Privacy Policy

1. INTRODUCTION

MYCV Pty Ltd (trading as CredsVault) ('we', 'us', or 'our') is committed to protecting the privacy and security of personal information. This Global Privacy Policy sets out how we collect, use, store, and disclose personal information in compliance with applicable privacy laws, including the Australian Privacy Act 1988 (Cth), the EU General Data Protection Regulation (EU GDPR), the UK General Data Protection Regulation (UK GDPR) and the UK Data Protection Act 2018, the UK Privacy and Electronic Communications Regulations (PECR), the California Consumer Privacy Act (CCPA/CPRA), and other data protection laws in the regions where we operate. By accessing or using our websites, services, or applications (collectively, the 'Services'), you agree to this policy.


2. PERSONAL INFORMATION WE COLLECT

We may collect personal information (also referred to as 'personal data' in some jurisdictions), which means any information relating to an identified or identifiable individual. The types of information we may collect include:

  • Name, contact details (email, address, phone number)
  • Account or profile information
  • Details of products or services provided to you
  • Technical and usage data (browser, device, IP address, analytics)
  • Communications with us via our site, apps, or social channels
  • Other personal information provided directly or indirectly through your use of our Services
  • Credential data, including credential type, qualifications, compliance records, issuance and expiry dates, events, status changes, and associated metadata processed through our platform on behalf of organizations that use our Services.

3. HOW WE COLLECT AND USE PERSONAL INFORMATION 

We collect personal information directly from you, from third parties you authorize, and automatically through your interaction with our Services.

We use this information for the following purposes, on the legal bases indicated:

  • To provide our Services (necessary to perform our contract with you)
  • To improve our Services, for example through usage analytics (our legitimate interest in developing and improving the platform)
  • To communicate with you about your account or the Services (necessary to perform our contract with you)
  • To send you marketing communications, where permitted (your consent, or our legitimate interest where the soft opt-in exception applies, see Section 5C)
  • To conduct analytics and business development (our legitimate interest in understanding and growing our business)
  • To comply with our legal obligations (necessary for legal compliance)
  • To protect our rights, users, and systems, including preventing fraud and maintaining security (our legitimate interest in keeping the Services and our users safe)

Where we rely on legitimate interests, we have considered and balanced those interests against your rights and freedoms. You have the right to object to this processing, see Section 5.

3A. CREDENTIAL DATA

3A.1 Credential Data We Collect and Retain

We process credential data on behalf of organizations that use our platform. This includes your name, contact details, credential type, qualifications, compliance records, issuance and expiry dates, verification events, and status changes.

We retain this data for the life of your credentials and for a reasonable period after they expire or are revoked, to support ongoing verification, credential portability, and platform integrity. We determine that period based on the regulatory and professional requirements that apply to the credential, the needs of the issuing organization, and our legal obligations.


3A.2 How We Use Credential Data

When operating the platform on behalf of the organization that issued your credential, we act as a service provider for that organisation, which remains responsible for that processing. Where we use credential data for our own purposes described in this section, we act as an independent controller for those specific purposes only. In addition to operating the platform on behalf of the organization that issued your credential, we use credential data in our capacity as an independent data controller for the following purposes:

  • Operating, maintaining, and improving the platform
  • Credential intelligence, workforce analytics, and industry benchmarking
  • Workforce discovery, skills matching, and workforce compliance services, including identifying skills and credentials relevant to workforce needs and confirming credential status for compliance purposes
  • Business continuity in the event of a sale, merger, or acquisition, as described in Section 3A.4.
  • Where required by law, we will ask for your consent before sharing your identifiable credential profile with a third party for recruitment or workforce discovery purposes or allowing a third party to contact you through our platform. You can object to the use of your credential data for workforce discovery and skills matching at any time by contacting privacy@credsvault.io.

3A.3 Lawful Basis for Processing

Where the EU GDPR or UK GDPR applies, our lawful basis for processing credential data is:

  • Contract performance: processing necessary to operate the credentialing platform on behalf of the issuing organization
  • Legitimate interests: processing for platform improvement, credential intelligence, workforce analytics, industry benchmarking, workforce discovery, skills matching, and workforce compliance services.
  • Consent: where required by law, sharing your identifiable credential profile with a third party for recruitment or workforce discovery purposes, or allowing a third party to contact you through our platform.
  • We have assessed that these interests are not overridden by your rights and freedoms, taking into account the professional and regulatory nature of credential data and the transparency of this disclosure.

You can object at any time to processing based on our legitimate interests by contacting privacy@credsvault.io. If you object, we will stop that processing unless we have compelling legitimate grounds that override your interests, rights, and freedoms, or we need the data to establish or defend legal claims.

3A.4 Transfer on Acquisition

In the event CredsVault is acquired or merged with another entity, your credential data and the rights described in this policy transfer to the successor entity. The successor entity will be bound by the terms of this Privacy Policy with respect to credential data collected prior to the transfer.

4. DISCLOSURE OF PERSONAL INFORMATION

We may disclose personal information to our employees, contractors, service providers, business partners, professional advisers, or regulatory authorities for the purposes set out in this Policy.



We do not transfer or store personal information outside your country of residence unless you have expressly consented to such transfer, for example, when engaging with a third-party service that you have chosen to connect to your account. In such cases, we take reasonable steps to ensure that the recipient handles your personal information in accordance with applicable data protection laws.

