Privacy Policy
As of: 2026-09-12Version 1.0
1. Data Controller
The controller responsible for data processing on this website in accordance with the GDPR is:
Threat-Informed Cybersecurity Solutions GmbH
Ober-Saulheimer Str. 15
55291 Saulheim
Germany
Register court: Amtsgericht Mainz, HRB 53346
VAT ID: DE 450829291
Represented by the managing director Daniel Thomas Heessel
Email: kontakt@certmap.de
CertMap is operated commercially. A data protection officer has not been appointed as the legal requirements for a mandatory appointment are not met.
2. Website Provision and Hosting
When accessing CertMap, technical access data is automatically collected in server log files.
Hosting Provider
Hetzner Online GmbH, Germany. Processing takes place exclusively in German data centres based on a data processing agreement (Art. 28 GDPR).
Data Categories
IP address, date and time, requested URL, referrer URL, and user agent.
Purpose and Legal Basis
Secure operation and IT security pursuant to Art. 6(1)(f) GDPR.
Retention
Server log files are automatically deleted after 7 days.
IP Anonymisation
Within the application, IP addresses are only processed as a SHA-256 hash, truncated to 12 hex characters, for abuse prevention (rate limiting). Re-identification is therefore practically excluded.
Reach Measurement via Plausible Analytics
For general reach measurement and statistical evaluation we use Plausible Analytics, operated by Plausible Insights OÜ, Västra 24, 10141 Tallinn, Estonia.
Plausible is cookieless and does not perform device fingerprinting. Only aggregated, non-personal data is collected: page accessed, referrer, device category (desktop/mobile), browser and OS major version, and country of origin. Identification of individual users with this data is not possible.
In addition to page views we report individual events without personal reference, to see which content is used. These six, and no others:
- opening a learning video on a certification page,
- clicking a text link in the learning path of a certification page,
- clicking from a knowledge article into a tool,
- clicking a training provider in the comparison,
- clicking the advisory note in the header,
- clicking our LinkedIn profile.
Only content identifiers are transmitted, e.g. the abbreviation of a certification, the name of an article, or the page the click came from.
Processing takes place exclusively within the EU. The IP address is briefly used to compute a daily-rotating, hashed visitor identifier and is not stored.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in reach measurement). As no personal identifiers are stored on or read from the end device, no consent under Sec. 25 TDDDG is required.
Plausible privacy policy: https://plausible.io/privacy
Embedded Videos on Certification Pages
On individual certification pages we embed learning videos from YouTube. The embedding happens in two stages:
- Before you click, we show only the video's preview image. Your browser loads this image directly from a Google server (
i.ytimg.com) and, as is technically necessary, transmits your IP address, the user agent and the page you are viewing to Google. No cookies are set and no video player is loaded. - Only after you click the preview image is the video player loaded, via the domain
youtube-nocookie.com. Only from that moment does YouTube process further data about your viewing behaviour.
The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Its parent company Google LLC in the USA is certified under the EU-US Data Privacy Framework.
Legal basis for the preview image: Art. 6(1)(f) GDPR (legitimate interest in a preview without embedding the player). Legal basis for loading the player: your consent through the active click (Art. 6(1)(a) GDPR). If you do not want the preview image to load either, you can block third-party images in your browser; the page remains fully usable.
Google's privacy notice: https://policies.google.com/privacy
3. Local Storage (Cookies and Browser Storage)
We do not use tracking cookies. We only use technically necessary local storage areas of your browser in accordance with Sec. 25(2) No. 2 TDDDG.
