Privacy Policy
GSCA Privacy Policy
Effective Date: August 9, 2026
Last Updated: August 9, 2026
Global Standard Certified Alliance ("GSCA"), operated by Techevent Limited and its affiliated entities ("GSCA", "we", "us", or "our"), is committed to protecting the privacy, security, integrity, and responsible use of information processed through the GSCA Trust Protocol and its associated digital trust services.
GSCA operates a global digital trust infrastructure designed to support trusted identities, digital assets, certificates, provenance, authenticity, verification, and trusted interactions across people, products, organizations, and connected ecosystems.
This Privacy Policy explains how we collect, use, protect, retain, and disclose information when you access or use GSCA services, websites, applications, digital trust services, or participate in a GSCA-enabled ecosystem.
1. Our Privacy and Trust Principles
GSCA is built around the principle that trust requires both verifiability and responsible data protection.
Our services are designed to enable trusted verification without unnecessarily exposing personal or confidential information.
Where technically and commercially appropriate, GSCA seeks to apply the following principles:
-
Data minimization — collecting only information reasonably required for the relevant service or purpose.
-
Purpose limitation — using information for defined and legitimate purposes.
-
Security by design — incorporating appropriate technical and organizational safeguards.
-
Verification without unnecessary disclosure — enabling verification while limiting exposure of underlying information where possible.
-
Integrity and traceability — maintaining reliable records of relevant trust and verification events.
-
User and organizational control — supporting appropriate control over information according to the applicable service, role, and authorization.
-
Responsible cross-border data handling — applying appropriate safeguards when information is processed across jurisdictions.
2. Scope of This Policy
This Privacy Policy applies to information processed through GSCA services and infrastructure, including, where applicable:
-
GSCA Trust Protocol
-
GSCA One ID
-
eAsset
-
eCert / eCertApp
-
eOrigin
-
eStamp
-
eForm
-
Pet ID and related trusted pet services
-
Digital certificates and credentials
-
Product identity and authenticity services
-
Organization and membership credentials
-
Digital asset verification
-
NFC and QR-based verification
-
GSCA websites, portals, APIs and related services
-
Partner, reseller, agency and ecosystem services
Different GSCA services may process different categories of information. The information actually collected depends on the service, configuration, user role, and relationship with GSCA.
3. Information We May Collect
Depending on the service being used, GSCA may process the following categories of information.
3.1 Identity and Account Information
This may include:
-
Name
-
Email address
-
Telephone number
-
Organization or company name
-
Job title or professional role
-
Country or region
-
Account credentials
-
One ID information
-
Authentication and authorization information
Where enhanced identity verification is enabled, additional verification information may be processed in accordance with the applicable service and legal requirements.
3.2 Digital Identity and Trust Credentials
GSCA may process information associated with digital identities and trusted credentials, including:
-
One ID identifiers
-
Digital credential identifiers
-
Certificate identifiers
-
Membership identifiers
-
License or award information
-
Credential status
-
Issuer information
-
Verification status
-
Issuance and expiration information
3.3 eAsset and Digital Asset Information
The GSCA Trust Protocol may support different types of digital assets and credentials.
Depending on the implementation, these may include:
-
eCert
-
eLicense
-
eMembership
-
eAward
-
eWarranty
-
ePassport
-
eCredential
-
Product identity information
-
Ownership or authorization information
-
Asset identifiers
-
Issuer and recipient information
-
Verification status
-
Associated metadata
The actual information contained within an eAsset is determined by the issuing organization and the relevant service configuration.
4. Product, Provenance and Authenticity Information
Where GSCA services are used for products and supply-chain trust, we may process information such as:
-
Product identifiers
-
Serial numbers
-
Batch or lot numbers
-
Manufacturer information
-
Country or region of origin
-
Certification information
-
Production or issuance information
-
Import or export-related information
-
Warranty information
-
Provenance records
-
eOrigin information
-
NFC or QR verification data
This information may be used to support product authenticity, provenance, traceability, certification, and verification.
5. Pet Identity and Pet-Related Information
Where GSCA Pet ID or related services are used, information may include:
-
Pet name
-
Pet ID
-
Species and breed
-
Photograph
-
Owner or authorized guardian information
-
Emergency contact information
-
Vaccination records
-
Medical or veterinary records
-
Insurance-related information
-
Identification tag information
-
NFC or QR verification information
-
Relevant certificates and credentials
-
Pet-related information may be provided by pet owners, authorized organizations, veterinary clinics, service providers, or other authorized parties.
GSCA processes such information for the purposes of identity, verification, safety, record management, and related trusted ecosystem services.
6. Verification and Technical Information
When a GSCA credential, eAsset, NFC tag, QR code, or other trust identifier is accessed or verified, we may process technical and verification information including:
-
Verification identifier
-
Date and time of verification
-
Issuer
-
Credential or asset status
-
Verification result
-
Device information
-
IP address
-
Browser or application information
-
Security and access logs
-
API transaction information
-
Fraud-prevention and security information
Verification records may be retained where necessary to maintain the integrity, security, auditability, and reliability of the GSCA Trust Infrastructure.
7. How We Use Information
GSCA may use information for the following purposes:
Service Delivery
To:
-
Create and manage accounts
-
Issue and manage digital credentials
-
Operate One ID
-
Create and manage eAssets
-
Provide certificate and credential verification
-
Support product authenticity and provenance
-
Maintain Pet ID and related services
-
Provide API and integration services
Trust and Verification
To:
-
Verify identities
-
Verify certificates and credentials
-
Verify products and provenance
-
Detect fraudulent or altered credentials
-
Maintain trust and verification records
-
Support anti-counterfeiting functions
-
Protect the integrity of the GSCA Trust Protocol
Security
To:
-
Prevent unauthorized access
-
Detect suspicious activity
-
Protect infrastructure
-
Investigate security incidents
-
Prevent fraud, abuse, and manipulation
Business and Ecosystem Operations
To:
-
Manage organizations
-
Support partners, resellers and agencies
-
Manage memberships
-
Provide customer support
-
Process transactions
-
Maintain business relationships
-
Improve GSCA services
Legal and Regulatory Compliance
To comply with applicable laws, regulations, lawful requests, contractual obligations, and legitimate governance requirements.
