How we handle personal information across the regions we operate in — written to meet GDPR, POPIA, and general global privacy expectations.
Skyeblanc Certification is the controller of the personal information described here. Our legal entity name, registered office and data-protection contact will be confirmed on this page and can be requested via our contact page.
We collect only what we need to provide certification and meet our obligations as a certification body:
We use personal information to assess applications, deliver and maintain certification, verify certificates, handle complaints and appeals, and meet legal and accreditation obligations. Depending on the activity and your region, our legal bases include:
We do not sell personal information. We share it only as needed to operate as a certification body:
We operate globally, so information may be processed in countries other than your own. Where it is, we apply appropriate safeguards for cross-border transfers consistent with GDPR and POPIA requirements.
Certification and audit records are retained for the periods required by our accreditation and certification obligations — typically across the certification cycle and beyond, as evidence of decisions. Other information is kept only as long as needed for the purpose it was collected.
Subject to your region and applicable law, you may have the right to:
Note that some records must be retained to meet our obligations as a certification body and cannot be erased on request.
We apply appropriate technical and organisational measures to protect personal information against loss, misuse and unauthorised access, and we require our auditors and sub-contractors to do the same.
To exercise any right, or to raise a privacy concern, use our contact page. You can also raise a formal complaint with us at any time.