Privacy
Privacy Policy
This policy explains how Cardoholding Digitalized Solutions handles personal data, document content, verification metadata, marketplace information, and support records connected to DecentraTrust.
1. Overview
This Privacy Policy explains how Cardoholding Digitalized Solutions collects, uses, stores, discloses, and protects personal data and customer content in connection with DecentraTrust, our website, product evaluations, subscriptions, implementations, support, and marketplace transactions.
DecentraTrust is designed for high-trust document workflows. Because customers may process credentials, records, audit evidence, holder information, issuer data, and verification metadata, customers should configure the service according to their own privacy, security, retention, and legal obligations.
2. Roles and responsibilities
For document content and verification workflows submitted by a customer, the customer is typically the controller, business, or data owner, and Cardoholding Digitalized Solutions acts as a processor, service provider, or vendor operating the service according to customer instructions and the applicable agreement.
For our website, lead forms, billing communications, account administration, security monitoring, and direct business contact information, Cardoholding Digitalized Solutions may act as an independent controller or business responsible for its own processing activities.
3. Information we collect
- Account and contact data: names, business emails, phone numbers, organization names, roles, administrator profiles, support contacts, and authentication-related records.
- Document and verification data: uploaded files, hashes, document metadata, issuer details, holder details, credential status, verification IDs, QR links, audit events, proof packages, signatures, review notes, and automated analysis signals configured for the service.
- Technical and usage data: IP addresses, device and browser information, timestamps, log events, API activity, diagnostic data, security events, feature usage, error reports, and performance data.
- Marketplace and billing data: AWS Marketplace subscription identifiers, buyer account references, entitlement status, offer metadata, billing events, procurement contacts, and transaction status where provided through marketplace workflows.
- Communications: inquiries, demos, support tickets, implementation notes, security questionnaires, feedback, and other messages sent to us.
4. How we use information
- Provide, secure, operate, support, and improve DecentraTrust.
- Register trusted records, process document verification, generate proof artifacts, maintain audit trails, and deliver configured workflow features.
- Authenticate users, administer accounts, enforce permissions, monitor service health, prevent abuse, and investigate security events.
- Respond to inquiries, provide implementation support, process product requests, and communicate service, security, legal, or administrative notices.
- Manage subscriptions, marketplace entitlements, invoicing, renewals, procurement requests, and support obligations.
- Comply with legal, contractual, tax, accounting, security, audit, sanctions, export, and regulatory obligations.
5. Automated analysis and verification signals
DecentraTrust may use configured automated analysis to identify document type, extract or compare metadata, flag anomalies, support review workflows, or produce verification signals. Automated analysis is intended to assist review, not to make legally binding decisions by itself.
Customers are responsible for deciding when human review, notice, consent, appeal rights, bias testing, recordkeeping, or other safeguards are required for their use case and jurisdiction.
6. Sharing and disclosure
We do not sell customer document content. We may disclose information to service providers, cloud infrastructure providers, security and monitoring vendors, professional advisors, payment or marketplace providers, support tools, and subprocessors that help operate the service under appropriate confidentiality and security obligations.
We may disclose information when required by law, legal process, sanctions or export checks, security investigation, protection of rights, business transfer, or with customer direction or consent. Customer-configured verification links, QR codes, proof packages, or public verification pages may disclose selected verification data to recipients chosen by the customer.
7. AWS Marketplace and cloud providers
If a customer purchases through AWS Marketplace, AWS may provide marketplace and entitlement information needed to activate, manage, bill, renew, or support the subscription. AWS and other cloud providers process data according to their own agreements and service terms for the services they provide.
Where the service is deployed on or integrated with cloud infrastructure, security and privacy responsibilities are shared between the cloud provider, Cardoholding Digitalized Solutions, and the customer according to the applicable architecture, agreements, and customer configurations.
8. Data retention, export, and deletion
Retention depends on the subscribed service, customer configuration, legal requirements, backup cycles, security needs, support obligations, and the applicable order or data processing terms. Customers may request export or deletion according to their agreement and the technical capabilities of the service.
Some records may be retained where needed for security, fraud prevention, legal compliance, dispute resolution, audit, backup integrity, billing, or enforcement of agreements. Tamper-evident logs and proof records may have limited mutability by design, so customers should define retention rules before using the service for regulated workflows.
9. Security measures
We use commercially reasonable safeguards intended to protect information processed by the service. Measures may include encryption, access control, logging, monitoring, backup procedures, least-privilege administration, vulnerability management, and incident response practices appropriate to the service tier.
No system can be guaranteed perfectly secure. Customers must protect their own accounts, credentials, devices, integrations, networks, exported files, and user permissions.
10. International transfers
Information may be processed in countries where Cardoholding Digitalized Solutions, customers, cloud providers, subprocessors, or support personnel operate. Where required, we use contractual, organizational, and technical safeguards intended to support lawful international transfers.
11. Privacy rights
Depending on location and applicable law, individuals may have rights to access, correct, delete, restrict, object to, or receive a copy of personal data, and to withdraw consent where processing is based on consent. Requests about customer-controlled document workflows should normally be directed to the customer organization first.
We will respond to verified requests that apply to our own processing and will assist customers with data subject requests where required by the applicable agreement and law.
12. Cookies and website analytics
Our website may use essential cookies, security technologies, server logs, and limited analytics to operate the site, protect forms, understand product interest, and improve performance. Browser settings may allow visitors to block or delete cookies, but some features may not work correctly without essential cookies.
13. Children and sensitive data
DecentraTrust is intended for organizational use and is not directed to children. Customers should not submit children personal data, health data, financial account data, government identifiers, biometric data, criminal records, or other sensitive data unless the applicable agreement, product configuration, security controls, and legal basis permit that processing.
14. Incident notification
If we determine that a security incident affects customer data processed by the service, we will notify affected customers as required by applicable law and contract. Customers are responsible for notifying their own users, issuers, holders, regulators, or other stakeholders where they are legally required to do so.
15. Changes and contact
We may update this Privacy Policy to reflect product, legal, security, or operational changes. The effective date will show the latest version. For privacy, security, or data processing questions, contact hello@cardoholding.com.