# IASC LTD # GLOBAL PRIVACY AND PERSONAL DATA NOTICE **Notice Version:** 1.0 **Effective Date:** [31.08.2026] **Last Updated:** [31.08.2026] ## 1. PURPOSE OF THIS NOTICE This Privacy and Personal Data Notice (the “Noticeâ€) explains how IASC LTD collects, uses, stores, shares and protects personal data in connection with its website, membership system, certificate creation Platform and certificate verification services. This Notice applies to: - Institutions registered on the IASC Platform, - Company representatives and responsible persons, - Individual trainers, - Platform users, - Certificate holders whose information is entered on the Platform by Members, - Website visitors, - Persons using the certificate Verification Page, - Persons who contact IASC. This Notice is not a contract or a request for explicit consent. No separate tick box is required in order to view or read this Notice. --- ## 2. DATA CONTROLLER The organisation responsible for the processing of personal data is: **IASC LTD** **Company Number:** [â—] **Registered Office Address:** [â—] **Website:** [https://iascert.uk](https://iascert.uk/) **Privacy Contact Address:** [â—] **General Contact Address:** [â—] You may submit requests concerning your personal data to the Privacy Contact Address. --- ## 3. ROLES OF IASC AND THE PLATFORM MEMBER ### 3.1. Membership and business data IASC processes personal data for its own purposes in connection with the creation of Member Accounts, administration of the Membership Agreement, payments and invoicing, Platform security, fraud prevention, support services and compliance with legal obligations. ### 3.2. Certificate holder data The certificate holder’s personal data is generally not collected by IASC directly from the certificate holder. This information is transferred to IASC by the institution, company or individual trainer registered on the Platform. The Platform Member is responsible for: - Verifying the identity of the certificate holder, - Ensuring that the information is accurate and current, - Collecting personal data lawfully, - Providing all necessary privacy information, - Establishing the necessary legal basis, - Obtaining permission or explicit consent where required, - Ensuring that they are authorised to transfer the data to IASC. ### 3.3. IASC’s technical data-processing role When creating a certificate in accordance with a Member’s instructions, IASC may process personal data in accordance with the Member’s documented instructions. IASC may also process data under its own responsibility for the purposes of generating certificate numbers, preventing fraud, managing the technical status of certificates, maintaining security records, responding to legal requests and operating the certificate verification system. ### 3.4. IASC’s technical processing of certificate data does not mean that IASC has independently verified the accuracy of the information appearing on the certificate. --- ## 4. FROM WHICH SOURCES DO WE OBTAIN PERSONAL DATA? Personal data may be obtained from the following sources: ### 4.1. Information obtained directly from the individual - Platform registration forms, - Contact and support requests, - Payment and invoicing transactions, - Email correspondence, - Data-subject rights requests, - Complaints and correction requests. ### 4.2. Information obtained from the Platform Member Information concerning certificate holders is entered on the Platform by the institution, company or individual trainer requesting the certificate. ### 4.3. Information generated automatically When the Platform or website is used, the following information may be generated automatically: - IP address, - Device information, - Browser information, - Operating system, - Session information, - Login and logout times, - Transaction logs, - Security records, - Cookie and similar technology information. ### 4.4. Information obtained from service providers Transaction or security information may be obtained from payment service providers, hosting providers, email systems, security services and technical service providers. ### 4.5. Information obtained from publicly available sources Information may be obtained from publicly available company and organisation registers for the purposes of preventing fraud, verifying corporate membership information or complying with legal obligations. --- ## 5. PERSONAL DATA THAT MAY BE PROCESSED ### 5.1. Member and Account information - First name, - Surname, - Email address, - Telephone number, - Company name, - Tax Identification Number, - Turkish Republic Identification Number, - Foreign identification number or national equivalent, - First name and surname of the responsible person, - Position/title of the responsible person, - Account number, - Membership and Account status, - Password hash value, - Authorised user information. ### 5.2. Certificate holder information Depending on the certificate template and the Member’s request, the following data may be processed: - First name and surname, - Turkish Republic Identification Number, - Passport number, - Foreign identification number or national identification number, - Date of birth, - Photograph, - Name of the training or activity, - Training start and end dates, - Duration of the training, - Trainer or organisation information, - Attendance, achievement or assessment information, - Certificate number, - Barcode or Verification Code, - Certificate creation and issue date, - Technical status of the certificate, - Correction, suspension or cancellation records. ### 5.3. Transaction and security information - IP address, - Device and browser information, - Session records, - Platform activity, - Version of the Agreement accepted, - Hash value of the Agreement, - Date and time of acceptance, - OTP/MFA result, where used, - Certificate Request records, - Email dispatch and delivery records, - Security incidents, - Failed login and access records. ### 