This Privacy Policy explains how CertFlow LTD (company number 17056886), a company registered in England and Wales whose registered office is 20 Wenlock Road, London, N1 7GU (CertFlow, we, us or our) handles personal data when you visit https://www.certflow.co.uk, enquire about or buy our services, use the CertFlow platform, mobile application, client portal, Network or public mini-sites, communicate with us, or otherwise deal with our business.
It is intended to provide the information required by Articles 13 and 14 of the UK GDPR. It should be read with our Cookie Policy, Data Processing Agreement and Terms & Conditions.
1. Who we are and how to contact us
CertFlow LTD is the controller for the business, account, website, billing, security and direct-relationship processing described in this Policy. We are registered in England and Wales under company number 17056886. Our registered office is 20 Wenlock Road, London, N1 7GU, and our trading address is Albion Chambers, Leeds, LS27 8DT.
For a privacy question, rights request or data-protection complaint, email info@certflow.co.uk with “Privacy” in the subject line, call 0114 392 2407, or write to our registered office. Please do not send identity documents until we ask for them through an appropriate channel.
2. When we are controller and when we are processor
2.1 CertFlow as controller
We decide why and how to process personal data about website visitors, prospects, Account users, customer administrators and billing contacts, suppliers, Network members in their direct relationship with us, and people who contact our support or business teams. For these activities, this Policy applies and you can exercise rights directly with us.
2.2 CertFlow as processor
A Customer normally decides why and how personal data in its operational workspace is used—for example employee and inspector records, client contacts, asset/site contacts, inspections, signatures, photos, qualifications, HR records, messages, jobs and certificates. For that Customer Personal Data, the Customer is controller and CertFlow acts as processor under the DPA.
If your data was placed in CertFlow by one of our Customers, please contact that Customer first. We will assist it with your request. We will not use Customer Personal Data for our own advertising or sell it. We may still act as controller for narrowly separated security, billing or legal-compliance records.
3. Who this Policy covers
- visitors to our website, public resources and Customer mini-sites;
- prospects, demo attendees, download recipients and people who send an enquiry;
- Customer owners, administrators, staff, inspectors, contractors and client-portal users;
- Network profile owners, members, reviewers, event participants, forum users and message recipients;
- supplier, partner, adviser and business contacts;
- people whose information a Customer asks us to process, where this Policy explains our processor role; and
- people who make a rights request, complaint or security report.
The Service is designed for businesses and adults. It is not directed to children, and we do not knowingly ask a child to create an Account. Customers must not give children platform access or upload children's data unless that use is lawful, necessary and appropriate for the Service.
4. Personal data we collect
| Category | Examples |
|---|---|
| Identity and contact | Name, work email, telephone number, job title, organisation, address, profile photo and professional identifiers. |
| Account and authentication | User ID, organisation membership, role, permissions, password hash, session and authentication events, invitation and recovery status. We do not see your plaintext password. |
| Subscription and transaction | Plan, seats, billing contact, invoices, payment status, Stripe customer/subscription references, tax and accounting records. Full card data is handled by the payment provider. |
| Website and enquiry | Contact/download form fields, requested resource, demo booking, correspondence, inspection workflow or sample report you choose to provide, and marketing preferences. |
| Technical, security and usage | IP address, device/browser/app version, timestamps, routes and features used, session identifiers, error reports, audit events, approximate location derived from network data, consent preference and diagnostic logs. |
| Network and public content | Organisation profile, public contact details, capabilities, regions, accreditations, posts, replies, reviews, messages, job applications, events and CPD records. Visibility depends on the feature and your settings. |
| Customer operational content | Companies, sites and addresses; asset and QR records; jobs; inspections; photos; annotations; signatures; certificates; schedules; qualifications; timesheets; availability; quotes; invoices; CRM and lead records; HR/workforce documents; client-portal requests; files and communications. We normally process this for the Customer. |
| Location and device capability | Site coordinates, geocoded addresses and—only when a user chooses a location-enabled or camera function—device location, camera images or scanned QR codes. |
| Communications and support | Emails, support requests, call notes, feedback, complaint records and the information needed to investigate and respond. |
You do not have to provide optional data. However, Account, organisation and billing information is needed to enter into and perform the subscription; authentication data is needed to secure access; and a form cannot be answered without its required fields. If required information is not provided, we may be unable to create an Account, provide a requested feature, take payment or respond.
5. Where personal data comes from
- Directly from you when you sign up, use features, complete a form, book a demo, communicate with us or change settings.
