Legal
Privacy Policy
Effective June 21, 2026. Supersedes the version effective June 11, 2026.
Contents
Definitions
The following terms have the meanings given below throughout this Privacy Policy and any related notices or agreements.
Personal Data
Any data, whether true or not, about an individual who can be identified from that data alone, or from that data together with other information to which AcadCert has or is likely to have access. This includes, but is not limited to, email addresses, names, institutional affiliations, IP addresses, and credential metadata.
Processing
Any operation or set of operations performed on Personal Data, including collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission, dissemination, or making available, alignment, combination, restriction, erasure, or destruction.
Data Controller
The organisation or person who determines the purposes and means of Processing Personal Data. For platform account data and service infrastructure, AcadCert is the Data Controller. For credential content and recipient data, each participating Institution is the Data Controller.
Data Processor
A person or organisation that Processes Personal Data on behalf of, and under the instructions of, a Data Controller. AcadCert acts as a Data Processor with respect to credential data collected and submitted by Institutions.
Data Subject
An individual to whom Personal Data relates. In the context of AcadCert, this includes students, institutional staff, administrators, and any natural person whose information is held on the Platform.
Credential
A verifiable digital document issued through the Platform by an Institution to a Data Subject, typically representing an academic qualification, transcript, certificate, award, or other official record.
Platform
The AcadCert web application, API, and associated infrastructure, including the public credential verification service.
Institution
A university, college, school, training provider, or other academic or professional body that has entered into a data processing agreement with AcadCert and uses the Platform to issue Credentials.
Verifying Party
Any individual or organisation that accesses the public verification endpoint or a shared verification link to confirm the authenticity and status of a Credential. Verifying Parties are not required to identify themselves to the Platform.
Third Party
Any person or organisation other than AcadCert, the relevant Institution, and the Data Subject. Sub-processors engaged by AcadCert are a subset of Third Parties, subject to contractual obligations described in this policy.
Scope
This Privacy Policy applies to all users of the AcadCert Platform, including students, institutional issuers, administrators, and Third Parties who access the public verification service. It describes how we collect, use, store, share, and protect Personal Data.
By accessing or using AcadCert, you acknowledge that you have read and understood this policy. If you are using AcadCert on behalf of an Institution, you represent that you have the authority to accept this policy on behalf of that Institution and that the Institution has satisfied all applicable legal obligations to its staff and students in connection with the use of the Platform.
This policy does not apply to the websites of third parties that may be linked to or from the Platform. We are not responsible for the privacy practices of those third parties and encourage you to review their policies separately.
Data controller and processor
The roles of Data Controller and Data Processor under the PDPA, and analogous roles under the Australian Privacy Act 1988, are allocated as follows:
AcadCert as Data Controller
For all data collected in the course of operating the Platform, including account registration information, authentication events, session records, audit logs, and verification analytics, AcadCert determines the purposes and means of Processing and accordingly acts as Data Controller.
AcadCert as Data Processor
For Credential data and recipient information submitted to the Platform by an Institution, AcadCert acts as Data Processor and Processes that data solely in accordance with the instructions of the relevant Institution, as set out in the applicable data processing agreement.
Institution as Data Controller
Each Institution is independently and solely responsible as Data Controller for: determining the lawful basis for collecting and submitting Credential data to the Platform; ensuring the accuracy and currency of Credentials; responding to Data Subject access or deletion requests relating to the academic content of Credentials; and obtaining any necessary consents from students prior to submitting their data.
Data ownership
Students
Retain rights of access, use, and sharing over Credentials issued to them. This encompasses Personal Data rights under applicable law but does not confer authority to alter, forge, or misrepresent official institutional records. The academic validity and content of a Credential rests solely with the issuing Institution.
Institutions
Retain full authority over the issuance, accuracy, revocation, supersession, and lifecycle of Credentials they issue. Institutions are responsible for the academic validity and correctness of all Credential content submitted through the Platform.
AcadCert
Acts as a custodian and verification service provider. We do not claim ownership over academic Credentials or their contents. We do claim ownership of the Platform infrastructure, the audit log system, and all anonymised aggregated analytics derived from usage of the Platform.
