Privacy Policy

Effective Date: 09 Feb 2026  |  Last Updated: 09 September 2026

1. Introduction

This Privacy Policy explains how UniCred (“UniCred,” “we,” “us,” or “our”), operated by Unicred Technologies Private Limited, collects, uses, stores, shares, and protects information when institutions, organizations, and individuals use our digital credential platform at unicred.io and related services (together, the “Platform”).

This policy applies to everyone who interacts with the Platform, including institutions and organizations that issue credentials (“Issuing Organizations”), individuals who receive credentials (“Credential Holders”), and anyone who verifies a credential through UniCred (“Verifiers”).

By using the Platform, you agree to the practices described in this policy. If you do not agree, please do not use the Platform.

2. Information we collect

Information Issuing Organizations provide to us:

  • Organization name, registration details, and authorized signatory information
  • Contact details for administrators and staff using the Platform
  • Institutional data needed to issue credentials, such as student or employee records, program details, and academic or professional achievement data
  • Billing and payment information, where applicable
  • Branding assets used to design certificate templates

Information Credential Holders provide or that is collected on their behalf:

  • Name, contact details, and identifying information as submitted by the Issuing Organization
  • Academic or professional achievement details tied to the credential being issued, such as grades, program names, dates, and certification status
  • Account information, if the Credential Holder creates a UniCred account to manage their credentials
  • Verification activity, such as when and where a credential is checked

Technical and usage information collected automatically:

  • IP address, browser type, device information, and general location data
  • Log data, including pages visited, actions taken, and timestamps
  • Cookies and similar tracking technologies, as described in Section 10

Blockchain-related information:

  • A cryptographic record of each issued credential is created and anchored to the Polygon network to support tamper-proof verification. This record does not contain full personal data. It typically includes a cryptographic hash or reference that allows verification without exposing underlying personal details publicly. Full credential content is stored separately in encrypted, access-controlled systems, except as described in Section 5, which should be reviewed alongside this bullet.
  • A Credential Holder's public wallet address, once a credential is issued to it. Wallet addresses are pseudonymous but may become linkable to an individual's identity over time — for example through an exchange's KYC records, an ENS name, or on-chain activity analysis — and should be treated as personal data under applicable law. See Section 5.

3. How we use information

We use the information we collect to:

  • Issue, manage, revoke, and verify digital credentials on behalf of Issuing Organizations
  • Provide Credential Holders with access to their own credentials
  • Operate, maintain, and improve the Platform
  • Respond to support requests and communicate about account or service matters
  • Detect and prevent fraud, unauthorized access, and misuse of the Platform
  • Meet legal, regulatory, and compliance obligations, including those relevant to educational and government credentialing
  • Send administrative notices, security alerts, and updates about the Platform
  • Support AI-assisted or automated credential validation where an Issuing Organization or integration partner has enabled this feature, which may involve sharing relevant credential data with a third-party AI provider as described in Section 6

We do not use Credential Holder data to build advertising profiles, and we do not sell personal data to third parties.

4. Legal basis for processing

Where required by applicable law, including the DPDP Act and, where relevant, GDPR, we process personal data based on one or more of the following:

  • Consent, where a Credential Holder or Issuing Organization has agreed to specific processing
  • Contractual necessity, where processing is required to provide the Platform under our agreement with an Issuing Organization
  • Legal obligation, where we are required to retain or disclose information under applicable law
  • Legitimate interest (where GDPR or a similar framework applies), where processing supports Platform security, fraud prevention, or service improvement, balanced against individual rights. This is GDPR's open-ended balancing test and is treated separately from the DPDP basis below, not as an equivalent to it.
  • Legitimate uses (where the DPDP Act, 2023 applies), limited to the closed list of specific categories set out in Section 7 of the DPDP Act — such as state functions, legal compliance, medical emergencies, and employment purposes. Where our processing does not fall within one of these enumerated categories, we rely on consent or contractual necessity instead of an open-ended interest test.

5. Blockchain and public ledger considerations

UniCred uses blockchain technology — specifically the Polygon network — to make credentials tamper-proof and independently verifiable. Some credential-related content may also be stored using IPFS (InterPlanetary File System), a distributed, content-addressed storage protocol. This has specific privacy implications worth understanding clearly.