- From your organisation when an administrator invites you, assigns a role, imports records, gives you work or manages your Account.
- From Customers and users when they add client, employee, contractor, prospect or Network information to the Service.
- Automatically from devices and services through security logs, local storage, cookies, telemetry and similar technologies described in the Cookie Policy.
- From service providers such as our payment, authentication, email, scheduling, hosting and analytics providers.
- From public or professional sources such as Companies House, an organisation's website, professional directories and information a Network member makes public, where appropriate for verification, fraud prevention or business contact management.
6. Why we use personal data and our lawful bases
This section describes processing for which CertFlow decides the purpose as Controller. Where we access Customer operational content solely to provide, support or secure the subscribed Service on a Customer's instructions, CertFlow acts as Processor under the DPA; the Customer determines the relevant Article 6 basis and any additional condition.
| Purpose | Data commonly used | UK GDPR lawful basis |
|---|---|---|
| Create Accounts, authenticate users and administer access to subscribed functions | Identity, contact, Account, organisation, role, authentication and Account-usage data | Contract; legitimate interests in administering business Accounts where the contract is with an organisation. |
| Administer plans, payments, invoices and Customer relationships | Identity, contact, organisation, subscription and transaction data | Contract; legal obligation for tax/accounting; legitimate interests in credit control and records. |
| Respond to enquiries, demos, downloads and pre-contract requests | Contact, organisation, form, correspondence and sample data | Steps at your request before a contract; legitimate interests in responding to business enquiries. |
| Administer support, onboarding and service communications | Account, contact, support correspondence and relevant technical logs | Contract; legitimate interests in effective support and service operation. Access to Customer operational content for a support/import task is instructed Processor activity under the DPA. |
| Protect users, investigate misuse and keep the Service secure | Account, authentication, IP, device, audit, error, access and communications data | Legitimate interests in network/information security, fraud prevention and enforcing our Terms; legal obligation where applicable. |
| Operate and moderate Network/public features | Profile, posts, reviews, messages, verification and activity | Contract; legitimate interests in a trustworthy B2B community and preventing abuse. Publication occurs at the user’s/Customer’s instruction. |
| Measure and improve the public website | Consent choice, page/interaction, device and analytics identifiers | Consent for optional Google Analytics storage and related personal-data processing. |
| Understand and improve product reliability and use | First-party feature events, normalised routes, app version, session ID, errors and limited Account/organisation context; not the substantive content of Customer records | Legitimate interests in operating, troubleshooting and improving a B2B service. We minimise event properties and retain in-house telemetry for a limited period. |
| Send product news and relevant business marketing | Name, work email, organisation, interests and engagement/preferences | Consent where required; otherwise legitimate interests in B2B marketing where PECR permits. You can object or unsubscribe at any time. |
| Meet legal duties, establish or defend claims and support corporate transactions | Relevant Account, billing, Customer, security and communications records | Legal obligation; legitimate interests in legal rights, insurance, due diligence and business continuity. |
Where we rely on legitimate interests, the interests are stated above. We consider necessity, proportionality, reasonable expectations and potential impact, and apply safeguards. You may object as explained in section 13. We do not use the newer “recognised legitimate interest” basis for routine commercial processing; if a defined public-interest condition requires it, we will document and explain that use.
Where we rely on consent, you can withdraw it without affecting processing already carried out lawfully. Cookie consent can be changed on the Cookie Policy. Marketing emails include an unsubscribe method.
7. Special-category and criminal-offence data
We do not require special-category or criminal-offence data for an ordinary website enquiry or basic Account. However, a Customer's HR, competency, health-and-safety, occupational, absence, right-to-work, free-text, photo or document records may contain health information, trade-union information, ethnicity or other sensitive data. The Customer decides whether to enter that data and is responsible for an Article 9 condition, any Data Protection Act 2018 Schedule 1 condition, appropriate policy document and safeguards.
We process sensitive Customer Personal Data only on the Customer's documented instructions and under the DPA. Customers should minimise it, use access controls, avoid placing it in public fields, and contact us before introducing high-risk or large-scale sensitive processing. The Service is not designed to store full payment-card numbers.
