Certer
Login Register

Privacy Policy

Last updated: Jul 22, 2026

This policy explains what personal data Certer collects, why we process it, how long we keep it, and the rights you have over it. It is written to comply with the EU General Data Protection Regulation (GDPR), which we apply to every user regardless of where they are located.

Certer manages TLS certificate metadata for teams. We store only public certificate information — names, hostnames, issuing and expiry details — and never store private keys.

Who is responsible for your data

The data controller for Certer is InfoCore d.o.o., a company established in Montenegro (the “Operator”). For any privacy question or to exercise your rights, contact us at root@infodev.me. Full identity and registration details are at the end of this policy.

Organizations as controllers

Certer is multi-tenant. The Operator is the controller for account-level data — the personal data tied to your individual Certer account.

However, when an organization invites you and manages you as one of its members, that organization is the controller for the data it holds about you in that context (for example, your membership, your role, and the notification settings it configures). For requests about data an organization manages, contact that organization directly. We will help route your request where we reasonably can.

The personal data we hold

We hold only the data needed to run the service:

  • Account details — your name, email address, and a securely hashed password. We never store your password in readable form.
  • Session data — the IP address and browser user-agent recorded when you sign in, used to keep your session secure.
  • Organization membership — which organizations you belong to and your role within them.
  • Invitation emails — if someone invites you to an organization before you have registered, we hold the email address the invitation was sent to until it is accepted or expires.
  • Notification recipients — the email addresses expiry notifications are sent to, together with delivery records of what was sent and when.
  • Rate-limiting data — IP addresses processed transiently to protect the service from abuse.

Why we process it, and our legal basis

Under Article 6(1) of the GDPR, we rely on the following grounds:

  • Performance of a contract (Art. 6(1)(b)) — creating and securing your account, providing the certificate-management service, and sending you the transactional and expiry notification emails you have configured.
  • Legitimate interests (Art. 6(1)(f)) — keeping sessions secure, rate-limiting to prevent abuse, and monitoring errors and usage during our beta (see below). You can object to processing based on legitimate interests at any time.
  • Legal obligation (Art. 6(1)(c)) — retaining records where the law requires it. This does not apply during the free beta, but will apply to billing and accounting records once Certer introduces paid plans.

We do not currently rely on consent (Art. 6(1)(a)): our email is transactional only, and we use only a strictly-necessary cookie.

Cookies

Certer uses a single, strictly-necessary cookie to keep you signed in. It is essential to providing a service you have requested, so under Article 5(3) of the ePrivacy Directive it is exempt from the consent requirement. We do not use advertising, analytics, or tracking cookies, and there is no consent banner because none is required.

Where your data is stored

All processing takes place within the EU/EEA. We do not transfer your personal data outside the EEA.

Our sole processor is Hetzner Online GmbH, which provides hosting within the EU/EEA under a data processing agreement we hold on file. We run our own email and error-monitoring infrastructure, so there are no third-party email or analytics processors involved in handling your data.

Monitoring during beta

While Certer is in beta, we capture detailed error and usage information — including session recordings of how pages are used — to diagnose problems and improve the product. This is processed on our own self-hosted infrastructure and is not shared with third parties. We will reduce this collection and minimise the data captured once the beta ends.

How long we keep it

  • Account and organization data is kept for as long as your account is active, and deleted when you close it.
  • Backups are retained for up to 90 days.
  • Notification delivery logs are retained for up to 12 months.
  • Invitations are held until they are accepted or expire.

Where the law requires us to keep certain records, that obligation overrides a deletion request for those specific records. This does not affect anything today, but once Certer introduces paid plans, tax and accounting law will require invoices and billing records to be retained for a number of years.

Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data erased;
  • restrict how we process it;
  • receive your data in a portable format;
  • object to processing based on our legitimate interests.

To exercise any of these rights, email root@infodev.me. We will respond within one month. For data an organization manages about you, contact that organization, as described above.

Complaints

If you believe we have mishandled your data, you have the right to lodge a complaint with a supervisory authority. Our authority is Montenegro's Agencija za zaštitu podataka o ličnosti i slobodan pristup informacijama (AZLP), Podgorica — azlp.me. You may also complain to the supervisory authority in your own country of residence.

EU/UK representative

As a controller established outside the EU and UK, we are required to appoint representatives under Article 27 of the GDPR and UK GDPR. [Representative details to be confirmed before public launch — placeholder.]

Changes to this policy

We may update this policy as Certer evolves. When we make material changes, we will update the date at the top of this page. Your continued use of Certer after a change means you have read the updated policy. See also our Terms of Service.

InfoCore d.o.o. 4. Jul 107/62, 81000 Podgorica, Montenegro Company registry number: 5 - 0609914 / 005 Tax ID (PIB): 02846713 Contact: root@infodev.me