5.4. Payment and invoicing information - Invoicing information, - Tax information, - Payment amount, - Payment date, - Currency, - Transaction number, - Payment status, - Refund or chargeback information. IASC may not retain within its own systems full payment-card details collected directly by the payment service provider. ### 5.5. Communication information - Email correspondence, - Support requests, - Complaints and objections, - Correction requests, - Call or meeting notes, - Legal notices. ### 5.6. Special-category data The Platform is not designed for the storage of health information, biometric information, criminal-record information or similar special-category personal data. The Member must not upload such data to the Platform unless it is expressly necessary and lawful to do so. --- ## 6. FOR WHAT PURPOSES DO WE PROCESS PERSONAL DATA? Personal data may be processed for the following purposes: - Creating a Member Account, - Recording the Member’s identity and contact information, - Entering into and performing the Membership Agreement, - Providing access to the Platform, - Processing a Certificate Request, - Creating a certificate in accordance with the Member’s instructions, - Displaying an identification number on a certificate, - Generating a certificate number and Verification Code, - Displaying the technical status of a certificate, - Correcting, placing under review, suspending or cancelling a certificate, - Preventing fraudulent certificates and unauthorised use, - Maintaining Account and Platform security, - Processing payments and invoices, - Retaining Agreement acceptance records, - Providing Member support, - Responding to complaints and data-subject rights requests, - Establishing, exercising or defending legal rights, - Complying with legal and regulatory obligations, - Improving service quality and technical performance, - Identifying system errors, - Preventing unauthorised access and misuse, - Sending promotional communications where permitted. --- ## 7. LEGAL BASES FOR PROCESSING PERSONAL DATA Depending on the nature of the processing activity, IASC may rely on one or more of the following legal bases when processing personal data. ### 7.1. Entering into and performing a contract Data necessary to create a Member Account, provide membership services, manage payments and grant access to the Platform may be processed. ### 7.2. Legitimate interests IASC may process personal data for the following legitimate interests: - Maintaining Platform security, - Preventing fraud and forgery, - Proving acceptance of the Agreement, - Preserving the technical verifiability of certificates, - Investigating complaints, - Defending legal rights, - Improving services, - Maintaining business and audit records. The rights and reasonable expectations of individuals shall be taken into consideration in connection with such processing. ### 7.3. Legal obligations Personal data may be processed for the purpose of complying with tax, accounting, corporate, data-security and other mandatory legal obligations, including requests from competent authorities. ### 7.4. The Member’s documented instructions Where IASC processes a certificate holder’s data solely in accordance with the Member’s instructions, the Member is responsible for determining and establishing the legal basis for the relevant processing activity. ### 7.5. Permission or explicit consent Where Applicable Law requires permission or explicit consent, personal data may be processed on the basis of the relevant individual’s valid permission or explicit consent. Where processing is based on explicit consent, the individual may withdraw that consent with prospective effect. ### 7.6. Legal claims Personal data may be processed for the establishment, exercise or defence of legal claims and the preservation of evidence. --- ## 8. DISPLAY OF IDENTIFICATION NUMBERS ON CERTIFICATES ### 8.1. In accordance with the Member’s Certificate Request, the certificate holder’s full: - Turkish Republic Identification Number, - Passport number, - Foreign identification number, - National identification number or national equivalent may be displayed on the Certificate PDF or printed Certificate. ### 8.2. IASC places the identification number on the Certificate in accordance with the instruction submitted by the Member through the Platform. ### 8.3. The Member is responsible for ensuring that the identification number is accurate, belongs to the relevant person and is lawfully transferred to IASC. ### 8.4. IASC does not independently verify the accuracy of an identification number. ### 8.5. The full identification number is not displayed by default on the publicly accessible certificate Verification Page. The identification number may be masked on the Verification Page. ### 8.6. Any person who shares a Certificate PDF or printed Certificate containing a full identification number with third parties is responsible for the consequences of that disclosure. --- ## 9. PUBLIC CERTIFICATE VERIFICATION PAGE The following information may be displayed on the certificate Verification Page: - The certificate holder’s first name and surname, - A masked identification number, - Certificate number, - Name of the training or activity, - Certificate date, - The relevant Platform Member, - Current technical status of the Certificate, - Correction, suspension or cancellation information. The Verification Page shows only whether the Certificate was created on the IASC Platform and its current technical status. The Verification Page does not mean that the information on the Certificate has been independently investigated or verified by IASC. IASC may implement reasonable technical measures to prevent the mass indexing of Verification Pages by search engines or public searches for full identification numbers. --- ## 10. WITH WHOM MAY WE SHARE PERSONAL DATA? Personal data may be shared with the following recipients to