Skip to content
PMCert

Privacy, terms of use and refunds.

This page holds three things: what PMCert Global Institute does with your data, the rules for using the platform, and the refund policy. It is written to be read by someone about to sit an exam, not only by lawyers.

Updated on August 22, 2026

Part 1: privacy

What we keep, why we may keep it, who we share it with, and for how long.

Who is responsible for your data

PMCert Global Institute is responsible for processing the data described on this page, and operates the platform at pmcert.org. For anything concerning personal data, the channel is support@pmcert.org.

What we keep

Nothing here is hypothetical: each item matches a field that exists in the system.

  • Account: your name, your email and, if you set a password, only its hash, never the password in readable form. If you sign in through an external provider, the identifier it returns to us, so that changing your email there does not lock you out here.
  • Profile: job title, location and LinkedIn link, all optional and filled in by you.
  • Sessions: while you are signed in we keep the session expiry, the browser and the originating IP address. The session code itself is never stored, so a leaked database backup does not become access to your account.
  • Exams: the questions drawn for you, your answers, the time spent on each, the name you chose for the certificate, the IP, the browser and a weak device signature.
  • Integrity: exam session events, such as losing and regaining window focus and attempts to copy or paste.
  • Payment: the amount paid, the currency and the purchase identifier. Card details never pass through PMCert at any point: payment happens inside the environment of the payment processor.
  • Communication: for each message sent, we keep the recipient, the subject and the date. The body of the email is not stored.

Why we may process each item

We process your data on the legal bases provided for in the GDPR and in the LGPD. Each purpose has its own, and none of them is "because we say so".

  • Running your account, issuing the voucher, delivering the exam and awarding the credential: performance of a contract. It is what you bought.
  • Exam integrity, through IP, device signature and session events: legitimate interest. The interest is the validity of everyone’s credential, including yours: a certification you can cheat your way into is worth nothing to whoever earned it.
  • The public credential register: performance of a contract and legitimate interest. A credential exists to be checked by third parties; a register nobody can consult is not a register.
  • Account security, sign-in rate limiting and the administrative log: legitimate interest, and legal obligation where applicable.
  • Payment records: performance of a contract and compliance with a legal obligation.
  • Content and news emails: consent, given by you when subscribing and withdrawable at any time through the unsubscribe link in every message.

What the integrity data does, and does not do

These signals never fail anyone automatically. They produce flags for human review, and they let us measure whether exam fraud is actually happening before deciding on heavier measures. The device signature is intentionally weak: it can notice thirty exams coming from one machine, and it is not designed to follow you anywhere else. It uses no canvas, no audio and no WebGL, which are the techniques capable of producing a strong, persistent identifier.

Who we share with

PMCert does not sell personal data, and does not hand it to anyone for advertising. The third parties below process data on our behalf, limited to what is necessary:

  • A payment processor, which receives your email, the amount, the currency and which exam was bought.
  • An external sign-in provider, only if you choose to sign in through it. In that flow we receive your identifier, your email and your name.
  • An email delivery provider, through which the messages we send you pass, with the address and the message content.
  • A hosting provider, where the application and the database run.

International transfers

PMCert serves candidates worldwide, and some of the services above operate outside the country of whoever uses the platform. That means your data may be processed in another country, always limited to the purposes on this page and subject to contractual protection commitments with each of those providers. If you want to know where a specific piece of data is processed, write to support@pmcert.org.

For how long we keep it

Different natures, different periods:

  • Raw exam session events: deleted after 180 days. Only the summary flags attached to the attempt remain.
  • Sign-in sessions: deleted when they expire, which happens within 14 days of disuse.
  • Account data, attempts and communication records: while your account exists.
  • Payment records: for the period required for keeping financial records.
  • Issued credentials: permanent, for the reasons in the section on deleting your account.

What is public, and what you control

A certification only means something if a third party can check it. So part of your data is public by product decision, and it matters that you know exactly which part:

  • An issued credential is public: your name, which certification you hold, the code and the date of issue. Scores and per-domain performance are never published; they belong to you and appear only in your account and on the certificate you choose to share.
  • Your public profile starts switched on, and it shows your name, your credentials and whatever you filled in for job title, location and LinkedIn. Public profiles are listed in the site directory and in the sitemap.
  • You can switch the public profile off at any time, in your account. Switched off, it leaves the directory, the search and the sitemap.
  • The code verifier keeps working even with the profile switched off, and it shows the holder name. Whoever holds the code must be able to check it: that is the register, and the profile is a different thing.

Cookies

The platform sets five cookies, all strictly necessary. There is no analytics, advertising or third-party tracking cookie, which is why you are not being asked to accept anything:

  • Session, which keeps you signed in, lasting 14 days.
  • Language, which remembers the language you chose so the site does not ask again on every visit, lasting one year.
  • Second factor, which lasts five minutes and exists only between your password and the code from your authenticator app.
  • External sign-in state, which lasts ten minutes and protects that flow against forgery.
  • Support return, created only when an administrator opens a view of your account to help with a ticket, and used to send them back to their own account.

Your rights

The GDPR and the LGPD give you the right to request: confirmation that we process your data, access to it, correction of anything wrong, portability, information about who we share it with, erasure, objection to processing based on legitimate interest, and withdrawal of consent for content emails. To exercise any of them, write to support@pmcert.org. We answer within 3 business days, at no charge.

