1. Scope and who we are
This policy explains how CIGGIC Certification Services (“CIGGIC”, “we”, “us”) handles personal information submitted through this website, client-access services, certification enquiries and public certificate-status checks.
For website privacy questions, rights requests or concerns, email info@ccsiso.com. The CIGGIC entity identified in the applicable quotation or certification agreement is the controller for contract-related processing. Relevant service providers may act as processors under our instructions.
2. Information we collect
Depending on how you use the website, we may collect:
- identity and contact information, including name, business email, telephone, country, city and address;
- organisation and certification-enquiry information, including requested services, current stage, locations, staff range and preferred response;
- client-access records, including registration status, sign-in identity and authorised account activity;
- certificate-verification requester details, the company or certificate searched, the stated purpose, result status, date and time;
- communications, complaints, appeals and information you choose to provide; and
- limited technical and security information needed to operate, protect and diagnose the website.
Please do not submit passwords, payment-card data, confidential audit evidence or sensitive personal information through a public form.
3. Why we use information
We use personal information to respond to enquiries; review quotation and account-access requests; administer authorised client relationships; record and protect certificate-status checks; prevent fraud and misuse; maintain security and service records; comply with legal or contractual obligations; and establish, exercise or defend legal claims.
Depending on location and context, processing may rely on steps requested before a contract, performance of a contract, legal obligations, legitimate interests in secure and accountable certification services, or consent where the law requires it. Consent can be withdrawn without affecting earlier lawful processing.
4. Certificate-verification identification
Before a certificate-status response is displayed, we ask the requester to identify themselves, their organisation and legitimate purpose. This helps CIGGIC understand who is checking a company in the certification directory, investigate suspected misuse, apply reasonable rate limits and maintain an audit trail.
Requester details are not shown in the public verification result. We may contact a requester where clarification, fraud prevention, certificate misuse or a lawful request requires it.
6. Retention and security
We keep personal information only for as long as reasonably necessary for the stated purpose, contractual and certification-record obligations, dispute handling, security, regulatory requirements and applicable limitation periods. Data is then deleted, anonymised or securely restricted, subject to lawful preservation requirements.
We apply organisational and technical safeguards appropriate to the information and risk, including access restriction, authentication, logging and controlled service providers. No internet service can guarantee absolute security; suspected incidents should be reported promptly to info@ccsiso.com.
7. Your data-protection rights
Subject to applicable law and valid exemptions, you may ask to access, correct, delete or restrict personal information; object to certain processing; receive portable data; withdraw consent; and complain to a competent supervisory authority. We may need to verify identity before acting on a request.
- Nigeria: rights and obligations are handled under the Nigeria Data Protection Act 2023, applicable regulations and guidance, and relevant requirements originating under the Nigeria Data Protection Regulation.
- EEA and UK: GDPR/UK GDPR rights and lawful-transfer requirements apply where their territorial scope is met.
- United States: residents may have rights under applicable federal and state privacy laws, including rights to know, access, correct, delete or opt out of covered uses. CIGGIC does not sell personal information or use it for targeted advertising through this website.
Submit a request to info@ccsiso.com with “Privacy request” in the subject. We will respond within the period required by the law that applies.
9. Complaints, regulators and changes
Contact us first at info@ccsiso.com so we can investigate. You may also complain to the Nigeria Data Protection Commission or another competent authority where applicable.
We may update this policy when services, technology or legal requirements change. Material changes will be identified by a revised effective date and, where required, an additional notice.

