Certifii Ltd — Company number 16705678 — Registered office: 128 City Road, London EC1V 2NX.
Legal docs referenced: Website Privacy Notice, Product Privacy Notice, Data Processing Addendum (Annex, below).
1. Introduction
Welcome to Certifii. These Product Terms of Service ("Terms") are a legal agreement between you and Certifii Ltd, a company registered in England and Wales under company number 16705678 ("Certifii", "we", "us", "our"). By creating an account, accessing the platform, using any of our services, or viewing a shared report, you agree to these Terms. If you are accepting on behalf of an organisation, you confirm you have the authority to bind that organisation. If you do not agree, do not use the Service.
2. Definitions
- "Aggregated Data" — data derived from Submitted Data, Provider Data, or usage of the Service that has been combined and de-identified so it cannot reasonably be linked back to any individual User, company, or person.
- "Company User" — a company that creates an account and submits data for scoring, analysis, or monitoring.
- "Derived Data" — all scores, analytics, models, reports, benchmarks, insights, and intelligence generated by the Service.
- "Investor User" — a User who subscribes to screen, assess, triage, or monitor companies.
- "Lender User" — a User who subscribes in connection with lending, credit, or debt facilities. References to Investor Users apply equally to Lender Users unless the context requires otherwise.
- "Order Form" — a document or online sign-up flow specifying products, tier, fees, and additional terms.
- "Provider Data" — data sourced from public registries and third-party providers, including Companies House, the FCA Register, The Gazette, and OpenCorporates.
- "Report" — any output generated by the Service, including sCTI reports, eCTI reports, evidence packs, triage outputs, dashboards, and monitoring outputs.
- "Service" — the Certifii platform and all related products, features, and functionality.
- "Submitted Data" — any data, content, or materials a User uploads or provides to the Service. Belongs to the User who submitted it.
- "Subscriber" — a User with an active paid subscription or Order Form.
- "User" — any individual or organisation that creates an account on, accesses, or uses the Service.
3. The Service
3.1 What Certifii does
Certifii is a private capital intelligence platform. We generate AI-powered trust scores and analytical reports on UK private companies. Our outputs are decision-support tools — analytical confidence indicators. They are not credit ratings, financial advice, investment advice, legal advice, or compliance advice.
3.2 Our products
Standard CTI (sCTI) — an AI-generated trust score compiled entirely from publicly available data.
Enhanced CTI (eCTI) — an enhanced trust score built on verified data the scored company provides directly, via Funding Readiness or Deal Triage.
Portfolio Monitoring — ongoing tracking of actuals versus forecast (the Say-Do Score).
Dashboard — continuous monitoring and alerts for subscribed Investor Users and Lender Users.
Knowledge Management — an enterprise knowledge management platform for existing contracted clients, governed by separate Master Service Agreements.
3.3 Beta and free access
We may offer free or beta access at our discretion. During beta, no fees are payable; we may withdraw or convert access; we may impose usage limits; and searches and Report outputs may be visible to the Certifii team for product development and quality assurance.
3.4 Mobile applications
Use of any mobile application is also subject to the app store operator's terms. To the extent required by Apple's terms, Apple Inc. and its subsidiaries are third-party beneficiaries of these Terms.
4. Users and Access
The Service is for business and professional use only. You must provide accurate information and maintain the security of your login credentials. Investor Users and Lender Users have equivalent rights and obligations. Company Users are bound by these Terms whether or not they have a direct commercial relationship with Certifii. Recipients of shared Reports have view-only rights.
5. How We Use AI
5.1 AI-generated outputs
Reports, scores, and analytics are generated by automated systems — not human analysts. AI outputs may contain errors. You must apply your own professional judgement and carry out independent verification before making decisions based on our outputs.
5.2 Third-party AI infrastructure
We use third-party AI and data processing providers as sub-processors. We do not permit them to use Submitted Data to train their own models.
5.3 Bespoke agents (future feature)
When launched, Users will own their agent configurations. Derived Data generated by bespoke agents belongs to Certifii. Detailed terms will be set out in an Order Form or product addendum.
6. Data
6.1 Submitted Data — ownership
You retain ownership of Submitted Data. By submitting data, you grant Certifii a licence to process it as necessary to provide the Service.
6.2 Responsibility
The User who submits data is responsible for its accuracy, completeness, and legality. Company Users are solely responsible for data presented to Investor Users or Lender Users.
6.3 How we use Submitted Data
To generate scores and Reports, run financial analysis, track actuals vs forecast, and power AI-driven analysis. We will not share identifiable Submitted Data with third parties except as necessary to provide the Service, as required by law, or with your consent.
