Privacy
What we collect, why we have it, and how long we keep it. Certification work means we hold information about the people who work for our clients, and that deserves a plain explanation rather than a page of boilerplate.
This website collects almost nothing
There is no analytics, no advertising network, no tracking pixel and no third-party script of any kind on this site. No cookie is set by us, so there is no cookie banner to dismiss. Fonts are served from our own server rather than a font network, which means your browser makes no request to anyone else while reading this.
That is not only a privacy position. This origin also serves the certificate verification page, and a third-party script here could interfere with what a verification shows. Keeping the origin clean is a security control as much as a privacy one.
Our web server keeps standard access logs — IP address, time, the page requested, the browser identifier — for a short period, for security and diagnostics. They are not used to build a profile of you and they are not shared.
What we hold about people at client organisations
An audit necessarily involves people. In the course of certification work we hold:
- Contact details of the people who deal with us — name, job title, work email, work telephone.
- Records of the audit itself, which can include the names and roles of people interviewed, and evidence they showed us.
- Competence evidence about auditors — qualifications, training, observations of their work — because we are required to demonstrate that whoever audited you was competent to.
- Correspondence, including quotations, appeals and complaints.
We collect the minimum an audit requires. An auditor does not need, and should not take, a copy of a personnel file to establish that your competence process works.
Why we are allowed to hold it
Mostly because it is necessary to perform the certification contract you have entered into with us, and because we have a legitimate interest in operating a certification body properly. Where a rule of ISO/IEC 17021-1 or an accreditation body requires us to keep something, that obligation is why we keep it.
What we publish, deliberately
The public register publishes the fact of an organisation's certification — its name, the standards, the scope, the location, the status and the dates. That is the point of a certificate and it is required of us. Individual names are not published. Audit findings are not published.
Who else sees it
- Our accreditation body. Assessors examine our audit files, including yours, to verify that we audit properly. They are bound by confidentiality in turn. This is not optional for either of us — it is how accreditation works.
- Where the law requires it. If we are legally obliged to disclose, we will tell you what was disclosed and to whom, unless telling you is itself prohibited.
Otherwise, nothing goes outside UMA without your written consent. We do not sell data, we do not share it for marketing, and we have no advertising relationships to share it with.
How long we keep it
Certification records are kept for the life of the certification and for a further period afterwards, so that a certificate we issued can still be accounted for and so an accreditation assessor can examine the cycle it belonged to. Enquiries that do not become engagements are kept only as long as they are useful, and then deleted.
Your rights
You can ask what we hold about you, ask for it to be corrected if it is wrong, and ask us to delete it. Write to contact@umacerts.ae.
One honest limit: we cannot delete an audit record on request. A certification body that could erase parts of an audit trail when asked would not be a certification body. Where deletion is not possible, we will say so and explain which obligation prevents it. That applies to the record itself — not to your contact details, which we can remove.
Our records are append-only by design: a correction is recorded as a correction, superseding what was there before, rather than overwriting it. So an error can always be corrected, and the correction is itself visible.
Where the data lives
Our systems are operated by UMA on infrastructure we control, not shared with any other business. UMA is established in Abu Dhabi, United Arab Emirates and that is where our records are administered.
Contact and complaints
Questions about this page, or about what we hold, go to contact@umacerts.ae. If you are unhappy with how we have handled personal data you can raise it as a formal complaint — that route is open to anyone, not only clients, and making one is never held against you.
Note: this mailbox is being set up and cannot yet receive mail. If you hold any UMA correspondence, use the address on it in the meantime.