Data Security & Privacy

Version: 1.1
Owner: Sarder Inc. (DBA AI CERTs)

1. Organization & Legal Entity

AI CERTs is operated by Sarder Inc., a United States–registered company, doing business as AI CERTs.

Sarder Inc. acts as the Data Controller and Data Processor for all learner and partner data processed within the AI CERTs certification ecosystem, unless contractually agreed otherwise.

2. Platform Architecture & Hosting

AI CERTs operates a cloud-based certification and partner management platform hosted entirely on Microsoft Azure.

  • Hosting provider: Microsoft Azure
  • Primary data residency: United States–based Azure datacenters
  • Infrastructure model: Cloud-native, multi-tenant SaaS
  • On-premise hosting: Not used
  • Unmanaged third-party hosting: Not used

AI CERTs relies on Azure’s enterprise security, compliance, and availability controls at the infrastructure and platform layers.

3. Multi-Tenant Partner Model

AI CERTs operates a multi-tenant Partner Portal and LMS environment.

  • Partners are not provided with a dedicated or isolated LMS instance
  • Logical segregation ensures partners can only access their own data
  • Partners manage learner enrollments and access through the Partner Portal

This approach ensures scalability, consistency of controls, and centralized security governance.

4. Learner Registration & Data Collected

AI CERTs follows data minimization and purpose limitation principles.

4.1 Learner Data Collected

Only data required for certification delivery and platform access is collected, typically:

  • First name
  • Last name
  • Email address
  • Course / certification enrollment metadata
  • Certification progress and results

4.2 Data Not Collected

AI CERTs does not require or store:

  • Government-issued identification numbers
  • Financial or payment card data
  • Biometric data
  • Special category personal data (as defined under GDPR)

5. Data Access & Role-Based Controls

Access to data is strictly controlled using Role-Based Access Control (RBAC).

5.1 Partner Access

  • Partners can view and manage only their own learners
  • No cross-partner data visibility is permitted

5.2 AI CERTs Internal Access

Access is limited to authorized personnel on a need-to-know basis, including:

  • Certification operations
  • Platform administration
  • Compliance and audit support
  • Technical support (when required)

All access is logged and monitored.

6. Data Security Controls

AI CERTs leverages Microsoft Azure’s enterprise-grade security framework.

6.1 Core Security Measures

  • Encryption of data at rest
  • Encryption of data in transit
  • Secure authentication and authorization
  • Role-based access enforcement
  • Network security controls and monitoring

6.2 Cloud Security

  • Azure Defender / Cloud Security posture management
  • Continuous monitoring and alerting
  • Secure configuration and patching practices

7. Data Usage & Purpose Limitation

Collected data is used exclusively for:

  • Learner account creation and authentication
  • Certification delivery and examination administration
  • Partner and learner support
  • Compliance, audit, and accreditation requirements

Data is not used for marketing or shared with third parties unless:

  • Explicit consent is obtained, or
  • Required by law or contractual obligation

8. Data Retention & Deletion

AI CERTs retains data only for as long as necessary to:

  • Deliver certification services
  • Meet contractual, legal, and accreditation obligations

Upon termination of a partner relationship or upon request (subject to legal requirements), data is securely deleted or anonymized in accordance with internal data retention policies.

9. Incident Response & Breach Management

AI CERTs maintains documented procedures for handling security incidents.

  • Security incidents are investigated promptly
  • Appropriate containment and remediation actions are taken
  • Partners are notified without undue delay where legally or contractually required
  • Azure platform monitoring supports early detection and response

10. Backup, Availability & Disaster Recovery

  • Regular backups are maintained at the cloud infrastructure level
  • Systems are designed for high availability
  • Disaster recovery mechanisms are in place as part of Azure’s managed services

High-level recovery objectives:

  • RPO/RTO: Defined and managed at the infrastructure and platform level

11. Sub-Processors

AI CERTs uses sub-processors only where necessary to deliver specific components of its certification programs.

Primary Infrastructure Sub-Processor

  • Microsoft Azure – Cloud hosting and infrastructure services
  • Data residency: United States–based Azure datacenters

Conditional / Program-Specific Sub-Processor

  • Skillable – Third-party virtual lab platform used only for selected certification programs that include hands-on lab environments
  • Data processed: First name, last name, email address
  • Purpose: Learner authentication and access to lab environments
  • Scope: Applies only when a certification program requires Skillable-hosted labs
  • Access mechanism: Learners receive a training access key and create an account directly on Skillable’s platform
  • AI CERTs does not use Skillable for core LMS, certification management, or learner administration

No additional sub-processors are used for learner data unless explicitly disclosed.

12. Privacy & GDPR Alignment

AI CERTs follows GDPR-aligned principles, including:

  • Lawfulness, fairness, and transparency
  • Purpose limitation
  • Data minimization
  • Integrity and confidentiality
  • Accountability

These principles are applied consistently across all partners and regions.

13. Assurance & Compliance Positioning

AI CERTs follows ISO/IEC 27001–aligned security practices and leverages Microsoft Azure’s certified infrastructure controls (including SOC and ISO certifications at the cloud provider level).

AI CERTs does not currently claim independent ISO 27001 or SOC 2 certification for its organization unless explicitly stated.

14. Summary

AI CERTs provides a secure, cloud-hosted, multi-tenant certification platform operated by Sarder Inc. Data is hosted in US-based Azure datacenters, protected through industry-standard encryption and access controls, and processed solely for certification-related purposes.

“This document is provided for informational purposes only and forms part of AI CERTs’ security and privacy disclosures. Binding obligations related to data protection, confidentiality, and security shall be governed solely by the applicable executed agreement, including any Data Processing Agreement (DPA), between the parties.”