This Privacy Policy ("Policy") describes the privacy practices of EDUCERT (PTY) LTD ("EDUCERT", "we", "us", or "our") in connection with:
EDUCERT® is a registered trade mark in South Africa, including trade mark registration numbers 2014/32267 in Class 41 and 2014/32259 in Class 35. See our Terms of Service for intellectual property and permitted use.
- the EDUCERT website at educert.co.za (the "Website"); and
- the EDUCERT software platform and related services at app.educert.co.za (the "Platform"),
together, the "Services".
This Policy should be read with our Terms of Service, POPIA information page, Cookie Policy, and Service Providers page. By using the Services, you acknowledge that you have read this Policy. Where you use the Platform on behalf of an organisation, you should also ensure that organisation's privacy obligations are met.
1. Responsible party and contact details
For purposes of the Protection of Personal Information Act, 2013 ("POPIA"), EDUCERT (PTY) LTD is the responsible party for personal information that we determine the purpose and means of processing through the Website and our own business operations.
- Entity: EDUCERT (PTY) LTD
- Registration number: 2013/155188/07
- Registered address: 140 Old Pretoria Road R114, Nooitgedacht, Krugersdorp, Gauteng, 1739, South Africa
- Postal address: PO Box 3156, Honeydew, Roodepoort, Gauteng, 2040, South Africa
- Information Officer: Jason Wayne Delport
- Privacy and information requests: admin@educert.co.za
- Website contact form: educert.co.za/contact.html
If you have questions about this Policy or wish to exercise a privacy right, contact us using the details above.
2. Scope and roles
EDUCERT may process personal information in different roles depending on context:
- Website and sales enquiries. We act as the responsible party for information submitted through contact forms, demo requests, and similar Website interactions.
- Platform account holders. We act as the responsible party for administrator, billing contact, and account user information needed to provide the Platform.
- Certificate and learner records. Where a training provider, employer, or other customer uploads learner, employee, or certificate holder information, that customer is generally the responsible party for deciding why and how that information is processed. EDUCERT processes that information as an operator on the customer's instructions to provide the Platform.
- Verification and public register features. Information shown on verification pages or the Public Register is controlled by the issuing organisation's configuration and business decisions, subject to product settings and applicable law.
3. Personal information we collect
The personal information we collect depends on how you interact with the Services. It may include:
3.1 Website enquiries and communications
If you contact us through the Website or by email, we may collect:
- name;
- company or organisation name;
- email address;
- phone number;
- organisation type;
- estimated certificate volume;
- message content; and
- other information you choose to provide.
Please do not submit special personal information or excessive personal information through enquiry forms unless we specifically request it.
3.2 Platform account and subscription information
If you register for or use the Platform, we may collect:
- account profile information such as name, email address, phone number, and role;
- organisation name, billing details, and subscription plan information;
- login, authentication, and security-related records;
- support requests, communications, and usage preferences; and
- audit, activity, and administrative logs relating to your Account.
3.3 Certificate records and operational data
Customers may upload or generate personal information in the course of issuing and managing certificate records, such as:
- learner, employee, or certificate holder names;
- identification or reference numbers where configured by the customer;
- contact details where included in templates or records;
- programme, course, issuer, issue date, expiry date, and certificate status;
- delivery records, renewal history, and related workflow metadata; and
- documents, templates, branding assets, and exports created through the Platform.
Customers decide what fields are collected, stored, displayed on certificates, shown on verification pages, or exposed through public register features.
3.4 Verification and public lookup interactions
Public certificate verification on the Platform is email-gated. Before viewing verification results, a person must provide an email address and complete a one-time passcode ("OTP") challenge sent to that address.
When a person requests or completes verification — including via QR code, verification link, or manual certificate reference — we may process:
- the verifier's email address and email domain;
- OTP request and verification events, including rate-limit counters associated with the email address and IP address;
- lookup queries, verification method (for example QR code, link, or manual reference), and certificate reference information;
- verification result status (for example valid, expired, revoked, or not found);
- IP address and user agent associated with the verification request;
- verifier session data managed through essential security cookies (see section 12 and our Cookie Policy); and
- public-safe certificate or issuer information configured by the customer for verification visibility.
OTP codes expire after 10 minutes. OTP verification must be completed in the same browser session used to request the code, because the OTP challenge is bound to an httpOnly cookie on that browser. OTP verification is not designed to work across separate devices or browsers.
Custom certificate fields are private by default and are shown on verification pages only where the issuing organisation has explicitly configured them for verification visibility.
Successful verifier access may create a security audit log entry containing the verifier email, verifier email domain, a hashed verification token (not the raw token), verification method, result status, IP address, and user agent. [TODO — legal review: specify retention period for verifier audit logs.]
