Legal

Data Processing Addendum

Last updated: September 20, 2026

This addendum is part of our Terms of Service. It applies automatically — you do not need to sign it. If you need a signed copy, email support@certlister.com.

Who does what

For the content you upload — recipient records, credentials, custom field values, uploaded files and the verification logs they produce — you are the controller and VISIONLANDER LTD. is your processor. We use that data only to provide the Service and only on your instructions. On this page, "your data" means the personal data in that content.

For your account, billing and usage data, we are the controller. Our Privacy Policy explains what we do with it.

"Personal data", "controller", "processor", "subprocessor" and "processing" have the meanings given in the data protection law that applies to you, such as the GDPR or the UK GDPR. If you are yourself a processor — for example, you issue credentials on behalf of a client — the same terms apply and we act as your subprocessor.

The data

Whose data. The people you issue credentials to, and your team members where they appear in the content you upload.

What it is. Names, email addresses, credential details such as title, category, credential number and issue and expiry dates, the custom field values you define, files you upload, and verification logs — the time of each lookup, the credential looked up, and the visitor's IP address and browser.

What must not go in. Health information, government identity numbers and payment card numbers do not belong in credential fields, custom fields or uploads. See Acceptable Use in the Terms. We neither ask for nor want special category data.

Why we process it. To provide the Service: storing records, generating credential files, sending the emails you ask us to send, and answering verification requests.

For how long. For the life of your account, then as described under Deleting and returning data.

How we process it

Your instructions. We process your data only on your documented instructions: the Terms, this addendum, what you do in the Service, and any other written instruction we accept. We follow them unless the law requires otherwise — and if that happens, we tell you, unless the law forbids us from telling you. If we believe an instruction breaks data protection law, we will say so. You confirm that your instructions are lawful and that you have a legal basis to give us the data.

Nothing else. We do not sell your data, use it for advertising, or use it to train AI models.

Confidentiality. Everyone who can reach your data is bound to keep it confidential, and access is limited to what the work requires.

Changes to the Service. If a new feature changes the kinds of data processed or what it is processed for, we update this page.

Security and breaches

We keep technical and organisational measures appropriate to the risk. The security measures described on our Security page are the standard we hold ourselves to under this addendum.

Where it is hosted. Primary hosting is Google Cloud in Montréal, Canada. Email, error monitoring and payment data are handled by vendors in the United States — see the list below.

If there is a breach. We notify you without undue delay after we become aware of a breach affecting your data. We tell you what we know, keep you updated as we learn more, and take reasonable steps to contain and investigate it. Notifying you is not an admission of fault. We also give you reasonable help with your own breach duties.

Our subprocessors

We use the vendors below. You give us general written authorization to use the vendors listed here. We have data-processing terms with each. We update this list at least 14 days before a new vendor starts handling your data. To be told by email, write to support@certlister.com.

Handles customer data

Vendor What it does Data it receives Where
Google Cloud Platform (including Firebase Hosting) Hosting, database, file storage All the content you upload Montréal, Canada (website delivery is global)
Stripe Payments Your billing contact details. No recipient data United States
Resend Sending email Recipient name and email address, and the credential details in the email United States
Sentry Error monitoring User ID and email, and technical details of the error United States
Cloudflare Custom domains, bot protection, delivering verify pages IP address, and the credential details shown on a verify page Global network
Anthropic AI category suggestions The category name and its field list. No recipient data United States
Hostinger Our support mailbox Whatever you send to support@certlister.com European Union

Analytics and sign-in

These vendors do not handle the content you upload. They receive account and usage data, which our Privacy Policy covers.

Vendor What it does Data it receives Where
Google Analytics and Tag Manager Usage statistics IP address, pages visited, a cookie ID. Verify page addresses are reported without the credential number United States
Hotjar App usage recordings Clicks and page views; on-page text is masked European Union
Google sign-in Optional single sign-on Name, email, Google account ID United States
Google Fonts Font loading IP address Global network

Our written terms with each vendor put the same duties on them that this addendum puts on us, and limit them to what we have asked them to do. We stay responsible for what they do with your data. On request we will show you those terms, with commercial details and other customers' information removed. If you object to a new vendor within 30 days of the list changing, we will work with you in good faith to resolve it; if we cannot, you may stop using the affected feature or close your account.