Accuracy of your information
Much of the personal data we process is supplied by your Institution or entered by authorised Users, rather than collected by us directly. We rely on the accuracy and completeness of that information and do not independently verify it.
You and your Institution are responsible for ensuring that personal data submitted to the Platform is accurate, current, and lawfully provided, and for promptly correcting, or requesting correction of, any inaccuracy. We are not responsible for any consequence arising from inaccurate, outdated, or incomplete information that we were not made aware of.
Lawful basis for processing
Under the PDPA, collection, use, and disclosure of Personal Data requires a lawful basis in the form of consent, or an exception permitted by the PDPA (such as legitimate interests or legal obligation). The table below identifies the basis applicable to each category of data we Process. Australian users should note that under the Australian Privacy Act 1988, collection is permitted where reasonably necessary for our functions and activities, and the bases below map substantially to the APPs.
Account information
Contract performance: necessary to create and maintain your Platform account, authenticate your identity, and provide the services you have registered to use. Institutional enrolment by an administrator is considered acceptance on the Institution's behalf.
Credential data
Contract performance (between AcadCert and the Institution) and, where applicable, PDPA consent obtained by the Institution from the Data Subject prior to submission. AcadCert relies on the Institution's authority as Data Controller for the lawfulness of the underlying collection.
Authentication and session data
Contract performance: necessary to verify your identity at login and to maintain a secure authenticated session for the duration of your use.
Audit and security logs
Legitimate interests: to maintain the security and integrity of the Platform, detect fraud and unauthorised access, support institutional compliance requirements, and provide tamper-evident accountability records. This interest is not overridden by Data Subject interests given the narrow, security-specific scope of the processing.
Verification request data
Legitimate interests: to maintain the integrity of the verification service, detect abuse, enforce rate limits, and provide aggregate usage analytics. Verification data does not require the Verifying Party to identify themselves. Where a verification request is made publicly, the Data Subject's Credential status is processed on the basis of the Data Subject's prior consent or explicit sharing action.
Legal and compliance data
Legal obligation: where applicable law, court order, regulatory requirement, or governmental authority with valid jurisdiction requires the retention or disclosure of specific data.
Information we collect
Account information
Email addresses, institutional affiliations, assigned roles (Student, Issuer, Administrator), and account verification status. Account creation is initiated by an institutional administrator; we do not offer public self-registration. Where an institution provides names or staff identifiers, those are stored as supplied.
Credential data
Document files (PDF), document metadata (type, issuance date, recipient name and identifier, issuer name and role), cryptographic signatures, Credential status (active, revoked, superseded), and revocation reasons where applicable. The content of submitted documents is determined entirely by the issuing Institution.
Authentication data
One-time passcodes (OTP) sent to registered email addresses for login. OTPs are short-lived, automatically expire, and are purged immediately upon use or expiry. We do not store passwords because the Platform does not use password-based authentication.
Audit and security data
Access logs, authentication events (successful and failed attempts), IP addresses, user agent strings, CSRF tokens, session identifiers, and administrative actions (issuance, revocation, supersession, role changes). This data is stored in a hash-chained, append-only audit log to provide tamper-evident accountability.
Verification request data
When a Credential is verified by any party using the public verification endpoint or a shared link, we record the timestamp of the request, the document identifier and hash, the verification result, and an approximate geographic region derived from the requesting IP address. We do not record the full IP address of Verifying Parties beyond what is captured transiently in infrastructure logs, and we do not require or collect the identity of the Verifying Party. See section 13 for full detail.
Public portfolio data
If a student enables their public portfolio, the Platform stores that preference and renders a public profile page. See section 14 for what is disclosed and how to disable this feature.
