Privacy Policy 202410505.pdf

Certn Privacy Statement

We are a technology company providing background checks and identity verification services. As privacy is at the core of our business, we put a lot of effort into ensuring we adequately protect the personal information of the individuals interacting with us. Your trust is crucial for us, and we are confident that this privacy policy will give you the information you need.

Key points you should know when we process your personal information

Our role in processing your personal information

We act as a "data processor" when we provide services to clients (e.g., employers, landlords), following their instructions regarding the collection and processing of data. It is the clients’ responsibility to obtain the necessary consent and ensure the accuracy of the data. We act as a "data controller" when you interact directly with us (e.g., using our services, visiting our website, applying for a job at Certn). In these cases, Certn is responsible for protecting your data and respecting your rights.

Main Processing Activities:

Certn processes personal information for:

We only process information based on a legal basis, such as your consent, a contract, a legal obligation, or a legitimate interest. We do not use your information for automated decision-making.

Information Relating to our Processing Activities:

Detailed information about specific processing activities, including biometric identification, Certn's subcontractor list, and details about individual checks (e.g., criminal check, OneID, etc.), can be found in the full Privacy Policy below. You can also contact us directly for further information.

Key Information Security Measures:

Certn maintains SOC2, SOC3, and ISO27001 certifications. We use robust security controls, including:


Rights of Data Subjects and Complaints Handling:

We review all privacy-related requests free of charge and take steps to help you exercise your privacy rights such as the right to: (i) information, (ii) access, (iii) rectification, (iv) erasure, (v) restriction of processing, (vi) data portability, (vii) withdraw consent and object to processing, (viii) refusal to be subject to a decision based solely on automated processing, and (ix) the right to lodge a complaint.

To exercise any of these rights or file a complaint, please contact our Privacy Office at privacy@certn.co. For residents of specific jurisdictions (Canada, US, EU, Brazil, Australia), specific contact information is available in the full version of the Privacy Policy. We will respond to your request promptly and within the legally required timeframes.

Certn's Privacy Statement may be updated periodically. Please review it regularly for any changes.

Privacy Policy

Version 3 / Effective June 30, 2025

I. Who are we and does this policy apply to you?

Certn is an information technology company that provides a wide range of identity and background products and services (the "Services"). This Privacy Policy (the "Policy") describes how Certn Holdings Inc. and its subsidiaries, including Certn (Canada) Inc., Certn (USA) Inc., Certn UK Ltd. and any other wholly owned subsidiary (collectively "Certn" or "we" or "our"), collects, uses, discloses, and processes Personal Information in connection with Certn owned websites ("Website(s)"), and its Services.

This Policy applies to you if you are:

a. A "Candidate": A person who applies for a position at Certn.

b. A "Consumer": A person about whom we have received information for the purpose of using our website(s) or performing our Services.

c. A "Client": A person representing an organization or an individual using our Services.

d. A "Prospect": A person representing an organization or an individual whom we contact to find out about your interest in using our Services.

e. A "Website Visitor": An individual, a Consumer, or a Client of legal age accessing our websites.

Please note that we do not knowingly solicit information from anyone under the age of thirteen (13). If you become aware of any Personal Information shared by or on behalf of a child, please contact us using the contact details provided in the relevant section below.


II. What is Personal Information and what do we do with it?

For the purposes of this Policy, "Personal Information" or "Personal Data" means any information that identifies, relates to, describes, can be associated with or could reasonably be linked, directly or indirectly, to an identified or identifiable individual. Personal information does not include business information, such as our clients’ business address and telephone number.

We only process the personal information necessary to provide our services. The term "processing" (or "processes" or "processed") refers to any operation or set of operations performed on personal information, whether by automated means or otherwise. This includes the collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, transfer, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction of personal information.

Certain information, including criminal records, credit information, and biometric data, may be considered sensitive or subject to special protections in certain jurisdictions. This information will not be collected systematically or where prohibited by law. Where permitted, it will be collected and used only in accordance with applicable laws.

We do not make any decisions about you, whether automated or not, and we do not seek to analyze or predict your behavior, preferences, interests, health status, or any other personal characteristics. However, we may carry out automated processing at the instruction of our Client.

By using our website or services, you consent to the processing of your Personal Information in accordance with the provisions of this Policy. If you do not agree to this policy or do not wish to provide us with your Personal Information, please do not use our website or services.

If you choose to limit the scope of the Personal Information you provide to us, we may not be able to provide you with all of our Services or offer you the best experience on our Website.


Generally, we process your Personal Information (i) to provide our Services, (ii) to communicate with you, (iii) for security and fraud prevention purposes, and (iv) for law enforcement and compliance purposes. We may also use your Personal Information for other purposes, subject to your consent. We will only process your Personal Information if we are legally permitted to do so.

To process your Personal Information lawfully, we rely on at least one legal basis, in accordance with applicable law. Depending on your relationship with us, the legal basis for processing your Personal Information may include, among other things, your consent, the obligation to process data for the performance of a contract with you, compliance with a legal obligation, or a legitimate interest.

If your consent is our legal basis for collecting and using your Personal Information, you may withdraw or modify it at any time for future collection or use of your Personal Information. We will explain the consequences of such a decision. If we use your Personal Information for commercial or marketing purposes, you may ask us to stop this type of use at any time, and we will do so.

II.1. When Certn Conducts Verification on Behalf of its Clients

Our clients, such as your employer or landlord, may ask you to use our Services for background or identity verification purposes. In this case, please note that Certn acts as a "processor" when processing your Personal Information. This means that we act solely on behalf of our clients as a service provider when processing your Personal Information.

More specifically, when we provide Services to clients:

We are generally responsible for the following aspects of collection and processing of Personal Information:

In this regard, please note that although we may interact directly with you in connection with the Services requested by our Clients, we do so on behalf of our Clients, and any information or request shared with us may be communicated to our Clients when necessary to provide the Services.

II.1.1. Authorised Processing Purpose

Our Clients must certify that they have a legitimate purpose before we can process Personal Information for the purpose of providing the Services. "Legitimate purpose" includes employment purposes, rental purposes, or processing in accordance with the written instructions of the consumer with whom the Client intends to contract.

We will not reuse Personal Information for purposes other than those for which it was collected, unless one or more of the following conditions are met:

We collect, use, and disclose Consumers' Personal Information when they are informed of the permitted purpose of the processing of that Personal Information and have given their consent to that processing, except where the processing of personal information without consent is permitted or required by law. Subject to regulatory requirements, the operation of our Services in certain jurisdictions requires that we or our Clients obtain additional or specific consents in the form of additional forms, telephone calls, via an online platform, or by other means. Where the Consumer does not provide us with this consent or specific consent directly, but rather provides it to our Clients, we require that the Clients also obtain the Consumer's consent before providing us with their Personal Information, subject to verification for any of our Services. The Consumer may withdraw this previously given consent at any time by contacting us. Withdrawal of this consent does not affect the lawfulness of any processing based on consent before its withdrawal.

You can find more information about the types of Services our Clients may ask you to use in the relevant section of this Policy. Please note that, depending on the type of verification our clients ask you to complete, we may not process all the Personal Information listed in that section. You can refer to the name of the verification you are required to complete in the Policy for more information about how your Personal Information is processed.

II.2. When Interact Directly with Certn

There are situations where Certn does not act on behalf of its Clients when processing your Personal Information. This can occur in the following cases:

In these circumstances, we act as "data controllers" under applicable data protection laws. This has implications for you because as data controllers, we are primarily responsible for respecting your rights regarding your Personal Information and for ensuring its adequate protection in accordance with applicable data protection laws.

In these circumstances, subject to your consent or the applicable legal basis and in accordance with applicable laws, we may process your Personal Information for the following purposes:

Additional information regarding call recordings: We may record calls for training and quality assurance purposes. While we rely on our legitimate interest to do so, we also ensure that you are informed beforehand about these recordings. If you do not wish your call to be recorded, you can use our chat agent or contact us by email at support@certn.co.

Additional information regarding quality assurance and controls: Our processes for collecting and transcribing Personal Information are automated to the greatest extent possible and are subject to rigorous quality controls. Information found to be inaccurate, either during our own audits or following your request for correction, is updated.

To ensure the effectiveness of our processes and systems, we audit them frequently. These audits may involve the processing of your personal information (for example, to ensure the accuracy of the checks performed).

Additional information regarding the provision of our Services: When registering for our Services, you may be asked to enter your full name, email address, company name and address, phone number, billing address, card address, and other customer-provided information via custom fields, if applicable. We never collect financial information, such as your payment method details (e.g., valid credit card number, card brand, expiration date), either through our website or otherwise. When processing payments, you are redirected to a secure page on the Stripe website or that of another PCI DSS-certified payment service provider. This page may feature our branding, but it is not managed by us. All financial information is processed by our payment processor. We encourage you to review their privacy policy and contact them directly with any questions.

