Buildkite Certification

Programme policy

Your data

Last updated 2026-08-12

What is held

Your address and name. Your email address identifies your account and is how sign-in links reach you. A name is held only if you gave one.

What you did here. Which units you completed, which quizzes you took and how you answered, which exams you attempted, what you submitted, and what each was marked as.

Your credentials. What you earned, when, against which version of which exam, and at what pass mark.

A record of actions. Every consequential act — an attempt starting, a credential issued or withdrawn, an administrator changing something — is recorded against an opaque identifier, with a timestamp. This record stores identifiers, never addresses or names.

Your Buildkite account id, if you have verified a hands-on exercise. Only the numeric id, so submissions can be attributed to you.

What is not held

Not your Buildkite API token. Hands-on verification needs one, and it is used for the single call that checks your build and then discarded. It is never written down. This is why you are asked for one each time rather than once.

Not your source code. Verifying a build reads its metadata, its configuration and its step results. Repository contents are not fetched or stored.

Not a password. There isn’t one. Sign-in is by a single-use link.

Why

To run the programme and to make the credential mean something. A credential nobody can check is worth nothing, so an issued credential is publicly verifiable by its identifier. Your exam records exist so a result can be explained, re-derived and appealed rather than merely asserted.

Who can see it

You can see your own record. Administrators of this programme can see all of it, which is what lets them help when something goes wrong and detect it when something is off. Every administrator action is recorded against the individual who took it.

Anyone with a credential identifier can see the public verification page: the holder’s name, the credential, when it was issued and whether it is still valid. Nothing else — not your score, not your answers, not your address.

How long

While your account exists: your address, name, credentials and learning progress.

Sign-in links: deleted once expired, and swept daily. A used link is dead immediately.

Exam records — attempts, what you submitted, how it was marked: kept for as long as the credential they support, because they are the evidence behind it. If you dispute a result, this is what the dispute is decided on. Deleting them on a timer would quietly destroy your ability to appeal.

The action record: kept indefinitely. It is what allows a decision about you to be explained years later, and it holds identifiers rather than personal data.

Having it removed

Ask an administrator. What happens:

Your address, name and any linked Buildkite account id are removed. Your record survives under an opaque identifier that no longer resolves to a person — attempts and credentials reference it, and deleting the row outright would break those references rather than protect you.

Your credentials are surrendered. They stop reading as valid, and the verification page says they were surrendered at your request. This is deliberately not the same as revoked. Revocation is what happens when we withdraw a credential, it carries a reason, and it reads as a finding against the holder. Asking for your data to be removed is not misconduct, and it would be a real harm to let a privacy request look identical to a cheating finding for the rest of your career.

Be aware that surrendering a credential is not reversible, and that anyone who verified it previously will see that it is no longer valid. If what you want is to keep the credential and remove your name from it, say so — that is a different request and it is worth discussing before anything is done.

The record that an erasure happened is itself kept, against your opaque identifier and without your address.

Getting in touch

Contact the administrator who enrolled you, or whoever runs this programme in your organisation.