Overview of cookies and storage entries
| Name | Type | Purpose | Lifetime | When set |
|---|---|---|---|---|
__Secure-certmap.session_token (production) or certmap.session_token (development) |
HTTP cookie (HttpOnly, Secure, SameSite=Lax, Path=/) | Authenticated login session | Up to 14 days, sliding refresh hourly on activity | After successful sign-in |
certmap-theme |
LocalStorage | Theme preference (light/dark/system) | Until browser storage is cleared or overwritten | When you actively click the theme switcher |
certmap-consent-llm |
LocalStorage | Legacy entry: consent for the AI analysis of job descriptions offered until 1 July 2026. We no longer set it; revoking in settings removes it | Until browser storage is cleared or you revoke in settings | No longer set |
certmap-updates-seen |
LocalStorage | Remembers which product update was shown last so the notice does not reappear on every visit | Until browser storage is cleared or overwritten | On the first page view and when the what's-new window is opened or closed |
org-sidebar-collapsed |
LocalStorage | Remembers whether the sidebar in the organization area is collapsed | Until browser storage is cleared or overwritten | When you collapse or expand the sidebar |
org_redeem_code |
SessionStorage | Holds the redemption code of an organization invitation across the sign-in process | Until redeemed, at the latest until the browser tab is closed | When redeeming an invitation without being signed in |
certmap.portal.sidebar |
LocalStorage | Remembers whether the sidebar in the account portal is collapsed | Until browser storage is cleared or overwritten | When you collapse or expand the sidebar |
pendingSave |
SessionStorage | Holds an unsaved portfolio across the sign-in process | Until saved, at the latest until the browser tab is closed | When you click save without being signed in |
We do not set tracking, advertising or third-party cookies. Plausible (analytics) operates without cookies, see Section 2.
Legal basis for all of the above: Sec. 25(2) No. 2 TDDDG (strictly necessary for a user-requested function) together with Art. 6(1)(b) GDPR (performance of a contract or pre-contractual measures).
4. User Account and Portfolio Features
You can optionally create a CertMap account to manage your own certifications, planned training, CPE activities (Continuing Professional Education) and associated costs.
Account Creation via Magic Code
Sign-in is passwordless via an eight-digit one-time code sent to your email address (Better-Auth Email-OTP, NIST SP 800-63B compliant).
Data processed: email address, sign-in timestamp, one-time code (hashed, short-lived), browser session token, IP address and user agent of the session (shown in the security area and used to detect suspicious activity).
Legal basis: Art. 6(1)(b) GDPR (contractual relationship for account usage).
Retention: account data is kept until you delete the account (self-service in settings or via email). Sessions expire automatically after at most 14 days and are extended hourly while in active use. In the account area you are signed out automatically after 8 hours without interaction, as long as the page stays open; if you close the browser earlier, the session remains valid until the 14 days expire. Security-relevant actions (account deletion) additionally require a fresh one-time code for confirmation.
Portfolio Contents
Within your account we store your own entries:
- List of certifications you hold (slug, issue and expiry date, optional certificate number)
- CPE activities (date, activity type, hours, optional cost and free-text description)
- Cycle accounts and bookings automatically derived from your CPE activities
- Optional settings such as hourly rate, current and target NICE role
- Your own certifications that are not in the catalog (name, issuer, dates)
- Releases of individual certifications to an organization you have linked your account to (Section 7)
Legal basis: Art. 6(1)(b) GDPR. The data does not leave our servers and is not shared with third parties; the only exceptions are certifications you release yourself to a linked organization (Section 7) and the Credly import at your request (Section 6).
Account Deletion and Hard Delete
You can delete your account at any time (Settings → Delete account). Deletion happens immediately and completely: all linked data (certifications, activities, cycle accounts, bookings, settings, consent history) is removed from the database via foreign-key cascade.
There are two deliberate exceptions, and we name them because "completely" would otherwise promise more than we deliver. First, the record of each individual transfer to Anthropic remains; the link to your account is removed, so the remaining row carries only the point in time, the occasion and the version of this policy. It can no longer be attributed to a person and serves solely as the accountability record under Art. 5(2) and Art. 7(1) GDPR. Second, the entry in an organization's activity log is retained without personal reference (Section 7). In addition we manually delete your email correspondence from our M365 mailbox (Section 9). There is no recovery window; backup copies expire with the regular backup rotation. If your account was linked to an organization, the link ends, released certifications are no longer visible to the organization, and the personal reference is removed from the organization's activity log (Section 7).
