Privacy Policy
This Privacy Policy explains how Verdacert LLC (“Verdacert”, “we”, “us”) collects, uses, shares, and protects personal information when you visit verdacert.com or use our certified-translation services (the “Services”). It also describes your rights and the choices available to you, including the rights of residents of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Tennessee, Texas, Utah, and Virginia, and individuals in the European Economic Area and the United Kingdom.
This Policy is incorporated into our Terms of Service. Capitalized terms not defined here have the meanings given in the Terms.
1. Information we collect
We collect the following categories of personal information, including the categories enumerated under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
- Identifiers and contact data - name, email address, postal address, phone number, account credentials, IP address, and device identifiers.
- Customer records - billing details (processed by our payment processor; we receive truncated card data and transaction confirmations), and order history.
- Document content - the source documents you upload for translation. These may contain sensitive personal information such as full date and place of birth, government identification numbers, family relationships, immigration status, criminal-history information, health information, biometric identifiers (e.g., signatures), and information about minors.
- Commercial information - products and Services purchased or considered, and refunds.
- Internet activity - browser type, pages viewed, referring URLs, timestamps, interactions with the Services, and similar log data.
- Geolocation - approximate location inferred from IP address (we do not collect precise GPS location).
- Inferences - preferences, interests, and service-quality signals derived from the above.
- Job applicants - if you apply for a role, the information you submit on our job board (CV, contact details, work eligibility) is collected and stored by Landearly, our applicant-tracking provider, and used only for recruiting.
- Sensitive personal information (CPRA, Va. CDPA, and similar laws) - government identifiers, precise location (if you affirmatively provide it), racial or ethnic origin, religious beliefs, citizenship or immigration status, health information, sex-life or sexual-orientation data, account login in combination with required credentials, and union membership, where such information appears in documents you upload.
We do not knowingly collect personal information from children under 13, and the Services are not directed to children. If we learn we have collected personal information from a child under 13 without verifiable parental consent, we will delete it. Where you upload documents about minors as part of an immigration filing, you represent that you are the parent, legal guardian, or authorized representative of that minor.
2. Sources of information
- Directly from you (orders, uploads, account, support).
- Automatically (cookies, analytics, server logs).
- From service providers (e.g., Stripe for payment confirmations; fraud-detection providers).
- From you on behalf of third parties whose information appears in your documents.
3. How we use information (purposes & legal bases)
- To translate, certify, and deliver your documents.
- To communicate about orders, deliveries, revisions, security, and support.
- To process payments and prevent fraud and abuse.
- To comply with legal, tax, and regulatory obligations.
- To operate, secure, debug, and improve the Services - including by using de-identified excerpts of prior reviewer-approved translations (names, identifiers, and dates removed where practicable) as reference examples that guide the AI draft for later orders of the same document type. Medical, court, and law-enforcement documents are never used this way.
- With your separate opt-in, to send marketing communications you can withdraw at any time.
- To establish, exercise, or defend legal claims and to enforce our terms.
- Where you affirmatively consent, for any other purpose disclosed at the time of collection.
For individuals in the EEA or UK, our legal bases under GDPR/UK GDPR are (a) performance of a contract, (b) compliance with a legal obligation, (c) our legitimate interests in operating and securing the Services (balanced against your rights), and (d) your consent where required (e.g., for non-essential cookies and certain marketing).
4. How we share information
We share information only as described below. We do not sell personal information for money. In the prior 12 months we have not sold or shared personal information for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA, and we have no plans to do so.
- Service providers / processors. Vendors that process information on our behalf under written contracts that restrict them to our instructions and require appropriate safeguards: hosting and web analytics (Vercel, United States), document storage (Cloudflare R2), database (Neon, hosted in the United Kingdom), transactional email (Resend), payments (Stripe), website analytics and advertising measurement (Google Analytics and Google Ads via Google Tag Manager, subject to your cookie choices), and applicant tracking for job applications (Landearly). Our current subprocessor list is published at /legal/subprocessors.
- Reviewers and translators. Vetted human reviewers under written confidentiality obligations, who can access only the documents they are qualified to review and are working on.
- AI providers. We use Anthropic (translation drafting and review support), OpenAI (embeddings and independent cross-checks), and Microsoft Azure AI Document Intelligence (page-layout analysis, where enabled) to process your documents. Each is bound by contract not to use your content to train its models, and content is sent only to produce the immediate response.
- Professional advisors. Lawyers, accountants, and auditors under duties of confidentiality.
