Effective Date: 09 Feb 2026 | Last Updated: 09 September 2026
This Privacy Policy explains how UniCred (“UniCred,” “we,” “us,” or “our”), operated by Unicred Technologies Private Limited, collects, uses, stores, shares, and protects information when institutions, organizations, and individuals use our digital credential platform at unicred.io and related services (together, the “Platform”).
This policy applies to everyone who interacts with the Platform, including institutions and organizations that issue credentials (“Issuing Organizations”), individuals who receive credentials (“Credential Holders”), and anyone who verifies a credential through UniCred (“Verifiers”).
By using the Platform, you agree to the practices described in this policy. If you do not agree, please do not use the Platform.
We use the information we collect to:
We do not use Credential Holder data to build advertising profiles, and we do not sell personal data to third parties.
Where required by applicable law, including the DPDP Act and, where relevant, GDPR, we process personal data based on one or more of the following:
UniCred uses blockchain technology — specifically the Polygon network — to make credentials tamper-proof and independently verifiable. Some credential-related content may also be stored using IPFS (InterPlanetary File System), a distributed, content-addressed storage protocol. This has specific privacy implications worth understanding clearly.
Information anchored to Polygon or pinned to IPFS is designed to be permanent and is generally visible to anyone with access to that network's public records. Our design intent is that UniCred does not write full personal data — such as names, grades, or identifying details — directly onto the public blockchain or into public IPFS metadata. Instead, we anchor a cryptographic reference (a hash) to the credential, while the actual credential content is stored in secured, access-controlled systems that UniCred manages.
Because certain blockchain and IPFS records are designed to be permanent by nature, some data associated with a credential's existence — such as the fact that a specific cryptographic record was created on a specific date — cannot be fully deleted once issued, even if the underlying credential is later revoked. Revocation updates the credential's status so it no longer verifies as active, but it does not erase the historical record of issuance. We disclose this clearly because it affects how certain data subject rights, particularly erasure, can be fulfilled. See Section 8 for more detail.
Public wallet addresses associated with issued credentials may also be viewable on Polygon's public block explorer. While pseudonymous, a wallet address may become linkable to an individual's identity over time (see Section 2), and — like the underlying credential record — cannot be deleted from the network once a credential has been issued to it.
We share information only in the following circumstances:
We do not share personal data with third parties for their own independent marketing purposes.
Information collected through the Platform may be stored and processed in [list relevant countries/regions, e.g. India, and any cloud regions used]. Where data is transferred across borders, we apply appropriate safeguards required under applicable law, such as standard contractual clauses or equivalent mechanisms, to protect personal data during international transfer.
Where UniCred serves Issuing Organizations or Credential Holders based in the European Union or United Kingdom, we [will appoint / have appointed] an EU representative under Article 27 GDPR (and, if applicable, a UK representative) to act as a point of contact for data protection authorities and data subjects.
We retain personal data for as long as necessary to fulfill the purposes described in this policy, including:
Where a Credential Holder requests deletion of their account or personal data, we will delete or anonymize personal information wherever technically feasible. As noted in Section 5, certain blockchain- and IPFS-anchored records tied to credential issuance may not be fully erasable due to the nature of the underlying technology. We will clearly explain what can and cannot be deleted at the time of any such request.
We apply industry-standard safeguards to protect information on the Platform, including:
No system can guarantee absolute security. If we become aware of a data breach affecting personal information, we will notify affected parties and relevant authorities as required by applicable law.
The Platform uses cookies and similar technologies to keep users logged in, maintain session security, understand how the Platform is used, and support basic analytics on traffic and engagement. Some of these cookies are placed by third-party providers on our behalf, as described in Section 11.
Marketing and advertising cookies are only activated after you provide consent through our cookie banner. You may withdraw consent at any time by adjusting your preferences through the cookie settings link in the website footer.
For a full breakdown of the specific cookies and tools we use, including individual cookie names and durations, see our separate Cookie Policy, which is incorporated into this Privacy Policy by reference.
Users can also control cookie preferences through their browser settings. Disabling certain cookies may affect Platform functionality.
We work with the following third-party providers to operate and improve our website:
Each of these providers may collect data such as your IP address, browser type, device information, and browsing behavior on our site, subject to your cookie consent choices. These providers process this data according to their own privacy policies, linked below:
You can also learn more about, or opt out of, specific tools directly:
The Platform is intended for use by institutions, organizations, and individuals who are old enough to hold or manage academic and professional credentials in their own right, or by institutions acting on behalf of students under applicable education and data protection laws. UniCred does not knowingly collect personal data directly from young children outside of an institutional relationship with a school, university, or training program that has its own lawful basis for managing that data. If you believe a child's data has been submitted to the Platform outside of an appropriate institutional relationship, please contact us using the details in Section 19.
The Platform may contain links to third-party websites or integrate with third-party services, such as learning management systems, HR platforms, or student information systems used by Issuing Organizations. This Privacy Policy does not apply to those third-party services. We encourage users to review the privacy practices of any third-party service they connect to UniCred.
Depending on your location and applicable law, you may have rights to:
You may request access to, correction of, or deletion of your personal data by contacting us at privacy@unicred.io. We will respond to verified requests within 30 days. We may need to verify your identity before fulfilling a request, particularly where the request involves a credential issued by a third-party institution.
The Platform's APIs can integrate with AI models, including large language models (LLMs), to support automated credential validation for Issuing Organizations and integration partners that choose to enable this feature. Where this feature is used and credential or personal data is sent to a third-party AI provider to perform validation, that provider processes the data as our service provider, subject to contractual obligations to protect it and use it only for the purpose specified. This use is also reflected in Sections 3 and 6 above.
For personal data submitted by Issuing Organizations to issue credentials (such as student or employee records), UniCred acts as a data processor / “fiduciary-on-behalf,” processing that data on the instructions of, and for the purposes defined by, the relevant Issuing Organization, which remains the data controller / Data Fiduciary for that information. Where UniCred independently determines the purposes and means of processing — for example, technical and usage data collected automatically, or a Credential Holder's own account data — UniCred acts as an independent controller / Data Fiduciary.
Our respective roles and responsibilities in this arrangement are set out in a separate Data Processing Agreement (DPA), available on request or referenced in an Issuing Organization's service agreement with UniCred.
If California or other US state residents interact with the Platform as Credential Holders, Issuing Organization staff, or otherwise, they may have additional rights under applicable US state privacy laws, such as the California Consumer Privacy Act (as amended).
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will post the updated policy on this page with a revised “Last Updated” date. Where changes are significant, we will provide additional notice, such as an email to registered users or a notice on the Platform.
If you have questions, concerns, or requests regarding this Privacy Policy or how your personal data is handled, contact us at:
Unicred Technologies Private Limited
10 Aaryans Corporate Park, Near Ambli Railway Crossing, Shilaj, Daskroi, Ahmedabad, 380059, Gujarat
Email: privacy@unicred.io
Name: Manoj Dhanak
Email: privacy@unicred.io
Response timeline: We aim to acknowledge grievances within 48 hours and resolve them within 30 days, as required under applicable law.