Last updated: 15 August 2026
UIK Global Standard, registered in England & Wales. Contact: privacy@uikglobalstandard.org
Identity (name, email, role), organization (name, country, sector, size), certification data (missions, uploaded evidence, audit status), payment data (processed by Stripe, never stored by UIK).
Performance of contract (GDPR 6.1.b), accounting legal obligations (6.1.c), legitimate interest for product analytics and fraud prevention (6.1.f), consent for non-essential cookies (6.1.a).
Deliver certification services, issue invoices, send transactional emails, improve the platform, prevent fraud.
Account: duration of use + 3 years. Invoices: 10 years (UK bookkeeping law). Certificates: indefinitely for public verification.
Stripe (payments), Resend (emails), MongoDB Atlas (database), Hostinger/Emergent (hosting). All under GDPR-compliant DPAs/SCCs.
Some processors are US-based (Stripe, Resend). Transfers rely on Standard Contractual Clauses (SCCs).
Access, rectification, deletion, restriction, portability, objection, consent withdrawal. Exercise these rights at privacy@uikglobalstandard.org.
You may file a complaint with the ICO (UK) or your local DPA.
We use only essential technical cookies (session, language preference). No advertising or third-party tracking cookies.