Controlled verification pilot CompanyConnect-issued · not government accreditation

Version 2026-08-29 · Operational draft

Pilot Privacy Notice

This notice explains the live pilot data flow in plain language. It is pending formal POPIA and multi-jurisdiction legal review.

What we receive

Sign in with ChatGPT supplies a stable user identifier, email, and available display name. CompanyConnect stores pilot consent, account status, application declarations, public evidence references, reviewer decisions, credentials, support cases, notifications, incidents, product feedback, rate-limit counters, and audit events. Public badge-misuse reports store the public page URL, factual description, optional credential ID, and optional contact email.

Why we use it

To control invitation access, review bounded verification claims, issue and maintain CompanyConnect credentials, answer support and appeals, investigate suspected badge misuse, improve the product, protect integrity, operate the service, and keep required records.

What becomes public

Only an approved credential’s public holder name, applicant type, credential type, assurance label, precise scope, decision summary, methodology version, dates, current reason, public ID, and status history. Email, legal name, raw application narrative, evidence links, feedback, misuse reports, reporter contact details, reviewer identity, and internal notes are not published.

Authentication and recovery

ChatGPT handles authentication, sign-out, and recovery. CompanyConnect does not receive your password. Public site access and pilot sign-in are separate.

Storage and location

The pilot uses managed Sites infrastructure and D1 storage. Formal data-residency selection is not available in this pilot. Do not use the service for information requiring a guaranteed storage region.

Retention, access, correction, export, and closure

The final retention schedule is pending legal approval. You can request correction, export, restriction, objection, or closure through a private support or privacy case. CompanyConnect may retain limited credential, appeal, fraud, misuse-report, and audit history where required for integrity or law.

External providers

No automated identity/KYB provider, payment provider, or transactional email provider is connected to this pilot. Public evidence links and reported badge-use pages are reviewed manually and are not server-fetched.