Effective date: July 27, 2026. This notice explains how CertLev, operating as CertLev, handles personal information through the public website, sales forms and project portal.
1. Information we collect
We collect account and contact details; company and billing-jurisdiction information; package and order records; project briefs, messages, revision lists and files; payment status and references (not full card or bank credentials); support and privacy requests; device, browser, security and approximate network information; and communications you send.
2. Sources
Information comes from you, authorized users at your organization, service providers used to operate the site, and technical interactions with the platform. Project materials may include information about employees, customers or other individuals supplied by a Client.
3. Purposes and legal bases
We use information to provide requested services, create and secure accounts, process orders, verify payment, communicate, manage scope and revisions, deliver files, support clients, prevent abuse, maintain records, improve operations, comply with law, and establish or defend legal claims. Depending on location, processing may rely on contract, steps requested before contract, legitimate interests, legal obligations, consent, or another lawful basis.
4. Sharing
We may share necessary information with hosting, email, storage, payment, accounting, security and professional-service providers; a successor in a business transaction; authorities or parties when legally required or reasonably necessary to protect rights and safety; and other parties with your direction or consent. We do not sell personal information for money. The delivered site does not include cross-context behavioral advertising by default.
5. Payment processing
Payment is completed on the configured third-party payment provider’s secure page. The payment provider’s notice governs information entered there. CertLev receives order-level confirmation or information needed for accounting and reconciliation but does not request that you send full card numbers or bank login credentials through the portal.
6. Cookies and essential storage
The platform uses essential session and security technologies needed for login, form protection and account operation. It does not include advertising cookies or nonessential analytics by default. See the Cookie Notice.
7. Project files and credentials
Project files are stored in private application storage and downloaded through authorization checks. Do not upload payment-card data, government identifiers, medical records, children’s data, biometric templates or production databases unless a signed scope and appropriate safeguards expressly permit it. Use temporary and role-limited credentials and rotate them after handoff.
8. Retention
We retain account, contract, payment, tax, delivery, support and audit records for the period reasonably needed for service, legal, accounting, security and dispute purposes. Files may be removed after the support or retention period. A request to delete information may be limited by legal obligations, security needs, active contracts, claims or the rights of others.
9. Security
We use measures intended to reduce risk, including encrypted transport when HTTPS is configured, password hashing, session protections, access controls, CSRF protection, private file storage, file validation and audit records. No system can guarantee absolute security. Notify support@certlev.com promptly about suspected unauthorized access.
10. International transfers
Information may be processed in the United States or other locations where providers operate. Where required, an appropriate transfer mechanism or contractual safeguard should be used. Contact support@certlev.com for information relevant to your location.
11. Your rights
Depending on law, you may have rights to know or access information, correct it, delete it, receive a portable copy, restrict or object to processing, withdraw consent, or appeal a decision. You may submit a request through the Privacy Request page or to support@certlev.com. We may verify identity and authority and may deny or limit a request where law permits.
12. United States state privacy notices
Residents of certain states may have specific rights regarding categories collected, sources, purposes, disclosures, correction, deletion, access, portability, opt-out and appeal. CertLev does not knowingly sell personal information or share it for cross-context behavioral advertising through this delivered platform. Applicability depends on statutory thresholds and the operating business’s actual practices.
13. European Economic Area, United Kingdom and similar laws
You may have rights to lodge a complaint with a supervisory authority and to object where processing relies on legitimate interests. Contract information is required to provide a purchased service; refusing it may prevent service. Consent can be withdrawn without affecting earlier lawful processing.
14. Children
The service is intended for adults and authorized business representatives, not children. We do not knowingly collect personal information from a child under 13 or a higher local digital-consent age. Contact support@certlev.com if you believe a child supplied information.
15. Client-controlled data
For some custom projects, CertLev may process personal information on behalf of a Client. The Client generally determines the purposes of its production data. A data-processing addendum, security schedule or separate hosting arrangement may be required before production personal data is provided.
16. Changes and contact
We may update this notice for legal, operational or technical changes. Material changes will be communicated where required.
CertLev (CertLev)
New York
United States
support@certlev.com