Privacy Policy
We handle sensitive documents. Here is exactly how we collect, use and protect your information — in plain language.
Privacy policy sections
Overview
The short version: We collect only what we need to translate your documents and deliver your order. We never sell your data. Your documents are encrypted in transit and at rest, and are automatically deleted 90 days after order completion.
Certilate Inc. (“Certilate”, “we”, “us” or “our”) operates the website at certilate.com and the related translation service. This Privacy Policy explains what personal information we collect, why we collect it, how we use it, and what rights you have over it.
By using our service you agree to the collection and use of information in accordance with this policy. If you have questions, email us at admin@certilate.com.
Data we collect
Information you provide directly
- Account information — name, email address and password when you create an account.
- Order details — source and target language, document type, delivery preference, and any special instructions.
- Documents — the files you upload for translation, such as passports, certificates and transcripts.
- Payment information — billing name, address and card details. Card numbers are processed directly by our payment provider and are never stored on our servers.
- Communications — emails, support tickets or messages you send to us.
Information collected automatically
- Usage data — pages visited, time spent and actions taken on our site.
- Device data — browser type, operating system, IP address and language settings.
- Cookies and similar technologies — see the Cookies section below.
How we use your data
We use the information we collect to:
- Fulfil your translation order — matching you with a certified translator, delivering your completed translation and issuing your certification.
- Process payments — charging you for the service you ordered and issuing receipts.
- Communicate with you — sending order updates, responding to support enquiries and notifying you when your translation is ready for review.
- Improve our service — analysing usage patterns to improve our website, quoting system and overall experience.
- Comply with legal obligations — maintaining business records, complying with tax laws and responding to lawful legal requests.
- Prevent fraud and abuse — detecting and preventing fraudulent transactions or misuse of our service.
We do not use your documents for any purpose other than fulfilling your translation order. We do not use them to train AI models.
Document handling
Your documents are sensitive. We treat them with care: encrypted during upload, stored encrypted at rest, shared only with your assigned translator under a strict confidentiality agreement, and deleted 90 days after your order is complete.
Upload security. All document uploads are transmitted over TLS 1.3 encrypted connections. Files are stored in encrypted object storage (AES-256) in data centres located in the Canada and the United States.
Who sees your documents. Only the certified translator assigned to your order has access to your original document. That translator has signed a confidentiality and data processing agreement with Certilate. Certilate staff may access documents when necessary to resolve a dispute or quality issue.
Deletion. Source documents and completed translations are automatically and permanently deleted 90 days after your order is marked complete. You may also request earlier deletion by contacting us at admin@certilate.com.
Sharing & disclosure
We do not sell, rent or trade your personal data. We share it only as follows:
- Certified translators — contractors who fulfil your translation order, bound by confidentiality agreements.
- Payment processor — to process your payment. The processor's own privacy policy governs their data use.
- Cloud infrastructure providers — for hosting, storage and email delivery. These providers act as data processors under our instruction.
- Analytics tools — anonymised, aggregated usage data only. We do not share identifiable information with analytics providers.
- Legal requirements — if required by law, court order, or to protect the rights, property or safety of Certilate or its users.
- Business transfers — if Certilate is acquired or merges, your data may transfer to the acquiring entity, which will be bound by this policy or a substantially similar one.
Data retention
- Documents — deleted 90 days after order completion, or earlier on request.
- Account information — retained for as long as your account is active. Deleted within 30 days of a verified account-deletion request.
- Order records — retained for 7 years to comply with tax and accounting obligations. Personal information in these records is minimised.
- Support communications — retained for 2 years, then deleted.
- Analytics data — anonymised after 13 months.
Your rights
Depending on your location, including the EU, UK and California, you may have the following rights:
- Access — request a copy of the personal data we hold about you.
- Correction — request that we correct inaccurate or incomplete data.
- Deletion — request that we delete your personal data, subject to legal retention obligations.
- Portability — receive your data in a machine-readable format.
- Objection — object to processing based on our legitimate interests.
- Restriction — request that we restrict processing while a dispute is resolved.
- Withdraw consent — where processing is based on consent, withdraw it at any time.
To exercise any of these rights, email admin@certilate.com. We will respond within 30 days.
Cookies
We use a minimal set of cookies:
- Essential cookies — required for the service to function, such as session management and authentication. These cannot be disabled.
- Analytics cookies — anonymous, aggregate data to understand how visitors use our site. You can opt out via the cookie banner.
We do not use advertising, tracking or retargeting cookies.
Security
We implement technical and organisational measures to protect your data, including:
- TLS 1.3 encryption for all data in transit
- AES-256 encryption for all data at rest
- Access controls limiting who can view order data
- Regular security reviews and penetration testing
- SOC 2 Type II compliant infrastructure providers
No system is perfectly secure. In the event of a data breach that affects your rights and freedoms, we will notify you and the relevant authorities as required by law.
Contact & updates
For privacy-related questions or requests, contact our Privacy Team at admin@certilate.com.
We may update this policy from time to time. Material changes will be communicated by email or a prominent notice on our website at least 14 days before taking effect. The “Last updated” date at the top of this page reflects the most recent revision.
Questions about how we handle your documents?
Our privacy team responds within one business day.
Have a privacy question?
Our team responds to all privacy enquiries within one business day.
Fixed quote before you pay · 256-bit encrypted · support 7 days a week