The short version
- We collect account details from the people who use Worklore, and we process certificate data that organizations upload about their recipients.
- We do not sell personal data, and we do not use it for advertising.
- This marketing website sets no cookies and runs no analytics or trackers.
- Verification pages are public by design — that's the point of a verifiable certificate. Section 5 explains exactly what is visible.
- Passwords are stored as bcrypt hashes, never in plain text.
- You can ask us to access, correct, or delete your data — see section 11.
This summary is for readability only. The numbered sections below are the terms that actually apply.
01 Who we are
Worklore is a digital certification platform that lets organizations generate, issue, and verify certificates. This Privacy Policy is issued by Aiudha Technolgies, LLP., a company incorporated in India with its registered office at Hyderabad, India. ("Worklore", "we", "us").
It applies to the Worklore website at worklore.in, the Worklore web application, our API, and the public certificate verification pages (together, the "Services").
By using the Services you agree to this policy. If you do not agree with it, please do not use the Services. This policy should be read alongside our Terms of Service.
02 Our two roles
Worklore handles personal data in two distinct capacities, and your rights differ depending on which one applies. This distinction matters, so it's worth being clear about it up front.
As a Data Fiduciary
For the people who hold Worklore accounts, for the organizations that subscribe to us, and for visitors who contact us through this website, we decide why and how the data is processed. We are the Data Fiduciary (equivalent to a "data controller") for that data.
As a Data Processor
When a customer organization uploads a list of certificate recipients — employees, students, trainees, event participants — that organization decides what to collect and why. We process that data on their instructions, as a Data Processor. The customer organization is the Data Fiduciary for it.
If you received a certificate through Worklore
The organization that issued your certificate controls your data, not us. Requests to correct or remove it should go to them first. We will support them in acting on your request, and if you cannot reach them, contact our Grievance Officer (section 15) and we will help.
03 What we collect
a. Account information
When you or your organization creates a Worklore account, we collect and store:
- Your name and email address
- Your password, stored only as a bcrypt hash — we never store or have access to the plain text
- Your role within the platform (super admin, organization admin, proposer, checker, HR, or employee) and the organization you belong to
- Account status, invitation records, and password-reset tokens with their expiry times
- Timestamps for account creation and updates
b. Organization information
- Organization name and identifier
- Billing address and tax registration details, where provided
- Invoice records — invoice numbers, amounts, dates, and payment status
- Uploaded logo and branding assets
- Plan, licence limits, and usage against those limits
c. Certificate data
Uploaded or entered by the issuing organization, or submitted through our API. Depending on how the organization configures its templates, this can include:
- Recipient name and email address
- Team or department name
- The achievement being recognised, and any supporting narrative the organization records about it
- Internal review notes added by the organization's checkers and HR approvers during the approval workflow
- Video and audio testimonial recordings — the proposer, checker, and HR may each attach one recording to a certificate, either recorded in the browser using their camera and microphone or uploaded as a file. A recording contains the voice, and for video the likeness, of the person who made it, together with their name and role
- Certificate identifiers, verification tokens, share links, and issue dates
- Any additional fields the organization chooses to add to its own certificate template
A note to customer organizations
Because you control the template, you control what personal data ends up on a certificate. Please do not place sensitive personal data — health information, financial details, government identifiers — into certificate fields. Certificate content is visible on public verification pages.
d. Website enquiries
If you submit the contact form on worklore.in, we collect your name, organization, email address, phone number, and the content of your message. We use this only to respond to your enquiry and to follow up about it.
e. Technical and log data
Our servers automatically record standard information when the Services are accessed: IP address, browser and device type, pages or endpoints requested, referring page, and the date and time of the request. We use this for security, abuse prevention, debugging, and understanding load.
f. What we do not collect
- We do not store payment card numbers on our servers.
- We do not run advertising networks, analytics scripts, or third-party trackers on worklore.in.
- We do not buy personal data from data brokers, and we do not build advertising profiles.
04 How we use it
We use personal data only for the purposes below:
- Providing the Services — authenticating you, generating certificates, running the approval workflow, and serving verification pages
- Transactional email — account invitations, password resets, and notifications that a certificate has been issued or announced
- Support — investigating and resolving issues you report
- Billing — issuing invoices and tracking plan usage against licence limits
- Security and integrity — detecting abuse, preventing fraudulent certificate issuance, and maintaining audit trails
- Legal compliance — meeting obligations under applicable law and responding to lawful requests
- Improving the Services — understanding aggregate usage patterns to decide what to build next
We do not sell personal data. We do not share it with third parties for their own marketing. We do not use certificate data to train machine learning models.
Where the law requires consent, we rely on the consent you or your organization gave when creating the account or submitting the data. You may withdraw consent at any time — see section 11 — though this may mean we can no longer provide the Services to you.
05 Public verification pages
A Worklore certificate carries a QR code and a unique identifier. Anyone holding that code or link can open a verification page without logging in. This is deliberate — a credential nobody can check is not worth much — but it means part of the certificate record is public.
A verification page shows:
- The recipient's name
- The issuing organization
- The date of issue
- The certificate status (for example active or revoked)
- Confirmation of authenticity — that the certificate was issued through Worklore and has not been altered since
- Any video or audio testimonials attached to the certificate, which play directly on the page, labelled with the name and role of the person who recorded each one
Verification pages are reachable only by someone who has the specific code or link; we do not publish a searchable directory of certificates or recipients. Even so, treat the certificate and its QR code as shareable material, because anyone you give it to can see the fields above.
