CertifactuaCertifactua
Log inGet started

Legal

Privacy policy

Last updated: 17 September 2026

This policy applies to the Certifactua Wallet app and related Certifactua services operated at www.certifactua.com.

Introduction

This privacy policy describes how Certifactua ("we", "us", "our") collects, uses, stores and shares personal data when you use:

• the Certifactua Wallet mobile application for iOS and Android ("the app");

• our public website at www.certifactua.com;

• web portals (wallet, issuer, admin and verifier) on certifactua.com subdomains; and

• related authentication and API services.

We are the data controller for processing described here. Questions: info@certifactua.com.

Data we collect

The data we process depends on how you use the service.

Account and identity data

When you sign in, an identity provider authenticates you. Depending on the method you choose and what that provider releases, we may receive:

• email address;

• display name;

• a stable subject identifier from the provider;

• session tokens needed to keep you signed in.

Sign-in methods include email/password via Keycloak, Sign in with Google, Sign in with Apple, or an organisation's federated directory. We never receive your Google or Apple password. Apple may send your name only on the first authorisation.

Wallet and credential data (stored on your device)

The app stores verifiable credentials, cryptographic holder keys, and wallet preferences on your device using the platform secure storage (iOS Keychain / Secure Enclave, Android Keystore where available).

Holder private keys do not leave your device. We do not upload the contents of your credentials to our servers for ordinary wallet use.

If you use the web wallet, credential data is held in browser storage for that session and origin.

Credential offers and issuance

When you accept a credential offer, the app contacts issuer and platform endpoints to complete OpenID4VCI. Those requests may include:

• the offer identifier and pre-authorized code;

• a proof of possession of your holder key (public key material, not the private key);

• network metadata (IP address, user agent) in server logs.

Receiving a credential through a pre-authorized offer does not require an account.

Presentation and verification

When you present a credential to a verifier, you choose which attributes to disclose. Presentation data is sent to the verifier you select; we do not automatically notify issuers when you present privacy-preserving credentials.

Claims, evidence and organisation portals

If you submit a claim or evidence through a portal, that data is processed within the issuing organisation's ecosystem. Retention and access are governed by that organisation's policies as well as this one.

Technical and diagnostic data

Our servers and apps may process:

• IP address, request timestamps, HTTP headers and user agent;

• authentication and API error logs;

• container and infrastructure metrics for reliability and security.

We do not sell personal data. We do not use your data for third-party advertising.

How we use data

We use personal data to:

• provide sign-in and session management;

• deliver, store locally, and help you manage credentials;

• operate, secure and improve the platform;

• comply with law and respond to lawful requests;

• communicate with you about the service when necessary.

Legal bases (EEA / UK)

Where the GDPR or UK GDPR applies, we rely on: performance of a contract (providing the service you request); legitimate interests (security, fraud prevention, improving reliability); and consent where required (for example optional features). You may withdraw consent without affecting the lawfulness of processing before withdrawal.

Sharing and processors

We share data only as needed to run the service:

• Identity providers (Google, Apple, Keycloak, organisation IdPs) when you choose to sign in with them;

• Cloud and hosting providers that operate our infrastructure;

• Issuers and verifiers you interact with when you receive or present credentials;

• Professional advisers or authorities when required by law.

Contracts with processors require appropriate safeguards.

International transfers

Data may be processed in the European Economic Area and in other countries where our providers operate. Where required, we use appropriate safeguards such as Standard Contractual Clauses.

Retention

Session and authentication logs are kept for a limited period for security, then deleted or aggregated.

Credentials remain on your device until you delete them or uninstall the app.

Account data at the identity provider follows that provider's retention settings.

Organisation-held claim and evidence data follows the relevant ecosystem retention rules.

Security

We use TLS in transit, access controls, and industry practices appropriate to the sensitivity of the data. Holder keys are designed to stay on your device. No method of transmission or storage is completely secure.

Your rights

Depending on your location, you may have the right to access, rectify, erase, restrict or object to processing, and to data portability. Contact info@certifactua.com. You may lodge a complaint with your supervisory authority.

Uninstalling the app removes locally stored wallet data from your device. Account deletion at the identity provider is handled through that provider or by contacting us.

Children

The service is not directed at children under 16. We do not knowingly collect personal data from children. Contact us if you believe a child has provided data.

Changes

We may update this policy. The "Last updated" date at the top will change. Material changes may be communicated through the app or website.

Contact

Certifactua — privacy enquiries: info@certifactua.com

See also our terms of service.

© 2026 Certifactua · Apache 2.0StandardsUse casesPrivacy policyTermsLog in