Legal
Privacy notice
Certification requires identity data, so the Foundation states plainly what it collects, why, what becomes public, and how long it is kept.
What we collect
- Account data: name, email address, country, and password credentials.
- Identity verification: the result of a third-party identity check (pass/fail, method, date) and a provider reference. The Foundation does not intend to store images of government-issued identity documents itself.
- Examination data: attempt dates, per-module scores, outcomes, and proctoring session records.
- Credential data: certificate number, status, issue and expiry dates.
- Communications: messages you send us and, if issued, mail handled through a ruofoundation.org address.
- Technical data: server logs including IP address and user agent, retained for security purposes.
Why we process it
- To verify that a credential belongs to a real, identified person.
- To administer examinations and maintain the integrity of scoring.
- To operate the public verification registry.
- To meet legal, audit, and safety-reporting obligations.
What is public
- The public registry shows only: certificate number, holder name as verified, status, credential level, issue date, and expiry date.
- Examination scores, attempt history, identity data, contact details, and payment records are never published.
Sharing
- Identity verification providers, examination proctoring providers, email and hosting providers, and payment processors - each limited to what their function requires.
- We do not sell personal data, and we do not share member lists with sellers of research materials.
- Disclosure to authorities only where legally required, or where there is a credible risk to life.
Retention
- Credential and examination records: retained for the life of the credential plus seven years, so a historical certificate can be verified.
- Identity verification results: retained for the life of the credential; provider-held documents are subject to the provider's own retention schedule.
- Proctoring recordings: retained no longer than needed to resolve integrity disputes.
- Server logs: retained for a short security window and then deleted.
Your rights
- Access, correction, deletion, portability, and objection, subject to the recordkeeping obligations that make a credential meaningful.
- Deleting a credential record ends the credential; it cannot be verified afterwards.
- Requests are handled through the contact page and answered within 30 days.
Security
- Encryption in transit and at rest, least-privilege access to member records, audit logging of administrative access, and a documented breach-notification process.
Children
- Certification is not offered to anyone under 18, and accounts are not knowingly created for minors.
Changes
Material changes will be posted here with a revision date and, once accounts exist, emailed to members.