Who is responsible for what#

Your organization decides which students or employees to register and which documents to issue; it remains the issuer of those documents. IVQA provides the infrastructure that stores the records and answers verifications. The Data Processing Agreement describes this relationship: ivqa.org/dpa. The Privacy policy (ivqa.org/privacy-policy) and Terms (ivqa.org/terms) apply to the service.

What is stored#

  • People: the profile fields you enter (identity, contact details, identifiers, programme or job data) and their registry status.
  • Documents and credentials: the generated or uploaded file, the public ID, the issuance snapshot of the holder's identity, the status history and, for uploaded files, a SHA-256 fingerprint.
  • Verification logs: each visit of a public verification page with its result, the approximate location derived from the visitor's IP address, and the device type.
  • Account activity: QR generation, revocations, token operations, subscription events, with the acting user.

What is public#

Only the public verification pages. For a valid document they show the document type, the issuing organization, the holder's name and UID, the public ID, dates and — for students — programme and level. They never show contact details, identifiers or the file. Revoked documents show only the banner and reason; drafts show nothing. See Public verification page.

Deletion#

  • Deleting a student removes their profile and the documents generated for them, and revokes the credentials of those documents. Certificates and diplomas already awarded are preserved so that their verification history remains — they can still be found and managed from Status & Revocations.
  • Deleting a document removes it from your dashboard; its credential can no longer verify.
  • Revoking keeps the record and tells verifiers the document was withdrawn. It is the recommended way to withdraw a document.

Requests from data subjects#

If a student or employee asks what IVQA holds about them, or asks for a correction, start from their profile in your dashboard. For requests you cannot fulfil from the dashboard, contact support.