How we use your information
- To provide credential issuance, storage, and verification services
- To authenticate users and maintain the security of active sessions
- To generate and maintain tamper-evident, hash-chained audit trails
- To detect, prevent, investigate, and respond to security threats, fraud, and unauthorised access
- To enforce rate limits and protect the verification API from abuse
- To fulfil legitimate institutional requests regarding Credentials they have issued, including revocation, supersession, and irreversible erasure of stored Credential content
- To deliver Institution-configured webhook notifications and to operate Institution-issued verification API keys, as described in this Policy
- To generate anonymised, aggregate analytics about verification activity for internal service improvement
- To send transactional communications strictly necessary for platform operation (OTP delivery, security alerts, material policy change notifications)
- To comply with applicable legal obligations, including responding to lawful requests from regulators, courts, and government authorities
- To investigate and respond to alleged infringement, fraud, or misuse of the Platform
No data sales, no advertising
AcadCert will never sell, rent, license, barter, exchange, or otherwise transfer Personal Data to any Third Party for commercial gain, for the purpose of targeted advertising, for lead generation, or for any purpose beyond the direct provision of credential verification services.
There are no advertising networks integrated into the Platform. There are no third-party analytics scripts (such as Google Analytics, Meta Pixel, or equivalent) embedded in Platform pages. The only third-party script we load is Cloudflare Turnstile, used solely to protect our sign-in and institution onboarding forms from automated abuse, as described in the “Cookies, local storage, and bot mitigation” section; it is not an analytics or advertising technology. There is no behavioural tracking of any kind beyond what is strictly necessary for security and abuse prevention.
This is a categorical, unconditional commitment. It applies equally to anonymised or aggregated data that could, in combination with other datasets, be used to identify individuals or institutions for commercial targeting purposes. We do not participate in data brokerage ecosystems in any form.
Aggregated and de-identified data
We may create aggregated, anonymised, or de-identified data from information processed through the Platform, in a form that does not identify you or any individual. This may include statistical measures such as verification volumes, usage trends, and performance metrics.
Because such data is not personal data, we may use and retain it for any lawful purpose, including operating, securing, analysing, and improving the Service, without restriction under this Policy. We do not attempt to re-identify de-identified data and maintain it in de-identified form.
Information sharing
We share Personal Data only in the following limited and specific circumstances:
- ✓With the issuing Institution: Institutions can access Credentials, user accounts associated with their domain, audit logs pertaining to their Credentials, and revocation records. Each Institution can access only data within its own domain and cannot access data belonging to another Institution.
- ✓At student direction: When a student explicitly shares a Credential via a verification link, or enables their public portfolio, the Credential metadata and verification status specified by the student is made available to the recipient or the public as applicable. Students retain control over this sharing and may revoke public access at any time.
- ✓Through Institution-configured webhooks: Institutions may register HTTPS endpoints to receive automated notifications when a Credential is issued or revoked. Webhook payloads are limited to Credential metadata: the document identifier, document type, credential type, the relevant timestamps, the stated reason where a Credential is revoked, and the public verification link. Payloads do not include the Data Subject's name or email address. Each delivery is cryptographically signed so the receiving system can authenticate its origin. Webhook endpoints are designated, controlled, and secured by the Institution; AcadCert transmits this data as a data processor acting on the Institution's documented instructions, and the Institution is responsible for the lawfulness of the onward flow and for the conduct of any third-party service operating the receiving endpoint.
- ✓With sub-processors: Infrastructure providers engaged by AcadCert (cloud hosting, transactional email delivery, CDN edge network) process limited data on our behalf, under written data processing agreements, for the sole purpose of providing their contracted services. See section 16 for detail.
- ✓For legal compliance: Where required by applicable law, regulation, court order, legal process, or a governmental or regulatory authority with valid jurisdiction. We will notify affected users of such requests to the extent permitted by law.
- ✓To protect rights and safety: Where disclosure is necessary to protect the rights, property, or safety of AcadCert, our users, Institutions, or the public from imminent harm, fraud, or abuse.
- ✓In a corporate transaction: In the event of a merger, acquisition, restructuring, or sale of all or substantially all assets of AcadCert, Personal Data may be transferred to the successor entity subject to that entity providing equivalent privacy protections. Affected users will be notified in advance.
Data retention schedule
We retain Personal Data only for as long as necessary for the purposes for which it was collected, or as required by applicable law. The following schedule applies. Upon expiry of a retention period, data is securely deleted or irreversibly anonymised.
