Skip to main content
Legal

Privacy Policy

Effective date: August 3, 2026

Who This Policy Covers

This Privacy Policy explains how Standard ESG ("we," "us") collects, uses, discloses, and protects personal data when you visit standardesg.org, register an organization for certification, or interact with our assessment platform in any role — Company Admin, Company User, Auditor, Partner Auditor, or Standard ESG staff.

It applies to visitors browsing our public website and resources; registered tenants — the companies that register for ESG assessment and certification, and the individuals who act on their behalf; auditors and partner auditors who conduct Level 3 on-site assessments; and third parties who look up a certificate on our public verification page or submit a complaint about a certified company.

It does not directly govern the personal data companies collect about their own employees when compiling evidence for their assessment (for example, payroll samples or training records) — that remains the submitting company's responsibility as a data controller in its own right; we process it as described in Section 3 solely to deliver the assessment and certification service.

Information We Collect

We collect account and registration data — name, work email, role, organization, and business registration details — provided at registration. We collect assessment data — questionnaire answers across Environmental, Social and Governance indicators — submitted by your Company Admin or Company User during Level 1. We collect evidence documents — business registration, environmental permits, payroll samples (anonymized where applicable), health and safety records, policies, audit reports, and other Level 2 document categories — uploaded by the company. We collect on-site assessment data — auditor observations, interview notes (kept confidential per participant), photographs of facilities, and findings — collected by our auditors and partner auditors during Level 3. We generate certificate data — certification level, composite and 1–10 score, issue/expiry dates, certificate ID, and template version and checksum — through our own systems. We automatically collect technical data — IP address, browser type, device identifiers, and pages visited — via cookies and server logs. And we collect communications you provide directly, such as support requests, appeal submissions, and third-party complaints.

We collect only what the assessment methodology requires. Evidence must be dated, attributable to the specific legal entity under assessment, and — unless inherently long-lived, like articles of incorporation — no older than 24 months, per the Certification Protocol's evidence rules.

Why We Collect It

We process personal data to operate your account and administer your organization's tenant; run the certification assessment by scoring questionnaire answers, verifying submitted documents, and, at Level 3, conducting and reporting on-site findings; generate, issue, and maintain certificates, including the public verification page; enforce the gates and governance rules of the Certification Protocol, for example flagging conflicts of interest for reviewers and auditors; process appeals (within the 30-day window) and third-party complaints about certified companies; communicate with you about your assessment, certificate status, or account; maintain the security and integrity of the platform; and meet legal and contractual obligations, including responding to lawful requests from authorities.

We do not sell personal data, and we do not use assessment data or evidence documents for advertising.

Confidentiality, Tenant Isolation, and Role-Based Access

All assessment data, uploaded documents, and on-site findings are confidential to the submitting company and to Standard ESG. This is enforced at the system level, not just by policy: every record carries a tenant identifier, and every read or write is scoped to the caller's own tenant in our data-access layer. We reinforce this with role separation — Company Admin, Company User, Standard ESG Admin, Auditor, and Partner Auditor each see only what their role requires to do their job. Worker interviews conducted during an on-site assessment are held in confidence from company management, consistent with the Certification Protocol's on-site framework.

What Becomes Public

We deliberately publish very little. Scanning the QR code on a certificate, or visiting the public verification page directly, shows only the validity status (active, expired, or revoked), the 1–10 score, the certification level, the company name, and the issue and expiry dates.

No indicator answers, no evidence documents, no on-site findings, and no interview content are ever made public. If a certificate is revoked, that status change is reflected immediately on the verification page.

How Long We Keep Information

Certificates and accompanying reports, including the Level 3 Findings & Recommendations Report, are retained in the company's dashboard for the lifetime of the tenant relationship. Assessment answers and evidence documents are retained for as long as needed to support the current and immediately prior certification cycle, and thereafter per our data-retention schedule. Account data is retained while the account is active and for a limited period after closure to meet legal, accounting, and dispute-resolution obligations. Technical and log data is retained for a limited period for security and diagnostic purposes, for a maximum of 180 days.

You may request earlier deletion where applicable law provides for it; see Section 10.

Who We Share Information With

We share personal data only as needed to deliver the service: with partner auditors, under a signed agreement binding them to the Certification Protocol, when they conduct a Level 3 assessment on our behalf; with service providers who host our infrastructure, process payments, or support operations, under contractual confidentiality obligations; with legal and regulatory authorities, where required by law or to protect our rights, users, or the public; and with successors, in the event of a merger, acquisition, or asset sale, subject to equivalent privacy protections.

We do not share assessment data or evidence with other companies, including a company's own suppliers or customers, beyond what the company itself chooses to disclose (for example, by sharing its certificate).

International Transfers

Standard ESG is based in the United States, and we maintain infrastructure in both the European Union and the United States, so personal data we collect may be stored and processed in either region depending on the system involved. Where we or our service providers transfer personal data across borders — including between the EU and the US — we use legally recognized safeguards appropriate to the jurisdictions involved, such as the EU Standard Contractual Clauses for transfers out of the EU/UK.

Security

We apply technical and organizational measures appropriate to the sensitivity of the data we hold, including tenant isolation and role-based access control (see Section 4), encryption in transit, and access logging. No system is completely secure, and we encourage you to use a strong, unique password and to report any suspected unauthorized access promptly.

Your Rights

Depending on your jurisdiction, you may have the right to access, correct, delete, or export personal data we hold about you, to object to or restrict certain processing, and to lodge a complaint with a supervisory authority. To exercise these rights, contact us using the details in Section 14. Note that some assessment and certificate data may need to be retained even after a deletion request — for example, where retention is necessary to preserve the integrity of a certificate's audit trail or to comply with a legal obligation — and we will explain the specific basis if we cannot fulfill a request in full.

Cookies

We use cookies and similar technologies on standardesg.org. Details of what we use them for, how long they last, and how to manage your preferences are set out in our separate Cookie Policy.

Children's Data

Our services are directed at businesses and professionals. We do not knowingly collect personal data from children, and our platform is not intended for use by anyone below the age of majority in their jurisdiction.

Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be reflected by an updated "Last updated" date above, and where required by law we will provide additional notice.

Contact Us

Standard ESG, 32 N Gould St, Sheridan, WY 82801, United States. For privacy questions or to exercise your rights under Section 10, contact [email protected]. For general support, contact [email protected].