LEGAL
Privacy policy.
What the federation collects, why, and what is published forever.
This page is published in English, the working language of the federation. The English text is authoritative. · Le texte anglais fait foi.
1. Who is responsible
The IFAIFPA secretariat is responsible for personal data processed through this site and the accreditation service. For any privacy matter, write to the public contact address shown in the footer.
2. What we collect
Account data: the email address you sign in with, one-time verification codes, and your interface language (stored so that messages reach you in the language you read). Application data: the organisation, contact, premises and evidence information an applicant submits under a scheme, including uploaded documents and their cryptographic hashes. Register data: the facts of published accreditation decisions. Technical data: the minimum server logs needed to operate and secure the service.
3. Why we process it
To take steps you request prior to and during an application; to carry out independent assessment and decision-making; to maintain a permanent public register of accreditation decisions, which is the federation's public-interest purpose; to secure the service; and to establish or defend legal claims.
4. The public register is permanent
When a certificate is published, the register shows the record identifier, subject name, scheme, scope, jurisdiction, validity dates, status, lifecycle history, certificate number, issue instant and content hash. Withdrawal from publication hides a record from the public view; it does not delete it, because a register that deletes its history cannot be relied on. Suspension and revocation remain permanently visible. This retention is deliberate and proportionate to the register's purpose.
5. Where your data goes
The service runs on contracted processors: web hosting and delivery (Vercel), database and authentication (Supabase), and a transactional email provider. Processing may involve transfers outside your jurisdiction, protected by the processors' safeguards and contractual commitments. Personal data is never sold, and this site carries no advertising and no third-party tracking. The only browser storage used is strictly necessary: your session, your language preference, local application drafts (until submitted or cleared), retry checkpoints containing application identifiers and hashes, and — on administrators' own devices — the administration workspace. Files selected for an unfinished application are not retained after closing or reloading the page; they must be selected again.
6. How long we keep it
Application files and evidence are retained for the accountability period of the scheme concerned; register entries are retained permanently as described above; account data is retained while the account exists.
7. Your rights
You may request access to, correction of, or deletion of your personal data, and you may object to processing. Deletion cannot extend to published register facts, whose retention is described in section 4; where correction of a register entry is warranted, the register records the correction rather than erasing history. You may also lodge a complaint with a data-protection supervisory authority.
8. Changes
Material changes to this policy are published on this page with a new effective date.