top of page

Privacy Policy

GSCA Privacy Policy

Effective Date: August 9, 2026
Last Updated: August 9, 2026

Global Standard Certified Alliance ("GSCA"), operated by Techevent Limited and its affiliated entities ("GSCA", "we", "us", or "our"), is committed to protecting the privacy, security, integrity, and responsible use of information processed through the GSCA Trust Protocol and its associated digital trust services.

GSCA operates a global digital trust infrastructure designed to support trusted identities, digital assets, certificates, provenance, authenticity, verification, and trusted interactions across people, products, organizations, and connected ecosystems.

This Privacy Policy explains how we collect, use, protect, retain, and disclose information when you access or use GSCA services, websites, applications, digital trust services, or participate in a GSCA-enabled ecosystem.

 

1. Our Privacy and Trust Principles

GSCA is built around the principle that trust requires both verifiability and responsible data protection.

Our services are designed to enable trusted verification without unnecessarily exposing personal or confidential information.

Where technically and commercially appropriate, GSCA seeks to apply the following principles:

  1. Data minimization — collecting only information reasonably required for the relevant service or purpose.

  2. Purpose limitation — using information for defined and legitimate purposes.

  3. Security by design — incorporating appropriate technical and organizational safeguards.

  4. Verification without unnecessary disclosure — enabling verification while limiting exposure of underlying information where possible.

  5. Integrity and traceability — maintaining reliable records of relevant trust and verification events.

  6. User and organizational control — supporting appropriate control over information according to the applicable service, role, and authorization.

  7. Responsible cross-border data handling — applying appropriate safeguards when information is processed across jurisdictions.

 

2. Scope of This Policy

This Privacy Policy applies to information processed through GSCA services and infrastructure, including, where applicable:

  1. GSCA Trust Protocol 

  2. GSCA One ID 

  3. eAsset 

  4. eCert / eCertApp 

  5. eOrigin 

  6. eStamp 

  7. eForm 

  8. Pet ID and related trusted pet services 

  9. Digital certificates and credentials

  10. Product identity and authenticity services

  11. Organization and membership credentials

  12. Digital asset verification

  13. NFC and QR-based verification

  14. GSCA websites, portals, APIs and related services

  15. Partner, reseller, agency and ecosystem services

Different GSCA services may process different categories of information. The information actually collected depends on the service, configuration, user role, and relationship with GSCA.

 

3. Information We May Collect

Depending on the service being used, GSCA may process the following categories of information.

3.1 Identity and Account Information

This may include:

  1. Name

  2. Email address

  3. Telephone number

  4. Organization or company name

  5. Job title or professional role

  6. Country or region

  7. Account credentials

  8. One ID information

  9. Authentication and authorization information

Where enhanced identity verification is enabled, additional verification information may be processed in accordance with the applicable service and legal requirements.

 

3.2 Digital Identity and Trust Credentials

GSCA may process information associated with digital identities and trusted credentials, including:

  1. One ID identifiers

  2. Digital credential identifiers

  3. Certificate identifiers

  4. Membership identifiers

  5. License or award information

  6. Credential status

  7. Issuer information

  8. Verification status

  9. Issuance and expiration information

 

3.3 eAsset and Digital Asset Information

The GSCA Trust Protocol may support different types of digital assets and credentials.

Depending on the implementation, these may include:

  1. eCert

  2. eLicense

  3. eMembership

  4. eAward

  5. eWarranty

  6. ePassport

  7. eCredential

  8. Product identity information

  9. Ownership or authorization information

  10. Asset identifiers

  11. Issuer and recipient information

  12. Verification status

  13. Associated metadata

The actual information contained within an eAsset is determined by the issuing organization and the relevant service configuration.

 

4. Product, Provenance and Authenticity Information

Where GSCA services are used for products and supply-chain trust, we may process information such as:

  1. Product identifiers

  2. Serial numbers

  3. Batch or lot numbers

  4. Manufacturer information

  5. Country or region of origin

  6. Certification information

  7. Production or issuance information

  8. Import or export-related information

  9. Warranty information

  10. Provenance records

  11. eOrigin information

  12. NFC or QR verification data

This information may be used to support product authenticity, provenance, traceability, certification, and verification.

