Skip to content
Certquill

Privacy Policy

Last updated 2 September 2026

1. Two kinds of data, two roles

This policy covers two different relationships, and it matters which one applies to you:

  • Account data (your name, email, billing details, organisation settings) — for this data, Zentez Solutions Private Limited is the data controller. We decide why and how it's processed, as described below.
  • Recipient/certificate data (the names, emails, course and date information an Issuer uploads to issue certificates) — for this data, the Issuer is the data controller and Certquill acts only as a data processor, processing it solely to render, deliver and host certificates on the Issuer's instructions. If you're a certificate recipient with a question about your data, your first point of contact should be the organisation that issued your certificate; we'll also action direct requests as described in section 6.

2. What we collect

  • Account information: name, email, password (hashed) or OAuth identifier, organisation name, billing address as needed for tax purposes.
  • Certificate/recipient data: names, email addresses, and any course/date/custom fields an Issuer includes in a CSV upload or API call.
  • Uploaded assets: logos and signature images used in certificate designs.
  • Payment metadata: plan, payment status and amounts, as reported to us by Dodo Payments. We do not receive or store your full card number.
  • Usage and analytics data: pages visited, feature usage, and aggregate performance metrics via Vercel Analytics (privacy-friendly, no cross-site tracking, no persistent individual profile).
  • Support communications: anything you send to support@zentez.io.

3. How we use it

  • To provide the Service: render and deliver certificates, host verification pages, operate your account and dashboard.
  • To process payments and prevent fraud, via Dodo Payments.
  • To send transactional email (certificate delivery, account notices, receipts) — not marketing email unless you separately opt in.
  • To maintain security, enforce rate limits, and investigate abuse reports.
  • To improve the Service, using aggregate, non-identifying usage data where possible.

4. Cookies

Certquill uses a minimal set of cookies:

  • An essential session/authentication cookie that keeps you signed in. This is required for the Service to function and isn't a marketing or tracking cookie.
  • Vercel Analytics, a privacy-friendly analytics tool that doesn't use persistent cookies to track individuals across sites and reports aggregate traffic and performance data only.

We don't run third-party advertising trackers or sell data to ad networks.

5. Sub-processors

We use the following sub-processors to operate the Service. Each is contractually bound to protect data it processes on our behalf:

  • Vercel — application hosting and file storage.
  • Neon — managed Postgres database (account, certificate and design records).
  • Resend — transactional email delivery (certificate emails, account notices).
  • Dodo Payments — payment processing and billing, acting as merchant of record.

6. Recipient rights and removal requests

If you received a certificate and want your data removed from Certquill's records, email support@zentez.io with the certificate ID or the email address it was sent to. We'll process legitimate removal requests directly where we can, and otherwise forward the request to the issuing organisation, since they control the underlying record as described in section 1.

7. Data retention

Certificates and related records are retained for as long as the issuing account remains active, so verification continues to work. If an account is deleted, we retain its data for up to 90 days to allow for recovery of an accidental deletion and to meet legitimate audit needs, after which it is permanently deleted from production systems (backups age out on their own retention schedule).

8. International data transfers

Our infrastructure (Vercel, Neon, Resend) may process and store data in multiple regions, including outside your country of residence. Where required, we rely on our sub-processors' standard contractual clauses or equivalent safeguards for cross-border transfers.

9. Security

We use industry-standard measures including encryption in transit (HTTPS), hashed passwords, hashed API keys, and access controls limiting who at Certquill can view account or certificate data. No system is perfectly secure, and we can't guarantee absolute security, but we treat data protection as a first-class requirement, not an afterthought.

10. Your rights (GDPR and India's DPDP Act)

Depending on your location, you may have rights to access, correct, export or delete your personal data, and to object to or restrict certain processing:

  • EU/UK residents (GDPR): you have the rights of access, rectification, erasure, restriction, portability and objection, and the right to lodge a complaint with your local data protection authority.
  • Indian residents (Digital Personal Data Protection Act, 2023): you have the right to access, correct and erase your personal data, to withdraw consent, and to nominate another person to exercise your rights in the event of death or incapacity.

To exercise any of these rights, email support@zentez.io. Account holders can also export or delete most of their own data directly from account settings.

11. Children's privacy

The Service is intended for use by organisations and adults issuing certificates, not for direct use by children. Certificates may of course be issued to minors (e.g. school certificates) by an issuing organisation acting as data controller for that data, per section 1.

12. Changes to this policy

We'll update the “Last updated” date above when this policy changes, and notify account holders by email for material changes.

13. Contact

Questions or requests regarding this policy: support@zentez.io. See also our Terms of Service and Acceptable Use Policy.