8. Information Sharing and Disclosure
GSCA does not sell personal information as a general business practice.
Information may be disclosed where reasonably necessary to:
-
Provide requested GSCA services
-
Enable authorized verification
-
Support an issuing organization or authorized service provider
-
Provide technical infrastructure and hosting services
-
Process payments
-
Provide customer support
-
Maintain security and fraud prevention
-
Comply with applicable law or lawful governmental requests
-
Protect the rights, property, security, or integrity of GSCA and its users
Where third-party service providers process information on behalf of GSCA, we seek to require appropriate confidentiality, security, and data-processing obligations.
9. Public and Verifiable Information
Some GSCA services are specifically designed to allow information or credentials to be verified by third parties.
For example, an organization may choose to issue a digital certificate containing information intended to be publicly verifiable.
Accordingly, users and issuing organizations should consider carefully what information is included in a credential or digital asset before publishing or issuing it.
Information intentionally configured as publicly verifiable may be accessible to anyone who has access to the relevant verification identifier, NFC tag, QR code, link, or other verification mechanism.
GSCA does not consider such information private merely because it is stored within a digital credential.
10. Data Security
GSCA applies reasonable technical and organizational measures designed to protect information against:
-
Unauthorized access
-
Unauthorized alteration
-
Loss
-
Destruction
-
Misuse
-
Disclosure
-
Fraudulent manipulation
Depending on the service, security measures may include:
-
Encryption
-
Secure authentication
-
Access controls
-
Cryptographic integrity mechanisms
-
Audit logging
-
Infrastructure monitoring
-
Backup and recovery controls
-
Security monitoring
-
Role-based access controls
No Internet-based system can guarantee absolute security. GSCA therefore continuously evaluates and improves its security controls as the Trust Infrastructure evolves.
11. Data Retention
GSCA retains information only for as long as reasonably necessary for the purposes described in this Policy, including:
-
Providing contracted services
-
Maintaining digital credentials
-
Maintaining verification integrity
-
Supporting auditability
-
Preventing fraud
-
Resolving disputes
-
Meeting legal and regulatory obligations
Retention periods may differ depending on the type of information, service, contractual requirements, and applicable law.
Certain trust, certificate, provenance, or verification records may need to be retained for longer periods to preserve the integrity and historical validity of the relevant trust record.
12. International and Cross-Border Data Processing
GSCA operates and supports an international digital trust ecosystem.
Information may therefore be processed in jurisdictions where GSCA, its affiliated entities, infrastructure providers, partners, or service providers operate.
Depending on the applicable jurisdiction and the nature of the information, GSCA seeks to apply appropriate safeguards and comply with applicable data protection requirements, which may include:
-
EU GDPR
-
Mainland China Personal Information Protection Law (PIPL)
-
Applicable Hong Kong privacy and data protection requirements
-
Applicable Malaysian Personal Data Protection requirements
-
Other applicable data protection and cybersecurity laws in relevant jurisdictions
Where required, appropriate contractual, technical, organizational, or other legally recognized safeguards may be applied to international transfers.
13. Children's Information
GSCA services are primarily designed for organizations, businesses, professionals, credential holders, product owners, and other authorized users.
GSCA does not knowingly collect personal information from children for purposes unrelated to a legitimate service.
Where a GSCA-enabled ecosystem involves children or educational credentials, the relevant organization remains responsible for ensuring that collection and processing are conducted with appropriate authorization and in accordance with applicable law.
14. Cookies and Similar Technologies
GSCA websites and online services may use cookies, analytics tools, session technologies, and similar technologies to:
-
Operate websites and services
-
Maintain sessions
-
Improve security
-
Understand service usage
-
Improve user experience
-
Measure performance
-
Where required by applicable law, appropriate consent mechanisms may be provided.
15. Your Rights and Choices
Depending on your jurisdiction, you may have rights concerning your personal information, including:
-
Access
-
Correction
-
Updating
-
Deletion
-
Restriction of processing
-
Objection
-
Data portability
-
Withdrawal of consent where processing is based on consent
Certain rights may be subject to legal, contractual, security, or record-integrity requirements.
Requests should include sufficient information for us to verify the identity of the requester and understand the nature of the request.
16. Organizational and Issuer Responsibilities
Where GSCA provides infrastructure to an organization, issuer, partner, reseller, agency, educational institution, veterinary organization, manufacturer, or other entity, that organization may determine what information is collected and included within its GSCA-enabled credentials or digital assets.
Such organizations may therefore have their own privacy policies and legal responsibilities.
Where applicable, users should review both:
the GSCA Privacy Policy
and
the privacy policy of the organization that issued or manages the relevant credential, asset, identity, or record.
17. Changes to This Privacy Policy
GSCA may update this Privacy Policy from time to time to reflect changes in:
-
GSCA Trust Protocol
-
Services and products
-
Technology
-
Security practices
-
Legal or regulatory requirements
-
Global operating jurisdictions
The updated version will be published on the relevant GSCA website with an updated effective date.
18. Contact Us
For privacy, data protection, security, or personal information requests, please contact:
Global Standard Certified Alliance (GSCA)
Operated by Techevent Limited
Email: cs@ecert.app
Website: www.ecert.app / www.gsca.cc