8. Who receives personal data
We disclose personal data only where needed for the purposes above, under an appropriate contract or other legal basis. The principal provider categories and named services currently used are:
| Recipient | Service and data involved | Typical processing location |
|---|---|---|
| Supabase | Platform database, authentication, object storage and server functions; Account and Customer Data. The primary production project is configured in London. | United Kingdom primary region; limited provider/support processing may occur internationally. |
| Vercel | Hosting and delivery of the website and web application, deployment, performance and aggregate web/app analytics; request and technical data and public content. | Global edge network, including UK/EEA and United States. |
| Journey Mobile / PowerSync | Offline synchronization for supported native/mobile use; the operational records scoped to the signed-in user and device. | Configured cloud region; provider/subprocessor operations may include UK/EEA and other countries. |
| Resend | Transactional and service email; recipient name/address and message content or secure links. | United States and provider subprocessor locations. |
| Stripe | Subscription checkout, billing portal, payment, fraud prevention and invoice/payment status; Customer and billing contact/transaction data. Stripe may act as an independent controller for parts of payment processing. | United Kingdom, EEA, United States and global service locations. |
| Cloudflare | DNS, network delivery, abuse prevention and DDoS/security services used within our delivery chain; IP and request/security data. | Global network. |
| Web3Forms | Public contact, download and calculator form delivery; submitted name, work email, company, phone, message, requested resource and form results. | Provider and subprocessor locations, which may include the United States. |
| Calendly | Optional demo scheduling and embedded booking calendar; contact, appointment and device/interaction data. Calendly controls additional providers used in its booking experience. | United States and global provider locations. |
| Google Tag Manager and Google Analytics | Optional public-website analytics after consent; online identifiers, page/interaction and device data. Tag Manager delivers the configured analytics tag. | United Kingdom/EEA, United States and global Google infrastructure. |
| OpenStreetMap / Nominatim | Optional map tiles and site-address geocoding; address query, coordinates and technical request data. | United Kingdom/EEA and distributed service infrastructure. |
We may also share relevant data with the Customer that controls it; Authorised Users according to permissions; a person you ask us to contact; professional advisers, auditors and insurers under confidentiality; banks and payment participants; law-enforcement, regulators, courts or authorities where lawfully required; and a buyer, investor or successor in a genuine corporate transaction subject to appropriate confidentiality and safeguards.
We do not sell personal data. We do not provide Customer Data to data brokers or use it for third-party behavioural advertising. Public Network or mini-site content is visible according to the publishing choices made by the Customer or user.
9. International transfers
Some providers, affiliates or support teams process personal data outside the United Kingdom. A destination may not provide identical legal protection. Where a restricted transfer occurs, we use an applicable UK adequacy regulation or an appropriate safeguard such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another mechanism permitted by Data Protection Laws. We carry out the required data-protection/transfer assessment and apply supplementary technical or contractual measures where appropriate.
The UK Extension to the EU-US Data Privacy Framework is relied on only where the US recipient is actively certified and the transfer is in scope. Otherwise an Article 46 safeguard is required. You may ask info@certflow.co.uk for more information about the safeguard relevant to your data, subject to protection of confidential commercial terms.
10. How long we keep personal data
We retain personal data only for a documented business or legal need, then delete, anonymise or securely isolate it. The usual periods below may be shortened after a valid request or extended for a legal hold, dispute, security incident, regulatory duty or other documented reason.
| Record | Usual retention |
|---|---|
| Account, profile and organisation administration data | For the active subscription, then normally up to 90 days after termination before active deletion, except data needed for another period below. |
| Customer Data processed for a Customer | For the Subscription Term and exit period, then returned or deleted in accordance with the DPA and Customer instructions; if no instruction, active deletion is scheduled within 90 days after termination. Protected backups age out in the ordinary backup cycle. |
| Prospect, enquiry, demo and download records | Normally up to 24 months after the last meaningful interaction, unless you ask us to delete sooner or an active relationship/claim requires longer. Demo sample materials are removed when no longer needed for the agreed demo or onboarding purpose. |
| Support and ordinary business correspondence | Normally up to 24 months after the matter closes; longer where it forms part of the contract, a complaint, security case or legal record. |
| Invoices, payment and tax/accounting records | Normally 7 years from the relevant transaction or financial year, to support UK accounting, tax and legal obligations. |
| Security and in-house product telemetry | Event-level product telemetry is ordinarily purged after 180 days. Security, access and audit records vary by risk and Customer record requirements and are retained no longer than needed for investigation, accountability and legal claims. |
| Marketing contact records | Until you unsubscribe/object or after 24 months without meaningful engagement, unless another lawful relationship continues. A minimal suppression record may be kept indefinitely so we honour the opt-out. |
| Cookie consent and Google Analytics | The website consent preference is recognised for up to 180 days. Analytics cookie durations are listed in the Cookie Policy; provider-side data follows our configured retention and is reviewed periodically. |
| Data-protection requests and complaints | Normally 6 years after closure to evidence how the matter was handled, unless a shorter period is appropriate. |
Deletion from live systems does not always remove a record immediately from encrypted or otherwise protected backups. Backup copies are isolated from ordinary use, retained only for recovery/security, and deleted or overwritten through the normal lifecycle.
