Legal

Privacy Policy

How Creda Technologies, LLC collects, uses, discloses, and protects information in connection with our identity, credential governance, and compliance mobility infrastructure.

Last Updated: January 2025

This Privacy Policy ("Policy") describes how Creda Technologies, LLC ("Creda Technologies," "we," "our," or "us") collects, uses, discloses, and protects information in connection with our digital identity, credential governance, compliance tokenization, and related infrastructure services (the "Services").

Creda Technologies provides enterprise-grade infrastructure for identity-bound credentials, compliance mobility, and cross-institution trust. Our products include Creda Protocol, Creda Registry, Creda 1, and related applications, APIs, SDKs, and verification interfaces (collectively, the "Creda Family"). This Policy applies to all websites, applications, portals, and service offerings where it is posted or referenced.

This Policy is written with the expectations of healthcare (HIPAA/HITECH), aviation (TSA/DHS), financial services (SEC/FINRA/BSA), and government sectors in mind, and is intended to align with prevailing privacy and security frameworks such as GDPR, CCPA, NIST 800-63, and ISO/IEC 27001/27701.

By accessing or using the Services, you acknowledge that you have read and understood this Policy. If you do not agree with this Policy, you must not use the Services.

1. Scope of This Policy

This Policy governs information we collect when:

This Policy does not apply to:

In those cases, the organization controlling the data is generally responsible for compliance, and their privacy notices govern their handling of personal data.

2. Definitions

For clarity in regulated environments, we use the following definitions:

3. Information We Collect

The information we collect will depend on how you interact with the Creda Family.

3.1 Information You Provide Directly

You may provide information directly when you, for example, create an account or profile, submit a contact form, request integration or pilot access, participate in the Advisory Council, or interact with a credential onboarding or verification workflow.

This can include:

Identity Information

Credential & Compliance Information

During pilots or integrations, we may also receive workflow descriptions and process details relating to how your institution manages identity, credentialing, and compliance today.

3.2 Information We Collect Automatically

Device & Technical Data

Operational & Security Metadata

Cookies & Similar Technologies

We use cookies and similar technologies to maintain secure sessions, provide basic analytics, and ensure reliable operation of portals and verification flows. We do not use advertising cookies.

3.3 Information We Receive from Third Parties

We may receive information from enterprise customers and selected third parties, such as:

Data received from third parties is handled in accordance with this Policy, any applicable data protection addenda, and the governing contracts with those parties.

4. How We Use Information

We use Personal Information and Credential Data to:

4.1 Provide and Operate the Services

4.2 Support Regulatory, Security, and Audit Requirements

4.3 Improve, Research, and Develop

4.4 Communicate with You

5. How We Share Information

We do not sell Personal Information. We may share Personal Information in the following limited ways:

5.1 With Enterprise Customers

If you interact with the Services as part of a hospital system, provider network, airport, financial institution, agency, or other organization, we may share:

Enterprise customers are responsible for their own internal use of such information in accordance with their legal and regulatory obligations.

5.2 With Service Providers

We use trusted third-party vendors to support hosting, security, logging, analytics, and related operations. These providers may have access to Personal Information solely to perform services on our behalf and are required to protect it under appropriate contractual and technical safeguards.

5.3 For Legal, Security, and Regulatory Reasons

We may disclose information when we believe it is necessary to:

5.4 During Corporate Events

In the event of a merger, acquisition, financing, or sale of all or part of our business, Personal Information may be transferred to another entity, subject to appropriate confidentiality and regulatory constraints.

6. How We Protect Information

We maintain a security program designed for high-stakes sectors where identity, credentials, and compliance must be correct the first time. Safeguards may include:

No system can be guaranteed 100% secure. However, we design and operate Creda infrastructure with the assumption that our customers operate under regulatory scrutiny and audit expectations.

7. Biometric Information

To the extent Creda Technologies interacts with biometric signals as part of identity-bound workflows (for example, integrating with proof-of-human systems), we follow these principles:

8. Data Retention

We retain Personal Information, Credential Data, and Operational Logs for as long as reasonably necessary to:

Credential revocation data, compliance tokens, and audit trails may be retained longer in order to preserve the integrity and evidentiary value of compliance records.

9. International Data Transfers

Where Personal Information is transferred across borders, we implement appropriate safeguards, which may include:

10. Your Privacy Rights

Depending on your location and applicable law, you may have certain rights regarding your Personal Information, including:

To exercise these rights, contact us using the information in the Contact Us section below. We may need to verify your identity before fulfilling your request, and certain rights may be limited where we are required to retain data for regulatory, security, or contractual reasons.

11. Children’s Privacy

The Services are not directed to children under 18, and we do not knowingly collect Personal Information from individuals under 18. If we become aware that we have collected such information, we will take reasonable steps to delete it or to work with the relevant enterprise customer to address the issue.

12. Third-Party Services and Links

The Services may include links to third-party websites, applications, or services that we do not control. This Policy does not apply to those third-party properties. We encourage you to review the privacy notices of any third-party services you access.

13. Changes to This Policy

We may update this Policy from time to time to reflect changes in our Services, applicable laws, or other operational needs. When we make material changes, we will update the "Last Updated" date at the top of this page and, where appropriate, provide additional notice.

Your continued use of the Services after any update constitutes your acceptance of the revised Policy.

14. Contact Us

If you have questions about this Policy or our privacy practices, you may contact us at:

Creda Technologies, LLC
7901 4th St N, Suite 300
St. Petersburg, FL 33702
Tel: 561.741.3000
Email: privacy@credahq.com