OTP request rate limiting is persisted in our database to help prevent abuse. Current limits are 5 OTP requests per email address per 15 minutes and 20 OTP requests per IP address per 15 minutes. [TODO — legal review: specify retention period for rate-limit records.]
We design verification and register features to support controlled disclosure. Customers remain responsible for avoiding unnecessary exposure of personal information.
3.5 Technical and security information
We automatically collect certain technical information when you use the Services, such as:
- IP address;
- browser type and device information;
- pages viewed, timestamps, and referral information;
- error logs and diagnostic data; and
- security events and anti-abuse signals.
3.6 Website analytics and marketing measurement
When you visit the marketing Website at educert.co.za, we may use Meta Pixel (Meta Platforms Ireland Limited and its affiliates) to measure page views, understand how visitors use the Website, and evaluate the effectiveness of our advertising on Meta platforms.
Meta Pixel is loaded only if you accept non-essential cookies through our cookie consent banner. If you reject non-essential cookies, we do not load Meta Pixel on that browser. You can change your choice using Cookie preferences in the Website footer.
Depending on your browser, device, and Meta account settings, this may involve cookies, pixels, or similar technologies that collect information such as pages viewed, browser and device characteristics, IP address, referral source, and visit timestamps. Meta may associate this information with your Meta account where you are logged in and where permitted by Meta's policies and your settings.
Meta Pixel is used on the marketing Website only. It is not deployed on app.educert.co.za for Platform accounts, certificate verification, or customer certificate record workflows. Details of associated cookies are set out in our Cookie Policy.
4. How we use personal information
We use personal information for purposes including:
- responding to enquiries, demo requests, and support messages;
- creating, administering, and securing Accounts;
- providing, operating, maintaining, and improving the Services;
- processing subscriptions, billing, and account communications;
- enabling certificate issuing, register management, expiry tracking, verification, and related workflows;
- sending verification OTP emails, validating verifier identity, and maintaining verifier sessions;
- applying rate limits and anti-abuse controls to verification and related public access features;
- creating and reviewing security audit logs for verification access and related events;
- monitoring usage, troubleshooting, auditing, and protecting against fraud or misuse;
- measuring Website visits, marketing performance, and the effectiveness of our advertising through Meta Pixel;
- complying with legal obligations and enforcing our Terms; and
- sending service-related notices, product updates, or administrative messages.
We may use organisation type, certificate volume, and similar enquiry details to assess product fit, recommend plans, and coordinate onboarding or sales discussions.
We do not sell personal information.
5. POPIA and lawful processing
We process personal information in accordance with POPIA and other applicable South African law.
Depending on the context, our processing may rely on one or more lawful grounds, including:
- performance of a contract or steps taken at your request before entering a contract;
- compliance with a legal obligation;
- legitimate interests of EDUCERT or a third party, where those interests are not overridden by your rights;
- consent, where required; or
- processing by an operator on documented instructions of a responsible party.
Where EDUCERT processes personal information as an operator for a customer, the customer is responsible for ensuring a valid legal basis exists and for providing required notices to data subjects.
6. Customer responsibilities for learner and certificate data
If you use the Platform to manage certificate records for other people, you are responsible for:
- determining what personal information is necessary for your workflow;
- providing appropriate privacy notices to learners, employees, contractors, or other data subjects;
- obtaining consent or another valid legal basis where required;
- configuring templates, verification pages, and public listings to minimise unnecessary disclosure;
- responding to data subject requests relating to records you control, where applicable; and
- meeting retention, accuracy, and deletion obligations under your policies and applicable law.
EDUCERT supports POPIA-conscious record workflows, but does not replace your organisation's privacy governance, policies, or legal advice.
7. How we share personal information
We may share personal information with:
- Service providers that help us operate the Services, such as hosting, email delivery (including verification OTP email), payment processing, authentication, database hosting, object storage, background job processing, monitoring, Website analytics and advertising measurement (including Meta Pixel), and customer support providers. See our Service Providers page for the current published list;
- Customer-authorised users within an organisation Account according to permissions configured by the customer;
- Verification or register viewers where a customer chooses to expose public-safe certificate or issuer information;
- Professional advisers such as lawyers, auditors, or insurers where reasonably necessary; and
- Authorities or third parties where required by law, court order, or to protect rights, safety, and security.
We require service providers to handle personal information appropriately and only for authorised purposes, subject to contract and applicable law.
If EDUCERT is involved in a merger, acquisition, reorganisation, or sale of assets, personal information may be transferred as part of that transaction subject to appropriate safeguards.
8. Cross-border processing
Some of our service providers may process or store information outside South Africa. Where personal information is transferred across borders, we take reasonable steps required by POPIA and applicable law, which may include ensuring the recipient is subject to adequate data protection rules or appropriate safeguards.
9. Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, unless a longer retention period is required or permitted by law.
