Legal

Privacy Policy

How personal information submitted through this website is used and protected.

Last updated: 7 August 2026.

1. Data controller and contact

BEQUAL CERTIFICATE™ manages the processing of personal data collected through this website and the BEQUAL certification process.

2. Scope

This policy applies to website visitors, people submitting eligibility or contact requests, representatives of applicant and certified organisations, auditors and certification professionals, and people requesting information about or correction of a verification record.

3. Personal data collected

Depending on the interaction, BEQUAL may process:

  • Name, job title, company, country, business email address and telephone number.
  • Diversity areas selected in the eligibility form and details of supporting certifications.
  • Communications, requests and information contained in certification documentation.
  • Certificate number, organisation, level, scope, issue date, expiry date and status.
  • Technical and security information, including IP address, session identifiers and server logs.

4. Special-category data

Applicants should not send identifiable employee information concerning disability, health, racial or ethnic origin, religion, trade-union membership, sexual orientation or other special categories of personal data. Supporting evidence should consist of corporate certificates, audit reports, aggregated information or appropriately anonymised documents.

If personal data relating to third parties is included in documentation, the submitting organisation is responsible for ensuring that it has a valid legal basis and that only necessary information is provided.

5. Purposes and legal bases

  • Enquiries and eligibility: to respond and assess initial eligibility, based on steps taken at the interested person's request before a potential contractual relationship.
  • Certification management: to manage an application, documentary verification, decision, renewal, suspension or withdrawal, based on performance of the certification relationship.
  • Security and integrity: to prevent fraud and protect the scheme, based on BEQUAL's legitimate interest in operating a secure and reliable service.
  • Public verification: to maintain the verification record of issued certificates, based on performance of the certification relationship and the legitimate interest of organisations and third parties in verifying authenticity and status.
  • Legal obligations: to meet accounting, tax, legal or regulatory requirements where applicable.
  • Marketing: only where separate consent has been requested and obtained.

6. Required information

Fields marked as mandatory are necessary to respond to an eligibility request. If the required information is not provided, BEQUAL may be unable to assess or respond to the request.

7. Recipients and service providers

Personal data may be accessed where necessary by authorised BEQUAL personnel, BEQUAL Accredited Auditors, hosting and technical providers including GoDaddy, email providers including Zoho, automatic website-translation providers including GTranslate and Google, professional advisers and public authorities where disclosure is required by law. When a visitor uses or loads the translation functionality, technical information and the website content required for translation may be transmitted to those providers. Personal data is not sold.

8. International transfers

Some technology providers may process information from locations outside the European Economic Area. Where applicable, BEQUAL will rely on legally recognised safeguards, such as an adequacy decision, standard contractual clauses or other mechanisms permitted by data-protection law.

9. Retention

  • Initial enquiries not resulting in certification: up to 12 months from the last relevant communication.
  • Certification applications and documentary records: for the validity period of the certificate and six additional years.
  • Public verification records: while necessary to verify the certificate and maintain an appropriate historical record of its status.
  • Technical and security logs: only for the period necessary to ensure security, investigate incidents and prevent misuse.

Information may be retained for longer where required by law or necessary for the establishment, exercise or defence of legal claims.

10. Rights

Subject to applicable law, individuals may request access, rectification, erasure, restriction, portability or objection, and withdraw consent where consent is the applicable legal basis. Requests should be sent to info@bequal.eu. Additional information may be requested where necessary to verify identity.

Individuals may also lodge a complaint with the Spanish Data Protection Agency.

11. Automated decisions

BEQUAL does not make certification decisions based solely on automated processing or profiling.

12. Security

BEQUAL applies organisational and technical measures designed to protect personal data against unauthorised access, loss, alteration or disclosure.

13. Policy updates

This policy may be updated to reflect legal, technical or operational changes. The current version and update date will always be published on this page.