Skip to content

Verification Records Notice

Nap OS · Napblog Limited

Last updated: 1 September 2026

This notice explains how we hold and confirm records of the project work our members complete. It sits alongside our Privacy Policy and covers the part of what we do that is most specific to Nap OS.


What a verification record is

When you complete supervised project work through Nap OS, we create a record of it. It contains:

  • your name and the identifier of your Nap OS account
  • the projects you selected and the dates you worked on them
  • the hours you logged
  • a description of the outputs you produced
  • the skills demonstrated
  • the name and role of the project manager who reviewed the work
  • the assessment outcome against the published rubric
  • a unique credential identifier and, where you have chosen to publish it, a public verification URL

The record is a factual account of what you did. It is not a reference, a character assessment, an accreditation, or a statement that you are suitable for any particular role.

Why we hold it

A certificate that only its issuer stands behind is worth very little. The value of a Nap OS record is that a third party can check it — an employer, or a background screening company acting for one — in the same way any organisation confirms someone’s history with it.

Holding an accurate record and confirming it on request is therefore not incidental to Nap OS. It is the thing Nap OS does.

Our lawful basis

Article 6(1)(b) — performance of a contract. Creating, maintaining and, on request, confirming your verification record is the service we agreed to provide when you joined the programme.

Your standing authorisation. In addition, when you complete a project you give a separate, explicit authorisation for us to confirm your record to third parties who ask. That authorisation is recorded with a timestamp, is visible to you in your account, and can be withdrawn at any time.

We do not rely on legitimate interests for this processing. We think it should rest on something you have actively agreed to, rather than on a balancing test we perform ourselves.

What we confirm, and what we do not

We will confirm, when asked by an employer or a screening provider:

  • that you completed a named project or programme with Nap OS
  • the dates and the hours logged
  • the outputs produced and the skills demonstrated
  • that the work was reviewed by a named project manager against a published rubric
  • that the participation was unpaid

We confirm the unpaid status because misrepresenting unpaid programme participation as paid employment would be a misrepresentation, and we will not assist with one.

We will not disclose:

  • the content of your submitted work, unless you have published it
  • the written feedback given to you
  • any opinion about your suitability, competence or character
  • anything about you that is not in the record
  • any special category data
  • anything at all where we cannot verify who is asking

How a request is handled

  1. The request arrives at palani@napblog.com.
  2. We confirm the identity of the requester and that they are acting for an employer or a screening provider.
  3. We confirm that a valid authorisation from you is on file.
  4. We confirm the facts of the record. Nothing else.
  5. We log the request, the requester, the date, and what was confirmed.
  6. We notify you that your record was confirmed, to whom, and when.

Step 6 is not required of us. We do it because you should know when someone has checked your record — a verification service you cannot see is one you cannot trust.

No fee is charged to you, to the employer, or to the screening provider for a verification response.

How long we keep it

RecordRetained for
Verification record6 years from the date the project was completed
Verification request log6 years from the date of the request
Underlying submitted work24 months, unless you ask us to keep it longer

Six years reflects the period over which an employer or screening provider realistically asks about earlier experience, and aligns with the general limitation period under the Statute of Limitations 1957.

At the end of the retention period the record is deleted and can no longer be confirmed. We will tell you before that happens.

Withdrawing your authorisation, and erasure

You can withdraw your authorisation at any time by emailing palani@napblog.com. From that point we will not confirm your record to anyone, and we will tell any future requester only that we are unable to respond — never why.

You may also ask us to erase the record entirely. We will do so, subject to any legal obligation to retain it.

We will explain the consequence before we act, once, and then do what you ask. An erased record cannot be restored, and any public verification URL you have shared — on a CV, or in a LinkedIn certification field — will stop working. That may matter to you more than it seems in the moment, so we would rather you decided with the facts in front of you.

Accuracy

If you believe your record is wrong, tell us and we will investigate and correct it. Where we have already confirmed an incorrect fact to a third party, we will contact them with the correction.

Ownership of your work

The work you produce in the programme is yours. We do not acquire ownership of it, we do not commercialise it, and we do not use it to build Napblog Limited’s products. Where we would like to use your work — as a case study, an example brief, or in marketing — we ask you first, separately, and a refusal has no effect on your record or your standing in the programme.


Napblog Limited · CRO 812006 · 77 Camden Street Lower, Saint Kevin’s, Dublin, D02 XE80, Ireland · palani@napblog.com

Data Protection Commission: dataprotection.ie

Chat with us
N

Privacy & Data Preferences

Nap OS · napblog.com · Controller: Napblog Limited

Legitimate Interest (Art.6(1)(f)): You may object at any time using the toggles below.
Fraud Prevention & Security
Object

Monitor fraudulent activity, bot traffic and abuse. Log security events for incident response.

IP AddressLogin LogsRequest Frequency
12 months
Transactional Communications
Object

Account confirmations, password resets, billing receipts, and critical product updates.

Email AddressNameAccount Status
Account + 7 years
Market Research & Benchmarking
Object

Aggregated, anonymised reports on skills trends and hiring benchmarks. Individuals are never identifiable.

Aggregated SkillsIndustry CategoryTool Popularity
Indefinite (anonymised)
Recruiter & Employer Matching
Object

Make your verified portfolio discoverable to recruiters via the Nap OS CRM. Control visibility in your profile settings.

Public PortfolioVerified SkillsAvailability Status
Until set to private

All data Nap OS collects and with whom it is shared. International transfers use Standard Contractual Clauses per GDPR Chapter V.

Data CategoryPurposeRecipientsSafeguard
Identity Data
Name, email, photo
Account, auth, commsAuth0, SendGrid, AWSSCCs
Career Profile
Skills, experience, tools
Portfolio, AI, CRMOpenAI, Algolia, ClearbitSCCs+DPAs
Integration Data
GitHub repos, GA, Figma
Portfolio verificationGitHub, Google, FigmaOAuth/SCCs
Usage Data
Clicks, sessions, features
Analytics, A/B, AI trainingMixpanel, Hotjar, PostHogSCCs
Device Data
IP, browser, fingerprint
Security, cross-deviceCloudflare, Sentry, SegmentSCCs
Marketing Data
Ad clicks, UTMs
Advertising, CRMGoogle Ads, Meta, LinkedInSCCs+DPAs
Financial Data
Plan, subscription
Subscription managementStripe (PCI DSS L1)SCCs
AI Interactions
NapAI prompts, responses
AI improvementOpenAI, Anthropic (anon)SCCs+DPA

Controller: Napblog Limited, UK · DPO: privacy@napblog.com · Authority: UK ICO

Under UK & EU GDPR you have the following rights. Contact privacy@napblog.com. We respond within 30 days.

Right to Access

Request a full copy of all personal data including your career profile and processing history.

Right to Rectification

Correct inaccurate data. Update your profile and contact details at any time.

Right to Erasure

Request deletion. Account deletion removes your portfolio within 30 days.

Right to Restriction

Request we restrict processing while a dispute is being resolved.

Right to Portability

Export portfolio, skills, and project history in JSON or CSV from your account settings.

Right to Object

Object to legitimate interest processing via the toggles in the Legitimate Interest tab.

Automated Decision Rights

Request human review of any NapAI recommendation that significantly affects you.

Withdraw Consent

Withdraw consent at any time via the Privacy Settings widget. Does not affect prior lawful processing.

Complaints: UK ICO or local EU authority. Contact us first at privacy@napblog.com.

Consent ID: