Privacy Policy
We are built to know as little about you as possible.
by Evoblox Ltd • Company No. 16253695
71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
1. Who We Are and How to Contact Us
Certelo is operated by EVOBLOX Ltd (Company No. 16253695), registered in England and Wales, with registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. We are the data controller for any personal data processed in connection with the Certelo service.
Contact: hello@certelo.io
EU Representative (GDPR Art. 27): Required before any EEA-facing marketing. Will be appointed and published here and at certelo.io/privacy before EU launch. EEA residents may contact hello@certelo.io in the meantime.
2. Our Privacy Principle: Minimum Data by Design
Certelo's core timestamping service is built on a no-registration, pay-and-use model. We do not ask for your name, email address, or any personal information to use the timestamping service.
Your original file never leaves your device. All hashing is performed client-side in your browser using SHA-256.
Only the cryptographic hash, which cannot be reversed to reconstruct your file, is transmitted to Certelo.
We do not create or maintain user accounts or personal data stores for the timestamping service.
Certelo offers one optional website analytics path. It is explained in Section 3.5 below.
3. What Data Is Processed and By Whom
3.1 Data processed directly by Certelo: core service
SHA-256 hash of your file: cannot identify you or reveal your file's contents.
Electra Protocol blockchain transaction ID: a public on-chain reference.
Timestamp of your proof creation.
IP address: collected transiently for security and DDoS protection. Not linked to your proof record.
Browser and device type: collected transiently for service stability.
Session log data: retained for a maximum of 90 days for security and debugging, then permanently deleted.
3.2 Data processed by the third-party payment processor
Payments are processed by an independent third-party payment processor. Certelo does not collect, process, or store your card number, bank details, or any financial credentials. The payment processor is an independent data controller operating under its own terms and privacy policy; see certelo.io/payments for a link.
As part of processing your transaction, the processor may independently collect and process the following data under its own legal obligations (AML, KYC, PCI DSS, fraud prevention):
Your name and billing address (if required for card verification).
Payment card details (processed and tokenised by the processor; never seen by Certelo).
Transaction amount, currency, and timestamp.
Device fingerprint and IP address (for the processor's fraud prevention).
Any other data required by the processor's own compliance obligations.
Certelo is not responsible for the data practices of the payment processor. Direct queries about the processor's data handling to them directly.
3.3 What Evoblox receives from the payment processor: merchant dashboard
When Evoblox accesses its merchant account with the payment processor to review payment activity, the processor may display transaction information including names, email addresses, amounts, and dates of transactions. This information is held and displayed by the payment processor and Evoblox views it solely for the purpose of:
Confirming that a payment was successfully made.
Resolving customer support queries or disputes.
Satisfying UK financial reporting and tax obligations.
Evoblox does not export, copy, store in its own systems, transfer to third parties, or use for any other purpose the personal information visible in the payment processor's merchant dashboard. The data remains within the payment processor's systems at all times.
Where required by applicable law or accounting obligations, Evoblox may retain a transaction identifier or receipt reference only: the minimum data needed to confirm a payment and satisfy legal obligations. This is retained for the minimum period required by law, typically up to 7 years under UK financial regulations.
3.4 What Certelo does NOT collect
Your name, email address, or postal address (for the core timestamping service).
Any account credentials (no accounts exist in the standard Service).
The contents, text, or data within your file.
The ideas, inventions, or information described in your file.
Any data that would allow anyone to reconstruct your original document.
3.5 Optional website analytics
Google Tag Manager (GTM-K6Q3GJKW) is optional.
It loads only after you choose Accept analytics on a public page. It does not load before that choice, after Keep only needed, or on Access and Admin pages.
Certelo stores only your choice, granted or denied, for 90 days. Use Change analytics choice in the footer to change it.
The first release does not send custom form values, certificate details, payment details, fingerprints, query values, hash values, or user-entered text to the container. It does not add advertising, remarketing, or audience-building tags.
Google may process information under its own policies after the browser loads the container. Certelo does not store Google Tag Manager events or a Google profile.
4. How We Use This Data
To generate your cryptographic hash and anchor it to the Electra Protocol blockchain.
To issue your proof certificate.
To confirm payment has been made and for accounting and dispute resolution purposes.
To retain a transaction reference where required by UK financial law.
To detect and prevent fraud, abuse, and unauthorised access to the Service.
To maintain the security and stability of the platform.
If you choose optional analytics, to understand aggregate public-site use and improve the website.
5. Legal Basis for Processing
We are subject to UK GDPR (Data Protection Act 2018) and EU GDPR (Regulation 2016/679). Our legal bases are:
Contract performance (Art. 6(1)(b)): hashing, blockchain anchoring, and issuing proof certificates; necessary to perform the Service.
