Privacy Policy | Certn: The World's Easiest Background Checks
Privacy Policy
Version 3 / Effective Jun 30, 2025
Certn Privacy Statement
We are a technology company providing background checks and identity verification services. As privacy is at the core of our business, we put a lot of effort into ensuring we adequately protect the Personal Information of the individuals interacting with us. Your trust is crucial for us, and we are confident that this privacy policy will give you the information you need.
Key points you should know when we process your Personal Information
Our role in the processing of your Personal Information
We act as a “processor” when providing services to clients (e.g., employers, landlords), following their instructions on data collection and processing. Clients are responsible for obtaining necessary consent and ensuring data accuracy. We act as a “controller” when you interact directly with us (e.g., using our services, visiting our website, applying for a job). In these cases, Certn is responsible for protecting your data and respecting your rights.
Main Processing Activities:
Certn processes Personal Information to:
- Provide services (background checks, identity verification)
- Communicate with you
- Ensure security and prevent fraud
- Comply with legal obligations
- Manage job applications (if applicable)
- Improve our services
We only process information with a legal basis, such as your consent, a contract, legal obligation, or legitimate interest. We do not use your information for automated decision-making.
Information About Processing Activities:
For detailed information about specific processing activities, including biometric identification, Certn’s subcontractor list, and details about individual checks (e.g., criminal check, OneID, etc.), can be found in the full Privacy Policy below. You can also contact us directly for further information.
Main Information Security Safeguards:
Certn maintains SOC2, SOC3, and ISO27001 certifications. We employ robust security controls, including:
- Regular security audits and penetration tests
- Security vetting and data protection training for staff, suppliers, and contractors
- Limited access to Personal Information
- Encryption for data at rest and in transit
Individuals’ Rights and Dispute Resolution:
We review any privacy request free of charge and take steps to support you in exercising your privacy rights to: (i) be informed, (ii) access, (iii) rectification, (iv) erasure, (v) processing restrictions, (vi) data portability, (vii) withdraw consent and object to processing, (viii) not be subject to a decision based solely on automated processing, and (ix) file a complaint.
To exercise any of these rights or raise a dispute, please contact our Privacy Office at privacy@certn.co. We will respond to your request promptly and within legal timeframes.
Certn’s Privacy Statement may be updated periodically. Please review it regularly for any changes.
I. What is Certn, and does this policy apply to you?
- Certn is a technology company that provides background checks and identity verification services.
- This privacy policy explains how Certn collects, uses, and shares Personal Information of individuals applying for jobs at Certn, those being screened by Certn, clients using Certn’s services, potential clients, and website visitors.
- Certn does not knowingly collect information from children under 13.
Read more
Certn is an information technology company that provides a wide range of products and services in the sphere of background screening and verification identity (“ Services“). This privacy policy (“ Policy“) describes how Certn Holdings Inc. and its affiliates, including Certn (Canada) Inc., Certn (USA) Inc., Certn UK Ltd. and any other wholly owned subsidiary (collectively “ Certn” or “ we” or “ our“), collects, uses, discloses, and processes Personal Information in connection with websites owned by Certn (“ Website( s)”), as well as its Services.
This Policy applies to you if you are whether:
- A “ Candidate“: An individual applying at Certn.
- A “ Consumer“: An individual about which we have received information for the purpose of using our Website(s) or performing our Services.
- A “ Client“: An individual representing an organization or an individual using our Services.
- A “ Prospect“: An individual representing an organization or an individual we are contacting in order to know your interest in using our Services.
- A “ Website Visitor“: An individual, a Consumer or a Client of legal age accessing our Websites.
Please note that we do not knowingly solicit information from anyone under the age of thirteen (13). If you become aware of any Personal Information shared by or on behalf of a child, please contact us using the contact information provided in the relevant section below.
II. What is Personal Information and what do we do with it?
- Personal Information is any information that can identify an individual directly or indirectly, but it doesn’t include general business contact details.
