Privacy Policy
Last updated: 7 July 2026
This policy explains how Certivus Compliance Ltd ("Certivus", "we", "us") collects and uses personal data in connection with our website, our AML compliance platform, and the identity verification services we provide to UK accountancy firms and law firms. We process personal data in accordance with the UK GDPR and the Data Protection Act 2018.
Data controller: Certivus Compliance Ltd, a company registered in England and Wales (Company No. 17319995)
Registered office: 64 Yardley Green Road, Birmingham B9 5QE, United Kingdom
ICO registration: ZC189266
Data Protection Officer: Harveys Legal; dpo@harveyslegal.com
1. Who this policy covers
We handle personal data in three distinct situations:
- Website visitors: people browsing certivus.com, requesting a demo, downloading resources, or subscribing to our newsletter.
- Customers and their users: accountancy and law firms that subscribe to the Certivus platform, and the individuals at those firms who use it.
- End clients of our customers: individuals asked by their accountant or solicitor to complete an identity verification or AML check through Certivus. If that is you, section 3 below and our dedicated identity verification privacy notice explain exactly what happens to your data.
2. What we collect, why, and our lawful basis
| Purpose | Personal data | Lawful basis (UK GDPR Art. 6) |
|---|---|---|
| Operating and securing this website | Device and usage data, IP address, pages visited | Legitimate interests (running and protecting our website) |
| Responding to enquiries, demo bookings, and support requests | Name, email, phone, firm name, message content | Legitimate interests / steps prior to entering a contract |
| Providing the Certivus platform to customer firms | Account, user, and billing data | Performance of a contract |
| Processing identity verification and screening checks instructed by a customer firm | End-client identity data (see section 3) | We act on the instructing firm's behalf; the firm establishes the lawful basis (typically legal obligation under MLR 2017) |
| Sending marketing emails and newsletters | Name, email, firm details | Consent (or soft opt-in for existing customers), with an unsubscribe link in every email |
| Analytics and advertising cookies | Cookie identifiers, usage data | Consent, collected through our cookie banner |
| Complying with law, regulation, and requests from authorities | Any of the above, as required | Legal obligation |
Where we rely on legitimate interests, we have carried out a balancing assessment and concluded our interests do not override your rights. You can request a summary of any assessment from our DPO.
3. Identity verification checks: who is responsible for what
When a firm uses Certivus to verify the identity of one of its own clients, that firm is the data controllerfor its client's personal data. The firm decides to run the check because of its own obligations under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 ("MLR 2017"). Certivus provides the platform and passes the check through to our verification and data partners on the firm's behalf and on its documented instructions.
The verification journey works like this:
- The firm initiates a check on its client. The client receives a link and lands on a verification page that clearly identifies which firm requested the check.
- The client is shown the firm's privacy terms and this notice before any data is captured.
- Identity data (for example, a passport or driving licence, a selfie for biometric comparison, name, date of birth, and address) is collected and checked against document, biometric, and database sources provided by our verification and data partners, which may include UK credit reference agencies.
- The result is returned to the instructing firm's own segregated workspace as part of its client file. Each firm's data is segregated from every other firm's.
Credit reference agency searches. Some checks verify identity against records held by UK credit reference agencies. These are soft searches: they leave a record on the individual's credit file that is visible to them but not to lenders, and they do not affect credit scores. On any such search, Certivus is identifiable as the entity conducting the search on the instructing firm's behalf. The credit reference agencies also process personal data in their own right, as described in the Credit Reference Agency Information Notice (CRAIN), published on each agency's website.
Biometric data.Where a check includes facial matching, biometric data (special category data under UK GDPR Art. 9) is processed with the individual's explicit consent, captured during the verification journey before the check runs.
4. Who we share personal data with
We share personal data only where necessary to run the service, and never sell it. Recipients fall into these categories:
- Identity verification and data partners: regulated providers of document, biometric, database, and PEP/sanctions screening checks, including UK credit reference agencies, engaged to perform the checks our customers instruct.
- Infrastructure providers: hosting, database, content delivery, and email delivery services.
- Payment processors: for subscription billing.
- Analytics and advertising providers: only with your cookie consent (see our Cookie Policy).
- Professional advisers and group companies: where needed for legal, accounting, insurance, or lead-handling purposes.
- Authorities and regulators: where required by law, or to establish, exercise, or defend legal claims.
The current list of sub-processors, with locations and transfer safeguards, is published on our sub-processors page and kept up to date.
5. International transfers
Platform data, including identity verification records, is stored in the United Kingdom. Where a service provider processes limited personal data outside the UK or EEA (for example, a US-based email or analytics provider), we rely on UK adequacy regulations or put in place the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, plus any additional safeguards required. Details for each provider are on our sub-processors page.
6. How long we keep data
| Category | Retention period |
|---|---|
| Customer account and billing records | Duration of the contract, then up to 7 years after account closure (tax, accounting, and limitation-period requirements) |
| Identity verification and screening records processed for a customer firm | The retention period set by the instructing firm, typically 5 years after the end of the firm's business relationship with its client, as required by Regulation 40 of the MLR 2017 |
| Enquiry, demo, and support correspondence | Up to 3 years from last contact |
| Marketing data | Until you unsubscribe or ask us to stop; suppression records kept so we don't contact you again |
| Website analytics data | Up to 26 months |
When a retention period ends, data is deleted or irreversibly anonymised.
7. Security
We apply technical and organisational measures appropriate to the sensitivity of AML and identity data, including:
- Encryption in transit (TLS 1.3) and at rest (AES-256)
- UK data residency for platform data
- Role-based access controls, multi-factor authentication, and audit logging
- Segregation of each customer firm's workspace and data
- An independent security assessment programme; our security controls are aligned to ISO 27001, and certification is in progress
More detail is on our security page. If we suffer a personal data breach likely to result in a risk to individuals, we will notify the ICO within 72 hours and affected individuals where the risk is high, as UK GDPR requires.
8. Your rights
Under the UK GDPR you have the right to:
- Access: ask for a copy of the personal data we hold about you
- Rectification: ask us to correct inaccurate or incomplete data
- Erasure: ask us to delete your data, subject to legal retention duties (for example, AML record-keeping)
- Restriction: ask us to limit how we process your data while a query is resolved
- Portability: receive data you provided to us in a machine-readable format
- Objection: object to processing based on legitimate interests, and to direct marketing at any time
- Withdraw consent: withdraw any consent you have given, as easily as you gave it
- Automated decisions: request human review of any decision made solely by automated means that significantly affects you
To exercise any right, email our DPO at dpo@harveyslegal.com or contact support@certivus.com. We respond within one month, free of charge. If your request concerns a check run at the instruction of your accountant or solicitor, we may refer the request to that firm (as controller) and will tell you if so.
9. Cookies
Non-essential cookies are set only with your consent, collected through the banner shown on your first visit. You can change or withdraw your choices at any time via "Cookie settings" in the footer. Our Cookie Policy lists every cookie and tracking technology we use.
10. Complaints and contact
If you have a question or concern about how we handle personal data, contact our Data Protection Officer first. We take every concern seriously:
Data Protection Officer (Harveys Legal)
Email: dpo@harveyslegal.com
Certivus Compliance Ltd, 64 Yardley Green Road, Birmingham B9 5QE, United Kingdom
You also have the right to complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We are registered with the ICO under registration number ZC189266.
11. Changes to this policy
We review this policy at least annually and whenever our processing changes. Material changes are posted here with an updated date, and customers are notified by email where the change affects how their data or their clients' data is processed.