Skip to content
Legal

Privacy Policy

How Certivo collects, uses and protects personal data, and the rights available to individuals under GDPR, CCPA/CPRA and comparable laws. This is a template for evaluation and must be reviewed by counsel before production use.

1. Who we are & our role

Certivo provides an enterprise compliance platform. Our role depends on the data. For account data about the people who administer and use our service, Certivo is the controller. For the verification, screening and case data that customers submit about their own end users, Certivo acts as a processor on the customer's documented instructions; that processing is governed by our Data Processing Addendum.

2. Data we collect

  • Account data: name, work email, organisation, role and authentication data.
  • Usage & technical data: log data, device and browser information, IP address and product-interaction events.
  • End-user verification / screening data (as processor): identity documents, biometric or liveness signals, screening and KYB results — processed only on the controlling customer's instructions.

3. How & why we use data — legal bases

We use account and technical data to provide, secure and improve the Services, to communicate with customers, and to meet legal obligations. Our legal bases are: performance of a contract (delivering the Services), legitimate interests (securing and improving the platform, subject to a balancing test), legal obligation (financial-crime, tax and accounting duties), and consent (optional cookies and marketing, where required). End-user data is processed on the customer's legal basis and instructions.

4. Sharing & sub-processors

We share personal data with vetted service providers who process it on our behalf under contract, including infrastructure, identity, screening, KYB and email providers. We do not sell personal data. See our Sub-processors list. We may also disclose data where required by law or to protect our rights and users.

5. International transfers

Where personal data is transferred across borders, we rely on appropriate safeguards such as Standard Contractual Clauses or an applicable adequacy decision. Enterprise customers can configure regional data residency.

6. Retention

We retain personal data only as long as necessary for the purpose for which it was collected, to provide the Services, or to meet legal, accounting and financial-crime requirements, after which it is deleted or anonymised. Retention of end-user data follows the controlling customer's configuration and the terms of the DPA.

7. Security

We maintain technical and organisational measures appropriate to the risk, including encryption in transit and at rest, access control, tenant isolation and audit logging. See our Security page for detail.

8. Your rights

Depending on your location, you may have rights to access, rectify, erase, restrict or object to processing, and to data portability. California residents have rights to know, delete, correct and to opt out of sale or sharing — Certivo does not sell or share personal information as those terms are defined under the CCPA/CPRA. Where Certivo processes data as a processor, please direct requests to the controlling customer; we will assist them in responding. To exercise rights against Certivo as controller, contact privacy@certivo.uk.

9. Cookies

Our use of cookies and similar technologies is described in our Cookie Policy.

10. Children

The Services are intended for businesses and are not directed to children. We do not knowingly collect personal data from children.

11. Changes & contact

We may update this policy from time to time; material changes will be signposted here. For privacy questions, or to reach our data-protection contact, email privacy@certivo.uk. You also have the right to lodge a complaint with your local data-protection supervisory authority, and may raise concerns through our Complaints process.

Company details

Registered entity name[Registered entity name]
Company number[Company number]
Registered office[Registered office]
GroupOnyxOne Group
General enquirieshello@certivo.example

Bracketed values are placeholders to be completed by the operating entity before this document is published or executed.

Last updated: 20 July 2026. Version 1.0 (evaluation template).

This document is a template maintained by Certivo and should be reviewed by qualified counsel before execution in a specific jurisdiction. It does not constitute legal advice.