Legal

CredaHub Privacy Policy

Last updated: December 2025

This Privacy Policy describes how CredaHub and related Creda Network services (“Creda,” “we,” “us,” or “our”) collect, use, and protect information when you visit our websites, use our dashboards, or access our platforms and APIs (collectively, the “Services”).

By using the Services, you agree to the practices described in this Privacy Policy. If you do not agree, you should not use the Services.

1. Information We Collect

A. Information You Provide to Us

We may collect information you provide directly, including:

B. Information We Process on Behalf of Organizations

CredaHub is designed primarily for use by organizations (such as hospitals, airports, financial institutions, and government agencies) to help manage identity, credentials, and compliance workflows.

In this context, we may process data about individuals (“End Users” or “Credential Holders”) on behalf of those organizations. This may include:

When we process such information on behalf of an organization, that organization is typically the data controller, and CredaHub acts as a processor or service provider. Your rights may be exercised through your organization.

C. Information Collected Automatically

When you access the Services, we may automatically collect:

D. Information from Third Parties

Subject to agreements and applicable law, we may receive information from:

2. How We Use Information

We use information for purposes including:

3. Legal Bases (Where Applicable)

Where required by law (for example, in the European Economic Area or the United Kingdom), we process personal data based on the following legal bases:

4. How We Share Information

We do not sell personal information.

We may share information with:

5. Cookies & Similar Technologies

We may use cookies and similar technologies to:

You can control cookies through your browser settings, but disabling certain cookies may affect functionality or security.

6. Data Security

We use technical and organizational measures designed to protect information, which may include encryption, access controls, monitoring, and audit logging.

No system is completely secure. You, your organization, and your users are responsible for:

7. Data Retention

We retain information for as long as necessary to:

When data is no longer needed, we may delete, anonymize, or aggregate it in accordance with our policies and any applicable agreements.

8. Your Rights

Depending on your location and applicable law, you may have rights regarding your personal data, such as:

When we process your data on behalf of an organization, you may need to direct your request to that organization. We will work with them to address appropriate requests.

9. International Data Transfers

The Services may involve transferring data across borders, including to countries that may not provide the same level of data protection as your home jurisdiction.

Where required, we implement safeguards (such as contractual protections) to help ensure that personal data is appropriately protected.

10. Children’s Privacy

The Services are not intended for direct use by children under 16. We do not knowingly collect personal data directly from children without appropriate authorization.

If you believe a child has provided personal data to us without authorization, please contact us so we can take appropriate steps.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page reflects the most recent changes.

Material changes will be communicated through the Services or other appropriate channels. Continued use of the Services after changes become effective constitutes your acceptance of the updated Policy.

12. Contact Us

If you have questions about this Privacy Policy or how we handle personal data, you can contact us at:

Creda Technologies
Email: privacy@credahub.com
Address: [Insert your business address here]