Privacy Policy
Last updated: August 12, 2026
1. Information We Collect
We collect information that you provide directly to us when you create an account, use our compliance tools, complete training courses, or communicate with us. This includes:
- Name, email address, phone number, and contact information
- Company information (name, address, industry, dangerous goods permits)
- Payment and billing information (processed securely via Stripe)
- Course progress, exam results, and certification records
- Communication preferences and newsletter subscriptions
- Tool usage data: placard calculations, SDS uploads and parsed data, shipping document details, UN number searches, tunnel calculation inputs
- AI interaction logs: questions submitted to our AI assistants, document scanning results, SDS parsing outputs
- Voice interactions: when you use a voice feature (such as the Normi assistant), your microphone audio is streamed for real-time processing and live transcripts of the conversation are generated
- Photos and camera captures you submit for label and document scanning
- Calculation history and saved shipment records
- Digital signatures on compliance documents
- File uploads including Safety Data Sheet (SDS) PDFs and hazmat documentation
- Company branding assets (logos, color schemes) for white-label portals
- Security and diagnostic data: sign-in events (IP address, browser type), technical error reports, and audit logs
2. How We Use Your Information
We use the information we collect to provide and improve our dangerous goods compliance platform:
- Provide, maintain, and improve our services and compliance tools
- Process placard calculations, generate shipping documents, and manage SDS records
- Power AI-assisted features including our regulatory chat assistants, the Normi voice assistant, SDS document parsing and translation, and hazmat document scanning
- Process transactions and manage subscriptions via Stripe
- Generate training certificates and track course completion
- Send technical notices, security alerts, and account notifications
- Send regulatory news updates and newsletters (with your consent)
- Respond to your comments, questions, and support requests
- Measure how visitors use our public interactive demo so we can improve it
- Monitor and analyze usage trends and diagnose technical errors to improve platform accuracy and reliability
- Maintain audit logs for compliance and security purposes
3. Information Sharing
We do not sell your personal information. We share data only with trusted service providers who act as data processors on our behalf, and only as necessary to deliver our services:
- With company administrators who manage your organization's account
- With Stripe for secure payment processing
- With Google for AI services (Google Cloud AI — Gemini, Vertex AI, and Document AI) used in regulatory assistance, voice features, and document parsing
- With Google Analytics and Google Tag Manager for platform usage analytics
- With Amazon Web Services (AWS) for secure file storage, infrastructure, and account authentication (Amazon Cognito)
- With Cloudflare (Turnstile) for bot protection on public forms
- With PubChem and NIOSH APIs for chemical data lookups (UN numbers, chemical properties)
- To comply with legal obligations or respond to lawful requests
- To protect our rights, safety, and property
- With your explicit consent
- Other Certigo customers — if you upload a Safety Data Sheet and do not mark it private, its product name, manufacturer, and parsed safety sections are added to Certigo's shared SDS library where other customers can find them; your inventory, quantities, and internal notes are never shared (see the Terms of Service)
4. Data Security
We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. All data is encrypted in transit (TLS/SSL) and at rest. Account authentication is handled through Amazon Cognito with industry-standard password protection. Our infrastructure is hosted on Amazon Web Services (AWS) with industry-standard security controls. We maintain strict access controls, conduct regular security reviews, monitor for technical errors, and keep audit logs of system access. Authorized Certigo support staff may access account data when needed to provide support or maintain the service, and such access is logged.
5. Data Retention
We retain your personal information for as long as necessary to provide our services and fulfill the purposes outlined in this privacy policy. Certification records are retained in accordance with industry standards and regulatory requirements (typically 3 years for TDG training records). Calculation history and compliance documents are retained for the duration of your subscription. Security logs, technical error reports, and demo analytics are retained only for a limited time proportionate to the purposes described above. Upon account deletion, personal data is removed within 30 days, except where retention is required by law.
6. Your Rights
Certigo complies with Quebec's Act respecting the protection of personal information in the private sector (as modernized by Law 25), the federal PIPEDA, and, where applicable, the EU GDPR. Depending on your jurisdiction, you have the right to:
- Access your personal information and obtain a copy
- Correct inaccurate or incomplete information
- Request deletion of your personal data
- Withdraw consent at any time where processing is based on consent
- Object to or restrict certain processing activities
- Receive computerized personal information you provided to us in a structured, commonly used technological format (data portability)
- Lodge a complaint with the Commission d'accès à l'information du Québec (CAI), the Office of the Privacy Commissioner of Canada, or your local supervisory authority
7. Cookies, Tracking, and Browser Storage
We use cookies and similar technologies to collect information about your browsing activities and improve your experience. We use Google Tag Manager to manage tracking scripts and Google Analytics to understand platform usage. We implement Google Consent Mode v2 to respect your cookie preferences, and our cookie consent banner allows you to accept or decline non-essential cookies. Cookies may persist for up to 1 year and operate across subdomains of certigo.net. We also use your browser's local storage for essential preferences (such as language and caption settings) and session state; this storage is not used for advertising. You can control cookies through your browser settings, though some features may not function properly if cookies are disabled.