Account data
Retained for the duration of the active account, plus one (1) year following account deletion or deactivation. The one-year window allows for the resolution of post-closure disputes, pending requests, and institutional reporting obligations.
Credential data
Retained for the duration of the institutional relationship between the issuing Institution and AcadCert, plus a two (2) year wind-down period following termination of that relationship. This ensures ongoing verifiability of Credentials during the transition period. Institutions may request early deletion under their data processing agreement, subject to the Platform's ability to honour outstanding verification requests.
Erased Credential content
An authorised Institution administrator may irreversibly destroy the stored content of a Credential through cryptographic erasure. Once erased, the underlying document file is permanently unrecoverable by any party, including AcadCert; there is no backup, escrow, or restoration path. The Credential's cryptographic record (document hash, signature, status, and issuance metadata) and the related audit entries are retained under this schedule, so the Credential remains verifiable and the erasure itself remains permanently evidenced. Erasure does not alter, remove, or conceal revocation records.
Audit logs
Retained for a minimum of five (5) years from the date of the logged event. This reflects the requirements of institutional accreditation frameworks, financial record-keeping obligations, and best practice for security incident investigation. Audit logs are stored in a hash-chained format and cannot be selectively deleted without breaking the integrity chain.
Authentication data: session tokens
Sessions expire eight (8) hours after issuance (a fixed absolute lifetime) and are purged from the backend upon expiry. Session records may be retained in audit logs for up to five years per the audit log schedule above.
Authentication data: OTPs
One-time passcodes are valid for three (3) minutes from issuance. They are purged immediately upon successful use or upon expiry, whichever is earlier. Expired unused OTPs are not retained.
Verification analytics
Raw verification request records (timestamp, document hash, result, IP-derived region) are retained for operational purposes. These records are anonymised or aggregated on a rolling basis and may be retained in anonymised form indefinitely for platform improvement and statistical reporting.
Revocation records
Records of Credential revocation (including revocation timestamp, reason, and the identity of the administrator who performed the revocation) are retained permanently. Revocation is a matter of institutional record and must remain permanently verifiable to protect Data Subjects, Institutions, and Verifying Parties from reliance on invalid Credentials.
Data security
We implement technical and organisational measures commensurate with the nature, scope, and risk of our Processing activities. Current measures include:
No system is perfectly secure. While we take commercially reasonable steps appropriate to the risk, we cannot guarantee absolute security against all threats. See our security overview for technical details.
Data breach notification
In the event of a data breach involving Personal Data, AcadCert will follow the notification requirements of the PDPA (as amended by the Personal Data Protection (Amendment) Act 2020, operative from 1 October 2022), which introduced mandatory data breach notification obligations in Singapore.
Notification to PDPC
Where a breach is assessed to result in significant harm to affected individuals, or where the breach is of a significant scale (500 or more individuals), AcadCert will notify the Personal Data Protection Commission (PDPC) as soon as practicable and in any event within seventy-two (72) hours of becoming aware of the breach, to the extent the full facts are available within that timeframe.
Notification to affected individuals
Where a breach is likely to result in significant harm to an individual, AcadCert will notify affected Data Subjects as soon as reasonably practicable after the breach is assessed. Notification will describe the nature of the breach, the type of data affected, the steps AcadCert is taking in response, and guidance on protective actions individuals may take.
Notification to Institutions
Where a breach involves Credential data held on behalf of an Institution, AcadCert will notify the relevant Institution without undue delay, enabling the Institution to fulfil its own obligations as Data Controller to its students and to relevant regulators.
Internal response process
Upon discovery of a potential breach, AcadCert will immediately initiate containment procedures, preserve forensic evidence, conduct an impact assessment, and engage relevant internal and external personnel (legal, technical, security). All breach events are recorded in an internal incident register maintained for a minimum of five (5) years.
Verification analytics
The public verification service logs a minimal record each time a Credential is verified. This section describes precisely what is and is not recorded.
