Data privacy & GDPR

Where your certification data lives, and who can see it

Certification records contain personal data about your employees. This page explains how Certify Pro stores, processes and shares that information so your compliance team can assess it. It is maintained by the Certify Pro team and describes the controls in place today — it is not an independent audit or certification.

Data region
EU — Frankfurt

AWS eu-central-1

Tenant isolation
Row-level security

Enforced per company

Documents
Private storage

No public bucket access

Certify Pro's database, authentication service and document storage are provisioned in the European Union — AWS eu-central-1 (Frankfurt, Germany). Application data (profiles, staff records, certification details and uploaded certificate files) is stored at rest in that EU region.

The platform runs on Lovable Cloud, which is built on Supabase (Postgres, GoTrue auth and S3-compatible object storage). Data in transit is encrypted with TLS; data at rest is encrypted by the cloud provider.

Web requests are served through a global edge network, so request routing may terminate outside the EU even though the database of record remains in Frankfurt. If your organisation requires a documented commitment on this, ask us for the current subprocessor list before signing.

Your cookie choices

Optional analytics and marketing cookies are off until you allow them, and your choice is stored in this browser only. Open the settings panel to change categories or withdraw consent — withdrawal takes effect immediately.

No choice recorded yet — only strictly necessary cookies are in use.
Privacy requests & security contact

For access, correction, export or erasure requests, a data processing agreement, or to report a suspected vulnerability, contact the Certify Pro team. We aim to acknowledge privacy requests within 5 working days and complete them within one month.

CertifyPro@proton.me