8. Interactive Demo Analytics
Our public interactive demo (certigo.net/demo) can be used without an account. To understand how the demo performs, we collect first-party analytics about demo visits: a random visit identifier stored in your browser's session storage (it is deleted when you close the tab and is not a persistent cookie), the demo sections you view and how far you progress, your language and device type, the campaign that referred you (UTM parameters), technical error reports, and your IP address and browser type. This data is used only to measure and improve the demo — no account or marketing profile is created from it. If you try a voice interaction during the demo, your microphone audio is processed as described in the AI section below; demo voice time is limited.
9. AI, Voice Features, and Automated Processing
Our platform uses Google Cloud AI (Gemini, Vertex AI, and Document AI) to power several features. AI is used for: our regulatory chat assistants, which answer questions about dangerous goods regulations; the Normi voice assistant, which answers spoken questions about your SDS library and compliance tools — when you speak to Normi, your microphone audio is streamed in real time to Google's Gemini Live service to generate a response and a live transcript, and Normi's spoken replies are synthesized audio that we may cache for performance (the cached audio contains only Normi's own script, never your voice); SDS document parsing, which extracts and translates safety data from uploaded documents, including OCR of scanned documents; hazmat document and label scanning, which analyzes photos of shipping labels and placards; and compliance validation, which provides confidence scores on regulatory checks. Course exams are scored automatically against the passing grade; if you believe a result is incorrect, contact us and a person will review it. AI outputs are supplementary tools designed to assist qualified personnel — they should always be verified by the user before being relied upon for compliance decisions. Data submitted to AI features may be processed by Google's AI services in accordance with their data processing terms.
10. Third-Party Services
We integrate with the following third-party services to deliver our platform:
- Stripe — payment processing: receives billing details, card information, and transaction data
- Amazon Web Services (AWS) — cloud infrastructure: hosts our servers and databases, stores uploaded SDS documents, compliance files, branding assets, and cached audio (S3), and manages account authentication (Amazon Cognito)
- Google Cloud AI (Gemini, Vertex AI, Document AI) — AI processing: receives user queries, voice audio from voice features, document content, and images submitted to AI features
- Google Analytics / Google Tag Manager — analytics: receives usage data, page views, and interaction events, subject to your consent choices
- Cloudflare Turnstile — bot protection on public forms: receives technical browser signals to distinguish humans from automated traffic
- PubChem API — chemical data: receives UN numbers and chemical identifiers for safety data lookups
- NIOSH API — occupational safety data: receives chemical identifiers for exposure limit lookups
11. International Data Transfers
Certigo is based in Quebec, Canada. Your information may be transferred to and processed in countries other than your country of residence, including the United States, where our service providers operate (AWS, Google, Stripe, Cloudflare). Before communicating personal information outside Quebec, we assess whether it will receive adequate protection, and we rely on appropriate safeguards such as standard contractual clauses where applicable.
12. Children's Privacy
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child, we will take steps to delete it promptly.
13. Newsletter and Regulatory Updates
With your consent, we may collect your email address to send you regulatory news updates, compliance tips, and platform announcements. You can unsubscribe from these communications at any time using the unsubscribe link included in each email, or by updating your notification preferences in your account settings.
14. Privacy Officer and Complaints
Certigo has designated a person in charge of the protection of personal information (privacy officer), as required by Quebec law. You can reach the privacy officer at privacy@certigo.net for any question about this policy, to exercise your rights, or to file a complaint. If you are not satisfied with our response, you may contact the Commission d'accès à l'information du Québec (CAI) or the Office of the Privacy Commissioner of Canada.
15. Confidentiality Incidents
We maintain a register of confidentiality incidents involving personal information. If an incident presents a risk of serious injury, we will notify the Commission d'accès à l'information du Québec and the affected individuals, and take reasonable measures to reduce the risk of harm, as required by applicable law.
16. Changes to This Policy
We may update this privacy policy from time to time to reflect changes in our practices, services, or legal requirements. We will notify you of any material changes by posting the new policy on this page and updating the 'Last updated' date. For significant changes, we may also notify you by email.
17. Contact Us
If you have questions about this privacy policy or our privacy practices, please contact us at: privacy@certigo.net
Submit a Data Request
Under Quebec's Law 25, Canada's PIPEDA, the EU GDPR, and other applicable privacy laws, you have the right to access, rectify, delete, or object to the processing of your personal information. Submit a request below and we will verify your identity via email.