Legal obligation (Art. 6(1)(c)): retaining a transaction reference where required by UK financial or tax law.
Legitimate interests (Art. 6(1)(f)): transient IP logging and session data for security and fraud prevention.
Your analytics choice: Google Tag Manager loads only after you choose Accept analytics. Use Change analytics choice in the footer to change that choice at any time.
6. Data Retention
Hash and blockchain transaction ID: retained as part of your proof record. The on-chain record is permanently immutable regardless.
Transaction identifier / receipt reference: retained where required by law, typically up to 7 years under UK financial regulations.
IP address and session log data: retained maximum 90 days, then permanently deleted.
Analytics choice: Certelo retains only granted or denied for 90 days. Certelo does not retain Google Tag Manager events or a Google profile.
Google Tag Manager provider data: Google controls its own retention under its policies after the browser loads the container.
No other personal data is retained by Certelo for the core timestamping service, as none is collected.
Payment dashboard data viewed in the merchant account is not retained by Evoblox beyond the transaction reference described in Section 3.3.
7. Data Sharing
Electra Protocol blockchain: hash and timestamp only. No personal identifiers.
Third-party payment processor: independent controller. Certelo receives only a transaction reference.
Google Tag Manager: the browser may contact Google only after your Accept analytics choice on an approved public page.
Infrastructure providers: hosting and cloud services under GDPR-compliant DPAs.
Legal requirements: disclosure if required by law or regulatory authority.
We do not sell personal data to any third party for their own commercial purposes.
8. International Data Transfers
Data processed by Certelo may be stored outside the UK. We rely on SCCs approved by the UK ICO or other lawful transfer mechanisms.
Google Tag Manager provider data may be processed outside the UK. Google describes its own processing in its policies.
Payment processor data transfers are governed by the processor's own transfer mechanisms.
9. Your Rights: UK and EU Users
9.1 UK and EU users
You have the right to: access data we hold; rectify inaccurate data; erase data (subject to legal retention requirements and on-chain immutability); restrict or object to processing; and data portability where applicable. To exercise rights, email hello@certelo.io. We respond within 30 days.
Analytics choice: use Change analytics choice in the footer at any time. This stops future Google Tag Manager loads; it cannot erase provider-held data already sent.
UK users: complain to the ICO at ico.org.uk.
EU users: complain to your national supervisory authority at edpb.europa.eu.
9.2 Payment processor data
Requests regarding data the payment processor holds must be directed to the processor directly under their privacy policy. Certelo cannot access, correct, or delete data stored within the processor's systems beyond the transaction reference it retains.
10. US Privacy Rights
10.1 California: CCPA / CPRA
California residents have rights under CCPA/CPRA including: right to know, right to delete, right to correct, right to opt-out of sale (we do not sell personal data), right to limit sensitive personal information, and right to non-discrimination. For analytics and advertising data, you may also opt out of sharing for cross-context behavioural advertising.
To exercise rights: email hello@certelo.io with subject 'CCPA Request'. Response within 45 days. Payment processor data requests must go to the processor directly.
10.2 Virginia, Colorado, Connecticut, Texas
Residents of these states have similar privacy rights. Email hello@certelo.io with subject 'US State Privacy Request: [Your State]'. Response within 45 days. For analytics opt-out, use the cookie settings on certelo.io.
11. International Users: Global Privacy Rights
Certelo is a global digital service. For users in countries not listed below, the global catch-all in Section 11.11 applies.
11.1 Australia
Subject to the Privacy Act 1988 and Australian Privacy Principles. Rights: access and correction. Complaint to OAIC at oaic.gov.au. Analytics and advertising tools are disclosed and subject to consent. Email hello@certelo.io with subject 'Australia Privacy Request'.
11.2 Brazil
Subject to the LGPD. Rights: confirmation, access, correction, anonymisation, portability, deletion, information, and objection. Complaint to ANPD at gov.br/anpd. Analytics and advertising tools disclosed and consent-based. Response within 15 days. Email hello@certelo.io with subject 'Brazil Privacy Request: LGPD'. Responses available in Portuguese.
11.3 Canada
Subject to PIPEDA and Quebec Law 25. Rights: access, correction, withdrawal of consent. Complaint to OPC at priv.gc.ca. Analytics and advertising tools disclosed and consent-based. Email hello@certelo.io with subject 'Canada Privacy Request: PIPEDA'.
11.4 Japan
Subject to the APPI (2022). Rights: disclosure, correction, deletion, suspension. PPC oversight at ppc.go.jp. Analytics and advertising tools disclosed and consent-based. Email hello@certelo.io with subject 'Japan Privacy Request: APPI'.
