Legal
Privacy policy
What personal data Securo Cert LLC holds, why we hold it, and what you can ask us to do with it. Written to be read, not to be survived.
Who is responsible for your data
Securo Cert LLC is the data controller for the personal data described here. We are a certification and audit body operating a public certificate register. You can reach us about anything on this page at support@securocert.com, or in writing at:
Cayman Corporate Centre
Office 1735
George Town, Grand Cayman
Cayman Islands
The public register is the point, not a side effect
Our core function is to publish and maintain a register that anyone can check. Where we certify an organisation, that entry contains the organisation’s legal name and address, the certificate number, the standard and scope, the sites within scope, the delivery mode and partner body where one applies, the dates, and the current status including any suspension or withdrawal. This information is published deliberately and indefinitely, because a register that only records the flattering entries and quietly drops the rest is worthless to the people who rely on it.
The register concerns organisations and their certifications. Names of individuals — such as a lead auditor or the person who took the certification decision — appear on issued documents as a matter of professional accountability, not as marketing data, and are never sold or used for any other purpose.
What we collect, and why
- Verification lookups. When you check a certificate number, we record the outcome and a one-way hash of your connection (derived from your IP address and browser string, never the raw address) for a short period. It exists only to rate-limit automated enumeration of the register. We do not build a profile from it.
- Forgery and misuse reports. If you report a document, we keep the name, organisation, email and description you provide, so we can investigate and reply. A report naming a certificate is matched to that register entry.
- Partner-document requests. If you request a partner-branded document, we keep your name, organisation, email and stated reason, so we can seek the certified organisation’s agreement and respond.
- The audit-duration estimator. The figures you enter are used to calculate a range and are not stored against you. They are processed for the length of the request and then gone.
- Client portal and certification console. Where you hold an account, we hold your login credentials (passwords are stored only as an Argon2id hash, never in readable form), the records of your engagement, and any evidence you upload. Uploaded files are stored outside the public web space and are reachable only through your authenticated session.
Legal bases
Where the UK or EU General Data Protection Regulation applies to you, we rely on: performance of the certification agreement, for account and engagement data; our legitimate interest in a trustworthy, non-repudiable public register and in preventing fraud, for register entries, verification logging and abuse reports; and legal or accreditation obligations, where a scheme or an accreditation body requires us to retain records.
Cookies and tracking
The public pages of this site set no cookies, run no analytics, and load nothing from third-party advertising or tracking networks. There is no consent banner because there is nothing to consent to. The certification mark embed you can place on your own website makes a single unauthenticated read of your public register entry and sets no cookie and no identifier — it reports nothing about your visitors to us.
The certification console and the client portal set one strictly-necessary session cookie so that you stay signed in. It carries no tracking value and is discarded when you sign out.
How long we keep it
- Register entries are retained permanently. A suspended or withdrawn certificate is never deleted, because a void document must remain catchable.
- Verification rate-limit records are short-lived and are pruned automatically.
- Reports and requests are kept for as long as needed to investigate and to evidence the outcome.
- Account and engagement records are kept for the life of the relationship and for the period our accreditation and the scheme rules require afterwards.
Who we share it with
We do not sell personal data and we do not share it for advertising. Where a certification decision is rendered by a partner body, information necessary to that engagement is shared with the named partner. We disclose data to an accreditation body where our accreditation requires it, and to a public authority where the law compels us. Our hosting and infrastructure providers process data on our instructions under confidentiality obligations.
International transfers
Securo Cert LLC is established in the Cayman Islands, and information you send us may be processed there and in the jurisdictions of our partner bodies. Where we move personal data across borders we do so only with appropriate safeguards in place.
Your rights
Subject to the law that applies to you, you can ask for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, or object to a particular use. Write to us at support@securocert.com and we will respond within the time the law allows.
One limit is worth stating plainly: we cannot erase a certification from the public register on request. The register’s integrity depends on entries — including withdrawals — staying in place, and that public-interest purpose overrides a deletion request for that specific data. Everything not bound up in the register can be corrected or removed as described above.
Changes to this policy
If we change how we handle personal data, we will update this page and move the date below. Material changes will be described here rather than made quietly.
Effective 27 July 2026.