Privacy Policy
Last updated: 25 September 2026
This policy explains how Certivus Compliance Ltd ("Certivus", "we", "us") collects and uses personal data in connection with our website, our AML compliance platform, and the identity verification services we provide to UK accountancy firms and law firms. We process personal data in accordance with the UK GDPR and the Data Protection Act 2018.
Data controller: Certivus Compliance Ltd, a company registered in England and Wales (Company No. 17319995)
Registered office: 64 Yardley Green Road, Birmingham B9 5QE, United Kingdom
ICO registration: ZC189266
Data Protection Officer: Harveys Legal; [email protected]
1. Who this policy covers
We handle personal data in three distinct situations:
- Website visitors: people browsing certivus.com, requesting a demo, downloading resources, or subscribing to our newsletter.
- Customers and their users: accountancy and law firms that subscribe to the Certivus platform, and the individuals at those firms who use it.
- End clients of our customers: individuals asked by their accountant or solicitor to complete an identity verification or AML check through Certivus. If that is you, section 3 below and our dedicated identity verification privacy notice explain exactly what happens to your data.
2. What we collect, why, and our lawful basis
| Purpose | Personal data | Lawful basis (UK GDPR Art. 6) |
|---|---|---|
| Operating and securing this website | Device and usage data, IP address, pages visited | Legitimate interests (running and protecting our website) |
| Responding to enquiries, demo bookings, and support requests | Name, email, phone, firm name, message content | Legitimate interests / steps prior to entering a contract |
| Providing the Certivus platform to customer firms | Account, user, and billing data | Performance of a contract |
| Processing identity verification and screening checks instructed by a customer firm | End-client identity data (see section 3) | We act on the instructing firm's behalf; the firm establishes the lawful basis (typically legal obligation under MLR 2017) |
| Sending service messages about a check, and recording whether they arrived | Email address, mobile number, and delivery events for each message (delivered, link clicked, bounced, reported as spam) with the time each happened | Legitimate interests in knowing a message actually reached the person it was sent to, and in not sending again to an address that has bounced. Where the recipient is a customer firm's client, we do this on that firm's instruction. This is separate from marketing email below, which relies on consent. |
| Sending marketing emails and newsletters | Name, email, firm details | Consent (or soft opt-in for existing customers), with an unsubscribe link in every email |
| Analytics and advertising cookies | Cookie identifiers, usage data | Consent, collected through our cookie banner |
| Complying with law, regulation, and requests from authorities | Any of the above, as required | Legal obligation |
Where we rely on legitimate interests, we have carried out a balancing assessment and concluded our interests do not override your rights. You can request a summary of any assessment from our DPO.
2a. Your Rajoka ID
Your account is a Rajoka ID, a single sign-in for Rajoka group services, operated by a company in the Rajoka group named in Rajoka ID's own privacy notice. We create it for you when you sign up here; you do not need a second registration. Rajoka ID holds your name, the email addresses you verify, your sign-in security settings (including two-factor methods) and a record of which Rajoka services you use. It does not hold the data you enter inside those services. You can see and manage your Rajoka ID, and the services connected to it, at identity.rajoka.com, and you can delete it there; deleting it removes your access to every connected service.
2b. Spaces created by a partner app
If you arrived here because your firm uses Bryxo or Clineso, that app created your firm's space in Certivus when you signed up there, and sent us your firm's name and company registration number, your Rajoka ID and email address, and a reference for your account in that app. The partner app may then open checks on your instruction, using access that is limited to your firm's space only. It cannot see any other customer's space, and we cannot see anything in the partner app beyond what it sends us for your firm.
Bryxo is operated by a company in the Rajoka group, named in its own privacy notice. Clineso is operated by a company in the Rajoka group, named in its own privacy notice.
The space is yours: you can sign in here directly with the same Rajoka ID, and it stays with you, with all its records, if you leave the partner app. Records are retained for the periods stated in the Retention section, whether or not you remain a customer of the partner app.
A partner app may ask us whether a person is a member of your firm and in what role, so that it can decide what that person may do; we answer only yes or no and the role, and only for firms the partner app created or attached.
2c. Connected AI assistants
If you connect Certivus to an AI assistant, it can request information and take approved actions. Access is limited to that assistant, your account, selected firm, and permissions in Settings > Integrations.
The connector may return the following information to the assistant:
- Find clients: client details, risk and compliance status, residence and nationality, monitoring status, and review dates.
- Client status: client details, identity and AML screening results including any matches, risk assessment history and answers, and unresolved matters.
- Compliance health: the firm's score and traffic light, areas needing attention, and action totals by priority.
- Prepare a check: the client's name, check type, current price, and expiry. It creates no verification case and charges nothing.
- Start a check: the verification case reference and whether the request already completed. It charges the firm's prepaid balance at the price shown.
- Get a risk assessment: the current risk level, next review date, active questions, and answers.
- Propose a risk update: the meeting transcript you choose to send, meeting date, proposal summary, and review link. The live assessment changes only after MLRO approval.
- List pending risk reviews: client names, meeting dates, change counts, creation dates, and review links. It excludes transcripts, quotes, and proposed answers.
The assistant provider, such as Anthropic or OpenAI, processes your prompt, tool input, and Certivus results under its own terms, privacy notice, and account settings.
The connector receives only information sent in a tool call. It does not independently read your chat history, assistant memory, or files. A transcript is received only when you choose to send it for a draft risk update.
For each tool call, Certivus logs the assistant, user, firm, tool, time, outcome, IP address, and browser or app details. The response itself is not stored.
We keep these records for 12 months and then delete them.