Where your data goes

Your data is stored in Canada. The European Commission recognizes Canada as providing adequate protection for commercial organizations covered by Canada's federal privacy law (PIPEDA), which includes us, and confirmed this in January 2024. Some of our vendors are outside Canada and the European Economic Area (EEA), as the list above shows.

For those onward transfers, the EU Standard Contractual Clauses (Commission Implementing Decision 2021/914) and the UK International Data Transfer Addendum (the "UK Addendum") apply and form part of this addendum by reference. Module Two applies where you are a controller; Module Three applies where you are a processor. The docking clause does not apply, general written authorisation for subprocessors applies with the notice period set out above, and the information their annexes call for is on this page: the parties, the data, the purposes, the vendors and the security measures. For Clause 17, the Clauses are governed by the law of Ireland. For Clause 18, disputes under the Clauses are resolved by the courts of Ireland. Those two choices apply to the Clauses only; the rest of this addendum stays under the law set out below. Where Swiss law governs a transfer, references to the GDPR read as references to the Swiss Federal Act on Data Protection, and the supervisory authority includes the Swiss Federal Data Protection and Information Commissioner.

Helping you with requests

From the people in your records. If someone asks us directly to see, correct or delete data you uploaded, we pass the request to you and point them to you; we do not answer it ourselves. Taking into account the nature of the processing, we help you answer such requests — first through the tools in the Service, and where those are not enough, with reasonable help from us.

From anyone else. If a regulator, a court or any other third party asks us about your data, we tell you and do not respond without your consent, unless the law forbids us from telling you. We follow your reasonable instructions about the request and help with your response, at your cost.

Impact assessments. Where the law requires one, we give you reasonable help with a data protection impact assessment, a transfer impact assessment, and any consultation with a data protection authority.

Audits and questionnaires

We give you the information you reasonably need to show that we are meeting this addendum. Once a year, on written request to support@certlister.com, we answer a reasonable written security questionnaire. We may hold back anything that would break a confidentiality duty, breach the law or weaken our own security. If the questionnaire does not answer your question, we will agree a further step with you, including an inspection where data protection law requires one.

Deleting and returning data

You can delete credentials, recipients and uploads in the Service at any time, and we act on that as soon as we reasonably can.

When you delete your account, your data is deleted as described in the Privacy Policy. Before your account closes you can export your records from the Service, and we will return a copy if you ask. We keep data for longer only where the law requires it; if that happens, we stop processing it for any other purpose and keep protecting it. On request, we confirm deletion in writing.

California

Where the CCPA applies, we act as a service provider. We process the personal information you give us only to provide the Service under this addendum. We do not sell or share it, and we do not keep, use or disclose it for any other purpose or outside our direct business relationship with you.

Liability and the rest

Liability. Each party's liability under this addendum is subject to the limits in the Terms. Nothing here limits anyone's own rights under data protection law, or either party's liability under the Standard Contractual Clauses or the UK Addendum.

If documents disagree. On data protection matters, this addendum wins over the Terms. The Standard Contractual Clauses win over this addendum.

Governing law. The same as the Terms: the laws of Ontario, and the courts in Toronto. The Standard Contractual Clauses are the one exception — theirs are named under Where your data goes.

When it applies. This addendum applies for as long as your agreement with us lasts, and after that until you have stopped sending us data and we have stopped processing it. It applies automatically and needs no signature. Email support@certlister.com if you need a signed copy.

We may update this addendum; material changes follow the notice rule in the Terms.

Where this text comes from

This addendum is based on the Common Paper Data Processing Agreement (version 1.1), with changes, used under CC BY 4.0.

Looking for our Privacy Policy? Read our Privacy Policy →

Ready to get started?

Start free. No credit card required.