Retention periods may vary based on:
- whether you have an active Account or Subscription;
- whether records are needed for billing, tax, audit, dispute, or legal compliance purposes;
- backup, security, and disaster recovery requirements; and
- customer instructions or contractual terms for Platform data.
Verifier-related records — including OTP rate-limit data and verification audit logs — are retained only for as long as reasonably necessary for security, abuse prevention, troubleshooting, and audit purposes. [TODO — legal review: confirm and publish specific retention periods for verifier audit logs and rate-limit records.]
When information is no longer required, we will delete, anonymise, or securely archive it according to our retention practices.
10. Security
We implement reasonable technical and organisational safeguards designed to protect personal information against unauthorised access, loss, misuse, alteration, or disclosure.
Measures may include access controls, encryption in transit where supported, httpOnly session cookies for verification flows, OTP expiry and same-browser validation, persisted rate limiting, security audit logging (including hashed verification tokens rather than raw tokens), logging, environment segregation, and secure development practices. See our Security overview for more information.
No method of transmission or storage is completely secure. You are responsible for safeguarding your login credentials and configuring user access appropriately within your organisation.
11. Your rights under POPIA
Subject to POPIA and applicable law, you may have the right to:
- request confirmation of whether we hold personal information about you;
- request access to personal information we hold about you;
- request correction or deletion of inaccurate, irrelevant, excessive, outdated, or unlawfully processed information;
- object to processing in certain circumstances;
- withdraw consent where processing is based on consent; and
- lodge a complaint with the Information Regulator.
To exercise these rights, contact us at admin@educert.co.za. We may need to verify your identity before responding. If your request relates to certificate records controlled by one of our customers, we may direct you to that customer where appropriate.
We will respond within a reasonable period and in accordance with POPIA.
12. Cookies and similar technologies
The Website and Platform may use cookies, local storage, pixels, or similar technologies that are necessary for security, session management, authentication, preferences, analytics, marketing measurement, and basic functionality.
Public certificate verification uses essential security cookies on the Platform, including educert_verifier_otp (to bind an OTP challenge to the browser that requested it) and educert_verifier_session (to maintain an authenticated verifier session after successful OTP verification). Verifier sessions use an idle timeout of 15 minutes, display a renewal warning from 10 minutes of inactivity, and end after an absolute maximum of 60 minutes. OTP challenge cookies are tied to a 10-minute OTP expiry.
Platform account authentication may use additional essential cookies provided by our authentication service provider. Details are set out in our Cookie Policy.
The marketing Website uses Meta Pixel to measure page views and marketing performance, but only after you accept non-essential cookies in our consent banner. Meta may set cookies such as _fbp and _fbc, and may receive technical and usage information about your visit as described in section 3.6 and our Cookie Policy. You can change your choice through Cookie preferences in the footer, your browser settings, or Meta's ad preference tools.
Disabling essential verification or authentication cookies may prevent verification or platform login from working. Disabling analytics cookies may limit our ability to measure Website performance but should not affect core Platform functionality.
13. Direct marketing
We may contact you about EDUCERT products, services, onboarding, or account matters where permitted by law. You may opt out of non-essential marketing communications by using the unsubscribe method in the message or contacting us directly.
We may use Meta Pixel and related tools to measure the effectiveness of advertising for EDUCERT on Meta platforms and to understand how visitors reach the Website. This does not mean we sell personal information. Where Meta processes information under its own policies, you may also manage certain preferences through Meta's ad settings.
Even if you opt out of marketing, we may still send service, security, billing, or legal notices.
14. Children
The Services are intended for business use by organisations and authorised adults. They are not directed at children under 18.
Customers must not upload children's personal information through the Platform unless they have a lawful basis and appropriate safeguards for doing so. If you believe a child's personal information has been submitted to us improperly, contact us so we can review the matter.
15. Links to other websites
The Services may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. You should review their privacy policies separately.
16. Changes to this Policy
We may update this Policy from time to time to reflect changes in law, product functionality, or our practices. If we make material changes, we will provide notice through the Website, Platform, or other appropriate means. The "Last updated" date at the top of this page indicates when the Policy was last revised.
17. Complaints
If you believe your personal information has been processed contrary to POPIA, please contact us first so we can try to resolve the issue.
You also have the right to complain to the Information Regulator (South Africa):
- Website: inforegulator.org.za
- Email: inforeg@justice.gov.za
18. Contact us
For privacy questions, Information Officer enquiries, or data subject requests:
- EDUCERT (PTY) LTD (Registration No. 2013/155188/07)
- Registered address: 140 Old Pretoria Road R114, Nooitgedacht, Krugersdorp, Gauteng, 1739, South Africa
- Postal address: PO Box 3156, Honeydew, Roodepoort, Gauteng, 2040, South Africa
- Information Officer: Jason Wayne Delport
- Email: admin@educert.co.za
- Website: educert.co.za/contact.html