Privacy Policy
Last updated: 6 August 2026
This Privacy Policy explains how Neo-2 Consulting Limited, a corporation registered in the Province of Saskatchewan, Canada, with its registered office in Saskatoon, Saskatchewan ("Neo-2", "Certivar", "we", "us"), collects, uses, discloses and protects personal information when you use the Certivar service (the "Service").
As a Canadian organization we handle personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial legislation. Where the GDPR, UK GDPR or the CCPA/CPRA apply to you, we honour the rights those laws give you as well. We sell compliance, so we hold ourselves to the standard we ask of our clients.
1. Information we collect
Account information — your name, work email, organization and role, provided when you register.
Customer Data — the answers, documents, evidence and control information you provide, or that we collect from systems you connect, in order to run your compliance program. This may incidentally include personal information about your staff, such as names in an access review or an approval record.
Connected system data — where you authorise an integration (for example AWS, GitHub, Google Workspace or Okta), we read configuration and posture data through scoped, read-only credentials. We do not install agents on your infrastructure.
Usage data — logs, device and browser information, and activity within the Service, used for security, troubleshooting and product improvement.
2. How we use information
We use personal information to deliver and secure the Service, authenticate users, run your compliance program, process payments, communicate with you, provide support, and meet legal obligations. We do not sell personal information, and we do not use Customer Data to train artificial intelligence models.
3. Automated processing and AI
Much of the Service is delivered by AI systems acting under human supervision. Customer Data — including intake answers, policy text, evidence metadata and test results — is sent to third-party AI providers to generate scope proposals, draft policies, answer questionnaires and assess readiness. Those providers are listed in section 4.
Two safeguards apply to that processing. Anything that attests to a fact about your organization must cite a resolvable artifact, or it is rejected before it is stored. And anything that attests is held for a named human reviewer before it reaches you, your auditor, or anyone else. Every AI action is recorded in an append-only log which you can inspect. No decision producing legal effects concerning an individual is made solely by automated means.
4. Service providers and subprocessors
We share personal information with vetted providers who process it only on our instructions and under confidentiality and data-protection obligations:
- Amazon Web Services — cloud hosting, database and evidence storage (United States).
- Anthropic — the AI models that draft policies, scope programs and answer questionnaires (United States).
- Voyage AI — text embeddings used to search your compliance corpus (United States).
- Stripe — subscription billing and payment processing. We do not store your card details.
- Our email delivery provider — transactional email such as task reminders and verification messages.
We will update this list before adding a subprocessor that materially changes how Customer Data is handled. We may also disclose information where required by law, and we will tell you unless we are legally prohibited from doing so.
5. Where your information is held
Neo-2 is based in Canada, but the Service and its providers currently operate in the United States. Your personal information is therefore stored and processed outside Canada, and while it is there it may be accessible to US courts, law enforcement and national security authorities under the laws of that country. We use contractual and technical safeguards for these transfers, including standard contractual clauses where required. If cross-border processing is not acceptable for your organization, contact us before you begin an engagement.
6. Security
We protect information with encryption in transit and at rest, tenant isolation, least-privilege access controls, credential encryption for connected systems, and audit logging. Evidence files carry a SHA-256 digest so tampering is detectable. No system is perfectly secure, but we work continuously to safeguard your information, and we will notify you and the relevant authorities of a breach of security safeguards as required by law.
7. Retention
We retain personal information for as long as your engagement is active and as needed to deliver the Service. After termination you may export your material for thirty days. We then delete or de-identify it, except where we must retain records to meet legal obligations, resolve disputes or enforce agreements. Audit and provenance logs are retained for the period your framework requires.
8. Your rights
Under PIPEDA you may request access to the personal information we hold about you, ask us to correct it, and withdraw consent subject to legal and contractual limits. Depending on where you live you may also have rights to erasure, portability, and to object to or restrict certain processing. To exercise any of these, contact our Privacy Officer below. We respond within thirty days. If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada.
9. Cookies
We use essential cookies to keep you signed in and to protect the Service, and limited analytics to understand and improve usage. You can control cookies through your browser settings; disabling essential cookies will prevent you from signing in.
10. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the Service or by email, and the "Last updated" date above will change.
11. Contact our Privacy Officer
Privacy Officer
Neo-2 Consulting Limited
Saskatoon, Saskatchewan, Canada
privacy@certivar.com