5. AI-Powered Features
CertMap uses AI processing for one optional feature. Use is voluntary.
Affected Feature
- Certificate-PDF Extraction (account portal only): You upload a certificate PDF, the AI reads cert title, certificate number, issue date and holder name and proposes structured fields to add to your portal. You review the suggestions and accept or correct them.
An earlier AI feature for analysing job descriptions has been switched off since 1 July 2026. No data is transmitted to Anthropic for it any more; the corresponding endpoint is closed.
Data Transfer for PDF Extraction
For text PDFs, only the readable text layer is transmitted to Anthropic, PBC (USA). A server-side filter replaces recognised email addresses, phone numbers, IBAN, credit card numbers and social security numbers (SSN) with placeholders before transmission.
Note: Plain-text names are not filtered automatically. The holder name printed on the certificate is therefore typically transmitted.
For image PDFs (scans), no text layer is extracted. The full image content is processed by Anthropic's Vision feature. This transmits the holder name, certificate number, logo and all other visible information on the certificate to Anthropic in the USA. Before uploading an image PDF, this notice is displayed again and you confirm the transmission separately (granular consent under Art. 7(2) GDPR).
Legal Basis
Your explicit consent according to Art. 6(1)(a) in conjunction with Art. 49(1)(a) GDPR. Without consent, the AI features are not usable; all other functions (manual cert entry, comparison, portfolio) remain fully available.
Third-Country Transfer
As there is currently no adequacy decision for Anthropic, the transfer is based on your informed consent regarding the risks of access by US authorities.
Consent and Revocation
PDF extraction exists only inside a signed-in account; we no longer offer anonymous AI use. You grant consent once at the first use, directly where the extraction starts. For image PDFs you additionally confirm the transmission separately (see above).
As proof under Art. 7(1) GDPR we store, attached to your account, the consent category, the timestamp and the version of this policy. Every grant and every revocation is a separate entry; the history is retained until you delete your account.
You can revoke at any time under Settings, Consents. After revocation, the extraction refuses further calls. The lawfulness of processing performed up to revocation remains unaffected.
Storage
CertMap does not persist transmitted texts or PDF contents on its own servers (transient runtime processing only). From the PDF extraction, only the structured fields you actively confirm (cert slug, certificate number, date) are stored permanently in your account portal. Anthropic retains transmitted data according to its own policies for up to 30 days for security purposes (no training of AI models).
Certificate Number Notice
Certificate numbers are stored in your account portal and are a prerequisite for later verification against third parties. Certificate numbers alone, in conjunction with the respective provider verification portals (e.g. PECB, ISC2, GIAC), allow re-identification of your real name. CertMap does not pass certificate numbers to third parties.
No Automated Decision-Making
There is no automated decision-making with legal effect within the meaning of Art. 22 GDPR. The extracted fields are non-binding suggestions that you review before accepting them; they have no legal consequences.
6. Credly Import
Optionally, you can enter the address of your public Credly profile in your account. CertMap then retrieves the publicly visible badges of that profile via the interface of Credly Inc. (Pearson VUE, USA) and suggests them as certifications to add to your account. We transmit only the Credly username read from the address; Credly receives no further data from us. Retrieval happens only at your request; there is no ongoing synchronisation.
We process the public badge details (title, issuer, issue date, badge identifier, public profile description). Only the certifications you actively adopt are stored permanently. If you report a badge that is not yet mapped to a certification in the catalog, we store the badge identifier and your report in order to extend the catalog.
Legal basis: your explicit consent (Art. 6(1)(a) in conjunction with Art. 49(1)(a) GDPR), given before the first import and revocable at any time in the settings. Credly is a company based in the USA; we point out the risk of access by US authorities. Without consent you enter your certifications manually.
7. CertMap for Organizations
Companies and institutions can manage their employees' certifications with "CertMap for Organizations". The Special Terms for Organizations at https://certmap.de/agb-org apply.