What is recorded for each verification request:
- Timestamp of the verification request (UTC)
- Document identifier (the Credential’s internal reference) and document hash (BLAKE3 of the Credential file)
- Verification result (valid, revoked, not found, or tampered)
- IP-derived geographic region (country or region level only, not city, street, or precise location)
What is explicitly not recorded:
- The identity, name, email, or account of the Verifying Party (verification is anonymous by design)
- The full IP address of the Verifying Party (only the derived region is retained; raw IPs are not persisted beyond transient infrastructure logs)
- The purpose or context of the verification request
- Any data about the Verifying Party’s device, browser, or browsing behaviour
Verification logs may be made available to the issuing Institution in aggregate or per-Credential form (total verification count and region breakdown) to support institutional reporting. Individual verification events are not surfaced to the student whose Credential was verified, beyond an aggregate count.
Authenticated API verification. In addition to the anonymous public service, Institutions may issue scoped API keys that allow their integration partners to perform the same verification checks programmatically. Requests made with an API key are attributed to that key and counted against its rate limit, and verification results returned through this channel redact the Credential holder’s email address. This channel is additive: the anonymous public verification service is unaffected by it.
Public portfolio data visibility
Students may optionally enable a public portfolio page. This feature is disabled by default and must be explicitly activated by the student in their account settings.
When enabled, the following is publicly visible to anyone with the portfolio URL:
- The student’s display name (as set in their account)
- The list of active (non-revoked) Credentials in their portfolio
- For each Credential: the document type, issuing Institution name, issuance date, and a verification link
- The total count of verified credentials
What is not disclosed on the public portfolio:
- The student’s email address or any contact information
- Revoked or superseded Credentials
- The content of the underlying Credential documents (the document file itself is not displayed inline)
- Any account, authentication, or session data
The public portfolio is accessible to any person on the internet without requiring login. There is no access control beyond possession of the URL. Students should consider this before enabling the feature.
To disable the public portfolio, navigate to Account Settings and toggle off “Public Portfolio.” Disabling the feature removes the public page immediately. Previously indexed copies may persist in third-party search engine caches; students may request removal directly from those search engines.
Automated decision-making
AcadCert does not engage in any form of automated decision-making that produces legal effects or similarly significant consequences for individuals, including automated profiling.
All decisions involving the issuance, revocation, supersession, or status of Credentials are made exclusively by authorised human personnel at the issuing Institution. No algorithmic or automated system determines whether a Credential is issued, revoked, or valid. AcadCert provides infrastructure to record and verify decisions made by humans; it does not make those decisions itself.
Automated processes are used only for: delivering OTPs, enforcing session timeouts, applying rate limits to API endpoints, and detecting anomalous authentication patterns for security purposes. None of these automated processes produce determinations about Credentials or Data Subjects’ rights or status.
Third-party sub-processors
AcadCert engages a limited number of third-party sub-processors to provide infrastructure services necessary for platform operation. We do not name individual providers in this policy to avoid creating a false impression of endorsement and to preserve operational flexibility. All sub-processors are subject to written data processing agreements requiring them to process Personal Data only on our documented instructions and to maintain appropriate security measures.
Cloud infrastructure provider
Hosts the application server, database, and file storage systems. Has access to all Personal Data stored on the platform, including account data, Credential files, and audit logs. Processes data solely for the purpose of providing managed infrastructure services. Basis: contract performance; legitimate interests in reliable and secure infrastructure.
Transactional email provider
Delivers OTPs and security alert emails to registered email addresses. Has access to the recipient email address and the content of the transactional message. Does not have access to Credential data, audit logs, or any other personal data. Processes data solely for the purpose of email delivery. Basis: contract performance (email delivery is necessary for authentication).
CDN and edge network provider
Serves static assets and provides edge-layer protection (DDoS mitigation, rate limiting). May transiently process IP addresses and HTTP request metadata in the course of routing and protection functions. Does not have persistent access to Personal Data stored in the database or file system. Basis: legitimate interests in platform availability and security.
For the avoidance of doubt, webhook endpoints registered by an Institution, and integration partners to whom an Institution provides a verification API key, are not sub-processors of AcadCert. They are systems and parties designated by the Institution and act under the Institution’s control and instructions. The Institution is responsible for assessing those recipients, for putting in place any data processing agreements they require, and for the security and lawful handling of data once it reaches them.