More information regarding the performance tracking of our Services and Websites: When we monitor the performance of our Services and Websites, we use information that cannot directly identify you, including by aggregating it or using other depersonalization and anonymization techniques.

Please also note that we may record your operating system name and version, device identifier, browser type, operating system, IP (Internet Protocol) address, screen resolution, pages viewed on our websites, length of visit, access times, general location information such as city, state, or geographic area, and information about your use of and actions on our websites. We may use this information for fraud prevention and security purposes.

The collection of personal information for security purposes is carried out on the basis of our legitimate interest and our legal obligation to ensure the protection of the personal information in our custody.

II.2.1. Things to Know When You Use MyCertn Wallet

MyCertn Wallet is designed to give you greater control over your personal information. It allows you to order specific checks and decide when, to whom, and for how long you want to share the results of those checks.

Here are some key points you should be aware of when using MyCertn Wallet:

II.2.2. Certn’s Use of Artificial Intelligence

We use artificial intelligence technologies to automate and optimize our internal processes and the delivery of our Services. This includes the use of AI agents such as chatbots and AI voice agents. We do not use AI to make automated decisions that could have legal consequences or significantly affect you. Our AI implementation is designed to improve operational efficiency while ensuring full human oversight.

II.2.3. Use of Cookies and Similar Technologies by Certn

Certn uses cookies to improve website functionality and personalize your experience. Some cookies are essential for the website to function, while others help us analyze your website usage and remember your preferences, with your consent. You can manage your cookie preferences through your browser settings.

Our website uses cookies and other similar technologies to provide functionality, analyze traffic, and personalize some of your web content.

II.2.3.1. What are Cookies?

Cookies are small text data files that are sent to your computer or mobile device by a website when you browse.

There are different types of cookies with different functions:

First-party cookies are necessary for the proper functioning of our website. Our website also allows the use of third-party cookies, which can be read externally by other organizations. Therefore, we cannot be held responsible for third-party cookies, i.e., cookies that we do not use.

II.2.3.2. Use of Cookies

Necessary cookies: By using our website, you agree to our storing and accessing necessary cookies on your device. These cookies do not collect any information about you that could be used for marketing purposes or to remember your browsing history.

Statistical cookies: These are anonymous and do not allow us to identify you. They help us improve the functionality of our website and collect information about your use of the site (frequency of visits, links clicked, favorite pages, etc.). By accepting these cookies, we can generate anonymous statistical reports for the purpose of improving the website.

Preference cookies: To remember your choices (such as your selected language or saved username and password), to allow for faster browsing, and to offer you enhanced features, we need to enable preference cookies. The information collected by these cookies is generally anonymized.

Marketing cookies: These can be installed on websites by third parties. They do not store personal information, but identify your browser and connected device to allow advertisers to show you relevant ads.

Website log data: Certn's web servers record the following information when you visit our website: IP addresses, operating system type, time and duration of visit, web pages viewed, and browser type. We do not link server log information to any other information that could identify visitors to our website. In addition to analyzing these logs to provide you with a better experience on our website, they may be accessed for security purposes and, if necessary, to detect any unauthorized activity on our site. In such cases, server log data, including IP addresses, will be shared with law enforcement so they can identify users in their investigations of unauthorized activities.

II.2.3.3. How Can I Manage My Cookie Preferences?

Information about our cookies will be presented to you during your first visit to our website, and then occasionally via the cookie banner. You can accept or reject all cookies at any time while browsing the website. You can choose and manage your cookies at any time through your browser settings. If you disable cookies, you may not be able to access or use certain parts or features of the website.


II.3. What You Need to Know Depending on the Type of Checks Carried Out by Certn

All our controls require us to process, at a minimum, the following personally identifiable information:

This information, combined with that required for any identity verification, allows us to ensure that the verification is for the correct person. If you are required to complete multiple verifications, you can use the sections below to obtain more information about the personal information we need to process, the reasons for this processing, the source of the information, and how long we retain your personal information. Please note that each verification is unique, and we may not process all the personal information listed below. Depending on your individual circumstances, we may also need to process your personal information from different jurisdictions (for example, if you have worked or lived in different countries).

The list below is not exhaustive and may not include information relevant to the check you are undergoing. For example, in some countries, such as the United States, Certn may offer drug screening tests, or in the United Kingdom, checks related to the Right to Work. For more information on how we process your personal information during these specific checks, please see the consent form and related documentation or contact us.

