Certify by Moosara Privacy Policy
Certify is operated by Moosara Limited Liability Company (Moosara LLC).
This Privacy Policy explains what personal information Certify collects, why it is collected, how it is used and shared, how long it is retained, and the choices available to you.
Certify provides technical assessment and certification services.
For purposes of this Privacy Policy:
User means a technical professional who registers with Certify or takes an assessment.
Client means a recruiter, employer, company, or other organization that uses Certify to find, invite, or evaluate Users.
1. Information Certify Collects
Depending on how you use Certify, we may collect:
Name
Email address
Account information
Assessment responses
Assessment scores
Assessment dates and status
Client invitations and whether a User accepted an invitation
Webcam recordings
Microphone recordings
Screen recordings
Internet Protocol address
Browser and device information
Connected-display information
Fullscreen status
Assessment monitoring events
Information used to detect use of a virtual private network
Identity-verification status
Payment and transaction information for Clients
We collect only information used to operate Certify, verify identity, administer assessments, protect assessment integrity, provide certification information, process Client services, and operate and improve the platform.
2. Identity Verification
Certify requires Users to verify their identity.
Certify uses Didit Identity, Inc. (Didit) as its identity-verification provider.
Certify currently uses Didit's:
Identification Verification service
Face Match service
The purpose of this verification is to:
Determine whether a government-issued identification document appears valid.
Confirm the identity information contained on the document.
Compare the name on the government-issued identification document with the name associated with the User's Certify account.
Determine whether the person completing verification appears to be the person shown on the government-issued identification document.
Didit performs these verification services on behalf of Certify.
Certify determines that verification is required and determines which Didit verification services are used. Didit acts as Certify's data processor for these activities, while Certify acts as the data controller.
3. Information Processed by Didit
When a User completes identity verification, Didit may process information including:
A government-issued identification document
Images of the identification document
Information extracted from the document
Name
Date of birth
Nationality
Document number
Document type
Issuing country
Document expiration information
Photograph contained on the identification document
Selfie or facial image captured during verification
Facial characteristics derived from the facial image and identification-document photograph
Face Match results
Verification results
Confidence information
Warnings or fraud indicators
Browser information
Device information
Internet Protocol address
Verification timestamps
Verification-session information
The exact information processed depends on the verification performed by Didit.
4. Facial and Biometric Information
Didit's Face Match service compares a facial image captured during verification with the photograph contained on the User's government-issued identification document.
To perform this comparison, Didit may derive characteristics from facial geometry contained in the images.
This information is used to determine whether the person completing verification appears to be the person shown on the identification document.
Certify does not use facial biometric information for advertising or marketing.
Certify does not sell, lease, trade, or otherwise profit from biometric identifiers or biometric information.
Where required by applicable law, Certify will provide appropriate notice and obtain consent before facial or biometric information is collected or processed.
5. Deletion of Didit Verification Data
Certify does not need to retain the underlying government identification document, facial images, or Face Match information after successful identity verification has been completed and confirmed.
After Certify receives and confirms a successful identity-verification result, Certify will cause the associated Didit verification session to be deleted.
Certify may retain a limited internal record showing that the User successfully completed identity verification. This may include information such as:
Verification status
Verification date
A reference associated with the verification
Certify does not retain the government identification document or facial verification images merely to demonstrate that verification previously occurred.
Certify does not intentionally retain a Didit biometric template after the verification session is deleted.
6. Didit's Handling of Verification Information
Didit states that verification information is:
Encrypted while being transmitted.
Encrypted while stored.
Processed and stored in the European Union by default.
Accessible only to authorized personnel according to access controls.
Didit processes verification information on Certify's behalf according to the verification services Certify enables.
Didit may separately process limited information where necessary for security, abuse prevention, legal compliance, audit logging, or legal claims.
Didit's own Verification Privacy Notice provides additional information about its handling of verification information.
7. Assessment Recordings
Certify records Users while they complete assessments.
Depending on the assessment, Certify collects:
Webcam video
Microphone audio
Screen recording
These recordings are part of Certify's assessment-integrity process.
They may be used to:
Support the validity of an assessment result.
Help determine whether the verified User completed the assessment.
Detect or investigate violations of assessment requirements.
Investigate suspected impersonation, fraud, or misconduct.
Resolve questions concerning how an assessment was completed.
Support the User's certification.
Because webcam, microphone, and screen recording captures the User's environment, recordings may incidentally contain information visible on the User's screen, visible around the User, or audible near the User.
