Privacy Policy
Version 2026-07-31.1 · How we handle your personal data on the Certification Platform.
1. Who is responsible for your data
The controller for the processing described on this page is IONOS Cloud GmbH, Elgendorfer Straße 57, 56410 Montabaur, Germany. You can reach us about data protection at datenschutz@ionos.de.
Our Data Protection Officer is IONOS SE — Der Datenschutzbeauftragte, contactable at datenschutz@ionos.de or in writing at 56410 Montabaur, Germany.
2. What we collect, why, and on what legal basis
We only collect what we need to run certification exams and issue credentials. Each purpose below is separate — we do not reuse data from one purpose for another without a basis to do so.
Your account
Your email address, display name, and (if you set one) avatar and public profile handle, together with your password hash, two-factor secret if enabled, language and timezone. If you sign in with Google, we receive your name, email address, and Google account identifier from Google. We also record the IP address and browser user-agent of each sign-in to protect your account against unauthorised access. Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR), and our legitimate interest in account security (Art. 6(1)(f)).
Booking and sitting an exam
Your booked slot, the exam you sat, your answers, your per-question and overall scores, your pass or fail result, and technical events from the exam client such as when the exam window lost focus. Legal basis: performance of our contract with you (Art. 6(1)(b)).
Proctoring during your exam
If your exam is proctored, we record video and audio from your camera and microphone and capture snapshots of your screen for the duration of the exam. Automated checks analyse this material for indicators such as where you are looking, whether more than one person is present, whether the video appears manipulated, and whether a phone is visible. Where a check fires, we store the finding, its confidence score, and the relevant frame.
This only happens after you have given explicit consent at the start of the exam, and we record when you gave it. You may withdraw consent at any time by ending the exam session; withdrawal does not affect processing that already took place, and an exam ended this way cannot be scored. Legal basis: your explicit consent (Art. 6(1)(a)).
Your credential
When you pass, we issue a digital credential in the Open Badges 3.0 format. Deliberately, this does not contain your email address — it contains a one-way salted hash of it, which lets anyone confirm the credential is genuine and belongs to you without your address ever being published or discoverable. Your name appears on a credential only if you switch that on in your privacy settings; it is off by default. Legal basis: performance of our contract (Art. 6(1)(b)) for issuing the credential, and your consent (Art. 6(1)(a)) for each optional public disclosure.
Administrative records
We keep an audit log of privileged actions taken in the platform, including who did what and from which IP address. Legal basis: our legitimate interest in the security and integrity of the certification process, and our accountability obligations under Art. 5(2) GDPR.
3. Automated decision-making
Your exam is scored automatically, and automated proctoring checks may flag your session for review. Because the outcome determines whether you receive a certification, this is automated decision-making within the meaning of Art. 22 GDPR.
Proctoring flags do not by themselves invalidate an exam — a human reviewer examines flagged sessions before any decision is taken. You have the right to obtain human intervention, to express your point of view, and to contest the outcome.
To do so, use the “Something went wrong with this exam?” link on your result page. A person will review your exam, including the technical record of your session, and reply. If we find a problem we can reopen the exam so you can sit it again, or correct the result. You can also write to us at datenschutz@ionos.de if you would rather not use the form.
4. Who else sees your data
We do not sell your data and we do not use it for advertising. This site sets no advertising or analytics cookies and embeds no third-party trackers.
Your exam data, including proctoring recordings, is stored on IONOS infrastructure in the European Union. The video server that carries your proctoring session is operated by us on that same infrastructure — your video is not sent to an external video provider.
Where you choose to sign in with Google, your sign-in is processed by Google LLC in the United States. Where we send you transactional email, such as a booking confirmation, the message is delivered by our email provider. Transfers to countries outside the EU/EEA are made on the basis of an adequacy decision of the European Commission or, where none applies, Standard Contractual Clauses. You can request a copy of the safeguards in place from datenschutz@ionos.de.
Credentials you have chosen to make public are, by their nature, visible to anyone with the link.
5. How long we keep it
Everything below is deleted automatically by a job that runs every day — these are not targets, they are what the system does.
- Proctoring video, audio and screen captures — 30 days. Including any still images captured when an automated check fired.
- Your answers — 90 days. What you actually typed or selected is erased after 90 days; the marks awarded are kept for a year so we can re-check a disputed result. Your overall score does not depend on either and is kept with your record.
- Technical events from the exam client — 90 days.
- Proctoring check results — one year. The finding itself, after the imagery behind it has gone.
- Exams you started but never completed — one year.
- Expired sign-in sessions — 7 days after they expire.
Your account and your certification records are kept for as long as you hold an account with us, because a certification has to remain verifiable for its stated lifetime. When you ask us to delete your account, we erase your personal data and anonymise your credential records so that the credential remains verifiable but is no longer linked to you.
Records we are required by law to retain, such as invoices, are kept for the statutory period and then deleted.
6. Your rights
Under the GDPR you have the right to:
- be informed about how your data is processed — this page
- access your data and obtain a copy of it (Art. 15)
- have inaccurate or incomplete data corrected (Art. 16)
- have your data erased (Art. 17)
- restrict how we process your data (Art. 18)
- receive your data in a structured, commonly used, machine-readable format, and have it transmitted to another organisation (Art. 20)
- object to processing based on our legitimate interests (Art. 21)
- withdraw any consent you have given, at any time, without affecting the lawfulness of processing carried out before withdrawal (Art. 7(3))
You can exercise several of these directly in your account settings. For anything else, contact datenschutz@ionos.de and we will respond within one month.
You also have the right to lodge a complaint with a data protection supervisory authority at any time.
7. How we protect your data
Data is encrypted in transit and at rest. Access is restricted by role, and administrative actions are recorded in a tamper-evident audit log. Passwords are stored only as hashes, and credentials are never written to our application logs. Two-factor authentication is available on every account and we recommend enabling it.
8. Changes to this policy
This is version 2026-07-31.1. If we change how we process your data we will update this page and, where the change is material, tell you directly. Where you have consented to proctoring, we record which version of this policy was in force at the time, and we will ask again rather than rely on old consent for new processing.