If you record a testimonial
Testimonial recordings are played on the public verification page, not kept inside your organization. Anyone the recipient shares the certificate with — on social media, in a job application, anywhere — can watch or listen to your recording and see your name and role alongside it.
Record accordingly, and only record if you are comfortable with that. You can ask your organization admin to remove your recording at any time; deleting it stops it being served on the verification page.
What verification does and does not prove
Verification confirms that a certificate was genuinely issued through Worklore by the named organization and has not been tampered with. It does not mean Worklore has independently checked that the underlying achievement took place — that responsibility sits with the issuing organization.
08 Where data is stored
Worklore data is stored with our infrastructure providers named in section 7. Depending on the region configured for your organization's deployment, this may involve storage or processing outside India.
Where personal data is transferred across borders, we rely on our providers' contractual data protection commitments and transfer safeguards. If your organization requires data residency in a specific region, contact us at sales@worklore.in before onboarding so we can confirm what we can support.
09 How we protect it
We apply the following technical and organizational measures:
- Password hashing — passwords are stored as bcrypt hashes and are never recoverable in plain text, including by us
- Encryption in transit — all traffic to the website, application, and API is served over HTTPS/TLS
- Cryptographic certificate identity — each certificate is bound to a secret-keyed signature, so any alteration to its contents breaks verification
- Role-based access control — users see only what their role and organization permit, enforced server-side on every request
- Expiring tokens — invitations, password resets, and session tokens all carry expiry times and are single-use where appropriate
- Segregation by organization — every record is scoped to an organization, and queries are filtered by that scope
- Access limitation — production data access is restricted to personnel who need it to operate the Service
No system is perfectly secure. If we become aware of a personal data breach that is likely to affect you, we will notify you and the Data Protection Board of India as required under applicable law.
10 How long we keep it
- Account data — for as long as the account is active. After an account is closed we delete or anonymise it within 90 days, unless we are required to retain it.
- Certificate records — retained for as long as the issuing organization's account remains active, because certificates must stay verifiable. If the organization closes its account, certificates become unverifiable and the records are deleted on the same 90-day schedule, unless the organization instructs otherwise.
- Testimonial recordings — retained for as long as the certificate they are attached to. Deleting a recording removes it from the verification page; replacing your own recording overwrites the previous one.
- Invoices and billing records — retained for the period required by Indian tax and company law, currently eight years.
- Contact form enquiries — retained for up to 24 months from the last correspondence, then deleted.
- Server logs — retained for up to 90 days for security and debugging.
- Expired tokens — invitation and password-reset tokens are invalidated on expiry and purged periodically.
11 Your rights
Under the Digital Personal Data Protection Act, 2023, if you are a Data Principal whose personal data we hold as a Data Fiduciary, you have the right to:
- Access — obtain a summary of the personal data we process about you and how we process it
- Correction and completion — have inaccurate or incomplete data corrected or completed
- Erasure — have your personal data deleted where we no longer need it and are not required to keep it
- Withdraw consent — withdraw consent you previously gave, as easily as you gave it
- Grievance redressal — raise a complaint with our Grievance Officer and receive a response
- Nominate — nominate another individual to exercise these rights on your behalf in the event of your death or incapacity
How to exercise them
Email privacy@worklore.in from the address associated with your account, telling us what you want us to do. We will acknowledge your request and respond within 30 days. We may need to verify your identity first, and we may be unable to act on a request where the law requires us to retain the data.
If your data was uploaded by an organization that issues certificates, see section 12 — your request usually needs to go to them.
If you are not satisfied with our response, you may complain to the Data Protection Board of India.
12 If you received a certificate
You may be reading this because an organization issued you a certificate through Worklore and you want to know what we hold about you, or you want it taken down.
As explained in section 2, the issuing organization controls that data — they decided to issue the certificate, they supplied your details, and they decide whether it should be revoked or removed. Contact them directly and they can action it in their Worklore account.
If you cannot identify or reach the issuing organization, email our Grievance Officer at privacy@worklore.in with the certificate identifier. We will pass your request to the organization, help you reach them, and act on their instruction.
13 Children
The Worklore application is intended for use by organizations and their staff. We do not knowingly create accounts for individuals under 18.
Educational institutions may issue certificates to students who are children. Where an organization uploads a child's personal data, that organization is responsible for obtaining verifiable consent from a parent or legal guardian, as required by the DPDP Act. We do not undertake tracking, behavioural monitoring, or targeted advertising directed at children — we do none of those things for anyone. If you believe we hold a child's data that was submitted without proper consent, contact our Grievance Officer and we will act on it.
14 Changes to this policy
We may update this policy as the Services change or as the law requires. The "Last updated" date at the top always reflects the current version.
If a change materially affects how we handle your personal data, we will give you notice — by email to account holders, or by a prominent notice in the application — before it takes effect. Continuing to use the Services after a change takes effect means you accept the updated policy.
15 Grievance Officer
In accordance with the Information Technology Act, 2000, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the Digital Personal Data Protection Act, 2023, the contact details of our Grievance Officer are:
- Grievance Officer
- Medha K
- privacy@worklore.in
- Entity
- Aiudha Technolgies, LLP.
- Address
- Hyderabad, India.
We acknowledge grievances within 24 hours and aim to resolve them within 15 days of receipt.
16 Contact us
For anything else, these reach the right team:
- Privacy and data requests
- privacy@worklore.in
- Technical support
- support@worklore.in
- Sales and partnerships
- sales@worklore.in
- General enquiries
- connect@worklore.in