Certify by Moosara Privacy Policy

Certify is operated by Moosara Limited Liability Company (Moosara LLC).

This Privacy Policy explains what personal information Certify collects, why it is collected, how it is used and shared, how long it is retained, and the choices available to you.

Certify provides technical assessment and certification services.

For purposes of this Privacy Policy:

  • User means a technical professional who registers with Certify or takes an assessment.

  • Client means a recruiter, employer, company, or other organization that uses Certify to find, invite, or evaluate Users.

1. Information Certify Collects

Depending on how you use Certify, we may collect:

  • Name

  • Email address

  • Account information

  • Assessment responses

  • Assessment scores

  • Assessment dates and status

  • Client invitations and whether a User accepted an invitation

  • Webcam recordings

  • Microphone recordings

  • Screen recordings

  • Internet Protocol address

  • Browser and device information

  • Connected-display information

  • Fullscreen status

  • Assessment monitoring events

  • Information used to detect use of a virtual private network

  • Identity-verification status

  • Payment and transaction information for Clients

We collect only information used to operate Certify, verify identity, administer assessments, protect assessment integrity, provide certification information, process Client services, and operate and improve the platform.

2. Identity Verification

Certify requires Users to verify their identity.

Certify uses Didit Identity, Inc. (Didit) as its identity-verification provider.

Certify currently uses Didit's:

  • Identification Verification service

  • Face Match service

The purpose of this verification is to:

  • Determine whether a government-issued identification document appears valid.

  • Confirm the identity information contained on the document.

  • Compare the name on the government-issued identification document with the name associated with the User's Certify account.

  • Determine whether the person completing verification appears to be the person shown on the government-issued identification document.

Didit performs these verification services on behalf of Certify.

Certify determines that verification is required and determines which Didit verification services are used. Didit acts as Certify's data processor for these activities, while Certify acts as the data controller.

3. Information Processed by Didit

When a User completes identity verification, Didit may process information including:

  • A government-issued identification document

  • Images of the identification document

  • Information extracted from the document

  • Name

  • Date of birth

  • Nationality

  • Document number

  • Document type

  • Issuing country

  • Document expiration information

  • Photograph contained on the identification document

  • Selfie or facial image captured during verification

  • Facial characteristics derived from the facial image and identification-document photograph

  • Face Match results

  • Verification results

  • Confidence information

  • Warnings or fraud indicators

  • Browser information

  • Device information

  • Internet Protocol address

  • Verification timestamps

  • Verification-session information

The exact information processed depends on the verification performed by Didit.

4. Facial and Biometric Information

Didit's Face Match service compares a facial image captured during verification with the photograph contained on the User's government-issued identification document.

To perform this comparison, Didit may derive characteristics from facial geometry contained in the images.

This information is used to determine whether the person completing verification appears to be the person shown on the identification document.

Certify does not use facial biometric information for advertising or marketing.

Certify does not sell, lease, trade, or otherwise profit from biometric identifiers or biometric information.

Where required by applicable law, Certify will provide appropriate notice and obtain consent before facial or biometric information is collected or processed.

5. Deletion of Didit Verification Data

Certify does not need to retain the underlying government identification document, facial images, or Face Match information after successful identity verification has been completed and confirmed.

After Certify receives and confirms a successful identity-verification result, Certify will cause the associated Didit verification session to be deleted.

Certify may retain a limited internal record showing that the User successfully completed identity verification. This may include information such as:

  • Verification status

  • Verification date

  • A reference associated with the verification

Certify does not retain the government identification document or facial verification images merely to demonstrate that verification previously occurred.

Certify does not intentionally retain a Didit biometric template after the verification session is deleted.

6. Didit's Handling of Verification Information

Didit states that verification information is:

  • Encrypted while being transmitted.

  • Encrypted while stored.

  • Processed and stored in the European Union by default.

  • Accessible only to authorized personnel according to access controls.

Didit processes verification information on Certify's behalf according to the verification services Certify enables.

Didit may separately process limited information where necessary for security, abuse prevention, legal compliance, audit logging, or legal claims.

Didit's own Verification Privacy Notice provides additional information about its handling of verification information.

7. Assessment Recordings

Certify records Users while they complete assessments.

Depending on the assessment, Certify collects:

  • Webcam video

  • Microphone audio

  • Screen recording

These recordings are part of Certify's assessment-integrity process.

They may be used to:

  • Support the validity of an assessment result.

  • Help determine whether the verified User completed the assessment.

  • Detect or investigate violations of assessment requirements.

  • Investigate suspected impersonation, fraud, or misconduct.

  • Resolve questions concerning how an assessment was completed.

  • Support the User's certification.

Because webcam, microphone, and screen recording captures the User's environment, recordings may incidentally contain information visible on the User's screen, visible around the User, or audible near the User.

