1. Who we are and scope
AutoCertify is a software platform that helps organizations design certificate templates, generate personalized certificates, distribute them by email, and verify authenticity via public verification pages and QR codes.
This Policy applies to visitors of https://autocertify.in, account holders, organization members, and individuals who interact with certificates or verification pages issued through the Services.
Controller / processor roles. When you create an account for yourself, we act as an independent controller of your account and billing data. When an organization uploads recipient lists, certificate fields, or sends campaigns, that organization is typically the controller (or equivalent under applicable law) of recipient personal data, and AutoCertify processes that data on the organization’s instructions as a processor / service provider.
2. Information we collect
2.1 Information you provide
- Account data: name, email address, password or authentication identifiers, organization affiliation, and profile details.
- Organization data: organization name, member roles (owner / admin / member), and workspace settings.
- Certificate & campaign content: templates, logos, signatures, recipient names and emails, custom merge fields, campaign settings, and related files you upload.
- Billing data: plan selection, credit purchases, and payment metadata processed by our payment provider (we do not store full card numbers on our servers).
- Support communications: messages you send to support@autocertify.in or privacy@autocertify.in.
2.2 Information collected automatically
- Device and log data (IP address, browser type, approximate location derived from IP, timestamps, referring URLs, and error logs).
- Usage data about product features (pages viewed, actions taken in the dashboard), subject to your cookie preferences for non-essential analytics.
- Cookies and similar technologies as described in our Cookie Policy.
2.3 Information from third parties
- Authentication providers (for example Google OAuth) when you choose to sign in with them.
- Payment processors (for example Razorpay) confirming payment status and subscription state.
3. How we use personal information
We use personal information to:
- Provide, operate, secure, and improve the Services
- Authenticate users and manage organizations and roles
- Generate certificates, store assets, send campaign emails, and operate public verification pages
- Process payments, subscriptions, and credit purchases
- Respond to support requests and send transactional notices
- Detect, prevent, and investigate fraud, abuse, and security incidents
- Comply with law and enforce our Terms of Service
- With consent where required, measure product usage and send product updates or marketing communications
4. Legal bases (where applicable)
If you are in the European Economic Area, UK, or similar jurisdictions, we process personal data under one or more of these bases: performance of a contract; legitimate interests (for example securing and improving the Services, provided those interests are not overridden by your rights); consent (for example optional cookies or marketing); and legal obligation.
If you are in India, we process personal data in accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and applicable rules, including for purposes you have consented to or that are otherwise permitted (such as employment-like contractual necessity for providing the Services you request).
5. How we share information
We may share personal information with:
- Service providers / subprocessors that host infrastructure, email delivery, object storage, databases, queues, analytics (when enabled), and payment processing — under contractual confidentiality and data-protection obligations.
- Organization administrators within your workspace, according to roles and permissions.
- Public verification surfaces when a certificate is issued: limited certificate authenticity details may be shown on the verification page associated with a certificate ID / QR code.
- Authorities when required by law or to protect rights, safety, and security.
- Business transfers in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate safeguards.
We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising unless you opt in to marketing/analytics technologies that enable such sharing where applicable law defines it that way.
6. International transfers
We may process and store information in India and other countries where we or our providers operate. Where required, we use appropriate transfer mechanisms (such as contractual clauses) and implement technical and organizational measures to protect personal data.
7. Retention
We retain account and organization data for as long as your account remains active and as needed to provide the Services. Certificate, recipient, campaign, and billing records are retained for the life of the customer relationship and thereafter for a limited period as required for audits, dispute resolution, security, and legal compliance, unless a shorter period is agreed in a customer contract or required by law. You may request deletion as described below; some residual copies may remain in backups for a limited time.
8. Security
We implement administrative, technical, and physical safeguards designed to protect personal information, including access controls, encryption in transit, and least-privilege practices. No method of transmission or storage is 100% secure; you are responsible for safeguarding account credentials and for configuring organization access appropriately.
9. Your rights and choices
Depending on your location, you may have rights to access, correct, delete, port, restrict, or object to certain processing; withdraw consent; and lodge a complaint with a supervisory authority. Under US state privacy laws (including CCPA/CPRA for California residents), you may also have rights to know, delete, correct, and opt out of sale/sharing, and not to be discriminated against for exercising rights.
To exercise rights related to your account data, contact privacy@autocertify.in. To exercise rights related to recipient / certificate data uploaded by an organization, please contact that organization first; we will assist them as their processor.
Cookie preferences can be managed via the Cookie settings link in our footer or our Cookie Policy.
10. Children
The Services are not directed to children under 16 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal information from children for account creation. If an organization issues certificates involving minors, that organization is responsible for having an appropriate legal basis and notices.
11. Third-party links and integrations
The Services may link to or integrate with third-party services (authentication, payments, email, storage). Their privacy practices are governed by their own policies.
12. Changes
We may update this Privacy Policy from time to time. We will post the updated version and revise the “Last updated” date. Material changes may be communicated by email or in-product notice where appropriate.
13. Contact
Privacy inquiries: privacy@autocertify.in
Support: support@autocertify.in
Legal: legal@autocertify.in
This Policy is intended to provide transparent notice for a global SaaS audience and is not legal advice. If you need a signed DPA or jurisdiction-specific addendum for enterprise use, contact legal@autocertify.in.