Legal

Privacy Policy

Version 1.0 · Effective 2026-09-11

1. Controller

CERTIFIED AI FREE, trading as AI FREE, is the controller of the personal data described in this notice. You can reach us through the contact page for any privacy request.

2. Data we collect and why

Account data (name, e-mail, country, company): to create and operate your account. Application data (work details, answers, declarations, uploaded evidence): to assess and decide your certification. Communication data (messages, support requests): to answer you and keep a record of the review. Technical data (IP address, device and browser information, usage logs, seal access logs): for security, fraud prevention, abuse detection and improving the service. Certificate data (certificate ID, work name, entity name, level, status and dates): published in the public registry so third parties can verify a seal.

3. Legal basis

We process account, application and certificate data to perform our contract with you; technical and security data on our legitimate interest in keeping the service safe and reliable; optional communications on your consent; and some records to comply with legal obligations such as accounting and fraud prevention.

4. Private evidence

Evidence files you upload are stored in a private area and are accessible only to you and to authorised reviewers. They are never published. Nothing from a private file appears in the public registry unless you explicitly approve it for the public summary.

5. Who we share data with

Service providers acting as processors (hosting, database, storage, e-mail and support tooling). Paddle.com, our Merchant of Record, for the sale of our products, subscription management, payments, tax compliance and invoicing. Where enabled and permitted, third-party analysis providers used internally as non-authoritative signals — only for evidence you allowed to be shared. Professional advisers (legal, accounting). Authorities where required by law. We do not sell personal data.

6. International transfers

Our providers may process data outside your country, including outside the UK and EEA. Where that happens we rely on recognised safeguards such as adequacy decisions or standard contractual clauses.

7. Retention

Account and application data are kept while your account is active and afterwards for as long as needed to defend the integrity of an issued certificate and to meet legal, accounting and audit obligations. Public certificate records are retained as a permanent verification record, including status changes. Data no longer needed is deleted or anonymised.

8. Your rights

Depending on where you live, you may request access, correction, deletion, restriction, portability, objection to processing based on legitimate interests, and withdrawal of consent. Contact us and we will reply within one month. If you are in the UK or EEA you may also complain to your supervisory authority; in Brazil, to the ANPD.

9. Security

We apply appropriate technical and organisational measures, including encryption in transit, access controls, row-level access rules, private storage for evidence and audit logging of sensitive actions.

10. Cookies

We use essential cookies and local storage to keep you signed in, remember your language and keep the service secure. Any analytics or marketing cookies, if introduced, will be optional and you will be able to manage your preferences at any time.

This document is published in the registry with version control. Every acceptance records the exact version accepted.