II.3.1. OneID

OneID Personal Information Concerned Full Name, Including Maiden Name and Aliases
Personal Information Concerned Date of Birth
OneID Personal Information Concerned Address History
Personal Information Concerned Phone Number and Email
Personal Information Concerned Identity Documents such as Passport or Driver's License
Personal Information Concerned Biometric Data (Facial Characteristics)
Purposes of the Processing Identity Verification, Fraud Detection and Prevention
Sources Provided by You
Storage Periods 30 Days from the Date of Biometric Data Collection
Storage Periods 3 Years from the Date of Collection of Contact Details and Results of the Check
More Information For more information, please read our Biometric Notice.

II.3.2. Identity Verification

Identity Verification Personal Information Concerned Full Name, Including Maiden Name and Aliases
Identity Verification Personal Information Concerned Date of Birth
Identity Verification Personal Information Concerned Address History
Identity Verification Personal Information Concerned Phone Number and Email
Identity Verification Personal Information Concerned Identity Documents such as Passport or Driver's License
Identity Verification Personal Information Concerned Biometric Data (Facial Characteristics)
Identity Verification Purposes of the Processing Identity Verification
Identity Verification Purposes of the Processing Fraud Detection and Prevention
Identity Verification Sources Provided by You
Storage Periods 30 Days from the Date of Biometric Data Collection
Storage Periods 3 Years from the Date of Collection of Contact Details and Results of the Check
More Information For more information, please read our Biometric Notice.

II.3.3. Canadian Criminal Record Check

Canadian Criminal Record Personal Information Concerned Place of Birth
Canadian Criminal Record Personal Information Concerned Police Files
Canadian Criminal Record Personal Information Concerned Court Files
Canadian Criminal Record Personal Information Concerned Criminal Record
Canadian Criminal Record Personal Information Concerned Status of the Sex Offenders Registry
Canadian Criminal Record Purposes of the Processing Criminal Background Check
Canadian Criminal Record Sources Provided by You
Canadian Criminal Record Sources Law Enforcement and Government Agencies
Canadian Criminal Record Sources Courts and Public Archives
Canadian Criminal Record Storage Periods 3 Years from the Date of Collection
Canadian Criminal Record More Information For more information, please read our Biometric Notice.

II.3.4. International Criminal Check

International Criminal Record Check Personal Information Concerned Sex
International Criminal Record Check Personal Information Concerned Police Files
Court Files
Criminal Record
Passport Details or Similar Information such as Identification Number, Visa Information, and Jurisdiction-Specific Documents
Purposes of the Processing Criminal Background Check
Sources Provided by You
Sources Law Enforcement and Government Agencies
Sources Courts and Public Archives
Storage Periods 3 Years from the Date of Collection

II.3.5. Employment Verification

Employment Verification Personal Information Concerned Employment History (Including Company Name, Contact Information, Fiduciary or Managerial Responsibilities, Positions, Titles, Income, or Start and End Dates)
Employment Verification Purposes of the Processing Verification of Employment or Activity History Over a Certain Period of Time
Employment Verification Sources Provided by You
Employment Verification Sources Previous Employers
Employment Verification Sources Employment Verification Providers
Employment Verification Sources References You Provided
Employment Verification Storage Periods 3 Years from the Date of Collection

II.3.6. Education Verification

Education Verification Personal Information Concerned Post-Secondary Information (Including the Name of the Institution, the Address of the Institution, the Title of the Degree/Certification and the Dates of Enrollment)
Education Verification Purposes of the Processing Checking Educational or Activity History Over a Certain Period of Time
Education Verification Sources Provided by You or Our Client(as Applicable)
Education Verification Sources Educational Institutions
Education Verification Sources Education Verification Providers
Education Verification Sources Government Educational Authorities
Education Verification Storage Periods 3 Years from the Date of Collection

II.3.7. Creditworthiness Report (Canada)

Creditworthiness Report (Canada) Personal Information Concerned Employment History (Including Name, Contact Information, Fiduciary or Managerial Responsibilities, Positions, Titles, Income, or Start and End Dates)
Creditworthiness Report (Canada) Personal Information Concerned Financial Information (Including Credit History, Bankruptcies or Financial Judgments)
Creditworthiness Report (Canada) Purposes of the Processing Credit and Bankruptcy History Check
Creditworthiness Report (Canada) Sources Credit Bureaus
Creditworthiness Report (Canada) Sources Government Agencies
Creditworthiness Report (Canada) Sources Public Documents
Creditworthiness Report (Canada) Storage Periods 3 Years from the Date of Collection

