Certifii Ltd — Company number 16705678 — Registered office: 128 City Road, London EC1V 2NX.
1. Introduction
This Product Privacy Notice explains how Certifii Ltd collects, uses, stores, and shares personal data when you use the Certifii platform and related services (the "Service"). It should be read alongside our Product Terms of Service. Terms defined in the Terms have the same meaning here. Where this notice and the Terms address the same topic, the Terms prevail.
Our Website Privacy Notice covers personal data collected through our marketing website. This notice covers only personal data processed through the Service itself.
2. Who we are
Certifii Ltd is a company registered in England and Wales under company number 16705678. For the purposes of Data Protection Laws, we act as both a data controller and a data processor depending on the type of data and the purpose of processing (see Section 4). Our data protection contact is legal@certifii.com.
3. Who this notice applies to
- Investor Users — investors, venture funds, and advisors who subscribe to screen, assess, and monitor companies.
- Lender Users — banks, funds, and alternative lenders who subscribe to assess, triage, and monitor companies.
- Company Users — companies that create accounts and submit data, whether directly or via an onboarding link.
- Subscribers — Users with active paid subscriptions or Order Forms.
- Report recipients — individuals who receive or view shared Reports.
- Data subjects within Submitted Data — directors, officers, shareholders, PSCs, and other individuals whose personal data appears in User submissions.
4. Our roles under Data Protection Laws
4.1 When we are a data controller
- Account data — the information you provide when creating an account.
- Provider Data — data sourced from public registries such as Companies House, the FCA Register, The Gazette, and OpenCorporates.
- Platform operations data — technical logs, security logs, authentication records, and the audit trail.
- Aggregated Data — de-identified, aggregated intelligence derived from platform activity.
- AI model training on Aggregated Data.
- Usage analytics — features used, pages visited, session data.
- Beta and free-tier activity — reviewed for product development and quality assurance.
4.2 When we are a data processor
We act as a data processor where we process personal data contained within Submitted Data on your documented instructions to deliver the Service. Our processing as processor is governed by the Data Processing Addendum attached to the Terms.
5. What personal data we collect
5.1 Data you provide directly
- Account registration data — name, email, organisation, job title, phone number.
- Submitted Data — including personal data within management accounts, governance documentation, pitch decks, or onboarding responses.
- Third-party authentication data (e.g., Sign in with Apple).
- Communications — emails, support requests, feedback.
5.2 Data we collect automatically
- Technical data — IP address, browser, OS, device identifiers.
- Usage data — features accessed, pages visited, timestamps.
- Audit trail — every Submitted Data input is logged with date, time, and User identity.
- Authentication data — login timestamps, MFA events, session tokens.
- Mobile application data — device model, OS version, app version. We do not access contacts, photos, camera, microphone, or location.
5.3 Data we obtain from third parties
Provider Data — personal data contained in public registry filings and open data sources, including director names, registered office addresses, appointment dates, shareholdings, and PSCs.
6. How and why we use personal data
6.1 Providing the Service
Lawful basis: performance of a contract (Article 6(1)(b)).
6.2 AI-powered analysis
Lawful basis: performance of a contract. Third-party AI providers are sub-processors and are not permitted to use Submitted Data to train their own models.
6.3 Audit trail
Lawful basis: legitimate interests (Article 6(1)(f)).
6.4 Platform security and operations
Lawful basis: legitimate interests.
6.5 Product development and improvement
Lawful basis: legitimate interests. AI model training uses only Aggregated Data (de-identified).
6.6 Aggregated intelligence
Once de-identified, Aggregated Data is no longer personal data. Creation from personal data is processed under legitimate interests.
6.7 Communications
Lawful basis: performance of a contract and legitimate interests.
6.8 Legal compliance
Lawful basis: legal obligation and legitimate interests.
7. Who we share personal data with
7.1 Within the Service
Where a Company User submits data through an Investor User's or Lender User's Deal Triage or Portfolio Monitoring licence, the Investor User or Lender User will see the Reports and outputs derived from that data.
7.2 Sub-processors
We use cloud infrastructure providers, third-party AI infrastructure providers, and subscription management and payment processing providers. A list of current sub-processors is available on request by emailing legal@certifii.com.
7.3 Third parties
We do not sell personal data. We do not share identifiable Submitted Data with third parties for their own purposes. We may share with payment processors, professional advisors, regulators, or a business successor.
7.4 Aggregated Data
Aggregated Data is de-identified and is not personal data. We may license aggregated benchmarks and analytics to third parties.
8. International data transfers
We store personal data in the United Kingdom. Where a transfer outside the UK is necessary, we rely on the UK IDTA or the UK Addendum to the EU Standard Contractual Clauses.
9. How long we keep personal data
9.1 Account data
Retained for the duration of your account and a reasonable period afterwards.
9.2 Personal data within Submitted Data
Deleted or returned within 90 days of termination, in accordance with the DPA.
9.3 Non-personal business data
Not personal data. Retained for the duration of the Terms and thereafter. Data subject rights, including erasure, apply only to personal data.
9.4 Aggregated Data and Derived Data
Survive termination indefinitely. Certifii's property.
9.5 Audit trail and logs
Retained as necessary for integrity, accountability, compliance, and defence of legal claims.
9.6 Provider Data
Retained and updated as part of the Service's ongoing operations.
10. Your rights
- Access — request a copy of the personal data we hold about you.
- Rectification — correct inaccurate personal data.
- Erasure — applies only to personal data, not to non-personal business data submitted to the Service.
- Restriction, Portability, and Objection.
To exercise these rights, contact legal@certifii.com. We will respond within one month. You may also complain to the ICO.
11. Security
We implement encryption of data in transit and at rest, access controls and role-based permissions, and regular security assessments and monitoring.
12. Automated decision-making and AI
The Service uses automated processing to generate scores, analytics, and Reports. These are decision-support tools only — not credit ratings, financial advice, or recommendations. No automated decision with legal or similarly significant effects is made solely by Certifii about any individual. You may not rely on any output as the sole basis for any investment, lending, credit, or other business decision.
13. Cookies and similar technologies
The Service uses cookies for authentication, security, and analytics. See our Cookie Policy.
14. Children
The Service is for business and professional use only and is not intended for individuals under 18.
15. Changes to this notice
We will give at least 30 days' notice of material changes.
16. Relationship to the Terms of Service
This notice should be read alongside the Certifii Product Terms of Service. All disclaimers and limitations of liability relating to the Service and its outputs are contained in the Terms.
17. Contact us
Email: legal@certifii.com — Certifii Ltd, 128 City Road, London EC1V 2NX. Company number 16705678.
This Product Privacy Notice was last updated in March 2026.
