Privacy
This notice describes how personal data is used in the IQQ certificate service.
David Fogaça is responsible for operating IQQ. For privacy questions or requests concerning your personal data, contact: support@iqqinstitute.org
The Registry Office should keep only what it needs.
Browser drafts
The site stores your interface language and nomination draft in this browser. That local draft may contain names, email addresses and wording. The portrait stays in this session and must be selected again after a reload. Clearing the site’s browser data removes the local draft. If you use a shared device, clear it when finished. Requesting a document proof saves a private server draft for 24 hours; it omits email addresses and includes a portrait only with your permission. Submitting checkout sends the nomination to the server.
Server records
Orders and certificates are stored in a PostgreSQL database. Records include purchaser email, an optional recipient email, names, grammatical form, wording, language, design, payment state, serial and signature. Photos and generated files are kept in private server storage. The image processor re-encodes portraits and strips photo metadata. Administration and reporting use restricted records and audit logs.
Client accounts
An optional client account stores your email, confirmation state and a password hash. It uses a private session cookie and single-use confirmation/recovery links. Only new orders placed while signed in are associated with that account. Confirming an email does not claim earlier guest orders. Client access is separate from administrative access.
Payment and email providers
Configured live checkout uses Stripe; card details are entered with the payment provider rather than in the IQQ form. Email processing uses Resend with a configured sender. It sends a private management link to the purchaser and, only when requested, one invitation to one recipient. In local sandbox testing no payment is charged and email payloads are captured in the local database without contacting recipients.
Public certificate pages
Anyone with the serial or public link can consult the recipient’s name, qualification, academic title, faculty, language, issue date, status and signature result. The public document image also contains the justification and the nominator’s name if printing it was selected. That public PNG can be downloaded and shared. Emails and the private portrait are omitted. Complete PNG/PDF documents with a portrait require a private purchaser or recipient access link. Certificate pages request no search indexing, and the site has no public search by recipient name. A shared link is still accessible to its holder.
Access links and invitations
Private management links expire after 30 days and authorize the holder to access files, request a resend or remove the document. Recipient reveal links also expire after 30 days. Opt-out links expire after 365 days; opting out stores a hash of the email address to suppress future recipient invitations. These tokens are private, so avoid forwarding them.
Reports and removal
Reports store the certificate number, reason, description and reply email for review. A removal clears the personal certificate snapshot and personal nomination fields, removes pending email content, and deletes the stored portrait and generated files. The serial and minimal transaction/audit evidence can remain. Removal cannot erase copies already downloaded, forwarded or retained by a provider.
Retention and backups
Private server drafts expire after 24 hours. Session access expires after eight hours; expired sessions and unusable account email content are cleaned up by the worker. Active certificates are retained to provide delivery and verification until removal is requested. Reports, payment references and audit evidence are kept as needed to review requests, prevent abuse and meet applicable legal obligations. Restricted access logs omit page paths, query strings and access tokens; they have a daily rotation with a 190-day retention setting. Daily IQQ backups normally retain 14 days; external recovery copies and hosting-provider backups follow their own recovery arrangements. Old copies may contain earlier data. Restoration must respect prior removal requests. For a review or removal request, contact support.
Your choices
Photos and recipient invitations are optional. Avoid sensitive information in a humorous certificate. Use the private management link to remove your document, the recipient link to stop invitations, or the reporting form to request a review of unwanted content. Administrative sign-in uses a session cookie; language and draft preferences use local storage.