Skip to main content
ASSUREVANCEASSURANCE BODY
ISO 27001 Requirements How it works FAQs Verify Start an application

Legal information

Privacy Notice

Effective date: 30 August 2026. This notice explains how Assurevance collects and uses personal information.

1. Controller and scope

Assurevance LLC of Registered Office: Samstagernstrasse 57, 8832 Wollerau Switzerland is the controller of personal information processed through Assurevance. Contact for privacy questions and data-protection requests.

2. Information we collect

We collect contact and organisation details, application answers, submitted evidence, correspondence, account and security records, credential decisions, public-registry preferences, and technical information such as IP address, browser, device, and cookie data. When someone checks a credential, we record their name, email address, IP address, browser information, entered identifier, referring page, and verification time. We collect information directly from applicants, authorised contacts, registry visitors, public sources, service providers, and people who contact us.

3. Why we use it

We use information to process applications, perform assessments, issue and administer credentials, operate and audit registry and QR verification activity, communicate with applicants, prevent fraud and misuse, secure systems, meet legal obligations, resolve disputes, and improve the Services. Our legal bases are contract, legitimate interests, legal obligation, and consent where required.

4. Public registry

For credentials selected or required for public verification, we may publish the organisation name, credential title and version, certificate number, status, issue/expiry dates, approved scope, and verification URL. We do not intentionally publish personal contact details in the registry. Registry entries remain available while operationally and legally necessary to demonstrate a credential’s current or historical status.

5. Sharing and international transfers

We may share information with authorised personnel, assessors, hosting, email, storage, payment, security, legal, and professional service providers; authorities where required; and parties involved in a dispute or corporate transaction. We require appropriate confidentiality and security commitments. If information is transferred internationally, we will use safeguards required by applicable law, such as an adequacy decision or approved contractual clauses.

6. Retention and security

We retain information only for as long as reasonably necessary to operate the Services, maintain credential records, respond to disputes, prevent fraud, and meet legal obligations. Credential-verification activity is normally retained for 12 months unless a longer period is reasonably required for security, investigation, dispute, or legal purposes. We use proportionate administrative, technical, and organisational safeguards, but no internet service can be guaranteed completely secure.

7. Your choices and rights

Subject to applicable law, you may request access, correction, deletion, restriction, objection, portability, or withdrawal of consent. Contact . We may need to verify identity and may retain information where required by law or legitimate operational needs. You may complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC), or the supervisory authority in your own country.

8. Children and changes

The Services are not directed to children. We may update this notice and will publish the current version and effective date here. Material changes will receive appropriate notice.

Related policies
Terms of Service Privacy Notice Cookie Notice Credential Use Policy Assessment Rules Complaints and Appeals Accessibility Statement Refunds and Cancellation Policy
ASSUREVANCEASSURANCE BODY

Evidence-led management-system assurance with credentials that can be checked in a public registry.

Explore

ISO/IEC 27001 Requirements guide Programme pathway Frequently asked questions

Registry & support

Verify a credential Contact the assurance team Complaints and appeals Assessment rules

Policies

Terms Privacy Credential use Accessibility