5. YOUR RIGHTS AND CHOICES

Depending on your location, you may have rights to access, correct, delete, or restrict processing of your personal information, as well as the right to data portability, to object to processing, and to withdraw consent. To exercise these rights, contact us at privacy@credsvault.io.

For credential data, deletion requests will be assessed against our retention obligations. We may decline or delay a deletion request where retention is necessary to comply with a legal obligation, to establish or defend legal claims, or to preserve an accurate record of a credential's status, including where it remains current, has expired, or has been revoked. If we decline a request, we will notify you of the reasons.

5A. Consent and Choice

Where we rely on your consent to process personal information (for example, for certain marketing communications or non-essential cookies), we will ask for it clearly and separately from other terms. For all other processing, we rely on the lawful bases described in Sections 3 and 3A.3.

You are not required to provide personal information, but if you choose not to, it may limit your ability to access certain Services or features.

You may withdraw your consent or object to processing at any time by contacting us at privacy@credsvault.io. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

5B. Information Received from Third Parties

If we receive personal information about you from a third party (for example, an employer, educational institution, or credentialing partner), we will handle it in accordance with this Policy.

Where applicable, we require that the third party has obtained your consent or is otherwise lawfully permitted to disclose such information to us.

5C. Marketing and Communications

We may, from time to time, send you communications about our Services, updates, or opportunities that we believe may be relevant or beneficial to you.

You may opt out of receiving marketing communications at any time by using the unsubscribe link in the communication or by contacting us at privacy@credsvault.io.

We do not sell or rent personal information to third parties for marketing purposes.

Service messages necessary to deliver the Services you have signed up for, for example issuing, updating, or verifying a Digital Credential, are not marketing communications. These messages will continue for as long as necessary to provide the Services, even if you have opted out of marketing communications.

5D. Links to Other Websites and Third-Party Services

Our Services may contain links to websites or services operated by third parties. We do not control and are not responsible for the content, privacy practices, or data handling of those external sites.

We encourage you to review the privacy policies of any third-party websites you visit or services you connect to through CredsVault.

6. DATA RETENTION

We retain personal information only for as long as necessary for the purposes described in this Policy, including to meet our legal, regulatory, accounting, and reporting obligations.

Credential data is retained for the life of the credential and for a reasonable period after it expires or is revoked, based on the regulatory and professional requirements that apply to the credential, the needs of the issuing organization, and our legal obligations. This supports ongoing verification, credential portability, and platform integrity, in line with recognized digital credentialing and open badges standards. At the end of that period, we delete or anonymize the data.

For other personal information, we determine the retention period based on the amount, nature, and sensitivity of the information, the purposes for which we hold it, and our legal obligations. You may request deletion of your personal information at any time. Deletion requests are handled as described in Section 5.

7. STORAGE AND SECURITY

We are committed to safeguarding personal information through appropriate physical, electronic, and managerial measures. While we take reasonable precautions to protect your data, no transmission over the Internet can be guaranteed as completely secure.

8. COOKIES AND TRACKING TECHNOLOGIES

We may use cookies, web beacons, and similar technologies to improve user experience and analyze website traffic. Where required by law, we seek consent before placing non-essential cookies. You can manage cookie preferences through your browser settings.

8A. Detailed Information on Cookies and Tracking Technologies

We use cookies and similar technologies (including web beacons, pixels, and analytics scripts) to improve user experience and analyze how our Services are used.

These technologies may collect information such as browser type, device identifiers, pages visited, and time spent on our website.

Cookies are categorized as follows:

  • •Essential Cookies – Required for our Services to function properly.•
  • Analytics Cookies – Help us understand how users interact with our Services.
  • Marketing Cookies – Used to personalize content and measure the effectiveness of our advertising.



Where required by law, we will request your consent before setting non-essential cookies. You can manage or disable cookies through your browser settings.

Third-party services we use (such as Google Analytics) may also collect information as described in their respective privacy policies.

9. CHILDREN’S PRIVACY

Our Services are not directed at children under 16 (or as required by local law). We do not knowingly collect personal information from children without parental consent.

10. COMPLAINTS AND SUPERVISORY AUTHORITIES

If you believe that we have breached applicable privacy laws, please contact us using the details below so we can investigate and respond. You may also lodge a complaint with the relevant data protection or privacy authority in your location.

10A. Access Requests and Administrative Fees

In accordance with applicable law, you may request access to the personal information we hold about you.

Where a request is manifestly unfounded or excessive, we may charge a reasonable administrative fee for processing it, or decline to act on the request.

We may also deny requests in circumstances where disclosure would breach another person's privacy or as otherwise permitted by law.

10B. Data Breach Notification

If we become aware of a data breach likely to result in a risk to your rights or personal information, we will: assess and contain the breach as quickly as possible; notify the relevant regulator where required by law; and notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms, or where otherwise required by law, including what happened, what information was involved, and what we recommend you do.

11. CHANGES TO THIS POLICY

We may update this Policy from time to time to reflect changes in law, technology, or our operations.

If we make material changes, we will notify you by email (where possible) or by posting a notice on our website prior to the change taking effect.

Your continued use of our Services following such notice will constitute your acceptance of the updated Policy.

12. CONTACT US

MYCV Pty Ltd (trading as CredsVault)

Email: privacy@credsvault.io

Website: www.credsvault.io

If you have any questions about this Privacy Policy or our data handling practices, please contact us.