II.3.8. Income Verification

Income Verification Personal Information Concerned Bank Details (Including Bank Name, Account Balance, Account Activity Trends, Account Balance Trends, Recurring Deposits, Recurring Payments, and Account Age)
Income Verification Personal Information Concerned Income Information (Including Income Sources, Average Monthly Income, Estimated Gross Annual Income, Employer Income, Non-Employer Income or Income Trends)
Income Verification Purposes of the Processing Verification of Your Income
Income Verification Sources Financial Institutions
Income Verification Sources Revenue Verification Providers
Income Verification Storage Periods 3 Years from the Date of Collection

II.3.9. Verification of Adverse Media

Verification of Adverse Media Personal Information Concerned Activity on Social Media (Posts, Interactions, etc.)
Verification of Adverse Media Personal Information Concerned Mentions in Online or Print Media
Verification of Adverse Media Purposes of the Processing Verification of Adverse Media
Verification of Adverse Media Sources Print and Digital Media
Verification of Adverse Media Sources Law Enforcement and Government Agencies
Verification of Adverse Media Storage Periods 3 Years from the Date of Collection

II.3.10. Verification of Politically Exposed Persons (PEPs)

Politically Exposed Persons(PEP) Screening Personal Information Concerned Work Address
Politically Exposed Persons(PEP) Screening Personal Information Concerned Inclusion on Watchlists or Sanctions Lists
Politically Exposed Persons(PEP) Screening Personal Information Concerned Financial Conduct Authority Reference Number (If Applicable)
Family or Business Relationships with Politically Exposed Persons
Purposes of the Processing A check to determine if you hold or have held a prominent public position or role that exposes you to potential risks of corruption, bribery, or money laundering.
Purposes of the Processing Verification of Global Sanctions Regimes and Sanctions Lists
Purposes of the Processing Verification of Adverse Media
Sources Global Watchlists and Registries
Sources Law Enforcement and Government Agencies
Sources Regulatory Bodies
Storage Periods 3 Years from the Date of Collection

II.3.11. Global Sanctions and Watchlists

Global Sanctions and Watchlists Personal Information Concerned Inclusion on Watchlists or Sanctions Lists
Global Sanctions and Watchlists Purposes of the Processing Verification of Global Sanctions Regimes and Sanctions Lists
Global Sanctions and Watchlists Sources Global Watchlists and Registries
Global Sanctions and Watchlists Sources Law Enforcement and Government Agencies
Global Sanctions and Watchlists Sources Regulatory Bodies
Global Sanctions and Watchlists Storage Periods 3 Years from the Date of Collection

II.3.12. Questionnaire

Quiz Personal Information Concerned Any Additional Information Submitted Voluntarily by You
Purposes of the Processing Provide Certn's Clients with the Additional Information They Need During the Requested Audits.
Sources Provided by You
Storage Periods 3 Years from the Date of Collection

III. How Do We Protect Your Personal Information?

III.1. Our Approach to Data Protection

At Certn, we are committed to protecting your privacy and personal information. We have implemented a comprehensive compliance framework based on key principles. We are responsible for protecting your information and have appointed a Data Protection Officer to oversee our practices and ensure compliance with applicable laws. We identify the purposes for collecting your information in advance and only collect it when permitted by law or with your consent. We limit data collection to what is strictly necessary, minimizing it throughout its lifecycle through strict retention policies. We ensure the accuracy of your data through technical controls and audits, allowing you to easily correct any inaccuracies. We protect your information with robust safeguards and train all individuals who handle it. We are transparent about our data protection practices and ensure our documentation is clear. We also respect your rights regarding your personal information and have implemented a complaints handling procedure. We regularly review our compliance. Our services are designed with confidentiality (state-of-the-art security), ease of management (individual data control), and predictability (transparent practices) in mind.

At Certn, we are committed to protecting your privacy and personal information. We have implemented a comprehensive framework that outlines our objectives and principles for handling personal information and defines our privacy governance as an organization. This framework is based on the following key principles:


We also strive to minimize the amount of personal information required throughout its lifecycle. This is achieved, in particular, through the implementation of strict retention periods. You will find more information about our retention practices in the relevant sections of this policy.

We ensure that your personal information is processed in accordance with these principles.

Furthermore, in accordance with our privacy framework, our services are designed to pursue these three main objectives:

III.2. How Long Do We Keep Your Personal Information?