Information anchored to Polygon or pinned to IPFS is designed to be permanent and is generally visible to anyone with access to that network's public records. Our design intent is that UniCred does not write full personal data — such as names, grades, or identifying details — directly onto the public blockchain or into public IPFS metadata. Instead, we anchor a cryptographic reference (a hash) to the credential, while the actual credential content is stored in secured, access-controlled systems that UniCred manages.

Because certain blockchain and IPFS records are designed to be permanent by nature, some data associated with a credential's existence — such as the fact that a specific cryptographic record was created on a specific date — cannot be fully deleted once issued, even if the underlying credential is later revoked. Revocation updates the credential's status so it no longer verifies as active, but it does not erase the historical record of issuance. We disclose this clearly because it affects how certain data subject rights, particularly erasure, can be fulfilled. See Section 8 for more detail.

Public wallet addresses associated with issued credentials may also be viewable on Polygon's public block explorer. While pseudonymous, a wallet address may become linkable to an individual's identity over time (see Section 2), and — like the underlying credential record — cannot be deleted from the network once a credential has been issued to it.

6. How we share information

We share information only in the following circumstances:

  • With Issuing Organizations, since they are the source and owner of the credential data they submit to the Platform
  • With Verifiers, limited to the specific credential information a Credential Holder or Issuing Organization has made available for verification
  • With service providers, such as cloud hosting, data storage, and payment processing partners, under contractual obligations to protect the data and use it only for the purposes we specify
  • With third-party AI/LLM providers, where an Issuing Organization or integration partner has enabled AI-assisted or automated credential validation, and credential-related data is passed to that provider to perform the validation
  • For legal reasons, if required by law, regulation, court order, or governmental request, or to protect the rights, safety, or property of UniCred, our users, or others
  • In connection with a business transaction, such as a merger, acquisition, or sale of assets, subject to standard confidentiality protections

We do not share personal data with third parties for their own independent marketing purposes.

7. Data storage and international transfers

Information collected through the Platform may be stored and processed in [list relevant countries/regions, e.g. India, and any cloud regions used]. Where data is transferred across borders, we apply appropriate safeguards required under applicable law, such as standard contractual clauses or equivalent mechanisms, to protect personal data during international transfer.

Where UniCred serves Issuing Organizations or Credential Holders based in the European Union or United Kingdom, we [will appoint / have appointed] an EU representative under Article 27 GDPR (and, if applicable, a UK representative) to act as a point of contact for data protection authorities and data subjects.

8. Data retention

We retain personal data for as long as necessary to fulfill the purposes described in this policy, including:

  • For as long as an Issuing Organization maintains an active account and relationship with UniCred
  • For as long as a Credential Holder's credential remains valid or reasonably useful to them, since credentials are designed to support permanent personal ownership
  • As required to meet legal, regulatory, tax, or accounting obligations
  • As needed to resolve disputes, enforce our agreements, and maintain security records

Where a Credential Holder requests deletion of their account or personal data, we will delete or anonymize personal information wherever technically feasible. As noted in Section 5, certain blockchain- and IPFS-anchored records tied to credential issuance may not be fully erasable due to the nature of the underlying technology. We will clearly explain what can and cannot be deleted at the time of any such request.

9. Security measures

We apply industry-standard safeguards to protect information on the Platform, including:

  • Encryption of personal data in transit and at rest
  • Access controls limiting internal access to personal data based on role and necessity
  • Regular security reviews and monitoring for unauthorized access
  • Cryptographic anchoring of credential records to support tamper detection

No system can guarantee absolute security. If we become aware of a data breach affecting personal information, we will notify affected parties and relevant authorities as required by applicable law.

10. Cookies and tracking technologies

The Platform uses cookies and similar technologies to keep users logged in, maintain session security, understand how the Platform is used, and support basic analytics on traffic and engagement. Some of these cookies are placed by third-party providers on our behalf, as described in Section 11.

Marketing and advertising cookies are only activated after you provide consent through our cookie banner. You may withdraw consent at any time by adjusting your preferences through the cookie settings link in the website footer.