6.3A Developing and calibrating the Service
You grant Certifii a perpetual, irrevocable, worldwide, royalty-free right to use Submitted Data — and the non-personal business data within it — to develop, train, calibrate, validate, benchmark and improve the Service. Certifii exercises this right internally. This survives termination.
6.4 Visibility
Investor Users and Lender Users see Reports and outputs, not underlying raw Submitted Data unless the Report expressly displays specific data points. Funding Readiness lets the company control sharing.
6.5 Aggregated Data
De-identified data belongs to Certifii and can be used for any business purpose, including benchmarks, model training, product development, and licensing. We will never license or share identifiable Submitted Data with third parties for their own purposes.
6.6 Provider Data
Sourced from public registries and third-party providers. We do not independently verify accuracy or timeliness and accept no liability for the accuracy of Provider Data or outputs derived from it.
6.7 Audit trail
All Submitted Data inputs are recorded with date, time, and User identity. The audit trail is Certifii's property.
6.8 Retention of non-personal business data
Data subject rights, including the right to erasure, apply only to personal data. They do not apply to non-personal business data such as financial forecasts, management accounts, or governance documentation.
6.9 Termination
Personal data within Submitted Data is deleted or returned within 90 days. Non-personal business data may be retained. Aggregated Data and Derived Data survive termination indefinitely.
6.10 Data export and access restrictions
You may not access, extract, or reverse-engineer Certifii's algorithms, scoring models, weighting factors, or underlying methodology. Scraping, screen-capture, automated extraction, and browser extensions used to bypass restrictions are prohibited. Breach is a material breach of these Terms.
7. Intellectual Property
Certifii owns the Service, Documentation, Provider Data, Derived Data, the proprietary intelligence database, the AI architecture, the scoring methodology, the CTI framework, and all benchmarks. To the extent any IP rights in Derived Data might vest in you, you assign them to Certifii. You retain ownership of Submitted Data. We grant you a limited, non-exclusive, non-transferable, revocable licence to use the Service during your subscription.
8. Sharing and Distribution
You may share Reports using the platform's built-in sharing features. Recipients get view access only. By sharing, you consent to the recipient's access and are responsible for sharing securely. You may download Reports as PDFs for internal business purposes. You must not systematically redistribute, resell, or republish Reports, operate a bureau service, or remove attributions.
9. Scored Companies
Under sCTI we generate reports on companies using publicly available data; the scored company does not participate and is not a party to these Terms. Reports reflect what a counterparty can verify from public sources and surface gaps. Under eCTI and Portfolio Monitoring, a company that submits data becomes a User and is bound by these Terms.
10. What We Are Not
- Certifii is not a credit rating agency.
- Certifii is not authorised or regulated by the Financial Conduct Authority.
- The CTI score is an analytical confidence indicator, not a credit rating, credit opinion, or credit assessment.
- Nothing in the Service constitutes financial, investment, credit, legal, or compliance advice.
- The absence of adverse findings in a Report does not constitute clearance, endorsement, or approval.
You must apply professional judgement and seek independent professional advice where appropriate.
11. Subscriptions and Payment
Annual subscriptions have a 12-month minimum and auto-renew; give at least 3 months' notice to cancel, no earlier than month 9. Monthly subscriptions have a 3-month minimum. Fees are exclusive of VAT; invoices due within 14 days; interest on overdue amounts at 4% above the Bank of England base rate. Upgrades are pro-rated; downgrades take effect at renewal. No refunds. For in-app purchases via the App Store, billing is handled by the marketplace operator.
12. Acceptable Use
- No unlawful use of the Service.
- No attempt to access unauthorised parts.
- No reverse-engineering, decompiling, or disassembly.
- No scraping, crawling, screenshotting, or bulk-extraction beyond provided download features.
- No attempt to reconstruct algorithms or scoring methodology.
- No interference with the Service or its infrastructure.
- No use to build a competing product.
- No misrepresentation of Certifii outputs as your own analysis or as a regulated rating.
- No false, misleading, or fraudulent data.
13. Confidentiality
Each party keeps the other's confidential information confidential. Submitted Data is confidential and belongs to the User. Aggregated Data is not confidential (de-identified). Derived Data is not your confidential information (it is Certifii's IP). Order Form terms are confidential.
14. Data Protection
Certifii acts as controller for Provider Data, platform operations, security logs, Aggregated Data, and AI training on Aggregated Data. Where we process personal data within Submitted Data on your instructions, we act as processor under the DPA (Annex). See our Website Privacy Notice and Product Privacy Notice. A list of sub-processors is available on request. During beta or free-tier, we may review activity for product development and quality assurance as a controller.
15. Disclaimers
The Service is provided "as is" and "as available." To the maximum extent permitted by law: no warranties of merchantability, fitness for a particular purpose, or non-infringement; no guarantees of availability, accuracy, completeness, timeliness, or reliability; AI outputs may contain errors; the Service is not a credit rating and not a substitute for independent professional advice; the absence of adverse findings is not clearance, endorsement, or approval; Certifii owes no duty of care to any User, Subscriber, report recipient, or third party; you may not rely on any output as the sole basis for any decision.