Certn retains your personal information to the extent necessary to provide services, comply with legal obligations, and enforce agreements. We delete your account and data upon request, although some information may be retained for legal reasons. Unless otherwise instructed by our clients, consumer information is generally retained for a maximum of three years, with exceptions for specific data types such as biometric data (30 days) and applicant information (3 years).

In accordance with our retention policy, we will retain your information for as long as necessary to provide you with our services and/or to comply with our contractual and legal obligations, resolve disputes and enforce our agreements.


Data necessary to establish proof of a right or contract will be retained for the period stipulated by applicable law. Upon your request to close your account, we will deactivate or delete your account and information from our active databases. However, certain information may be retained in our files to prevent fraud, resolve issues, assist in investigations, enforce our terms and conditions, and/or comply with legal requirements.

Regarding Consumers' personal information, unless our Clients have requested its deletion or a different retention period, the retention and disposal period will not exceed three (3) years. More specific information about our retention periods, based on the controls we perform, can be found in the relevant section of this policy. Exceptions may exist for specific data sets, in accordance with regulatory requirements or the retention requirements of third-party data providers. For example, we will retain your biometric data for 30 days after the completion of your OneID identity verification. Where necessary, we may retain general log information and information for auditing purposes.

If you are a candidate, we will keep your personal information for a maximum of three years.

III.3. How Do We Protect Your Personal Information?

We are SOC2, SOC3, and ISO 27001 certified and maintain advanced technical, administrative, and physical security controls that comply with these standards and protect your Personal Information from unauthorized access, loss, misuse, interference, or alteration during its collection, use, disclosure, and storage on our site. We regularly conduct security audits, vulnerability assessments, and penetration tests to ensure compliance with industry security practices and standards.

All our staff, suppliers, and subcontractors undergo background checks before being hired. All staff members are trained in data protection and are aware of their responsibilities. This training is provided repeatedly, either regularly or randomly, but at least once a year.

We limit access to Personal Information to individuals with a legitimate business need, consistent with the purpose and objective for which the information was provided. We implement various security measures to maintain the safety of your Personal Information when orders are placed or when you enter, submit, or access your personal information. For example, we use encryption at rest and in transit. All sensitive information provided is transmitted via Transport Layer Security (TLS) technology and then stored in our database. It is accessible only by individuals with special access rights to our systems, who are bound by confidentiality agreements.

In addition, we have implemented processes to encourage our clients to comply with applicable privacy laws and security standards. These processes include, among other things, entering into binding agreements with our clients and conducting random mutual audits of each other's internal procedures and practices to ensure that regulatory standards and security levels are mutually met and exceeded at all times.


IV. How and to Whom Can We Disclose Your Personal Information?

Certn processes personal information globally and stores data in Canada, the United States, the United Kingdom, and Australia. We may transfer data across borders to provide services such as employment or education verification. These transfers are based on adequacy decisions, contractual and security safeguards, consent, or other legal considerations. We take steps to ensure data security and comply with the specific requirements of regions such as California, Quebec, the United Kingdom, Australia, the EU, and the EEA. We may share personal information with auditors, affiliates, partners, and service providers such as payment processors and cloud providers. We do not sell or disclose personal information to governments, marketing services, or other clients unless required by law or as stated in this policy. We may disclose information to law enforcement authorities or similar bodies if legally required to do so.

IV.1. Does Certn Process Personal Information Cross-Border?

Certn operates globally and may need to transfer your Personal Information across borders as part of its business operations. We rely on storage infrastructure in Canada, as well as in the United States, the United Kingdom, and Australia. We may also process your Personal Information across borders to provide you with the Services, for example, to verify your employment or education history. When we transfer Personal Information to you, we rely on, among other things, the following:

In cases where our client is located, or the consumer resides or has resided, in the State of California, the Province of Quebec, the United Kingdom, Australia, the EU and/or the EEA, specific requirements may apply to the transfer of Personal Information.

We take all steps reasonably necessary to ensure that your Personal Information is treated securely and in accordance with this Policy, and we will not transfer Personal Information to an organization or country unless adequate controls are in place to ensure the security of your data.

If you are wondering whether your information will be processed abroad and/or if you have any restrictions or conditions regarding the disclosure of your information abroad, please contact us as soon as possible so that we can discuss your specific needs.

IV.2. Third Parties

We only share your personal information with third parties with your consent, or when permitted or required by applicable regulations.