For a full breakdown of the specific cookies and tools we use, including individual cookie names and durations, see our separate Cookie Policy, which is incorporated into this Privacy Policy by reference.

Users can also control cookie preferences through their browser settings. Disabling certain cookies may affect Platform functionality.

11. Third-party analytics and advertising partners

We work with the following third-party providers to operate and improve our website:

  • Google LLC (Google Analytics, Google Tag Manager, Google Ads)
  • Microsoft Corporation (Microsoft Clarity)
  • Meta Platforms, Inc. (Meta Pixel)
  • LinkedIn Corporation (LinkedIn Insight Tag)

Each of these providers may collect data such as your IP address, browser type, device information, and browsing behavior on our site, subject to your cookie consent choices. These providers process this data according to their own privacy policies, linked below:

You can also learn more about, or opt out of, specific tools directly:

12. Children's privacy

The Platform is intended for use by institutions, organizations, and individuals who are old enough to hold or manage academic and professional credentials in their own right, or by institutions acting on behalf of students under applicable education and data protection laws. UniCred does not knowingly collect personal data directly from young children outside of an institutional relationship with a school, university, or training program that has its own lawful basis for managing that data. If you believe a child's data has been submitted to the Platform outside of an appropriate institutional relationship, please contact us using the details in Section 19.

13. Third-party links and services

The Platform may contain links to third-party websites or integrate with third-party services, such as learning management systems, HR platforms, or student information systems used by Issuing Organizations. This Privacy Policy does not apply to those third-party services. We encourage users to review the privacy practices of any third-party service they connect to UniCred.

14. Your rights

Depending on your location and applicable law, you may have rights to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete personal data
  • Request deletion of your personal data, subject to the blockchain- and IPFS-related limitations described in Section 5 and Section 8
  • Object to or restrict certain processing of your personal data
  • Request a copy of your data in a portable format
  • Withdraw consent, where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal

You may request access to, correction of, or deletion of your personal data by contacting us at privacy@unicred.io. We will respond to verified requests within 30 days. We may need to verify your identity before fulfilling a request, particularly where the request involves a credential issued by a third-party institution.

15. AI and automated processing

The Platform's APIs can integrate with AI models, including large language models (LLMs), to support automated credential validation for Issuing Organizations and integration partners that choose to enable this feature. Where this feature is used and credential or personal data is sent to a third-party AI provider to perform validation, that provider processes the data as our service provider, subject to contractual obligations to protect it and use it only for the purpose specified. This use is also reflected in Sections 3 and 6 above.

16. Data Fiduciary and data processor role

For personal data submitted by Issuing Organizations to issue credentials (such as student or employee records), UniCred acts as a data processor / “fiduciary-on-behalf,” processing that data on the instructions of, and for the purposes defined by, the relevant Issuing Organization, which remains the data controller / Data Fiduciary for that information. Where UniCred independently determines the purposes and means of processing — for example, technical and usage data collected automatically, or a Credential Holder's own account data — UniCred acts as an independent controller / Data Fiduciary.

Our respective roles and responsibilities in this arrangement are set out in a separate Data Processing Agreement (DPA), available on request or referenced in an Issuing Organization's service agreement with UniCred.

17. US state privacy rights

If California or other US state residents interact with the Platform as Credential Holders, Issuing Organization staff, or otherwise, they may have additional rights under applicable US state privacy laws, such as the California Consumer Privacy Act (as amended).

18. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will post the updated policy on this page with a revised “Last Updated” date. Where changes are significant, we will provide additional notice, such as an email to registered users or a notice on the Platform.

19. Contact us and grievance officer

If you have questions, concerns, or requests regarding this Privacy Policy or how your personal data is handled, contact us at:

Unicred Technologies Private Limited

10 Aaryans Corporate Park, Near Ambli Railway Crossing, Shilaj, Daskroi, Ahmedabad, 380059, Gujarat

Email: privacy@unicred.io

Grievance Officer:

Name: Manoj Dhanak

Email: privacy@unicred.io

Response timeline: We aim to acknowledge grievances within 48 hours and resolve them within 30 days, as required under applicable law.