Skip to content
Legal

Privacy Policy

How Certivo collects, uses and protects personal data, and the rights available to individuals under the EU GDPR and the Cyprus Data Protection Law 125(I)/2018 (and comparable laws such as the UK GDPR and CCPA/CPRA where they apply).

1. Who we are & our role

Certivo provides an enterprise compliance platform. This policy is issued under the UK General Data Protection Regulation (EU GDPR) and the Cyprus Data Protection Law 125(I)/2018, and, where the EU GDPR applies to particular processing, under that regulation. Our role depends on the data. For account data about the people who administer and use our service, Certivo is the controller. For the verification, screening and case data that customers submit about their own end users, Certivo acts as a processor on the customer's documented instructions; that processing is governed by our Data Processing Addendum. Our data-protection contact is privacy@certivo.uk (the point of contact for our data-protection / DPO function).

2. Data we collect

  • Account data: name, work email, organisation, role and authentication data.
  • Usage & technical data: log data, device and browser information, IP address and product-interaction events.
  • End-user verification / screening data (as processor): identity documents, biometric or liveness signals, screening and KYB results — processed only on the controlling customer's instructions.

3. How & why we use data — legal bases

We use account and technical data to provide, secure and improve the Services, to communicate with customers, and to meet legal obligations. Our legal bases are: performance of a contract (delivering the Services), legitimate interests (securing and improving the platform, subject to a balancing test), legal obligation (financial-crime, tax and accounting duties), and consent (optional cookies and marketing, where required). End-user data is processed on the customer's legal basis and instructions.

4. Sharing & sub-processors

We share personal data with vetted service providers who process it on our behalf under contract, including infrastructure, identity, screening, KYB and email providers. We do not sell personal data. See our Sub-processors list. We may also disclose data where required by law or to protect our rights and users.

5. International transfers

Where personal data is transferred outside the European Economic Area (EEA), we rely on an appropriate safeguard: an EU adequacy decision, or the EU Standard Contractual Clauses, together with a transfer risk assessment and any supplementary measures required. Enterprise customers can configure regional data residency.

6. Retention

We retain personal data only as long as necessary for the purpose for which it was collected, to provide the Services, or to meet legal, accounting and financial-crime requirements, after which it is deleted or anonymised. Retention of end-user data follows the controlling customer's configuration and the terms of the DPA.

7. Security

We maintain technical and organisational measures appropriate to the risk, including encryption in transit and at rest, access control, tenant isolation and audit logging. See our Security page for detail.

8. Your rights

Under the EU GDPR and the Cyprus Data Protection Law 125(I)/2018 you have rights to be informed, and to access, rectify, erase, restrict or object to processing, to data portability, and to withdraw consent where processing relies on it — exercisable without detriment. California residents have rights to know, delete, correct and to opt out of sale or sharing — Certivo does not sell or share personal information as those terms are defined under the CCPA/CPRA. Where Certivo processes data as a processor, please direct requests to the controlling customer; we will assist them in responding. To exercise rights against Certivo as controller, contact privacy@certivo.uk.

9. Cookies

Our use of cookies and similar technologies is described in our Cookie Policy.

10. Children

The Services are intended for businesses and are not directed to children. We do not knowingly collect personal data from children.

11. Changes & contact

We may update this policy from time to time; material changes will be signposted here. For privacy questions, or to reach our data-protection contact, email management@certivo.uk. If you are not satisfied with how we handle your data, you have the right to lodge a complaint with the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus, at dataprotection.gov.cy — we would, however, appreciate the chance to address your concern first. Individuals in another EEA state may complain to their local supervisory authority. You may also raise concerns through our Complaints process.

Company details

Registered entity namePuzzle Piece Ventures Ltd
Company numberHE 469272
Registered office[Registered office — Cyprus, to be confirmed]
JurisdictionRepublic of Cyprus
Governing lawthe Republic of Cyprus
GroupOnyxOne Group
General enquiriesmanagement@certivo.uk

Any bracketed value is a registration detail to be confirmed by the operating entity.

Last updated: 20 July 2026.

This document is published by Certivo (Puzzle Piece Ventures Ltd) and is governed by the laws of the Republic of Cyprus. Questions about it can be directed to management@certivo.uk. It does not constitute legal advice; you should take your own advice on how it applies to your circumstances.