IACG — International Accreditation Consortium Group ("IACG", "we", "us") operates the IACG accreditation and certificate verification platform. This Privacy Policy explains what personal data we collect when you use our website, submit an accreditation inquiry, register as a Certification Body, or verify a certificate, and how that data is used and protected.
1. Data We Collect
- Identity and contact data: organization name, legal entity name, contact person, email address, phone number, country, and website address.
- Account data: your email address, full name, role, and authentication records when you register or log in to the IACG platform.
- Accreditation and certification data: application documents, audit records, certificate details (certificate numbers, standards, issue and expiry dates), and the organizations associated with them.
- Billing data: subscription details, invoice and payment records, and payment confirmations. Card details are processed by our payment providers (Stripe and doit.id) and are never stored on IACG servers.
- Discrepancy and complaint data: reports submitted through our public discrepancy reporting channel, including reporter contact details.
- Technical data: IP address, browser type, and access logs used for security monitoring and platform analytics.
2. How We Use Your Data
- To assess and process accreditation applications for Certification Bodies in accordance with ISO/IEC 17011.
- To operate the public certificate verification service and maintain the public registry of accredited Certification Bodies.
- To manage subscriptions, invoices, receipts, and payment confirmations.
- To investigate discrepancy reports and complaints, and to maintain the integrity of the accreditation scheme.
- To communicate with you about your application, account, accreditation status, or platform updates you have requested.
- To comply with legal, regulatory, and audit obligations applicable to an accreditation body.
3. Public Registry Data
Certain data is published deliberately as part of the public trust function of accreditation: the names and codes of accredited Certification Bodies, their accreditation numbers, accredited standards, approval and expiry dates, and the certificate numbers and status of issued certificates. By participating in the IACG scheme, Certification Bodies consent to this publication.
4. Legal Basis for Processing
- Contract performance: processing necessary to deliver accreditation services and platform subscriptions you have signed up for.
- Legitimate interests: operating the public verification registry, fraud prevention, and maintaining the integrity of the scheme.
- Consent: optional communications, and the consent you give when submitting public inquiries or discrepancy reports.
- Legal obligation: retaining audit records and complying with applicable laws.
5. Data Sharing
We do not sell personal data. Data is shared only with: (a) our accreditation assessors and decision committees to the extent necessary for the accreditation process; (b) payment providers (Stripe and doit.id) strictly to process payments; (c) IT service providers who host and secure the platform under data processing agreements; and (d) authorities where required by law.
6. International Transfers
IACG operates internationally with offices in the United Kingdom and the United States, and the platform is hosted on cloud infrastructure that may process data in multiple regions. Where personal data is transferred outside your region, we apply appropriate safeguards such as contractual data protection clauses.
7. Data Retention
- Accreditation and audit records: retained for the duration of accreditation plus the period required by our documentation policy and applicable audit standards.
- Public certificate and registry records: retained while the certificate is valid and thereafter as an archive of accreditation history.
- Billing records: retained for the period required by tax and accounting law.
- Discrepancy reports and inquiries: retained while the matter is open, and for a reasonable period thereafter, then deleted or anonymized.
8. Your Rights
Depending on your jurisdiction, you may have the right to access, correct, or delete your personal data, object to or restrict certain processing, and receive a portable copy of your data. To exercise these rights, contact us using the details below. Public registry data may be limited in its ability to be removed while the accreditation record it represents remains subject to verification and audit obligations.
9. Security
We apply technical and organizational safeguards including encryption in transit, access controls, role-based permissions, audit logging, and regular review of our systems. No method of transmission or storage is completely secure; we cannot guarantee absolute security, but we work to protect your data and notify affected individuals and authorities of breaches as required by law.
10. Cookies
The platform uses essential cookies to maintain your session and, where enabled, analytics cookies to understand aggregate usage. You can control non-essential cookies through your browser settings; disabling them does not prevent use of the public verification service.
11. Children's Data
The IACG platform is intended for professional and organizational use. We do not knowingly collect data from children under 16. If you believe a child has provided us data, contact us and we will delete it.
12. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements. The "Last updated" date above indicates the most recent revision. Material changes will be announced on the platform before they take effect.
13. Contact
IACG — International Accreditation Consortium Group, 51 Pancras Way, Kings Cross, London, United Kingdom. Privacy enquiries: office.uk@iacg.uk.