Users should remove or conceal information from their environment that they do not want included in an assessment recording.

8. Assessment Monitoring Information

Certify monitors technical conditions while an assessment is being completed.

Information collected may include:

  • Whether webcam recording remains active

  • Whether microphone recording remains active

  • Whether screen recording remains active

  • Whether the assessment remains in fullscreen mode

  • Whether additional displays are detected

  • Whether the mouse pointer leaves the permitted assessment area

  • Right-click events

  • Assessment start and completion times

  • Internet Protocol address

  • Browser information

  • Device information

  • Information used to detect a virtual private network

  • Events indicating that an assessment requirement was violated

Certify uses this information to enforce assessment requirements and protect assessment integrity.

9. Assessment Responses and Scores

Certify collects the selections or responses a User makes during an assessment.

Certify calculates the resulting assessment score on its systems.

Identifiable assessment score data is retained for as long as the User chooses to maintain it.

A User may request deletion of their identifiable assessment data through Certify's authenticated privacy-request process.

When a User requests deletion, Certify removes information that identifies or can reasonably be linked to the User from assessment data.

Certify may retain the resulting anonymous assessment data.

Anonymous assessment data may be used to:

  • Analyze assessment performance.

  • Determine how questions perform across Users.

  • Improve assessment quality.

  • Evaluate question difficulty.

  • Develop or improve future assessments.

  • Perform statistical analysis.

Anonymous assessment data is not maintained in a form intended to identify the User who originally generated it.

10. Assessment Recording Retention

Webcam, microphone, and screen recordings are retained until the User requests their deletion.

A User may request deletion of assessment recordings through Certify's authenticated privacy-request process.

Once an authenticated deletion request is processed, Certify deletes the applicable recordings.

Certify does not retain those recordings after processing the User's deletion request merely because they may theoretically be useful in the future.

The underlying Certify assessment itself is not deleted as part of a User's request because the assessment is part of Certify's service rather than personal information belonging to a particular User.

11. Certificates

Certify does not store a separate certificate document or certificate file.

Certificate pages are generated when they are requested using applicable User and assessment information maintained by Certify.

A User may choose to make their certificate public.

When a User makes a certificate public, information displayed on that certificate can be accessed by people with whom the User shares it and potentially by other people who obtain the public certificate link.

Making a certificate public is voluntary.

If the identifiable information used to generate a certificate is deleted, Certify may no longer be able to generate that certificate in its previous identifiable form.

12. Sharing Scores With Clients

A User's assessment score is not generally available to all Clients.

Certify makes a User's score available to a Client in either of the following circumstances:

  1. A Client invites the User through Certify and the User accepts that Client's invitation.

  2. The User makes their certificate public and shares the certificate.

When a User accepts a Client invitation, Certify may make the applicable assessment score available to that Client.

Acceptance of one Client's invitation does not automatically make the User's information available to unrelated Clients.

If a User makes a certificate public, information displayed on the public certificate may be viewed by anyone who obtains access to the public certificate.

13. Client Information

When a recruiter, employer, company, or other organization uses Certify as a Client, Certify may collect:

  • Name

  • Business email address

  • Company or organization information

  • Account information

  • Invitations sent to Users

  • Records showing whether Users accepted invitations

  • Credit purchases

  • Subscription information

  • Transaction records

  • Communications with Certify

Certify uses this information to operate Client accounts, provide Certify services, manage invitations, process purchases, provide support, prevent fraud, and maintain necessary business records.

14. Payments

Certify uses Stripe to process payments.

Clients may use Stripe when purchasing Certify credits, subscriptions, or other paid services.

Stripe may process information such as:

  • Name

  • Email address

  • Billing information

  • Payment-method information

  • Transaction amount

  • Transaction date

  • Information used to authenticate or protect a payment

Payment-card information submitted through Stripe is processed according to Stripe's own privacy practices.

Certify receives transaction information necessary to provide purchased services, maintain account balances, process refunds where applicable, and maintain accounting and tax records.

15. How Certify Uses Personal Information

Certify may use personal information to:

  • Create and operate User and Client accounts.

  • Verify User identity.

  • Compare registration information with government identification information.

  • Confirm that a User appears to be the person shown on a government-issued identification document.

  • Administer assessments.

  • Calculate assessment scores.

  • Record assessments.

  • Monitor assessment requirements.

  • Detect suspected impersonation or misconduct.

  • Protect assessment integrity.

  • Generate certificate pages.

  • Process Client invitations.

  • Share assessment scores when a User accepts a Client invitation.

  • Display certificate information when a User chooses to make a certificate public.

  • Process purchases and subscriptions.

  • Provide customer support.

  • Diagnose technical problems.

  • Prevent fraud and abuse.