 

5. Pet Identity and Pet-Related Information

Where GSCA Pet ID or related services are used, information may include:

  1. Pet name

  2. Pet ID

  3. Species and breed

  4. Photograph

  5. Owner or authorized guardian information

  6. Emergency contact information

  7. Vaccination records

  8. Medical or veterinary records

  9. Insurance-related information

  10. Identification tag information

  11. NFC or QR verification information

  12. Relevant certificates and credentials

Pet-related information may be provided by pet owners, authorized organizations, veterinary clinics, service providers, or other authorized parties.

GSCA processes such information for the purposes of identity, verification, safety, record management, and related trusted ecosystem services.

 

6. Verification and Technical Information

When a GSCA credential, eAsset, NFC tag, QR code, or other trust identifier is accessed or verified, we may process technical and verification information including:

  1. Verification identifier

  2. Date and time of verification

  3. Issuer

  4. Credential or asset status

  5. Verification result

  6. Device information

  7. IP address

  8. Browser or application information

  9. Security and access logs

  10. API transaction information

  11. Fraud-prevention and security information

Verification records may be retained where necessary to maintain the integrity, security, auditability, and reliability of the GSCA Trust Infrastructure.

 

7. How We Use Information

GSCA may use information for the following purposes:

Service Delivery

To:

  1. Create and manage accounts

  2. Issue and manage digital credentials

  3. Operate One ID

  4. Create and manage eAssets

  5. Provide certificate and credential verification

  6. Support product authenticity and provenance

  7. Maintain Pet ID and related services

  8. Provide API and integration services

Trust and Verification

To:

  1. Verify identities

  2. Verify certificates and credentials

  3. Verify products and provenance

  4. Detect fraudulent or altered credentials

  5. Maintain trust and verification records

  6. Support anti-counterfeiting functions

  7. Protect the integrity of the GSCA Trust Protocol

Security

To:

  1. Prevent unauthorized access

  2. Detect suspicious activity

  3. Protect infrastructure

  4. Investigate security incidents

  5. Prevent fraud, abuse, and manipulation

Business and Ecosystem Operations

To:

  1. Manage organizations

  2. Support partners, resellers and agencies

  3. Manage memberships

  4. Provide customer support

  5. Process transactions

  6. Maintain business relationships

  7. Improve GSCA services

Legal and Regulatory Compliance

To comply with applicable laws, regulations, lawful requests, contractual obligations, and legitimate governance requirements.

 

8. Information Sharing and Disclosure

GSCA does not sell personal information as a general business practice.

Information may be disclosed where reasonably necessary to:

  1. Provide requested GSCA services

  2. Enable authorized verification

  3. Support an issuing organization or authorized service provider

  4. Provide technical infrastructure and hosting services

  5. Process payments

  6. Provide customer support

  7. Maintain security and fraud prevention

  8. Comply with applicable law or lawful governmental requests

  9. Protect the rights, property, security, or integrity of GSCA and its users

Where third-party service providers process information on behalf of GSCA, we seek to require appropriate confidentiality, security, and data-processing obligations.

 

9. Public and Verifiable Information

Some GSCA services are specifically designed to allow information or credentials to be verified by third parties.

For example, an organization may choose to issue a digital certificate containing information intended to be publicly verifiable.

Accordingly, users and issuing organizations should consider carefully what information is included in a credential or digital asset before publishing or issuing it.

Information intentionally configured as publicly verifiable may be accessible to anyone who has access to the relevant verification identifier, NFC tag, QR code, link, or other verification mechanism.

GSCA does not consider such information private merely because it is stored within a digital credential.