Roles
For the data an organization records about its employees (name, role, certifications and validity periods, evidence, cost and training details, notes), the organization is the controller under data protection law. We process this data as a processor under the data processing agreement at https://certmap.de/avv-org. Please direct questions about this data to your employer.
For the accounts of administrators (email address, sign-in data, timestamps of their actions) and for personal CertMap accounts that employees link to an organization, we remain the controller. Legal basis: Art. 6(1)(b) GDPR.
Invitations
An organization can invite employees by email. To do so it provides the business email address, and we send an invitation with a time-limited redemption code on its behalf. We store the address for the organization as a contact address; for redeeming the code we additionally use a hash and a masked form (for example a***@company.com). Anyone who does not accept the invitation is not contacted again after it expires.
Linked Accounts and Release Principle
If you link your personal account to an organization, the organization sees only the certifications you expressly release. You can end any release and the link as a whole at any time, including while the organization only has read-only access. Cost per person is visible to the organization only under the conditions of the application's data protection model (collective basis or consent, depending on the organization's market).
Activity Log and Notice Emails
Administrative actions are recorded in a log of the organization (event, acting person, affected entry, time). When a linked account is deleted, we remove the personal reference from this log. Administrators receive emails about deadlines of their organization (read-only access, upcoming deletion).
Retention and Deletion
An organization's data is deleted together with the organization. When this happens is governed by the Special Terms: after the end of the trial or of a contract, in each case after a read-only period. The organization can download its data at any time as a complete data copy. We keep a record of the deletion that contains no personal data. Personal accounts of employees are not affected by the deletion of an organization.
8. Contact, Feedback and Inquiries
Feedback on the Catalog
Via "Report an error / suggest a certification" you can send us notes on the catalog. We process the selected category, your message and, if you want a reply, your email address. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in an accurate catalog).
Contact for Companies
Via the contact form for companies we process name, email address, optionally company and your message in order to answer your inquiry. Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures).
Application as Training Provider
Via the form for training providers we process company, contact person, email address, optionally website, your interest in a visibility tier and your message. Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures).
You can write to us directly at any time at kontakt@certmap.de. Legal basis: Art. 6(1)(b) or (f) GDPR, depending on the matter.
All messages from the forms are sent as email to our Microsoft 365 mailbox (Section 9). Retention: six months after the end of correspondence; if a contract is concluded, for its duration and thereafter in accordance with statutory retention periods. The forms contain an invisible field to fend off automated submissions and a rate limit per IP address; for this purpose the IP address is processed only as a truncated hash (Section 2).
9. Microsoft 365 (Email)
All emails sent by CertMap (sign-in codes, invitations and deadline notices for organizations, confirmations) as well as incoming messages are processed via Microsoft Ireland Operations Ltd. (Microsoft 365). Microsoft processes in data centers in the EU; for sub-processors outside the EU the EU-US Data Privacy Framework and the EU standard contractual clauses apply. To maintain data minimisation, confirmation emails to you are not stored in the Sent folder.
When you delete your account (Section 4) we manually delete all your email correspondence from the mailbox, including recoverable items.
10. Your Rights
You have the following rights regarding personal data we process about you:
- Right of access (Art. 15 GDPR): which data we hold about you
- Right to rectification (Art. 16 GDPR): correction of inaccurate data
- Right to erasure (Art. 17 GDPR): „right to be forgotten"
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR): export of your data in a structured, common format
- Right to object (Art. 21 GDPR) to processing based on legitimate interest
- Right to withdraw consent with effect for the future
You can export your account data yourself as a file in the settings at any time; organizations download their data copy in the organization area.
Please contact us at kontakt@certmap.de. Access and erasure requests are typically processed within 30 days.
Right to Lodge a Complaint with the Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The competent authority for us is:
The State Commissioner for Data Protection and Freedom of Information Rhineland-Palatinate
Hintere Bleiche 34
55116 Mainz, Germany
Email: poststelle@datenschutz.rlp.de
https://www.datenschutz.rlp.de