  • Protect Certify systems and accounts.

  • Improve Certify assessments using anonymous information.

  • Comply with applicable legal obligations.

16. Service Providers

Certify uses third-party service providers to operate portions of the service.

Didit

Didit provides government identification verification and facial comparison services.

Stripe

Stripe provides payment-processing services.

Microsoft Azure

Certify uses Microsoft Azure for infrastructure, application hosting, storage, and related technology services.

These service providers may process personal information as necessary to provide their services to Certify.

Certify may use additional service providers when necessary for hosting, security, communications, support, monitoring, or other operational purposes.

17. International Processing

Certify is operated by Moosara LLC in the United States.

Personal information may be processed in the United States and in countries where Certify's service providers operate.

Didit processes and stores verification information in the European Union by default.

Therefore, information provided by Users in the United States, India, or another country may be transferred to and processed outside the country where the User resides.

Where applicable law requires safeguards for international transfers, Certify and its service providers will use safeguards required by applicable law.

18. Sale of Personal Information

Certify does not sell Users' personal information.

Certify does not sell, lease, trade, or otherwise profit from Users' biometric identifiers or biometric information.

Sharing information with service providers that process information on Certify's behalf is not treated by Certify as a sale of that information.

19. Information Security

Certify uses administrative, technical, and organizational measures intended to protect personal information from unauthorized access, disclosure, alteration, destruction, or loss.

Access to personal information is limited according to operational need.

No electronic system, transmission method, or storage system can be guaranteed to be completely secure.

20. Privacy Requests

Users may submit privacy requests through Certify's authenticated in-app Privacy Requests feature.

Depending on applicable law and the nature of the request, a User may request:

  • Access to personal information associated with their account.

  • Correction of inaccurate personal information.

  • Deletion of personal information.

  • Deletion of assessment recordings.

  • Deletion of identifiable assessment data.

  • Information about how their personal information is processed.

  • Withdrawal of consent where applicable.

Certify requires Users to authenticate through their Certify account before Certify fulfills requests involving account information or personal data.

This authentication requirement is intended to prevent another person from gaining access to, changing, or deleting a User's information by falsely claiming to be that User.

Where applicable law requires an additional method for submitting a privacy request, Certify will make the legally required method available.

21. Requests Concerning Didit Information

Certify determines why Didit verification is required and instructs Didit to perform the configured verification.

Questions or privacy requests concerning a Certify identity-verification session should therefore generally be submitted to Certify through the authenticated in-app Privacy Requests feature.

Because Certify deletes the Didit verification session after successful verification has been completed and confirmed, the underlying verification-session information may no longer exist when a later request is submitted.

22. Deletion and Anonymous Assessment Data

When a User requests deletion of identifiable assessment information:

  1. Certify removes identifying information associated with the assessment data.

  2. Certify may retain the resulting anonymous assessment information.

  3. The anonymous information may continue to be used to analyze and improve Certify's assessments.

Information is treated as anonymous for this purpose only when it is no longer maintained in a form that reasonably identifies or can reasonably be linked to the User.

Anonymous information is not treated as User personal information under this Privacy Policy.

23. Minimum Age

Certify is available only to individuals who are 18 years of age or older.

Certify does not knowingly permit individuals under 18 years of age to create accounts or complete Certify assessments.

If Certify learns that information was collected from an individual under 18 in violation of this requirement, Certify will take appropriate steps to remove the information.

24. Required Legal Disclosures

Certify may disclose personal information when disclosure is reasonably necessary to:

  • Comply with applicable law.

  • Respond to a valid court order, subpoena, or other legally enforceable request.

  • Respond to a lawful governmental request.

  • Protect Certify systems or accounts.

  • Investigate fraud or security incidents.

  • Protect the rights or safety of Certify, Users, Clients, or others.

Certify does not retain information solely because it could hypothetically become useful in a future legal matter.

25. Business Transfers

If Certify or Moosara LLC is involved in a merger, acquisition, restructuring, financing, sale of assets, or similar business transaction, information may be transferred as part of that transaction subject to applicable law.

26. Changes to This Privacy Policy

Certify may update this Privacy Policy when:

  • Certify's services change.

  • Data-collection practices change.

  • Identity-verification services change.

  • Assessment features change.

  • Service providers change.

  • Applicable legal requirements change.

The Effective Date at the beginning of this Privacy Policy identifies the date of the current version.

Where applicable law requires additional notice or consent for a material change, Certify will provide that notice or obtain that consent.

27. Contacting Certify About Privacy

Users should submit privacy questions, access requests, correction requests, recording-deletion requests, and personal-data deletion requests using the authenticated Privacy Requests feature within Certify.

Certify may require additional verification when reasonably necessary to protect the User's information from unauthorized access, alteration, or deletion.