Credfex is built by Profiden Technologies Private Limited ("Credfex", "we", "us"). This Privacy Policy explains how we collect, use, share and protect personal data when you use the Credfex website, the Issuer Console, the Credential Wallet, the Verification Hub and the Exchange API (together, the "Services").
1. Our roles
Credfex operates a multi-party exchange. Our role depends on the data in question:
- Employers (issuers) determine what employment data to issue as a credential. For that data, the employer is the data fiduciary / controller and Credfex is a data processor acting under a written agreement.
- Professionals (credential holders) create a wallet account. For account and consent data, Credfex is the data fiduciary / controller.
- Verifiers submit verification requests. For verifier account data and request logs, Credfex is the data fiduciary / controller.
2. Data we collect
- Credential data issued by employers, such as organisation name, employee ID, designation, dates of employment and exit type. Employers decide which fields to include.
- Account data such as name, email address, mobile number, organisation, role and authentication details.
- Consent and verification records, including which verifier requested access, which fields were shared, when, and under which consent reference.
- Technical data such as IP address, device and browser information, and security logs.
- Enquiry data you submit through forms on this website, such as demo requests.
3. How we use data
- To issue, store, display and verify employment credentials as instructed by employers and consented to by professionals.
- To operate, secure, monitor and improve the Services, including fraud and abuse prevention.
- To send service notifications such as consent requests, verification alerts and security messages.
- To respond to enquiries and, where you have asked us to, to contact you about Credfex.
- To comply with legal obligations and enforce our terms.
We do not sell personal data. We do not use credential data for advertising or profiling.
4. Consent and sharing
A credential is shared with a verifier only when the professional it describes has granted consent, or where the verifier has lawfully obtained and recorded that consent through its own process and passed a consent reference to Credfex. Consent is specific to a verifier, may be time-limited and can be withdrawn at any time from the wallet. Withdrawal does not affect verifications that were completed before it.
We share data with service providers who host and support the Services under contractual confidentiality and security obligations, and with authorities where required by law.
5. Security
We protect data with encryption in transit and at rest, role-based access control, multi-factor authentication for privileged access, logging and monitoring, and regular independent security testing. Details are available on our Security & Compliance page.
6. Retention
Credential data is retained for as long as the issuing employer maintains it on the exchange or as required by law. Consent and verification logs are retained to evidence compliance. Account data is retained while your account is active and for a limited period afterwards. Enquiry data is retained for up to 24 months.
7. Your rights
Subject to applicable law, including, where applicable, the GDPR, you may access, correct, export or request deletion of your personal data, withdraw consent, and raise a grievance. Professionals can exercise most of these rights directly from the wallet. For requests relating to credential content, we will route your request to the issuing employer and keep you informed.
8. International transfers
Where data is transferred across jurisdictions, we use appropriate safeguards such as contractual clauses and, for enterprise customers, regional hosting options.
9. Changes and contact
We may update this policy from time to time and will post the revised version with a new "last updated" date. Questions, requests and grievances can be sent to [email protected].