Privacy Policy

Privacy Policy

Last updated: 01 September 2025
Plain English: We run privacy-first systems. We only handle personally identifiable information (PII) when you directly share contact details with us (e.g., emailing us). Otherwise, we do not collect, process, or store PII.
Who we are

CertM8 ("we", "us") is the controller for the limited personal data we handle. Registered address: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ.

Contact: [email protected].

Scope

This policy covers our websites, products, and services (the "Services"). It explains what we collect, why, and your rights.

Our stance on PII

We do not collect or process PII from users or visitors, except in the following cases:

  • Contacts: when you reach out to us (e.g., name, email, phone) to respond to your inquiry.
  • Partners & suppliers: business contact details needed to perform a contract or maintain our relationship.

Outside of these cases, we do not process data that identifies an individual.

What we do collect (non-PII)

To keep our Services reliable, we may process non-PII such as de-identified operational metrics and system logs (e.g., request counts, uptime, error rates). These do not identify an individual.

No tracking of individuals

We do not create user profiles, perform interest-based advertising, or sell personal data.

Cookies & analytics

We use only strictly necessary cookies for security and core functionality. We do not use cookies or analytics that capture PII. Any analytics used are aggregated and de-identified.

Lawful bases (UK/EU)

For contacts and partners only, we process limited PII under:

  • Legitimate interests (e.g., reply to your message, manage B2B relationships).
  • Contract (e.g., perform our agreement with you/your company).
  • Legal obligation (e.g., record-keeping, compliance).
Sharing

We do not sell or rent data. We may share limited contact information with:

  • Service providers acting on our instructions (bound by confidentiality & data protection terms).
  • Authorities when required by law.
Retention

Contact and partner details are kept only as long as necessary for our relationship, to provide Services, or to meet legal requirements - then securely deleted.

Security

We apply reasonable technical and organisational measures to safeguard the limited PII we may hold for contacts and partners, and to protect non-PII operational data.

International transfers

If we transfer contact or partner data outside the UK/EEA, we use appropriate safeguards (e.g., Standard Contractual Clauses) where required.

Your rights

If we hold your contact/partner details, you can request access, correction, deletion, or restriction/objection (where applicable). To exercise rights, email [email protected].

UK/EU residents can also lodge a complaint with a supervisory authority (e.g., the ICO in the UK).

Children

Our Services are not directed to children. We do not knowingly collect children's data.

Changes to this policy

We may update this policy from time to time. We will post changes here and revise the "Last updated" date above.

Contact

Data Controller: CertM8 Ltd

Address: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ

Email: [email protected]

We do not process PII except for contacts and partners required for communication, contracts, or legal obligations.