ZERTI · Legal document
Personal Data Processing Policy
1. Data Controller
The Data Controller of personal data collected through zerti.co and its subdomains is PLATCOM SAS, a company identified with Tax ID (NIT) 900405003-6, domiciled at Calle 118 No. 19-52, Of. 204, Bogotá D.C., Colombia, phone +57 320 4919308.
The official channel for exercising the rights of the Data Subject and for queries and complaints regarding habeas data is the public form at Contact. We do not publish direct email addresses in order to reduce spam risk; requests sent through the form receive formal treatment within the timeframes stated in this Policy.
2. Scope
This Policy applies to personal data that ZERTI collects and processes directly as part of the service, as well as to data that its Customers upload to the platform about their own data subjects (for example, participants in a course to whom a certificate is issued).
With respect to the data that Customers upload to the platform, ZERTI acts as a Data Processor and follows the Customer's instructions; the Customer is the Data Controller in relation to those subjects.
3. Definitions (Law 1581/2012)
- Data Subject: natural person whose personal data are subject to Processing.
- Data Controller: the one who decides on the database and the Processing.
- Data Processor: the one who carries out the Processing on behalf of the Controller.
- Processing: any operation on personal data (collection, storage, use, circulation or deletion).
- Authorization: prior, express and informed consent of the Data Subject.
4. Data we collect
We may collect, depending on how the service is used:
- Customer account data: name, email, hashed password, country and billing details.
- Certificate holder data: whatever the Customer chooses to include in each certificate (typically name, ID number, email and any custom field configured by the Customer).
- Technical data: IP address, device type, browser and pages visited, for security, fraud prevention and usage statistics.
- Validation data: when someone validates a certificate by QR or serial, we record the date, IP and approximate geolocation, in order to give the issuer evidence that their certificate is being consulted.
- Payment data: processed through the provider Stripe. ZERTI does not store full card numbers.
We do not deliberately collect sensitive data (health, biometrics, political opinion, sexual orientation, etc.). If a Customer decides to upload such data in a certificate, they must have the qualified authorization required by Article 6 of Colombian Law 1581/2012.
5. Purposes of Processing
Data are processed for the following purposes:
- Delivering the contracted service: issuing, delivering, storing and validating certificates.
- Sending transactional communications (confirmations, security alerts, contractual changes).
- Managing billing and payment collection.
- Handling queries, requests, complaints and claims.
- Preventing fraud, abuse or misuse of the service.
- Complying with legal, accounting and tax obligations.
- Sending commercial information about ZERTI products and services, only where the Data Subject has authorized it and until such authorization is revoked.
6. Legal basis
Processing is based on the prior, express and informed authorization of the Data Subject, given at the time of registration and acceptance of this Policy; on the performance of the service contract; on compliance with legal obligations; and on the legitimate interest of the Controller in preventing fraud and safeguarding the security of the platform.
For data that Customers upload about their own data subjects, the Customer states that it has the required authorization and remains liable to those subjects as Data Controller.
7. Minors
The service is aimed at adults and organizations. Processing of minors' data requires that the holder of parental authority or legal representation provide the corresponding authorization, and provided that the processing serves and respects the best interests of the minor, in accordance with Article 7 of Law 1581/2012.
8. Sensitive data
ZERTI does not request sensitive data from the Data Subject. If the Customer configures fields that may contain sensitive data (e.g., health information in a medical certificate), the Customer must obtain explicit authorization, inform about the optional nature of answering and warn about the purpose. ZERTI may refuse to process sensitive data whose collection is manifestly disproportionate.
9. Rights of the Data Subject
In accordance with Law 1581/2012 and Decree 1377/2013, every Data Subject has the right to:
- Know, update and rectify their personal data.
- Request proof of the authorization granted.
- Be informed, upon request, about the use given to their data.
- File complaints with the Superintendence of Industry and Commerce (SIC) for breaches of the law.
- Revoke authorization and/or request deletion of the data, save for a legal or contractual obligation to keep it.
- Access their personal data being processed, free of charge.
- Object to the use of their data for commercial purposes.
These rights are exercised before the Data Controller through the Contact form.
10. Procedure for queries and complaints
QUERIES are answered within a maximum term of ten (10) business days counted from receipt. Where this is not possible within that term, the interested party will be informed, stating the reasons for the delay and the date on which the query will be answered, which in no case may exceed the five (5) business days following the expiration of the first term.
COMPLAINTS will be answered within a maximum term of fifteen (15) business days counted from the day following the date of receipt. Where this is not possible within that term, the interested party will be informed of the reasons for the delay and the date on which their complaint will be answered, which in no case may exceed the eight (8) business days following the expiration of the first term.
If the complaint is incomplete, the interested party will be required, within five (5) days after receipt, to correct the deficiencies. If two (2) months pass from the date of that requirement without the applicant providing the required information, it will be understood that the complaint has been withdrawn.
11. Processors and technology providers
To provide the service ZERTI uses trusted technology providers that act as Data Processors, including:
- OVH (France/EU): hosting and email infrastructure.
- Stripe (United States/Ireland): payment processing.
- Cloudflare (United States): web distribution and security network.
- Backblaze B2 (United States): encrypted backups.
All processors are bound by agreements that guarantee the confidentiality and security of personal data. ZERTI will select only processors that guarantee adequate levels of protection.
12. International transfers
Due to the global nature of cloud services, some personal data may be transferred to countries whose legal framework may differ from that of Colombia. ZERTI adopts the appropriate safeguards (standard contractual clauses, data-processing agreements with its processors) so that such transfers meet the level of protection required by Colombian Law 1581/2012 and, where applicable, by the European Union's General Data Protection Regulation (GDPR).
By accepting this Policy, the Data Subject expressly authorizes such international transfers for the purposes described.
13. Security measures
ZERTI applies reasonable technical and administrative measures to protect personal data against unauthorized access, loss, alteration or improper disclosure, including:
- Encryption in transit (HTTPS/TLS) across all site pages and in the communication with the database.
- Storage of passwords with key-derivation (hash) functions and sensitive content encrypted with AES-256-GCM.
- Regular encrypted backups with controlled retention.
- Role-based access controls within the ZERTI team, principle of least privilege, and logging of sensitive activities.
14. Data retention
Account data are kept while the relationship with the Customer exists and for the additional time necessary to comply with legal, accounting or claim-defense obligations.
Data of the certificate holders included in certificates are kept as long as the Customer keeps them in their account. Deletion of a certification or participant by the Customer deletes the corresponding data, without prejudice to backups, which are purged in accordance with the defined retention cycle.
15. Cookies and similar technologies
ZERTI uses cookies strictly necessary for the operation of the site (session, language preference, CSRF protection) and aggregate statistics cookies. We do not use third-party advertising cookies. The User can configure their browser to block cookies; some features may become unavailable.
16. Changes to the Policy
ZERTI may update this Policy. Prior versions are archived and available upon request. Material changes will be notified to the Customer's email with reasonable advance notice.
17. Effective term
This Policy is effective as of its publication and remains in force while the service is provided through zerti.co. Databases managed by ZERTI shall have a validity equal to the time for which the purpose of Processing is maintained.