Deleting your account, and the limit of that

Deletion happens on request: write to support@pmcert.org from the address on the account. We delete your account, your attempts, your exam telemetry, your vouchers and your communication records. What cannot simply disappear is a credential already issued: an employer who verified it must still be able to verify it, and a register that can be quietly erased is not a register. If a credential has to be withdrawn, that is a revocation, and it stays visible marked as revoked rather than vanishing. Authorship records for internal content remain, with the identification removed.

How we protect it

Passwords are stored only as a hash, using a slow derivation algorithm, and never in readable form. Your session code is not written to the database, only a fingerprint of it. Repeated sign-in attempts are rate limited. You can turn on a second authentication factor in your account, and we recommend that you do. No system is infallible: if an incident affects your data, we will notify you and the competent authorities as the applicable law requires.

Minors

The platform is intended for professionals and should not be used by minors without the authorisation of whoever is responsible for them. We do not knowingly collect data from children. If we learn that an account was created against this, it will be removed.

Part 2: terms of use

The rules for anyone who creates an account, buys a voucher and sits an exam.

What PMCert offers

PMCert Global Institute assesses product management knowledge through its own exams and issues credentials to those who pass. A credential attests to the result of an exam, not to employment, prior experience or membership of any organisation. No course is required to sit an exam, and no course guarantees a pass.

Your account

The account is personal and non-transferable, and some obligations come with it:

  • Use your real name. It is the name that appears on the certificate and in the public register, and correcting it after issue depends on support.
  • One person, one account. Multiple accounts for the same person may be removed.
  • Your password is your responsibility. If you suspect improper access, change the password, which ends all other sessions, and tell support.

Voucher and attempt

Each purchase generates a voucher, and each voucher is worth one exam attempt:

  • A purchased voucher has no expiry date. You sit the exam whenever you want.
  • The voucher is not tied to an account: whoever enters the code uses the attempt. Treat the code the way you would treat a ticket, and do not publish it.
  • The attempt is consumed when the exam is opened, not when it is submitted. Abandoning an open exam consumes the voucher.
  • If you do not pass, a new attempt requires a new voucher.

Rules of conduct

The exam is individual and closed book. The rules below exist so that each person’s pass keeps meaning something, and they apply to every PMCert exam:

  • Sit your own exam. Do not use help from another person, and do not sit an exam in anyone else’s place.
  • Do not consult material, websites, apps or artificial intelligence assistants during the exam.
  • Do not copy, photograph, transcribe, reproduce or publish the questions, the options or any part of the item bank, during or after the exam.
  • Do not use automation, scripts or any means of circumventing the normal operation of the exam.
  • Do not attempt to reach administrative areas, other candidates’ data, or parts of the system that are not yours.
  • Do not state, display or imply a credential you have not earned, and do not alter an issued certificate.

When a credential is revoked

Revoking is the gravest act on the platform, which is why the grounds are explicit. A credential may be revoked when:

  • There was fraud in the exam, including help from third parties, an exam sat by someone else, prohibited consultation or the use of automation.
  • The exam questions were published, in whole or in part, by the holder.
  • The credential was obtained with a false identity or false data.
  • The credential is being presented in a misleading way, or the certificate has been tampered with.
  • It was issued through an administrative or technical error by PMCert itself.

What revocation does

A revoked credential does not disappear: the code stays checkable and starts answering that the credential is revoked, because vanishing would make the code look forged to anyone who verified it in good faith in the past. The public profile stops listing it. The reason is recorded internally, and the holder may request a review by writing to support@pmcert.org. An administrative error is reversible, and restoring returns the credential to its previous state. Revocation for fraud does not entitle you to a refund.

Content and trademark

The questions, options, syllabuses, texts and the PMCert name belong to PMCert Global Institute. Your certificate and your credential are yours, and you may display, share and add them to your professional profile freely. What may not be reproduced is the content of the exams.

Availability and changes

We work to keep the platform available, but maintenance and failures happen. If a problem on our side interrupts an exam in progress, write to support@pmcert.org and we will release a new attempt at no cost. We may change prices, the exam catalogue, syllabus content and this text; changes apply to later purchases, never retroactively to a voucher already bought.

Part 3: refunds

When you can back out of a purchase, and how to ask.

Refund within 7 days

You have 7 days from the date of purchase to request a full refund, as long as the voucher has not been used. Just send an email to support@pmcert.org saying you want the refund, from the same address used in the purchase.

What happens after the request

The process is simple, and it has one effect worth knowing in advance:

  • We return the amount through the same payment method used in the purchase. How long until the money appears depends on your bank or card issuer.
  • The voucher is cancelled in the same act, and the code stops working. This is necessary: without the cancellation, the code would still open an exam after the money had gone back.
  • A voucher already used is not refundable, even within the seven days. The attempt is consumed when the exam is opened, and from then on the service has been delivered.
  • After the seven days, the voucher remains yours and never expires, but it is no longer refundable.

How to reach us

To exercise any right over your data, request a refund, contest a revocation or ask about this text, write to support@pmcert.org. We answer within 3 business days.