Your data. Your export. Your exit plan.
The three questions that should kill most SaaS deals, "can I get my data out?", "what if you go bust?", "who sees my data?", answered in writing before you upload a single roster.
You can export your data: any time
An admin can export your business data whenever you want, with no export add-on and no per-export fee: classes, students, certificates, invoices, expenses, clients and more, in one JSON archive.
- One click on "Export all business data" in Settings → Data & Privacy, delivered as a download link
- Student, client, invoice and expense lists also export to CSV, and completed classes export as regulator roster CSVs
- One archive holds up to 5,000 records of each type, and the export tells you if anything was left out
- Certificates are PDFs with a QR code that links to online verification
You own your data: contractually
Your training records are your property. Our MSA and Terms are explicit: Certivo is the data processor, you are the data controller. We have no rights to repurpose, resell, or analyze your tenant data for any purpose other than operating the service for you.
- Zero AI training on customer data (we use pre-trained Google Gemini on Vertex AI, rate-limited per tenant)
- Zero data sales: we're a SaaS, not an ad network
- No aggregation across tenants unless you opt-in to benchmarking reports
- DPA (Data Processing Agreement) executed before first data upload
Tenant isolation enforced at three layers
Your data cannot be seen by other Certivo customers, even accidentally.
- Client-side: every Firestore query is wrapped in TenantGuard, auto-adding your tenant's orgId filter
- Database: 3,912 lines of Firestore Security Rules enforce tenant isolation on every read/write
- Server-side: every Cloud Function validates the caller's orgId from their auth token before touching data
- Certivo's platform administrator (today, the founder) can access tenant data for support and operations without asking you first. That account requires multi-factor authentication, and a support session inside your account lasts at most 60 minutes and is recorded in the audit log
Data residency: Toronto compute, Google US storage
Application compute and Cloud Functions (invoicing, certificates, integrations) run in Google Cloud's Toronto region (northamerica-northeast2). Data at rest: database, file storage, backups, and authentication, is hosted in Google Cloud's US multi-region under Google's SOC 2 Type II controls.
- Compute and Cloud Functions run in-region in Toronto (northamerica-northeast2)
- Data at rest (Cloud Firestore database, file storage, backups, Firebase Authentication) is hosted in Google Cloud's US multi-region
- Protected under Google's SOC 2 Type II / ISO 27001 controls and the safeguards described in our DPA
- Built for PIPEDA (collection, use, and disclosure); full cross-border transfer disclosure in our DPA and sub-processor list
If Certivo goes out of business
Our contingency plan is public.
- When a subscription ends, the Master Subscription Agreement gives you a 30-day export window with read-only access. Export from Settings during that window, or ask us and we will run the export and send you a download link. Automatic export on cancellation day is not in place today, so please ask rather than wait.
- No source-code escrow agreement is in place today. Enterprise customers who need one can raise it during contract negotiation.
- Certificates are PDF files your students and clients can download and keep, and the certification itself does not depend on Certivo. The QR code and online verification link only work while Certivo is running.
- Your clients' safety managers can download certificates, a compliance report and CSV exports from their portal at any time.
Right to deletion
An admin can schedule deletion of your business data from Settings, and the people in your records can ask for their personal information to be removed.
- Self-serve deletion is scheduled to run 7 days after you request it, so a mistake can still be caught. Login accounts, settings, the audit log, payment receipts and financial history are kept.
- Training records (classes with their rosters, certificates, class sign-ins and class form responses) are kept for 5 years after each course, even after deletion, with phone numbers, dates of birth, addresses, health details and similar fields removed. They are hidden from the product and deleted when the 5 years end.
- After a subscription ends, the rest of your data is deleted within 60 days of the 30-day export window closing, and copies in backups are overwritten within the 90-day backup rotation. Financial records and incident reports are kept for as long as tax and safety law require.
- A record that something was deleted, and by whom, is kept for legal and regulatory reasons: not the deleted data itself.
- Students in your registry can request deletion under PIPEDA, and we handle it with you as the controller. Their contact and other personal details are removed; the course record itself (their name, the course, the date and the result) is kept under the 5-year training-record hold.
Frequently asked
Who on the training-provider side can see my workers' data?
The role-based access control is configured by your training provider. Typical roles: admin (sees everything), scheduler (sees class rosters), instructor (sees only their assigned classes), billing (sees invoices but not worker health data). On the Certivo side, the platform administrator (today, the founder) can technically access any account's data. Our Super-Admin Governance Policy limits that to support, troubleshooting and incidents and prohibits any competitive use. The administrator account requires multi-factor authentication, and a support session inside an account lasts at most 60 minutes and is recorded in the audit log with who started it and when.
What happens if my training provider switches systems?
Your certificates are PDFs, and the certification itself does not depend on the software your provider uses. Your training provider is obligated under our DPA to export your compliance records to CSV and hand them to you or your next provider. If the switch is contentious, we can mediate a data-portability handover directly.
Can Certivo marketing email me or my workers?
No. We do not use client-portal user data for marketing. We do not email your workers. We do not sell lists. The only platform-generated emails your workers receive are transactional (certificate delivery, class reminders, booking confirmations) and only if your training provider enables them in their tenant settings.
What if I'm a data subject and want my data removed?
Email privacy@certivo.ca from the email on file. We'll confirm your request within 2 business days, verify identity, coordinate with your training provider (as the data controller), and complete it within 30 days. Your contact and other personal details are removed; the record of a course you took (your name, the course, the date and the result) is kept for 5 years after that course, because training providers must be able to show who was trained. Full process detailed in our Privacy Policy.
Is my data used to train AI models?
No. Certivo's AI features (Ask Certivo, Certivo Intelligence) use rate-limited calls to pre-trained Google Gemini models on Google Cloud Vertex AI, in the northamerica-northeast1 (Montreal, Canada) region. We do not fine-tune on customer data, and Google's Vertex AI terms prohibit using customer prompts or responses to train their models. Google Cloud is named as a sub-processor on our sub-processor list; no other AI provider receives customer data.
Need a signed commitment before you evaluate?
Email privacy@certivo.ca with your counsel's name. We'll send our standard DPA within 1 business day. Red-line review welcome.
Contact us