- Certn collects, uses, stores, and shares only the necessary Personal Information to provide its Services.
- Broadly speaking, we process your Personal Information (i) to provide our Services, (ii) to communicate with you, (iii) for security and fraud prevention, and (iv) to comply with the law. We may also use Personal Information for other purposes, subject to your consent.
- Certn doesn’t use your information for automated decision-making.
- You can choose to limit the Personal Information you share, but this might affect the Services Certn can provide.
Read more
For the purposes of this Policy, “ Personal Information” is any information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, to or with an identified or identifiable individual.
Personal Information does not include business information, such as our Clients’ business address and telephone number.
We process only the Personal Information required in the course of providing our Services. “ Processing” (or “ processes” or “ processed“) includes any operation or set of operations which is performed on Personal Information, or on sets of Personal Information, whether or not by automated means. This includes the collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, transfer, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction of Personal Information.
Some information, including criminal records, credit information, and biometric data, may be considered sensitive or may be subject to special protections in some jurisdictions. Such information will not be collected in every case, and will not be collected where prohibited by law, and where permitted, will only be collected and used in accordance with applicable law.
By using our Website or our Services, you consent to the processing of your Personal Information subject to the provisions of this Policy. If you do not agree with this Policy or do not wish to provide your Personal Information to us, please do not use our Website or Services.
II.1. When Certn conducts verification on behalf of its clients
- Certn acts as a “data processor” for its clients (like employers or landlords) who use Certn’s services for background checks and identity verification. This means that Clients instruct Certn on what information to collect and how, ensure they have legal grounds and necessary consent for the collection, and are responsible for the accuracy and protection of the data. Certn carries out the client’s requests, protects the data, and complies with applicable laws.
- Clients must have a “Permissible Purpose” (e.g., employment, tenancy) for processing data. Certn won’t reuse data without consent, legal requirement, or compatibility with the original purpose.
- Personal information is collected with your awareness and consent, except where permitted or allowed by law.
- Different checks need different information, so not all of the information described in the policy might be collected for every check. You can look up the specific check you’re going through in the policy to learn more.
II.2. When you are directly interacting with Certn
- Certn acts as a “Controller” of your Personal Information in certain situations, such as when you directly use our services, navigate our website, consent to marketing contact, or apply for a job with us. In these instances, we are responsible for protecting your data and respecting your rights.
- We may process your Personal Information to provide services, manage job applications, monitor performance, comply with laws, improve our offerings, ensure quality, train employees, maintain security, and prevent fraud.
- When providing services, we do not collect financial information directly; payments are processed securely by third-party providers.
More information relating to call recordings: We may record calls for training and quality assurance purposes. While we rely on our legitimate interest to do so, we also make sure that you are informed beforehand of such recordings.
More information relating to quality assurance and controls: Our processes for collecting and transcribing Personal Information are automated to the extent possible and are subject to rigorous quality controls. Information that is found to be inaccurate, either through our own audits or following your request for correction, is updated.
To ensure that our processes and systems are effective and efficient, we frequently audit them.
II.3. How do we protect your Personal Information?
We maintain SOC2, SOC3, and ISO27001 certifications, implementing robust security controls to protect Personal Information. Certn regularly conducts security audits and penetration tests to ensure compliance. Our staff, suppliers, and contractors undergo security vetting and data protection training. We limit access to Personal Information and utilize encryption for secure data handling.
IV. How and to whom can we share your Personal Information with?
Certn processes Personal Information globally, storing data in Canada, the US, the UK, and Australia. We may transfer data across borders to provide services like verifying employment or education. These transfers are based on adequacy decisions, safeguards, consent, or other legal considerations. We take measures to ensure data security and comply with specific requirements for regions like California, Quebec, the UK, Australia, the EU, and the EEA. We may share Personal Information with auditors, affiliates, partners, and service providers like payment processors and cloud providers. We do not sell or disclose Personal Information to governments, marketing services, or other clients, except as legally required or as outlined in this policy.