Users should remove or conceal information from their environment that they do not want included in an assessment recording.
8. Assessment Monitoring Information
Certify monitors technical conditions while an assessment is being completed.
Information collected may include:
Whether webcam recording remains active
Whether microphone recording remains active
Whether screen recording remains active
Whether the assessment remains in fullscreen mode
Whether additional displays are detected
Whether the mouse pointer leaves the permitted assessment area
Right-click events
Assessment start and completion times
Internet Protocol address
Browser information
Device information
Information used to detect a virtual private network
Events indicating that an assessment requirement was violated
Certify uses this information to enforce assessment requirements and protect assessment integrity.
9. Assessment Responses and Scores
Certify collects the selections or responses a User makes during an assessment.
Certify calculates the resulting assessment score on its systems.
Identifiable assessment score data is retained for as long as the User chooses to maintain it.
A User may request deletion of their identifiable assessment data through Certify's authenticated privacy-request process.
When a User requests deletion, Certify removes information that identifies or can reasonably be linked to the User from assessment data.
Certify may retain the resulting anonymous assessment data.
Anonymous assessment data may be used to:
Analyze assessment performance.
Determine how questions perform across Users.
Improve assessment quality.
Evaluate question difficulty.
Develop or improve future assessments.
Perform statistical analysis.
Anonymous assessment data is not maintained in a form intended to identify the User who originally generated it.
10. Assessment Recording Retention
Webcam, microphone, and screen recordings are retained until the User requests their deletion.
A User may request deletion of assessment recordings through Certify's authenticated privacy-request process.
Once an authenticated deletion request is processed, Certify deletes the applicable recordings.
Certify does not retain those recordings after processing the User's deletion request merely because they may theoretically be useful in the future.
The underlying Certify assessment itself is not deleted as part of a User's request because the assessment is part of Certify's service rather than personal information belonging to a particular User.
11. Certificates
Certify does not store a separate certificate document or certificate file.
Certificate pages are generated when they are requested using applicable User and assessment information maintained by Certify.
A User may choose to make their certificate public.
When a User makes a certificate public, information displayed on that certificate can be accessed by people with whom the User shares it and potentially by other people who obtain the public certificate link.
Making a certificate public is voluntary.
If the identifiable information used to generate a certificate is deleted, Certify may no longer be able to generate that certificate in its previous identifiable form.
12. Sharing Scores With Clients
A User's assessment score is not generally available to all Clients.
Certify makes a User's score available to a Client in either of the following circumstances:
A Client invites the User through Certify and the User accepts that Client's invitation.
The User makes their certificate public and shares the certificate.
When a User accepts a Client invitation, Certify may make the applicable assessment score available to that Client.
Acceptance of one Client's invitation does not automatically make the User's information available to unrelated Clients.
If a User makes a certificate public, information displayed on the public certificate may be viewed by anyone who obtains access to the public certificate.
13. Client Information
When a recruiter, employer, company, or other organization uses Certify as a Client, Certify may collect:
Name
Business email address
Company or organization information
Account information
Invitations sent to Users
Records showing whether Users accepted invitations
Credit purchases
Subscription information
Transaction records
Communications with Certify
Certify uses this information to operate Client accounts, provide Certify services, manage invitations, process purchases, provide support, prevent fraud, and maintain necessary business records.
14. Payments
Certify uses Stripe to process payments.
Clients may use Stripe when purchasing Certify credits, subscriptions, or other paid services.
Stripe may process information such as:
Name
Email address
Billing information
Payment-method information
Transaction amount
Transaction date
Information used to authenticate or protect a payment
Payment-card information submitted through Stripe is processed according to Stripe's own privacy practices.
Certify receives transaction information necessary to provide purchased services, maintain account balances, process refunds where applicable, and maintain accounting and tax records.
15. How Certify Uses Personal Information
Certify may use personal information to:
Create and operate User and Client accounts.
Verify User identity.
Compare registration information with government identification information.
Confirm that a User appears to be the person shown on a government-issued identification document.
Administer assessments.
Calculate assessment scores.
Record assessments.
Monitor assessment requirements.
Detect suspected impersonation or misconduct.
Protect assessment integrity.
Generate certificate pages.
Process Client invitations.
Share assessment scores when a User accepts a Client invitation.
Display certificate information when a User chooses to make a certificate public.
Process purchases and subscriptions.
Provide customer support.
Diagnose technical problems.
Prevent fraud and abuse.
Protect Certify systems and accounts.
Improve Certify assessments using anonymous information.
Comply with applicable legal obligations.
