Skip to content
Traducción pendiente — el texto en inglés a continuación es la versión jurídicamente vinculante.

Privacy Policy

Last updated: 2026-05-05.

This policy explains what personal data CertSelect collects, why we collect it, the lawful basis on which we process it, who we share it with, how long we keep it, and the rights you have under the General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA / CPRA), Canada's PIPEDA, Brazil's LGPD, and the Australian Privacy Act.

1. Who we are (data controller)

CertSelect is published by Kulik Media UG (haftungsbeschränkt), a German Unternehmergesellschaft. The full legal-imprint details — registered address, managing director, commercial register entry, and VAT identification number — are available on our Imprint page. For all data-protection enquiries, write to [email protected].

2. What data we collect

We collect three categories of data:

We do not knowingly collect data from children under 16. We do not collect special-category data (health, political opinion, religion, biometric, sexual orientation) and ask that you not include any in correspondence.

3. Why we collect it (purposes)

4. Lawful basis (GDPR Art. 6)

For UK readers, equivalent bases under the UK GDPR apply. For Brazilian readers, equivalent bases under LGPD Art. 7 apply (legitimate interest, consent, contract execution).

5. Cookies

The cookies that may be set when you visit CertSelect are:

Cookie / storage keySet byPurposeRetentionConsent required
__cf_bmCloudflareBot management / abuse prevention30 minutes (rolling)No (strictly necessary)
cf_clearanceCloudflareCAPTCHA challenge clearance30 daysNo (strictly necessary)
_ga, _ga_<id>Google Analytics 4Analytics — pseudonymous user / session identification13 monthsYes
analytics_storageGA4 Consent ModeRecords analytics-cookie consent state13 monthsRecords consent itself
ad_storage (placeholder)GA4 Consent ModeReserved for any future advertising/measurement integration. We do not currently run advertising cookies.n/aYes (when activated)

You can refuse non-essential cookies through the consent banner. You can also clear cookies in your browser settings at any time.

6. Affiliate links

CertSelect carries affiliate links to course platforms and training partners. Affiliate networks (Impact, Awin, and direct-program partners) typically set their own cookies on the destination site after you click an affiliate link. CertSelect does not set those cookies on this site, but the destination site does — please consult that site's privacy notice. The full list of affiliate programs we use, and our conflict-of-interest policy, is on the Methodology page.

7. Third parties we share data with

We share data only with the providers that operate the site and with partners that you choose to interact with:

We do not sell personal data. We do not share personal data with advertising networks for cross-site tracking or for the construction of targeted-advertising profiles.

8. International transfers

Some of our processors (Google, Cloudflare) operate infrastructure in the United States. Where personal data is transferred outside the European Economic Area or the United Kingdom, transfers are made under the EU–US Data Privacy Framework adequacy decision (Google), Standard Contractual Clauses (Cloudflare), or, for transfers to other jurisdictions, equivalent safeguards. You may request a copy of the safeguards used by writing to [email protected].

9. Retention

10. Your rights

Under the GDPR / UK GDPR you have the right to:

To exercise any of these rights, write to [email protected]. We respond within 30 days as required by GDPR Art. 12(3).

11. California residents — CCPA / CPRA addendum

If you are a California resident, the California Consumer Privacy Act and the California Privacy Rights Act give you the rights to know what categories of personal information we collect, to request deletion, to correct inaccurate information, and to opt out of the "sale" or "sharing" of personal information.

We do not sell personal information. We do not "share" personal information for cross-context behavioural advertising as those terms are defined in the CPRA. Because we do not sell or share, we do not currently provide a "Do Not Sell or Share My Personal Information" link — but we document that fact here so that California readers can rely on it. If we ever begin a practice that triggers that requirement, we will publish the link before doing so.

To exercise any CCPA / CPRA right, write to [email protected]. We will not discriminate against you for exercising a CCPA right.

12. Other jurisdictions

13. Security

The site is served over HTTPS with TLS 1.2 or later. Our hosting provider (Cloudflare Pages) provides DDoS protection and edge filtering. We do not store payment data and do not operate a user-account system, so the attack surface for personal data is limited to the categories described above.

14. Changes to this policy

If we change this policy, we will update the "Last updated" date at the top of the page and, for material changes (new categories of data, new processors, new lawful bases), publish a brief change-log note in the About page. Continued use of the site after a change indicates acceptance of the revised policy.

15. Contact

Privacy questions, GDPR / CCPA / LGPD requests, or correction requests: [email protected].