11. How we protect personal data
We use technical and organisational measures appropriate to the nature, context and risk of the processing. Measures include encrypted transport, managed encryption at rest, role-based access, organisation scoping and database row-level access controls, authentication and session controls, restricted administrative access, logging and monitoring, backups and recovery measures, secure development and change processes, incident handling, staff confidentiality, and processor due diligence. More detail is in the DPA and on our Security page.
Security is a shared responsibility and no system can promise absolute security. Customers must configure permissions, protect credentials and devices, remove leavers, verify recipients and exports, and avoid placing sensitive data in public or unrestricted fields. Please report a suspected vulnerability or data incident promptly to info@certflow.co.uk.
12. Marketing, cookies and communication choices
We may send essential service, account, billing, security and legal messages; these are not marketing and cannot always be opted out of while an Account remains active. We may send relevant product or business marketing where you have consented or where legitimate interests and PECR permit B2B contact. Every electronic marketing message provides an unsubscribe route, and you may object at any time by emailing info@certflow.co.uk.
The public website uses local storage and, after consent, Google Analytics cookies. The platform uses necessary authentication, security and workspace storage, plus separate appearance/functionality storage for preferences such as theme and navigation state. The optional Calendly booking calendar and its providers load only when you choose to load that service. Names, purposes, durations and controls are explained in the Cookie Policy.
13. Your data-protection rights
Depending on the circumstances and lawful basis, you may have the right to:
- be informed about how your personal data is used;
- access your personal data and receive supplementary information;
- rectify inaccurate data and complete incomplete data;
- erase data where a legal ground applies;
- restrict processing in specified circumstances;
- data portability for data you provided where processing is automated and based on consent or contract;
- object to processing based on legitimate interests, and object at any time to direct marketing;
- withdraw consent at any time; and
- appropriate safeguards for significant solely automated decisions, including information, human intervention, representation and challenge where the law applies.
Rights are not absolute and exemptions may apply. Send a request to info@certflow.co.uk, stating the right you wish to exercise and enough information to locate the data. We may ask for proportionate proof of identity or authority. We normally respond without undue delay and within one month; where law permits, a complex or numerous request may take up to two further months. The time may pause while we reasonably await necessary clarification, and searches need only be reasonable and proportionate. We will explain any extension, fee or refusal allowed by law.
If a CertFlow Customer controls the data, send the request to that Customer. If you send it to us, we will normally forward it or tell you whom to contact and assist the Customer under the DPA.
14. Automated decisions and profiling
CertFlow includes rules-based indicators such as compliance status, qualification checks, partner matching, lead scores, reminders and commercial dashboards. These support human users; they do not, on our behalf, make a solely automated decision about an individual that produces a legal or similarly significant effect.
Customers decide how to use outputs and must not use a score or suggestion as the sole basis for a legally or similarly significant employment, safety, credit or other decision unless they have a lawful basis, provide required information and safeguards, and can explain and review the result. If our own processing changes to include significant automated decisions, we will provide the specific logic, significance, consequences and safeguards before it begins.
15. Data-protection complaints
You have the right to make a data-protection complaint directly to us. Email info@certflow.co.uk with “Data protection complaint” in the subject, or write to our registered office. Please describe what happened, the data or Account involved, relevant dates and the outcome you seek. If you complain for another person, include evidence of your authority.
We will facilitate the complaint, acknowledge it within 30 days of receipt, make appropriate enquiries without undue delay, keep you informed where an investigation continues, and communicate the outcome without undue delay. This complaints timetable is separate from the one-month timetable that may apply to an individual-rights request.
You also have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF; telephone 0303 123 1113. You do not have to complain to us first, although giving us a chance to resolve the issue may provide a quicker outcome.
16. Changes to this Policy
We review this Policy as our Service, providers and law change. We will publish updates here with a new “Last updated” date. If a change materially affects how we use personal data, we will give an appropriate additional notice—such as email, an in-product message or a just-in-time notice—before the new use begins where required.
Questions, rights requests and complaints can be sent to info@certflow.co.uk, 0114 392 2407, or CertFlow LTD, 20 Wenlock Road, London, N1 7GU.