the extent necessary for the provision of the services: ### 10.1. Platform Member The institution, company or individual trainer requesting the Certificate. ### 10.2. Certificate holder The Certificate and any related correction or status information may be provided to the relevant person. ### 10.3. Technical service providers - Cloud and server providers, - Data-storage services, - Email services, - Cybersecurity providers, - Software and support services, - Backup services, - Certificate and QR-code infrastructure providers. ### 10.4. Payment and financial service providers - Banks, - Payment service providers, - Accounting service providers, - Tax and financial advisers. ### 10.5. Professional advisers - Lawyers, - Auditors, - Insurance providers, - Technical experts, - Professional consultants. ### 10.6. Competent authorities Where legally required or necessary to protect legal rights, personal data may be shared with courts, regulatory authorities and other competent organisations. ### 10.7. Corporate transactions In the event of a merger, acquisition, investment, restructuring or transfer of business, personal data may be shared with the relevant parties subject to appropriate confidentiality and security safeguards. IASC does not sell personal data to third parties as commercial data lists. --- ## 11. SUB-SERVICE PROVIDERS IASC may use sub-service providers to deliver the Platform services. Sub-service providers may access only the data necessary to perform the services assigned to them and shall be subject to appropriate confidentiality, security and data-protection obligations. An up-to-date list of sub-service providers may be published at: **[Link to sub-service provider list: â—]** --- ## 12. INTERNATIONAL DATA TRANSFERS IASC is a company based in the United Kingdom, and the Platform may be used globally. Personal data may be processed: - In the United Kingdom, - In the country in which the Member or certificate holder is located, - In countries in which IASC’s technical service providers are located. Where personal data must be transferred to another country, the following safeguards may be used to the extent applicable: - Adequacy decisions, - Standard data-protection clauses, - The International Data Transfer Agreement, - Applicable standard contractual addenda, - Binding corporate rules, - Other transfer mechanisms permitted by law. IASC applies contractual and technical safeguards to protect personal data in connection with international transfers. --- ## 13. DATA-RETENTION PERIODS Personal data shall be retained for as long as necessary for the purpose for which it was collected and for as long as the relevant legal obligations continue to apply. Our general retention criteria are as follows: ### 13.1. Member Account information Member Account information may generally be retained throughout the membership period and for up to six years after the Account is closed for the purposes of legal claims, financial records and proof of the Agreement. ### 13.2. Agreement and electronic acceptance records The accepted version of the Agreement, its hash value, date, time, IP address and related transaction records may generally be retained for up to six years after the membership ends. Where a dispute is ongoing, the records may be retained until the dispute has been resolved. ### 13.3. Payment and invoicing records Payment and invoicing records shall be retained for the applicable financial and legal retention periods. ### 13.4. Certificate records Certificate content and technical status information may be retained for as long as the Certificate needs to remain verifiable. When a Certificate is cancelled or the need for verification ends, access to full identity information may be restricted. Unless there is a legal reason for longer retention, a full identification number shall be retained for no more than six years after the Certificate is cancelled or the need for verification ends. Minimum records, such as the Certificate number, hash value, creation date and most recent technical status, may be retained for a longer period for fraud-prevention and historical-verification purposes. ### 13.5. Security logs Security logs may be retained for up to 12 months under normal circumstances. Where there is a security incident, suspected fraud or legal investigation, the relevant records may be retained for the duration of the investigation and applicable claim periods. ### 13.6. Support and communication records Support and communication records may generally be retained for up to three years after the relevant request has been closed. ### 13.7. Marketing preferences Marketing preferences may be retained until the preference is withdrawn. A minimum opt-out record may be retained for a longer period to prevent unwanted communications from being sent again. ### 13.8. When the applicable retention period ends, personal data shall be securely deleted, anonymised or permanently restricted from access. --- ## 14. DATA SECURITY IASC applies measures proportionate to the relevant risks to prevent personal data from being lost, altered, disclosed to unauthorised persons or accessed without authorisation. These measures may include: - Authorisation and role-based access controls, - Storage of passwords using hashing methods, - Encryption in transit, - Security and access logs, - Backups, - Firewalls and malicious-traffic controls, - Unauthorised-access detection, - Confidentiality obligations for personnel and service providers, - Incident-response procedures, - Regular system updates. No internet or data-storage system can provide absolute security. If a personal data breach occurs that is legally required to be notified, the affected persons and competent authorities may be informed. --- ## 15. COOKIES AND SIMILAR TECHNOLOGIES IASC may use cookies or similar technologies on its website and Platform for essential functions such as: - Signing