Your rights
Depending on your jurisdiction and the capacity in which you use the Platform, you may have the following rights with respect to your Personal Data. Rights under the PDPA apply to individuals in Singapore. Rights under the Australian Privacy Act 1988 apply to individuals in Australia. Where rights overlap, we apply the more protective standard.
Request a copy of the Personal Data we hold about you, together with information about how it is used and with whom it is shared. Signed-in users can also download their own data on demand from the dashboard ("Download my data"), which exports your profile, your Credentials, and your recent account activity as a structured file.
Request correction of inaccurate or incomplete Personal Data. Note that Credential content corrections (e.g., a name or grade listed in a Credential document) must be initiated by the issuing Institution, as AcadCert does not alter the academic content of Credentials unilaterally.
Request deletion of your account and associated Personal Data, subject to our retention obligations, legal obligations, and the Institution's data processing requirements. You may also ask the issuing Institution to perform cryptographic erasure of a stored Credential document; the Institution decides whether to do so in its capacity as Data Controller, and erasure permanently destroys the stored file while preserving the Credential's verification record and audit history. Permanent revocation records and audit log entries cannot be deleted as they form part of the integrity infrastructure.
Request your Personal Data in a structured, commonly used, machine-readable format (such as JSON or CSV) to facilitate transfer to another service, where technically feasible.
Object to Processing carried out on the basis of legitimate interests. We will assess whether our legitimate interests are overridden by your interests and rights in the specific circumstances.
Request restriction of Processing in circumstances where you contest the accuracy of data, object to Processing, or require data to be retained for legal claims while a deletion request is assessed.
Where Processing is based on your consent, withdraw that consent at any time with effect going forward. Withdrawal does not affect prior lawful Processing.
To exercise these rights, contact your Institution’s credential administrator in the first instance for matters relating to Credential content. For platform-level requests, contact us. We will respond within thirty (30) calendar days of receipt of a verifiable request.
Links to third-party websites
The Platform and our communications may contain links to third-party websites or services that we do not operate or control. This Policy does not apply to those third parties, and we are not responsible for their content, security, or privacy practices. We encourage you to review the privacy policy of any third-party site before providing personal data to it.
Cookies, local storage, and bot mitigation
AcadCert uses httpOnly session cookies for authentication. These cookies are inaccessible to JavaScript running in the browser, cannot be read by cross-site scripts, and are scoped to the Platform domain. No authentication tokens are stored in browser local storage or sessionStorage.
We use browser local storage exclusively to persist non-sensitive user interface preferences, such as table sort order or display state. No Personal Data, session tokens, or Credential content is stored in local storage.
We do not use third-party tracking cookies, advertising cookies, analytics cookies, or any form of cross-site tracking technology. Other than Cloudflare Turnstile, which we load solely for bot mitigation on our sign-in and onboarding forms (described below), there are no third-party scripts, pixels, beacons, or trackers embedded in the Platform. The Platform does not participate in any ad network, data management platform, or audience profiling system.
Cloudflare Turnstile
To protect our sign-in and institution onboarding forms from automated abuse, the Platform uses Cloudflare Turnstile, a bot-mitigation service provided by Cloudflare, Inc. On these pages a Turnstile script is loaded from Cloudflare and runs a verification check in the background to distinguish human visitors from automated traffic. To perform this assessment, Cloudflare may process technical signals from your browser and device, such as IP address, user-agent string, and interaction characteristics.
Turnstile is used exclusively for security and abuse prevention. It is not an analytics, advertising, or behavioural tracking technology, and Cloudflare states that it does not use the data it collects through Turnstile to track individuals across websites or to serve advertising. This processing is carried out by Cloudflare as our service provider and is governed by Cloudflare’s privacy policy, available at cloudflare.com/privacypolicy.
Do Not Track signals
Some browsers transmit “Do Not Track” (DNT) signals. There is no industry or legal standard governing how operators must respond to them, and we do not currently respond to DNT signals. We do not track Users across third-party websites or services, and we do not engage in behavioural advertising. Our limited use of cookies and local storage is described in the Cookies, local storage, and bot mitigation section.
