Privacy Policy
Last updated: September 29, 2026
This Privacy Policy explains how Adaptive Smart Tech ("AST Certify," "we," "us," or "our") collects, uses, and protects information when you use astcertify.com and its related subdomains (collectively, the "Service").
1. Who This Applies To
The Service is used by three kinds of people, and this policy covers all of them:
- Certification bodies — organizations that register to build and run certification programs, and the people who work in them.
- Candidates — individuals who learn, take exams and are certified through a certification body.
- Visitors — anyone visiting our public website or using the public credential verification tool.
2. Information We Collect
We collect only what's needed to operate the Service:
- Account information: organization name, your name, email address, and phone number (if provided) when a Company registers.
- Candidate information: name and email address, progress through a certification program, exam attempts and scores, and certifications, provided by or recorded for the certification body you're certified through.
- Exam records: each exam paper is kept exactly as it was presented to the candidate — the questions, options, order, answers given and timing — so that results can be checked, appeals judged fairly and accreditation requirements met.
- Preferences: choices a candidate makes, such as the language they take an exam in and their display settings.
- Usage information: records of significant actions (such as registration, review decisions, and token purchases) for security, support, and accountability purposes.
- Website analytics: on our public website, astcertify.com, anonymous information about how visitors find and use the site (see section 4).
- Enquiries and demo requests: when you contact us, book a demo or create an account, the details you give (such as your name, organization and what you certify) and, if you tell us, how you heard about us. We use them to reply and to follow up on your interest.
- How you first found us: on your first visit to astcertify.com, a small cookie on your own browser records the page you arrived on, the site that sent you, and any campaign tags in the link (for example, from an advertisement or newsletter). If you later send us a form, this is saved with it so we know which of our efforts reach people. It is kept for 90 days and is not used anywhere in the certification platform.
- Your email choices: whether you have chosen to receive news or event emails from us, and a record of each choice — when it was made, where, and the exact wording you agreed to.
We do not collect payment card numbers directly — token purchases are processed through a third-party payment processor, which handles that information under its own privacy practices.
3. How We Use Information
- To create and manage your account and deliver the Service you signed up for.
- To send account-related communications, including email verification links and important notices about your account.
- To issue and publicly verify certifications, as intended by the Service's core function.
- To maintain security, detect misuse, and keep an audit trail of significant account activity.
- To send marketing email — news about AST Certify, or invitations to events — only if you have chosen to receive it. A choice made on one of our forms is confirmed by email before it counts. Every email we send includes an Email preferences link where you can change your choices or unsubscribe from all marketing at any time. Emails about your account, your demos and your conversations with us are always sent.
4. Third-Party Services We Use
We rely on a small number of third-party providers to operate the Service:
- Email delivery (currently Brevo) — to send verification and account emails.
- Google reCAPTCHA — to protect our registration form from automated abuse.
- Google Sign-In — as an optional way to verify your identity and sign in, if you choose it.
- Google Analytics — on our public website, astcertify.com, only, to understand how visitors find and use it. Google Analytics is not used anywhere in the certification platform itself — not when certification bodies build their programs, and not when candidates learn, take exams or view their results.
- AI services (currently Anthropic) — to help certification bodies with tasks such as translating questions and suggesting how to organize them. What is sent is the content being worked on, such as question and answer text; no candidate's personal information is sent. Every AI suggestion or translation is reviewed and approved by a person at the certification body before it is used, and the record keeps who approved it.
- Hosting — the Service runs on servers located in the United States, operated by our cloud hosting provider.
We do not sell personal information to third parties, and we do not use it for advertising.
5. Public Credential Verification
A core feature of the Service is allowing anyone to verify that a specific certification is real and active, using a unique verification link. Only the minimum information needed to confirm a credential (such as the certification name and status) is shown publicly. Verification does not expose a candidate's full account, contact information, or exam results.
6. Data Retention
We retain account and certification records for as long as your account is active, and as needed to maintain the integrity of the public verification system (a certification's record shouldn't disappear just because it later expires). You may request deletion of your account information as described below, subject to any records we're required to keep for legal, security, or verification-integrity purposes.
7. Your Rights
You can request access to, correction of, or deletion of your personal information by contacting us at [email protected]. We'll respond within a reasonable time and explain any limits on deletion (for example, where a certification record needs to remain verifiable).
8. Data Security
We use industry-standard safeguards to protect your information, including encrypted connections, database-level access controls that keep each organization's data isolated from others, and least-privilege access for our own systems. No system is perfectly secure, but we take this seriously and continue to improve it as the Service grows.
9. Children's Privacy
The Service is intended for use by organizations and adult professionals. It is not directed at children under 13, and we do not knowingly collect personal information from children under 13.
10. Changes to This Policy
We may update this Privacy Policy as the Service evolves. We'll update the "Last updated" date above when we do. Continued use of the Service after changes means you accept the updated policy.
11. Contact Us
Questions about this policy can be sent to [email protected].
This policy is a working draft reflecting the Service's current features and data practices. It has not yet been reviewed by an attorney and should not be treated as final legal advice for your organization's specific compliance needs.