Legal
Privacy policy
This policy applies to the Certifactua Wallet app and related Certifactua services operated at www.certifactua.com.
Introduction
This privacy policy describes how Certifactua ("we", "us", "our") collects, uses, stores and shares personal data when you use:
• the Certifactua Wallet mobile application for iOS and Android ("the app");
• our public website at www.certifactua.com;
• web portals (wallet, issuer, admin and verifier) on certifactua.com subdomains; and
• related authentication and API services.
We are the data controller for processing described here. Questions: info@certifactua.com.
Data we collect
The data we process depends on how you use the service.
Account and identity data
When you sign in, an identity provider authenticates you. Depending on the method you choose and what that provider releases, we may receive:
• email address;
• display name;
• a stable subject identifier from the provider;
• session tokens needed to keep you signed in.
Sign-in methods include email/password via Keycloak, Sign in with Google, Sign in with Apple, or an organisation's federated directory. We never receive your Google or Apple password. Apple may send your name only on the first authorisation.
Wallet and credential data (stored on your device)
The app stores verifiable credentials, cryptographic holder keys, and wallet preferences on your device using the platform secure storage (iOS Keychain / Secure Enclave, Android Keystore where available).
Holder private keys do not leave your device. We do not upload the contents of your credentials to our servers for ordinary wallet use.
If you use the web wallet, credential data is held in browser storage for that session and origin.
Credential offers and issuance
When you accept a credential offer, the app contacts issuer and platform endpoints to complete OpenID4VCI. Those requests may include:
• the offer identifier and pre-authorized code;
• a proof of possession of your holder key (public key material, not the private key);
• network metadata (IP address, user agent) in server logs.
Receiving a credential through a pre-authorized offer does not require an account.
Presentation and verification
When you present a credential to a verifier, you choose which attributes to disclose. Presentation data is sent to the verifier you select; we do not automatically notify issuers when you present privacy-preserving credentials.
Claims, evidence and organisation portals
If you submit a claim or evidence through a portal, that data is processed within the issuing organisation's ecosystem. Retention and access are governed by that organisation's policies as well as this one.
Technical and diagnostic data
Our servers and apps may process:
• IP address, request timestamps, HTTP headers and user agent;
• authentication and API error logs;
• container and infrastructure metrics for reliability and security.
We do not sell personal data. We do not use your data for third-party advertising.
How we use data
We use personal data to:
• provide sign-in and session management;
• deliver, store locally, and help you manage credentials;
• operate, secure and improve the platform;
• comply with law and respond to lawful requests;
• communicate with you about the service when necessary.
Legal bases (EEA / UK)
Where the GDPR or UK GDPR applies, we rely on: performance of a contract (providing the service you request); legitimate interests (security, fraud prevention, improving reliability); and consent where required (for example optional features). You may withdraw consent without affecting the lawfulness of processing before withdrawal.
Sharing and processors
We share data only as needed to run the service:
• Identity providers (Google, Apple, Keycloak, organisation IdPs) when you choose to sign in with them;
• Cloud and hosting providers that operate our infrastructure;
• Issuers and verifiers you interact with when you receive or present credentials;
• Professional advisers or authorities when required by law.
Contracts with processors require appropriate safeguards.
International transfers
Data may be processed in the European Economic Area and in other countries where our providers operate. Where required, we use appropriate safeguards such as Standard Contractual Clauses.
Retention
Session and authentication logs are kept for a limited period for security, then deleted or aggregated.
Credentials remain on your device until you delete them or uninstall the app.
Account data at the identity provider follows that provider's retention settings.
Organisation-held claim and evidence data follows the relevant ecosystem retention rules.
Security
We use TLS in transit, access controls, and industry practices appropriate to the sensitivity of the data. Holder keys are designed to stay on your device. No method of transmission or storage is completely secure.
Your rights
Depending on your location, you may have the right to access, rectify, erase, restrict or object to processing, and to data portability. Contact info@certifactua.com. You may lodge a complaint with your supervisory authority.
Uninstalling the app removes locally stored wallet data from your device. Account deletion at the identity provider is handled through that provider or by contacting us.
Children
The service is not directed at children under 16. We do not knowingly collect personal data from children. Contact us if you believe a child has provided data.
Changes
We may update this policy. The "Last updated" date at the top will change. Material changes may be communicated through the app or website.
Contact
Certifactua — privacy enquiries: info@certifactua.com
See also our terms of service.