11.5 Singapore
Subject to the PDPA 2021. Rights: access, correction, withdrawal of consent, portability. PDPC at pdpc.gov.sg. Mandatory breach notification applies. Analytics and advertising tools disclosed and consent-based. Email hello@certelo.io with subject 'Singapore Privacy Request: PDPA'.
11.6 South Korea
Subject to PIPA (2023). Rights: access, correction, deletion, suspension. PIPC at pipc.go.kr. Strict data transfer rules noted. Analytics and advertising tools disclosed and consent-based. Email hello@certelo.io with subject 'South Korea Privacy Request: PIPA'.
11.7 India
Subject to the DPDP Act 2023. Rights: access, correction, erasure, grievance redressal, nomination. DPBB oversight. Implementing rules pending; this section will be updated when finalised. Analytics and advertising tools disclosed and consent-based. Email hello@certelo.io with subject 'India Privacy Request: DPDP Act'.
11.8 South Africa
Subject to POPIA 2021. Rights: access, correction, deletion, objection. Information Regulator at inforegulator.org.za. Analytics and advertising tools disclosed and consent-based. Email hello@certelo.io with subject 'South Africa Privacy Request: POPIA'.
11.9 China
Subject to the PIPL 2021. Rights: access, copy, correction, deletion, withdrawal of consent, explanation. CAC oversight. Data localisation limitation: Certelo's infrastructure is UK-based. Analytics and advertising tools disclosed and consent-based. Email hello@certelo.io with subject 'China Privacy Request: PIPL'.
11.10 Russia
Subject to FZ-152. Rights: access, correction, deletion, blocking. Roskomnadzor oversight. Data localisation limitation disclosed. Sanctions compliance applies. Analytics and advertising tools disclosed and consent-based. Email hello@certelo.io with subject 'Russia Privacy Request'.
11.11 All Other Countries: Global Catch-All
Certelo is committed to respecting applicable privacy laws in all jurisdictions. Users in any country may contact hello@certelo.io to exercise privacy rights. We will respond within 30 days or the period required by local law. Our minimal data collection, consent-based analytics, and transparent processing reflect best practice under most global privacy frameworks.
12. Security and Data Breach Response
We implement TLS 1.3 encryption, access controls, and regular security reviews. To report vulnerabilities, email hello@certelo.io.
Breach Protocol: (1) Contain immediately; (2) Assess within 24 hours; (3) Notify UK ICO within 72 hours (UK GDPR Art. 33); (4) Notify EU supervisory authorities within 72 hours where required (EU GDPR Art. 33); (5) Notify affected individuals without undue delay where high risk; (6) Notify other applicable authorities (OAIC, PDPC, ANPD, PIPC, etc.) within their required timeframes.
13. Cookies and Tracking Technologies
13.1 Essential Cookies & Technical Data
Certelo uses strictly necessary technical mechanisms required for the website and Service to function securely, including session security tokens provided during the checkout process (e.g., via Stripe for fraud prevention and payment handling). These strictly necessary technologies are processed based on legitimate interest and do not require user consent (UK PECR Reg. 6(4) / EU ePrivacy Directive).
13.2 Privacy-Friendly Analytics (Umami)
We use Umami, an open-source, privacy-focused website analytics solution. Umami does not use cookies, does not track individual users across different websites, and does not store personal data or IP addresses. All analytics data is aggregated and processed strictly for website performance optimization.
13.3 Optional Google Tag Manager
Google Tag Manager (GTM-K6Q3GJKW) is optional. It loads only after you choose Accept analytics. Keep only needed makes no Google Tag Manager request. Use Change analytics choice in the footer to change your choice.
14. Children's Privacy
The Service is not intended for individuals under 18 (or the applicable age of majority in the user's jurisdiction where higher). We do not knowingly collect personal data from children. Contact hello@certelo.io immediately if you believe a child has used the Service.
15. Future Changes to How We Operate
15.1 EU GDPR Representative (Article 27)
Evoblox will appoint an EU representative before any EEA-facing marketing or launch activities. The representative's details will be added to Section 1 and published at certelo.io/privacy.
15.2 Account registration
Certelo currently operates without user registration. If introduced in the future, this Privacy Policy will be updated with advance notice.
15.3 Changes to optional analytics
If Certelo changes optional analytics, this Privacy Policy and the Change analytics choice footer control will be updated to describe that change.
16. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be published on certelo.io with a revised version number and effective date. Optional analytics changes will also update the Change analytics choice footer control.
17. Contact
EVOBLOX Ltd t/a Certelo
71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
Company No. 16253695 (England and Wales)
Contact: hello@certelo.io
UK Supervisory Authority (ICO): ico.org.uk
EU Supervisory Authorities: edpb.europa.eu
Payment Processor Policy: certelo.io/payments
Cookie Settings: certelo.io/cookies
Website: certelo.io