International data transfers
AcadCert infrastructure may be located in, or route data through, jurisdictions outside Singapore or Australia. Where Personal Data is transferred across national borders, we ensure that appropriate safeguards are in place.
For transfers outside Singapore, we rely on the PDPA’s transfer limitation obligations and, where applicable, binding contractual clauses that impose data protection standards at least equivalent to those required under the PDPA.
For transfers of Personal Data of Australian users outside Australia, we ensure that the overseas recipient is subject to a law, binding scheme, or contractual arrangement that provides substantially similar protections to the Australian Privacy Principles, consistent with APP 8. By using the Platform, Australian users consent to such transfers where undertaken in accordance with these safeguards.
Children’s privacy
AcadCert is designed for use by adults and is not directed at individuals under the age of 16. We do not knowingly collect Personal Data from children under 16.
Where an Institution registers a user who may be under 16 (for example, a secondary school student receiving a certification), that Institution, as Data Controller, is solely responsible for ensuring that appropriate parental or guardian consent has been obtained in compliance with applicable law, including the PDPA and, for Australian Institutions, the Australian Privacy Act 1988. If we become aware that Personal Data has been collected from an individual under 16 without verifiable appropriate consent, we will take steps to delete that data in consultation with the relevant Institution.
Complaint resolution
We take privacy complaints seriously. If you believe we have handled your Personal Data in a manner inconsistent with this policy or applicable law, please follow the process below.
Step 1: Contact AcadCert directly
Submit your complaint via our contact page. Please describe the nature of your concern in as much detail as possible. We will acknowledge receipt within five (5) business days and will respond with our findings and any proposed remedy within thirty (30) calendar days. If additional time is required due to complexity, we will notify you within the initial 30-day period.
Step 2: Escalation to PDPC (Singapore)
If your complaint is not resolved to your satisfaction through our internal process, you may submit a complaint to the Personal Data Protection Commission (PDPC) of Singapore. The PDPC can be reached at pdpc.gov.sg. The PDPC has authority to investigate complaints and issue directions to organisations subject to the PDPA.
Step 2 (alternative): OAIC (Australia)
Australian users who are not satisfied with our internal response may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au. The OAIC has jurisdiction to investigate complaints relating to Australian Privacy Principle breaches by organisations covered by the Privacy Act 1988 (Cth).
Governing law and jurisdiction
This Privacy Policy and all matters relating to the collection, use, disclosure, and protection of Personal Data by AcadCert are governed by and construed in accordance with the laws of the Republic of Singapore, including the Personal Data Protection Act 2012 and its subsidiary legislation and guidelines.
The courts of Singapore shall have non-exclusive jurisdiction over any dispute arising out of or in connection with this Privacy Policy or the Processing of Personal Data by AcadCert. Nothing in this clause limits the rights of Data Subjects to seek remedies from a regulatory authority (such as the PDPC or OAIC) in their jurisdiction of residence, regardless of the governing law clause.
To the extent that the Australian Privacy Act 1988 applies to the Processing of Personal Data of Australian users, that Act applies concurrently with Singapore law and AcadCert will comply with the Australian Privacy Principles in respect of such users.
Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. The effective date at the top of this document will be updated whenever a revision is made.
Material changes (meaning changes that alter the type of data we collect, the purposes for which we use it, the parties with whom we share it, or your rights with respect to it) will be communicated via email to all registered users and posted within the Platform dashboard at least fourteen (14) days before taking effect. For changes required by law, shorter notice may apply.
Continued use of AcadCert after the effective date of a revised policy constitutes acceptance of the revised terms. If you do not agree to a revised policy, you should discontinue use of the Platform and contact your Institution to arrange account closure.
Contact
For questions, concerns, or requests relating to this Privacy Policy or the handling of your Personal Data, contact your Institution’s credential administrator in the first instance for matters relating to issued Credentials. For platform-level privacy matters, data subject access requests, or complaints, reach us via our contact page.
When contacting us about a privacy matter, please include: your name and email address, a description of your request or concern, and (if applicable) the Institution with which you are associated. This will allow us to route your request to the appropriate team and respond within the timeframes set out in this policy.