In addition to the third parties listed in the section on types of controls, we may share or disclose your Personal Information to the following third parties in the course of our business activities:

When we provide Services to a Customer, the Consumer's Personal Information is processed and reported through our secure platform. In addition to our Customers and authorized Certn personnel who may access your Personal Information for the purposes described in this Policy, we may provide your Personal Information to authorities or partner companies that provide services to assist us in our business operations, such as offering customer service or processing your payment. For more information about the third-party companies that provide us with such services, please click here.

Finally, please note that we do not sell or disclose your Personal Information to governments, marketing or advertising services, other clients or any other person, except as described in this policy or when required by law.

IV.3. Government Entities

In exceptional circumstances, we may be required to disclose personal information to law enforcement agencies, national security agencies, courts, or other similar institutions, as required by law. Upon receipt of a production order, subpoena, warrant, or any other enforceable request, we will act in accordance with applicable laws.

V. Essential Information Tailored to Your Country and How to Contact Us to Assert Your Rights

V.1. Your Rights

Certn is committed to ensuring that your rights regarding your Personal Information are respected in all jurisdictions where it operates.

Regardless of your jurisdiction, we grant the following rights to individuals whose Personal Information we process. If you reside outside the jurisdictions described below, please see the details provided to exercise your rights.

Regardless of where you live, we will review any privacy request free of charge and take steps to help you exercise your privacy rights: (i) information, (ii) access, (iii) rectification, (iv) erasure, (v) restriction of processing, (vi) data portability, (vii) withdrawal of consent and objection to processing, (viii) refusal to be subject to a decision based solely on automated processing, and (ix) lodging a complaint.

If you do not reside in one of the jurisdictions listed below, you can contact our Privacy Office at privacy@certn.co to exercise your privacy rights. If you reside in one of these jurisdictions, please use the contact information provided in the section that applies to your situation.

Upon receipt of a written request and after verifying that you are indeed the data owner, we will respond to requests, disputes, and complaints concerning your privacy rights as soon as possible and, in any event, within the time limits prescribed by law. However, if we refuse your request, we will send you a written explanation within 30 days of receiving it.

For compliance purposes and where required by law or contract, before complying with any privacy request, we will inform the Client involved in the request, if applicable, as well as any other third parties who may have processed your Personal Information. On their instructions, we will respond to your request accordingly. You may challenge their decision by contacting them directly or by contacting your local data protection or privacy authority.

V.1.1. Right to Be Informed

You have the right to be informed about the nature of the processing of your personal information. You have the right to know what personal information we process, with which third parties it may be shared, and how long we will retain it.

V.1.2. Right to Access

Subject to the exceptions provided by applicable law, you have the right to access the Personal Information that Certn holds about you or on behalf of its Clients. You can request that we provide you with your Personal Information using the contact details provided in this Policy or the tools and forms we make available to you in our various Services.

V.1.3. Right to Rectify, Correct or Update Your Personal Information

V.1.4. Right to Erasure or Deletion

You have the right to request the deletion or erasure of your Personal Information. This right is exercised in accordance with applicable laws and may be limited depending on the nature, scope, and laws applicable to your request. Certn may retain some of your Personal Information when required or permitted by applicable laws. For example, we may need to retain your Personal Information to demonstrate our compliance with data protection or privacy laws. If you request the deletion of your Personal Information, we must retain certain information regarding your request for deletion and our compliance with your request.

V.1.5. Right to Portability

You have the right to obtain your Personal Information in a structured, commonly used, and machine-readable format and to request that we transmit it to another qualified third party under applicable law. This right is limited to Personal Information that you have directly provided to us.

V.1.6. Right to Withdraw Your Consent and Right to Object

Subject to the exceptions set forth in applicable law, you have the right to withdraw your consent if we rely on it to process your Personal Information. In this case, please note that we may no longer be able to provide the services. If the Services are requested for purposes authorized by the Client, such as employment or rental, this may affect related processes. Where possible, we encourage you to contact the tenant, employer, or organization that requested the verification to obtain further information about the consequences of withdrawing your consent.

You have the right to object to specific processing activities involving your personal information, depending on the legal framework that applies to your situation. For example, you have the right to object to the processing of your personal information for direct marketing purposes, including profiling.

V.1.7. Right to Restriction of Processing

Under the circumstances provided for by applicable laws, you have the right to ask us to restrict the processing of your personal information.

V.1.8. Right to Not Be Subject to a Decision Based Solely on Automated Processing

Certn does not use your Personal Information to make decisions based solely on automated processing.

V.1.9. Right to File a Complaint

If you have any concerns about our data protection practices or the handling of your personal information, you can file a complaint with our Privacy Office. Contact information can be found in this Policy.

