after completion of the communication, unless longer retention is required by law.
10. Protection of Minors
Our services are exclusively intended for persons who are at least 18 years of age. We do not knowingly collect personal data from minors.
11. Changes to This Privacy Policy
We reserve the right to amend this privacy policy to adapt it to changes in the legal situation or changes to our services. The current version is always available on our website at www.eucerta.com.
Effective: February 2026