Privacy Policy

Last updated: 25 March 2026 · Effective: 25 March 2026

This Privacy Policy explains how Ertzyx ("we", "us", or "our"), operated at ledger.ertzyx.com, collects, uses, shares, and protects your personal information. We are committed to compliance with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and Canada's Personal Information Protection and Electronic Documents Act (PIPEDA).

1. Who We Are

Ertzyx is a SaaS platform for storing and verifying personal achievements, credentials, and cultural heritage records. We serve individuals and institutions worldwide.

2. Data We Collect

We collect the following categories of personal data:

Account Information

Full name, email address, account type (individual or institution), and password (stored as a secure hash — never in plain text).

Achievement Records

Achievement titles, descriptions, dates, associated institutions, pillar categories, verification status, and verification history including timestamps and reviewer identifiers.

Uploaded Media Files

Documents, images, certificates, and other files you upload as supporting evidence for your achievements.

Usage Data

IP address, browser type, pages visited, actions taken within the platform, and session duration — collected for security and service improvement purposes.

Payment Information

Billing details processed via Stripe. We do not store full card numbers — Stripe handles all payment data under their own PCI-DSS compliance.

Communications

Messages you send via our contact form, including name, email, organisation, subject, and message content.

3. How We Use Your Data

  • To create and manage your account
  • To store, display, and share your achievement records as you direct
  • To facilitate verification requests between individuals and institutions
  • To process payments via Stripe
  • To send transactional emails (account confirmation, verification updates, password reset)
  • To respond to support and contact form submissions
  • To improve platform security and detect fraudulent activity
  • To comply with legal obligations
  • To analyse aggregate usage patterns (anonymised) for product improvement

We do not use your personal data for advertising or sell it to third parties.

4. Legal Basis for Processing (GDPR)

PurposeLegal Basis
Account creation and managementContract performance
Processing paymentsContract performance
Sending transactional emailsContract performance
Security and fraud preventionLegitimate interests
Analytics (anonymised)Legitimate interests
Marketing communicationsConsent (opt-in only)
Legal complianceLegal obligation

5. Who We Share Your Data With

We share data only with the following categories of recipients:

Supabase (Infrastructure Provider)

Our database, authentication, and file storage are hosted on Supabase. Your data is stored on Supabase infrastructure. Supabase is GDPR-compliant and processes data under a Data Processing Agreement. Supabase Privacy Policy

Stripe (Payment Processor)

Payment processing is handled by Stripe, Inc. Stripe is PCI-DSS Level 1 certified. We share only the minimum necessary billing information. Stripe Privacy Policy

Partner Institutions

When you submit an achievement for verification, the relevant institution receives the achievement details you submitted. Institutions do not receive your full profile or unrelated data.

Public Credential Pages

If you choose to make a credential public, it will be accessible to anyone with the unique credential link. You control this setting.

Legal Authorities

We may disclose data when required by law, court order, or to protect the rights and safety of our users or the public.

We do not sell, rent, or trade your personal data to any third party for commercial purposes.

6. Cookies

We use the following types of cookies:

  • Essential cookies: Required for authentication and session management. Cannot be disabled.
  • Preference cookies: Remember your cookie consent choice.
  • Analytics cookies: Used to understand how visitors use the platform (only with your consent).

You can manage cookie preferences via our cookie consent banner or your browser settings. See our Cookie Policy for full details.

7. Data Retention

We retain your data for as long as your account is active or as needed to provide services. See our Data Retention Policy for full details on retention periods and deletion schedules.

8. Your Rights

Depending on your jurisdiction, you have the following rights:

Right of Access

Request a copy of all personal data we hold about you.

Right to Rectification

Correct inaccurate or incomplete data.

Right to Erasure

Request deletion of your account and all associated data.

Right to Portability

Receive your data in a machine-readable format.

Right to Restrict Processing

Limit how we use your data in certain circumstances.

Right to Object

Object to processing based on legitimate interests.

Right to Withdraw Consent

Withdraw consent for marketing or analytics at any time.

CCPA Rights (California)

Know, delete, opt-out of sale, and non-discrimination rights.

To exercise any of these rights, contact us at support@ertzyx.com. We will respond within 30 days.

9. How to Delete Your Account and Data

To request full deletion of your account and all associated data:

  1. Log in to your Ertzyx account
  2. Navigate to Settings → Account → Delete Account
  3. Confirm deletion — this action is irreversible

Alternatively, email support@ertzyx.com with the subject "Account Deletion Request". We will process your request within 30 days. Note that some data may be retained for legal compliance purposes (e.g., payment records) as outlined in our Data Retention Policy.

10. International Data Transfers

Your data may be processed in countries outside your own, including the United States and the European Union, where our infrastructure providers operate. We ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) where required by GDPR.

11. Security

We implement industry-standard security measures including TLS encryption in transit, AES-256 encryption at rest, row-level security on all database tables, and regular security reviews. However, no system is completely secure. Please use a strong, unique password and enable two-factor authentication where available.

12. Children's Privacy

Ertzyx is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us immediately at support@ertzyx.com.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or a prominent notice on the platform. Continued use of Ertzyx after changes constitutes acceptance of the updated policy.

14. Contact Us

For privacy-related questions, requests, or complaints:

Ertzyx Privacy Team

Email: support@ertzyx.com

Platform: ledger.ertzyx.com

If you are in the EU and are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.