GDF — Global Diplomacy Forum

Data Collection Notice

MUN CertView, powered by the Global Diplomacy Forum (GDF). Last updated: 28 July 2026.

Purpose of this notice

This notice itemizes every category of personal data MUN CertView collects, why we collect it, the legal basis for processing (GDPR-style: consent, contract, or legitimate interest), how long we keep it, and who it is shared with. It supplements our Privacy Policy. The service is free — GDF's gift to the MUN community — and we never sell or rent data or use it for advertising.

Data we collect

Data categoryWhy we collect itLegal basisRetentionShared with
NameIdentify the account holder and name credential recipients.ContractWhile the account or credential is active; deleted on request.Supabase (storage). Recipient name appears on the credential's verification page.
Email addressAuthenticate accounts and send credential notifications.ContractWhile the account is active; deleted on request.Supabase; self-hosted SMTP (mailcow) for delivery. Never shown publicly.
Password (hash only)Secure sign-in; never stored in plain text.ContractWhile the account is active.Supabase Auth only.
Credential data (award, conference, committee, country/portfolio, issue date)Issue, display and verify badges and certificates.ContractAs long as the credential is meant to remain verifiable; stops on revocation/deletion.Supabase; visible on the verification page to anyone with the link.
Salted SHA-256 hash of recipient emailLet a holder prove a credential is theirs without exposing the email.Legitimate interest (credential integrity)Lifetime of the credential.Included in the public Open Badges 3.0 credential JSON (hash only, not the email).
Delegate roster data (uploaded by organizers)Bulk-issue credentials to delegates of a conference.Contract / legitimate interest (organizer is controller)Until the conference is closed or the organizer deletes it; on request.Supabase; visible to the issuing conference's organizers only (isolated by RLS).
MyMUN conference linkProof the conference is genuine before it can issue credentials.Legitimate interest (fraud prevention)Retained as proof for as long as the conference exists.Supabase; reviewed by GDF only.
Public visibility choices (profile / per-credential)Let members choose which credentials appear on their public profile.ConsentUntil changed; private by default.Public profile shows only credentials the member marks public.
Event & audit logs (issued, claimed, revoked, viewed)Maintain credential integrity and detect fraud or abuse.Legitimate interest (security)Only as long as needed for integrity and security.Supabase; internal to GDF.
Authentication / session cookieKeep you signed in. No advertising or tracking cookies are used.Legitimate interest (strictly necessary)Duration of the session.Stored in your browser; not shared.
Text sent for optional AI clean-up (may include delegate names)Tidy or draft text only when an organizer clicks the AI button.Consent (organizer-initiated, feature-flagged)Processed on request; not retained by us beyond the result.Google Gemini API (processor), only when triggered.

Processors and sub-processors

Supabase — Postgres database, authentication and file Storage (primary data store). Self-hosted SMTP (mailcow) at mail.radixai.tech — transactional email delivery. Google Gemini API — optional, feature-flagged AI clean-up/drafting, invoked only when an organizer clicks the AI button. Video meetings run in the separate GDF meeting app at meet.apextech.llc, which has its own privacy and terms.

International transfers

Some processors may store or process data on servers outside your country, including outside the European Economic Area. Where that happens we rely on appropriate safeguards such as standard contractual clauses. Contact us for details.

Children and delegates under 18

Many delegates are under 18. Data about minors is normally provided by a conference organizer, who is responsible for obtaining any parental or guardian consent required by law and for limiting the data to what is necessary. We do not knowingly collect data directly from children without appropriate authorization.

Your rights and contact

You may request access to, rectification of, erasure of, or a portable copy of your data, and may object to or restrict certain processing or withdraw consent. Revoked or deleted credentials stop verifying immediately. To exercise any right, or to ask a question about this notice, email rajiv@gdf.social.

Data Collection Notice — MUN CertView