V.2. Canada Residents

You will find detailed information about our policies and processes relating to the protection and retention of your personal information in the relevant sections of this policy.


As indicated in the sections above, please note that Certn may transfer your personal information outside of Canada, including outside the province of Quebec, whenever necessary for the purposes for which it was collected.

V.2.1. Personal Information Agent (Quebec)

Certn is a registered Personal Information Agent in Quebec. In this regard, please note that:

V.2.2. Who to Contact?

For any questions, complaints or requests regarding this policy you can contact our Privacy Officer at the following address:

| CANADA | Certn (Canada) Inc. | 1006 Fort St Unit 300 Victoria, BC V8V 3K4 +1-844-987-0690 privacy@certn.co | | --- | --- |

V.3. Residents of the United States

V.3.1. Your Rights Under the Fair Credit Reporting Act

As a U.S. resident, please be aware that some of the personal information processed by Certn may be subject to the Fair Credit Reporting Act ("FCRA"), and that your state's privacy laws may be overridden by this federal law. Unless you have applied for a position at Certn, we do not make any decisions regarding your employment. For more information about the FCRA, your rights under this law, and how it may apply to your situation, please contact your employer.

V.3.2. California Residents

For the purposes of the California Consumer Privacy Act ("CCPA"), we do not sell consumers' personal information to third parties for direct marketing purposes. Personal information processed as part of a background check is not subject to the CCPA.

If you are a California resident and we have processed categories of your Personal Information beyond the CCPA exemption for a background check, you have the right to access, delete, disclose, refuse the sale of, and be free from discrimination against your Personal Information. You may contact us to exercise any of these rights. For compliance purposes, we may request additional information from you to fulfill your request.

V.3.3. Nevada Residents

We do not sell consumers' personal information to third parties for direct marketing purposes.

V.3.4. Who to Contact?

For any questions, complaints or requests regarding this policy, you can contact our Privacy Officer at the following address:

| UNITED STATES | Certn(USA)Inc. | Trust Center 1209 Orange Street Wilmington, New Castle County, Delaware, 19801 +1-844-987-0690 privacy@certn.co for any privacy-related questions | | --- | --- |

V.4. Residents of the EU, EEA, Switzerland and the United Kingdom

Given that we occasionally process Personal Information of residents of the EU, EEA, Switzerland and the UK, we have taken steps to comply with these jurisdictional standards and ensure that all recipients of such Personal Information provide an adequate level of data protection based on, but not limited to, commitments under standard contractual clauses and/or international data transfer agreements, as appropriate.

Consumers in the EU, EEA, Switzerland, and the UK have certain rights regarding the processing of personal information. If you are an EU/EEA/UK resident, you have:

If you wish to exercise your rights regarding your background report, we will respond to your request in our capacity as data processor and in accordance with our client who commissioned the report, acting as the data controller. In this case, please note that our clients are ultimately responsible for responding to your request.

To register your request, please contact us. We will contact you if we need additional information from you to provide the applicable information or to take specific actions to follow up on your request regarding the exercise of your rights.

V.4.1. Who to Contact?

For any questions or requests regarding this policy, you can contact our data protection officer at the following address:

| UNITED KINGDOM | Certn(UK)Limited | 160 London Road Sevenoaks, Kent,TN13 1BT +44(0)1732748900 support@certn.co for general queries and dpo.emea@certn.co for privacy-related queries | | --- | --- |

V.5. Brazil

Residents of Brazil may be entitled to certain rights:


To exercise your rights relating to your consumption report, we will support your request in our capacity as a subcontractor and in agreement with our client who ordered the report in their capacity as data controller.

To register your request, please contact us using the contact details provided below. We will contact you if we require further information from you to provide the applicable information or to take specific actions to honor your request and exercise your rights.

V.6. Australia

Certn conducts checks in Australia through its subsidiary InterCheck. For more information on how Intercheck handles your personal information, please visit: https://intercheck.com.au/privacy-policy/.

For any questions, complaints or requests regarding this policy, you can contact our privacy officer at the following address:

Australia 356 Collins Street Melbourne, 3000, Victoria +61(03)88204069 apac-privacy@certn.co for privacy-related questions or inquiries and help@intercheck.com.au for any other questions.

VI. How is the Policy Updated?

We reserve the right to modify this Policy at any time. All website visitors are encouraged to review this Policy regularly to stay informed of updates. By continuing to use our website and services after the posting of changes to this Policy, you accept the new revised policy and agree to be bound by it.