Who is responsible for what#
Your organization decides which students or employees to register and which documents to issue; it remains the issuer of those documents. IVQA provides the infrastructure that stores the records and answers verifications. The Data Processing Agreement describes this relationship: ivqa.org/dpa. The Privacy policy (ivqa.org/privacy-policy) and Terms (ivqa.org/terms) apply to the service.
What is stored#
- People: the profile fields you enter (identity, contact details, identifiers, programme or job data) and their registry status.
- Documents and credentials: the generated or uploaded file, the public ID, the issuance snapshot of the holder's identity, the status history and, for uploaded files, a SHA-256 fingerprint.
- Verification logs: each visit of a public verification page with its result, the approximate location derived from the visitor's IP address, and the device type.
- Account activity: QR generation, revocations, token operations, subscription events, with the acting user.
What is public#
Only the public verification pages. For a valid document they show the document type, the issuing organization, the holder's name and UID, the public ID, dates and — for students — programme and level. They never show contact details, identifiers or the file. Revoked documents show only the banner and reason; drafts show nothing. See Public verification page.
Deletion#
- Deleting a student removes their profile and the documents generated for them, and revokes the credentials of those documents. Certificates and diplomas already awarded are preserved so that their verification history remains — they can still be found and managed from Status & Revocations.
- Deleting a document removes it from your dashboard; its credential can no longer verify.
- Revoking keeps the record and tells verifiers the document was withdrawn. It is the recommended way to withdraw a document.
Requests from data subjects#
If a student or employee asks what IVQA holds about them, or asks for a correction, start from their profile in your dashboard. For requests you cannot fulfil from the dashboard, contact support.