16. Service Providers
Certify uses third-party service providers to operate portions of the service.
Didit
Didit provides government identification verification and facial comparison services.
Stripe
Stripe provides payment-processing services.
Microsoft Azure
Certify uses Microsoft Azure for infrastructure, application hosting, storage, and related technology services.
These service providers may process personal information as necessary to provide their services to Certify.
Certify may use additional service providers when necessary for hosting, security, communications, support, monitoring, or other operational purposes.
17. International Processing
Certify is operated by Moosara LLC in the United States.
Personal information may be processed in the United States and in countries where Certify's service providers operate.
Didit processes and stores verification information in the European Union by default.
Therefore, information provided by Users in the United States, India, or another country may be transferred to and processed outside the country where the User resides.
Where applicable law requires safeguards for international transfers, Certify and its service providers will use safeguards required by applicable law.
18. Sale of Personal Information
Certify does not sell Users' personal information.
Certify does not sell, lease, trade, or otherwise profit from Users' biometric identifiers or biometric information.
Sharing information with service providers that process information on Certify's behalf is not treated by Certify as a sale of that information.
19. Information Security
Certify uses administrative, technical, and organizational measures intended to protect personal information from unauthorized access, disclosure, alteration, destruction, or loss.
Access to personal information is limited according to operational need.
No electronic system, transmission method, or storage system can be guaranteed to be completely secure.
20. Privacy Requests
Users may submit privacy requests through Certify's authenticated in-app Privacy Requests feature.
Depending on applicable law and the nature of the request, a User may request:
Access to personal information associated with their account.
Correction of inaccurate personal information.
Deletion of personal information.
Deletion of assessment recordings.
Deletion of identifiable assessment data.
Information about how their personal information is processed.
Withdrawal of consent where applicable.
Certify requires Users to authenticate through their Certify account before Certify fulfills requests involving account information or personal data.
This authentication requirement is intended to prevent another person from gaining access to, changing, or deleting a User's information by falsely claiming to be that User.
Where applicable law requires an additional method for submitting a privacy request, Certify will make the legally required method available.
21. Requests Concerning Didit Information
Certify determines why Didit verification is required and instructs Didit to perform the configured verification.
Questions or privacy requests concerning a Certify identity-verification session should therefore generally be submitted to Certify through the authenticated in-app Privacy Requests feature.
Because Certify deletes the Didit verification session after successful verification has been completed and confirmed, the underlying verification-session information may no longer exist when a later request is submitted.
22. Deletion and Anonymous Assessment Data
When a User requests deletion of identifiable assessment information:
Certify removes identifying information associated with the assessment data.
Certify may retain the resulting anonymous assessment information.
The anonymous information may continue to be used to analyze and improve Certify's assessments.
Information is treated as anonymous for this purpose only when it is no longer maintained in a form that reasonably identifies or can reasonably be linked to the User.
Anonymous information is not treated as User personal information under this Privacy Policy.
23. Minimum Age
Certify is available only to individuals who are 18 years of age or older.
Certify does not knowingly permit individuals under 18 years of age to create accounts or complete Certify assessments.
If Certify learns that information was collected from an individual under 18 in violation of this requirement, Certify will take appropriate steps to remove the information.
24. Required Legal Disclosures
Certify may disclose personal information when disclosure is reasonably necessary to:
Comply with applicable law.
Respond to a valid court order, subpoena, or other legally enforceable request.
Respond to a lawful governmental request.
Protect Certify systems or accounts.
Investigate fraud or security incidents.
Protect the rights or safety of Certify, Users, Clients, or others.
Certify does not retain information solely because it could hypothetically become useful in a future legal matter.
25. Business Transfers
If Certify or Moosara LLC is involved in a merger, acquisition, restructuring, financing, sale of assets, or similar business transaction, information may be transferred as part of that transaction subject to applicable law.
26. Changes to This Privacy Policy
Certify may update this Privacy Policy when:
Certify's services change.
Data-collection practices change.
Identity-verification services change.
Assessment features change.
Service providers change.
Applicable legal requirements change.
The Effective Date at the beginning of this Privacy Policy identifies the date of the current version.
Where applicable law requires additional notice or consent for a material change, Certify will provide that notice or obtain that consent.
27. Contacting Certify About Privacy
Users should submit privacy questions, access requests, correction requests, recording-deletion requests, and personal-data deletion requests using the authenticated Privacy Requests feature within Certify.
Certify may require additional verification when reasonably necessary to protect the User's information from unauthorized access, alteration, or deletion.