16. Limitation of Liability
Our total aggregate liability is limited to fees paid by the relevant Subscriber in the 12 months preceding the claim (or the cap in the Order Form). Neither party is liable for loss of profits, revenue, business, goodwill, or anticipated savings, or indirect, consequential, special or incidental losses. Nothing excludes liability for death or personal injury caused by negligence, fraud, or fraudulent misrepresentation. You indemnify Certifii against claims arising from your Submitted Data or breach of these Terms.
17. Term and Termination
Terms begin when you create an account or first access the Service. Either party may terminate by giving notice per Section 11, or immediately on material breach not remedied within 30 days, or on insolvency. On termination: access ends; personal data within Submitted Data is deleted or returned within 90 days; non-personal business data may be retained; Aggregated Data and Derived Data survive; Section 6.3A rights survive; outstanding fees remain payable.
18. Enterprise and legacy agreements
Where a Master Service Agreement or Order Form conflicts with these Terms, the MSA or Order Form prevails to the extent of the conflict.
19. Changes to These Terms
We may update these Terms with at least 30 days' notice of material changes. Continued use after changes take effect constitutes agreement.
20. General
Assignment. You may not assign without our consent; we may assign in a corporate transaction. Force majeure. Neither party is liable for delays beyond reasonable control. Entire agreement. These Terms plus any Order Form and the DPA. No partnership. Severability and Waiver as standard. Notices to legal@certifii.com or our registered office. Governing law: England and Wales. Jurisdiction: exclusive courts of England and Wales.
21. Contact us
Certifii Ltd, 128 City Road, London EC1V 2NX. Email: legal@certifii.com. Company number 16705678.
These Terms were last updated in March 2026.
Annex — Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of the Terms and sets out how we process personal data contained within Submitted Data on your behalf. Terms defined in the Terms have the same meaning here. "Data Protection Laws" means the UK GDPR, the Data Protection Act 2018, and successor legislation.
1. Scope and roles
This DPA applies where Certifii processes personal data within Submitted Data on your documented instructions. You are the controller; Certifii is the processor. It does not apply to processing where Certifii acts as controller (Provider Data, platform operations, security logs, Aggregated Data, AI training on Aggregated Data).
2. Details of processing
Subject matter: processing of personal data within Submitted Data as necessary to provide the Service. Duration: the duration of the Terms plus the 90-day post-termination period. Types of personal data: names of directors, officers, shareholders, and key personnel; contact details; financial information relating to identifiable individuals; employment and appointment details. Data subjects: directors, officers, shareholders, PSCs, key personnel.
3. Our obligations as processor
- Process personal data only on your documented instructions, unless required by law.
- Ensure authorised persons are bound by confidentiality.
- Implement technical and organisational security measures consistent with ISO 27001.
- Assist you with data subject requests, security, breach notification, DPIAs, and prior consultation.
- At your choice, delete or return personal data after the end of the Service.
- Make information available to demonstrate compliance and contribute to audits.
4. Sub-processors
You give general authorisation for Certifii to engage sub-processors. We notify you at least 30 days before adding or replacing a sub-processor. Sub-processors are bound by equivalent obligations, and we remain liable for their acts and omissions. Third-party AI infrastructure providers are sub-processors and are not permitted to use Submitted Data to train their own models.
5. International transfers
We will not transfer personal data outside the UK without appropriate safeguards, such as the UK IDTA or the UK Addendum to the EU SCCs.
6. Audits
You may audit our compliance once per year, or more frequently following a breach or where required by a supervisory authority, on at least 30 days' notice, at your cost. Where possible we will satisfy audit requests through certifications (such as ISO 27001) rather than on-site access.
7. Personal data breach notification
We will notify you without undue delay (and within 72 hours) after becoming aware of a personal data breach affecting Submitted Data, and cooperate with investigation and remediation.
8. Data subject requests
We will not respond to data subject requests directly unless you instruct us to do so or we are required by law. We will provide reasonable assistance. Data subject rights apply only to personal data.
9. Deletion and return of data
On termination, we will (at your choice) delete or return all personal data within Submitted Data within 90 days, unless required by law to retain it. This obligation does not apply to non-personal business data, Aggregated Data, Derived Data, or Provider Data.
10. Aggregated Data carve-out
Nothing in this DPA restricts Certifii's right to create, use, and retain Aggregated Data. Aggregated Data is not personal data and falls outside the scope of this DPA.
11. Contact
Email: legal@certifii.com — Certifii Ltd, 128 City Road, London EC1V 2NX.
