Version: 1.1
Owner: Sarder Inc. (DBA AI CERTs)
1. Organization & Legal Entity
AI CERTs is operated by Sarder Inc., a United States–registered company, doing business as AI CERTs.
Sarder Inc. acts as the Data Controller and Data Processor for all learner and partner data processed within the AI CERTs certification ecosystem, unless contractually agreed otherwise.
2. Platform Architecture & Hosting
AI CERTs operates a cloud-based certification and partner management platform hosted entirely on Microsoft Azure.
- Hosting provider: Microsoft Azure
- Primary data residency: United States–based Azure datacenters
- Infrastructure model: Cloud-native, multi-tenant SaaS
- On-premise hosting: Not used
- Unmanaged third-party hosting: Not used
AI CERTs relies on Azure’s enterprise security, compliance, and availability controls at the infrastructure and platform layers.
3. Multi-Tenant Partner Model
AI CERTs operates a multi-tenant Partner Portal and LMS environment.
- Partners are not provided with a dedicated or isolated LMS instance
- Logical segregation ensures partners can only access their own data
- Partners manage learner enrollments and access through the Partner Portal
This approach ensures scalability, consistency of controls, and centralized security governance.
4. Learner Registration & Data Collected
AI CERTs follows data minimization and purpose limitation principles.
4.1 Learner Data Collected
Only data required for certification delivery and platform access is collected, typically:
- First name
- Last name
- Email address
- Course / certification enrollment metadata
- Certification progress and results
4.2 Data Not Collected
AI CERTs does not require or store:
- Government-issued identification numbers
- Financial or payment card data
- Biometric data
- Special category personal data (as defined under GDPR)
5. Data Access & Role-Based Controls
Access to data is strictly controlled using Role-Based Access Control (RBAC).
5.1 Partner Access
- Partners can view and manage only their own learners
- No cross-partner data visibility is permitted
5.2 AI CERTs Internal Access
Access is limited to authorized personnel on a need-to-know basis, including:
- Certification operations
- Platform administration
- Compliance and audit support
- Technical support (when required)
All access is logged and monitored.
6. Data Security Controls
AI CERTs leverages Microsoft Azure’s enterprise-grade security framework.
6.1 Core Security Measures
- Encryption of data at rest
- Encryption of data in transit
- Secure authentication and authorization
- Role-based access enforcement
- Network security controls and monitoring
6.2 Cloud Security
- Azure Defender / Cloud Security posture management
- Continuous monitoring and alerting
- Secure configuration and patching practices
7. Data Usage & Purpose Limitation
Collected data is used exclusively for:
- Learner account creation and authentication
- Certification delivery and examination administration
- Partner and learner support
- Compliance, audit, and accreditation requirements
Data is not used for marketing or shared with third parties unless:
- Explicit consent is obtained, or
- Required by law or contractual obligation
8. Data Retention & Deletion
AI CERTs retains data only for as long as necessary to:
- Deliver certification services
- Meet contractual, legal, and accreditation obligations
Upon termination of a partner relationship or upon request (subject to legal requirements), data is securely deleted or anonymized in accordance with internal data retention policies.
9. Incident Response & Breach Management
AI CERTs maintains documented procedures for handling security incidents.
- Security incidents are investigated promptly
- Appropriate containment and remediation actions are taken
- Partners are notified without undue delay where legally or contractually required
- Azure platform monitoring supports early detection and response
10. Backup, Availability & Disaster Recovery
- Regular backups are maintained at the cloud infrastructure level
- Systems are designed for high availability
- Disaster recovery mechanisms are in place as part of Azure’s managed services
High-level recovery objectives:
- RPO/RTO: Defined and managed at the infrastructure and platform level
11. Sub-Processors
AI CERTs uses sub-processors only where necessary to deliver specific components of its certification programs.
Primary Infrastructure Sub-Processor
- Microsoft Azure – Cloud hosting and infrastructure services
- Data residency: United States–based Azure datacenters
Conditional / Program-Specific Sub-Processor
- Skillable – Third-party virtual lab platform used only for selected certification programs that include hands-on lab environments
- Data processed: First name, last name, email address
- Purpose: Learner authentication and access to lab environments
- Scope: Applies only when a certification program requires Skillable-hosted labs
- Access mechanism: Learners receive a training access key and create an account directly on Skillable’s platform
- AI CERTs does not use Skillable for core LMS, certification management, or learner administration
No additional sub-processors are used for learner data unless explicitly disclosed.
12. Privacy & GDPR Alignment
AI CERTs follows GDPR-aligned principles, including:
- Lawfulness, fairness, and transparency
- Purpose limitation
- Data minimization
- Integrity and confidentiality
- Accountability
These principles are applied consistently across all partners and regions.
13. Assurance & Compliance Positioning
AI CERTs follows ISO/IEC 27001–aligned security practices and leverages Microsoft Azure’s certified infrastructure controls (including SOC and ISO certifications at the cloud provider level).
AI CERTs does not currently claim independent ISO 27001 or SOC 2 certification for its organization unless explicitly stated.
14. Summary
AI CERTs provides a secure, cloud-hosted, multi-tenant certification platform operated by Sarder Inc. Data is hosted in US-based Azure datacenters, protected through industry-standard encryption and access controls, and processed solely for certification-related purposes.
“This document is provided for informational purposes only and forms part of AI CERTs’ security and privacy disclosures. Binding obligations related to data protection, confidentiality, and security shall be governed solely by the applicable executed agreement, including any Data Processing Agreement (DPA), between the parties.”