 

10. Data Security

GSCA applies reasonable technical and organizational measures designed to protect information against:

  1. Unauthorized access

  2. Unauthorized alteration

  3. Loss

  4. Destruction

  5. Misuse

  6. Disclosure

  7. Fraudulent manipulation

Depending on the service, security measures may include:

  1. Encryption

  2. Secure authentication

  3. Access controls

  4. Cryptographic integrity mechanisms

  5. Audit logging

  6. Infrastructure monitoring

  7. Backup and recovery controls

  8. Security monitoring

  9. Role-based access controls

No Internet-based system can guarantee absolute security. GSCA therefore continuously evaluates and improves its security controls as the Trust Infrastructure evolves.

 

11. Data Retention

GSCA retains information only for as long as reasonably necessary for the purposes described in this Policy, including:

  1. Providing contracted services

  2. Maintaining digital credentials

  3. Maintaining verification integrity

  4. Supporting auditability

  5. Preventing fraud

  6. Resolving disputes

  7. Meeting legal and regulatory obligations

Retention periods may differ depending on the type of information, service, contractual requirements, and applicable law.

Certain trust, certificate, provenance, or verification records may need to be retained for longer periods to preserve the integrity and historical validity of the relevant trust record.

 

12. International and Cross-Border Data Processing

GSCA operates and supports an international digital trust ecosystem.

Information may therefore be processed in jurisdictions where GSCA, its affiliated entities, infrastructure providers, partners, or service providers operate.

Depending on the applicable jurisdiction and the nature of the information, GSCA seeks to apply appropriate safeguards and comply with applicable data protection requirements, which may include:

  1. EU GDPR 

  2. Mainland China Personal Information Protection Law (PIPL) 

  3. Applicable Hong Kong privacy and data protection requirements

  4. Applicable Malaysian Personal Data Protection requirements

  5. Other applicable data protection and cybersecurity laws in relevant jurisdictions

Where required, appropriate contractual, technical, organizational, or other legally recognized safeguards may be applied to international transfers.

 

13. Children's Information

GSCA services are primarily designed for organizations, businesses, professionals, credential holders, product owners, and other authorized users.

GSCA does not knowingly collect personal information from children for purposes unrelated to a legitimate service.

Where a GSCA-enabled ecosystem involves children or educational credentials, the relevant organization remains responsible for ensuring that collection and processing are conducted with appropriate authorization and in accordance with applicable law.

 

14. Cookies and Similar Technologies

GSCA websites and online services may use cookies, analytics tools, session technologies, and similar technologies to:

  1. Operate websites and services

  2. Maintain sessions

  3. Improve security

  4. Understand service usage

  5. Improve user experience

  6. Measure performance

Where required by applicable law, appropriate consent mechanisms may be provided.

 

15. Your Rights and Choices

Depending on your jurisdiction, you may have rights concerning your personal information, including:

  1. Access

  2. Correction

  3. Updating

  4. Deletion

  5. Restriction of processing

  6. Objection

  7. Data portability

  8. Withdrawal of consent where processing is based on consent

Certain rights may be subject to legal, contractual, security, or record-integrity requirements.

Requests should include sufficient information for us to verify the identity of the requester and understand the nature of the request.

 

16. Organizational and Issuer Responsibilities

Where GSCA provides infrastructure to an organization, issuer, partner, reseller, agency, educational institution, veterinary organization, manufacturer, or other entity, that organization may determine what information is collected and included within its GSCA-enabled credentials or digital assets.

Such organizations may therefore have their own privacy policies and legal responsibilities.

Where applicable, users should review both:

the GSCA Privacy Policy

and

the privacy policy of the organization that issued or manages the relevant credential, asset, identity, or record.

 

17. Changes to This Privacy Policy

GSCA may update this Privacy Policy from time to time to reflect changes in:

  1. GSCA Trust Protocol

  2. Services and products

  3. Technology

  4. Security practices

  5. Legal or regulatory requirements

  6. Global operating jurisdictions

The updated version will be published on the relevant GSCA website with an updated effective date.

 

18. Contact Us

For privacy, data protection, security, or personal information requests, please contact:

Global Standard Certified Alliance (GSCA)
Operated by Techevent Limited


Email: cs@ecert.app
Website: www.ecert.app / www.gsca.cc

bottom of page