Privacy policy
Draft template. A data-protection lawyer must review this before it is final. It is published for transparency and describes the system's real architecture.
Who we are
Glemo is a credential verification network. For credentials issued by our customers, Glemo acts as a processor; the issuer is the data controller.
What data we process and why
| Data | Basis | For what |
|---|---|---|
| Holder email | Service delivery (issuer's instruction) | Deliver the credential and its verification link |
| Credential claims (name, achievement) | Same | The verifiable content |
| Account email (users) | Contract | Authentication and account management |
| Verification events (verdicts, latencies, no claims) | Legitimate interest | Metering, anti-fraud, and aggregate analytics |
What we don't do
- We publish no personal data on any blockchain: only keyed hashes (commitments) travel on-chain, and they cannot be reversed or linked without the key.
- We don't sell data. We don't use claims for advertising.
Your rights
Access, rectification, erasure, portability. Erasure follows the pattern the CNIL endorses: we destroy the cryptographic key (the public anchor becomes unlinkable) and delete the internal copies. Target time: 72 h from a validated request; backups rotate out fully within the stated retention window. Contact: privacy@glemo.io.
Retention
Credential data: while the credential is active, or until an erasure request. Verification events: aggregated without claims, retained for billing and audit.