in, - Account security, - Language preferences, - Load balancing, - Form and transaction security. Where non-essential analytics, advertising or behavioural-tracking technologies are used, the necessary preference and consent mechanism shall be provided separately. Further information about cookies is provided in a separate Cookie Policy. --- ## 16. PROMOTIONAL COMMUNICATIONS Where permitted by law, IASC may send Members communications concerning products, services, updates or campaigns. Promotional messages requiring consent or a stated preference shall be sent in accordance with the relevant individual’s preference. To opt out of promotional communications: - The unsubscribe link in the communication may be used, - Account preferences may be changed, - A request may be submitted to the Privacy Contact Address. Service, security, payment and Agreement notices are not promotional communications and may be sent for as long as the membership continues. --- ## 17. CHILDREN’S DATA Member Accounts may not be opened by persons under the age of 18. Where a certificate holder is under the age of 18, the Member must: - Establish an appropriate legal basis for processing the data, - Provide the necessary privacy information, - Obtain permission from a parent or legal representative where required, - Have regard to the best interests of the child. IASC may apply more restrictive access and display measures to children’s data. --- ## 18. AUTOMATED PROCESSING A Certificate may be created automatically in accordance with the information entered on the Platform and the instructions provided by the Member. This automated creation process is not an automated decision-making system that: - Assesses the certificate holder’s qualifications, - Determines whether the certificate holder has passed an examination, - Determines whether the certificate holder received training, - Makes a legal or similarly significant decision concerning the individual. The Platform Member is responsible for making such assessments. IASC may automatically flag or temporarily place under review transactions that give rise to security or fraud concerns. --- ## 19. YOUR RIGHTS IN RELATION TO YOUR PERSONAL DATA Depending on the country in which you are located and Applicable Law, you may have the following rights: - To be informed whether your personal data is being processed, - To access your personal data, - To request the correction of inaccurate or incomplete data, - To request the deletion of data, - To request the restriction of processing, - To object to certain processing activities, - To request data portability, - To withdraw explicit consent where processing is based on explicit consent, - To object to direct marketing, - To lodge a complaint. These rights are not absolute. Certain data may need to be retained due to legal obligations, third-party rights, fraud prevention, Certificate verification records and legal claims. --- ## 20. HOW TO SUBMIT A DATA-SUBJECT RIGHTS REQUEST Data-subject rights requests may be sent to: **Privacy Contact Address:** [â—] Where possible, the request should include the following information: - First name and surname, - Contact details, - Relevant Member Account or company name, - Certificate number, - A clear description of the request. We may ask you to verify your identity for security purposes. Do not send your full identification number or a copy of your identity document by unencrypted email when making your initial request. If necessary, you will be informed of a secure verification method. If the request relates to a data-processing activity for which the Platform Member is responsible, the request may be referred to the relevant Member or you may be asked to contact that Member. IASC shall respond to valid requests within the period prescribed by Applicable Law. --- ## 21. CORRECTION OF CERTIFICATE INFORMATION If information on a Certificate is incorrect, the certificate holder may contact the Platform Member that requested the Certificate or IASC. IASC may: - Request supporting documentation for the correction, - Forward the request to the relevant Platform Member, - Place the Certificate under review while the request is being examined, - Create a new version of the Certificate, - Suspend or cancel an incorrect or unlawful Certificate. The previous version of a Certificate may be retained with restricted access for audit-trail and legal-evidence purposes. --- ## 22. RIGHT TO LODGE A COMPLAINT You may first submit your complaint to IASC through the Privacy Contact Address. You also have the right to lodge a complaint with the data-protection supervisory authority in the United Kingdom: **Information Commissioner’s Office – ICO** [https://ico.org.uk/make-a-complaint/](https://ico.org.uk/make-a-complaint/) If you are located outside the United Kingdom, you may also submit a complaint to the competent data-protection authority in your location, where applicable. --- ## 23. EXTERNAL LINKS The IASC website or Platform may contain links to websites operated by third parties. The data-processing activities of third-party websites are governed by their own privacy notices. IASC is not responsible for the content or data-processing practices of third-party websites. --- ## 24. CHANGES TO THIS NOTICE IASC may update this Notice due to legal, technical or operational changes. The current version shall be published on the website. Material changes may be communicated by email, a Platform notification or a notice on the website. The current version number and last-updated date shall be displayed at the beginning of this Notice. --- ## 25. CONTACT If you have any questions concerning this Notice or your personal data, please contact: **IASC LTD** **Address:** SUITE 11029, 5 BRAYFORD SQUARE, LONDON, UNITED KINGDOM, E1 0SG **Privacy Email:** info@iascert.uk **General Email:** info@iascert.uk **Website:** [https://iascert.uk](https://iascert.uk/)