You can revoke access in Settings > Integrations. This stops the next tool call. You must grant access again to reconnect.
3. Identity verification checks: who is responsible for what
When a firm uses Certivus to verify the identity of one of its own clients, that firm is the data controller for its client's personal data. The firm decides to run the check because of its own obligations under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 ("MLR 2017"). Certivus provides the platform and passes the check through to our verification and data partners on the firm's behalf and on its documented instructions.
The verification journey works like this:
- The firm initiates a check on its client. The client receives a link and lands on a verification page that clearly identifies which firm requested the check.
- The client is shown the firm's privacy terms and this notice before any data is captured.
- Identity data (for example, a passport or driving licence, a selfie for biometric comparison, name, date of birth, and address) is collected and checked against document, biometric, and database sources provided by our verification and data partners, which may include UK credit reference agencies.
- The result is returned to the instructing firm's own segregated workspace as part of its client file. Each firm's data is segregated from every other firm's.
Credit reference agency searches. Some checks verify identity against records held by UK credit reference agencies. These are soft searches: they leave a record on the individual's credit file that is visible to them but not to lenders, and they do not affect credit scores. On any such search, Certivus is identifiable as the entity conducting the search on the instructing firm's behalf. The credit reference agencies also process personal data in their own right, as described in the Credit Reference Agency Information Notice (CRAIN), published on each agency's website.
Biometric data. Where a check includes facial matching, biometric data (special category data under UK GDPR Art. 9) is processed with the individual's explicit consent, captured during the verification journey before the check runs.
4. Who we share personal data with
We share personal data only where necessary to run the service, and never sell it. Recipients fall into these categories:
- Identity verification and data partners: regulated providers of document, biometric, database, and PEP/sanctions screening checks, including UK credit reference agencies, engaged to perform the checks our customers instruct.
- Infrastructure providers: hosting, database, content delivery, and email delivery services.
- Payment processors: for subscription billing.
- Analytics and advertising providers: only with your cookie consent (see our Cookie Policy).
- Professional advisers and group companies: where needed for legal, accounting, insurance, or lead-handling purposes.
- Authorities and regulators: where required by law, or to establish, exercise, or defend legal claims.
The current list of sub-processors, with locations and transfer safeguards, is published on our sub-processors page and kept up to date.
5. International transfers
Platform data, including identity verification records, is stored in the United Kingdom. Where a service provider processes limited personal data outside the UK or EEA (for example, a US-based email or analytics provider), we rely on UK adequacy regulations or put in place the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, plus any additional safeguards required. Details for each provider are on our sub-processors page.
6. How long we keep data
| Category | Retention period |
|---|---|
| Customer account and billing records | Duration of the contract, then up to 7 years after account closure (tax, accounting, and limitation-period requirements) |
| Identity verification and screening records processed for a customer firm | The retention period set by the instructing firm, typically 5 years after the end of the firm's business relationship with its client, as required by Regulation 40 of the MLR 2017 |
| Message delivery records (email and WhatsApp) | Kept alongside the check they relate to, so they follow that record's retention period. Records that an address bounced or reported us as spam are kept until you ask us to contact that address again, so we do not keep writing to it |
| Enquiry, demo, and support correspondence | Up to 3 years from last contact |
| Marketing data | Until you unsubscribe or ask us to stop; suppression records kept so we don't contact you again |
| Website analytics data | Up to 26 months |
When a retention period ends, data is deleted or irreversibly anonymised.
7. Security
We apply technical and organisational measures appropriate to the sensitivity of AML and identity data, including:
- Encryption in transit (TLS 1.3) and at rest (AES-256)
- UK data residency for platform data
- Role-based access controls, multi-factor authentication, and audit logging
- Segregation of each customer firm's workspace and data
- Published sub-processors and a stated retention period for every category of record
More detail is on our security page. If we suffer a personal data breach likely to result in a risk to individuals, we will notify the ICO within 72 hours and affected individuals where the risk is high, as UK GDPR requires.
8. Your rights
Under the UK GDPR you have the right to:
- Access: ask for a copy of the personal data we hold about you
- Rectification: ask us to correct inaccurate or incomplete data
- Erasure: ask us to delete your data, subject to legal retention duties (for example, AML record-keeping)
- Restriction: ask us to limit how we process your data while a query is resolved
- Portability: receive data you provided to us in a machine-readable format
- Objection: object to processing based on legitimate interests, and to direct marketing at any time
- Withdraw consent: withdraw any consent you have given, as easily as you gave it
- Automated decisions: request human review of any decision made solely by automated means that significantly affects you
To exercise any right, email our DPO at [email protected] or contact [email protected]. We respond within one month, free of charge. If your request concerns a check run at the instruction of your accountant or solicitor, we may refer the request to that firm (as controller) and will tell you if so.
9. Cookies
Non-essential cookies are set only with your consent, collected through the banner shown on your first visit. You can change or withdraw your choices at any time via "Cookie settings" in the footer. Our Cookie Policy lists every cookie and tracking technology we use.
10. Complaints and contact
If you have a question or concern about how we handle personal data, contact our Data Protection Officer first. We take every concern seriously:
Data Protection Officer (Harveys Legal)
Email: [email protected]
Certivus Compliance Ltd, 64 Yardley Green Road, Birmingham B9 5QE, United Kingdom
You also have the right to complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We are registered with the ICO under registration number ZC189266.
11. Changes to this policy
We review this policy at least annually and whenever our processing changes. Material changes are posted here with an updated date, and customers are notified by email where the change affects how their data or their clients' data is processed.
