Home
UIK Global Standard · Legal

Privacy Policy

Last updated: 15 August 2026

Data Controller

UIK Global Standard, registered in England & Wales. Contact: privacy@uikglobalstandard.org

Data Collected

Identity (name, email, role), organization (name, country, sector, size), certification data (missions, uploaded evidence, audit status), payment data (processed by Stripe, never stored by UIK).

Legal Basis

Performance of contract (GDPR 6.1.b), accounting legal obligations (6.1.c), legitimate interest for product analytics and fraud prevention (6.1.f), consent for non-essential cookies (6.1.a).

Purposes

Deliver certification services, issue invoices, send transactional emails, improve the platform, prevent fraud.

Retention

Account: duration of use + 3 years. Invoices: 10 years (UK bookkeeping law). Certificates: indefinitely for public verification.

Processors

Stripe (payments), Resend (emails), MongoDB Atlas (database), Hostinger/Emergent (hosting). All under GDPR-compliant DPAs/SCCs.

International Transfers

Some processors are US-based (Stripe, Resend). Transfers rely on Standard Contractual Clauses (SCCs).

Your Rights

Access, rectification, deletion, restriction, portability, objection, consent withdrawal. Exercise these rights at privacy@uikglobalstandard.org.

Supervisory Authority

You may file a complaint with the ICO (UK) or your local DPA.

Cookies

We use only essential technical cookies (session, language preference). No advertising or third-party tracking cookies.