- Corporate transactions. In a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our assets, information may be transferred, subject to standard confidentiality protections and continued application of this Policy or a successor policy.
- Legal compliance & protection. Where required by law, valid legal process, or to protect rights, property, safety, or to investigate fraud or unlawful activity. We notify customers of governmental requests where permitted.
- With your direction or consent. Such as when you ask us to deliver a translation to a third party.
- Public certificate verification. Each certified translation carries a verification code and QR. Anyone holding the code can see, on our public verification page, the reviewer's name and credentials, the certificate's status and issue date, and - when the order named an applicant - that applicant's name, so a receiving agency can match the document in front of it. Nothing else about the order is shown.
5. AI processing and no training
We do not use customer documents or personal information to train third-party artificial-intelligence models, and our AI providers are contractually prohibited from doing so. We do use de-identified excerpts of prior reviewer-approved translations - with names, identifiers, and dates removed where practicable - as reference examples that improve the quality of later drafts for the same document type; medical, court, and law-enforcement documents are excluded. Every certified translation is verified and finalized by a human reviewer.
6. Cookies & similar technologies
We use strictly-necessary, functional, analytics, and advertising-measurement cookies (Google Ads conversion measurement only - never retargeting or personalized advertising). Where prior consent is required (EEA, United Kingdom, Switzerland), nothing non-essential runs until you choose; everywhere else you can opt out at any time through the “Privacy choices” link in the footer. See our Cookie Policy for the full list of cookies, their durations, and how to manage them.
Global Privacy Control / Do Not Track. We honor Global Privacy Control (GPC) signals everywhere: a GPC signal turns advertising measurement off and is treated as an opt-out of any sale or sharing of personal information under California, Colorado, Connecticut, and similar state laws. We do not currently respond to Do Not Track (DNT) signals because there is no industry consensus on how to interpret them.
7. Data retention
We retain translation deliverables (the certified PDF and the reviewer-approved text) and certification records for seven (7) years to support reissuance and verification requests and to comply with recordkeeping, tax, and dispute-resolution obligations. Source documents you upload, and the AI’s working text derived from them, are automatically deleted from our active systems one (1) year after delivery; uploads that never became a paid order are deleted after 30 days. Raw payment-processor event logs are deleted after 90 days and email delivery logs after 24 months; backups follow shorter rolling schedules. You may request earlier deletion by emailing privacy@verdacert.com; we will confirm in writing when deletion is complete, except where retention is required by law.
8. Security
We implement administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit (TLS 1.3) and at rest (AES-256), strict access controls, audit logging, secret rotation, vendor due diligence, and SOC 2 Type II–aligned controls. For documents containing protected health information, we apply HIPAA-aware handling. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. You are responsible for safeguarding your account credentials.
9. International data transfers
We operate on infrastructure in the United States (application hosting on Vercel; document storage on Cloudflare R2) and the United Kingdom (our database is hosted by Neon in AWS eu-west-2, London). If you are located outside those countries, your information will be transferred to and processed in them, which may have different data-protection laws than your jurisdiction. Where required, transfers from the EEA, UK, or Switzerland are made pursuant to the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism. By using the Services you consent to these transfers to the extent permitted by law.
10. Your privacy rights
Depending on where you live, you may have some or all of the following rights regarding personal information about you:
- Access / know - confirm whether we process personal information about you and obtain a copy.
- Correct - correct inaccurate personal information.
- Delete - request deletion, subject to legal exceptions (e.g., recordkeeping, fraud prevention).
- Portability - receive your information in a portable, machine-readable format.
- Opt-out of sales/sharing - we do not sell or share for cross-context behavioral advertising, but you may still submit a verified request.
- Opt-out of profiling / targeted advertising - we do not engage in profiling that produces legal or similarly significant effects, nor in targeted advertising.
- Limit use of sensitive personal information - we use sensitive personal information only for purposes permitted under CPRA (e.g., providing the Service, security, quality control).
- Non-discrimination - we will not deny goods or services, charge different prices, or provide a different quality of service because you exercised a privacy right.
- Appeal (Colorado, Connecticut, Texas, Virginia, others) - appeal a denial of your request by replying to our decision notice; if your appeal is denied you may contact your state attorney general.
- Withdraw consent - where processing is based on consent.
- Lodge a complaint - with a supervisory authority (EEA/UK) or your state attorney general.
How to exercise rights. Email privacy@verdacert.com or write to Verdacert LLC, Attn: Privacy, 4112 Manor Oaks Ct, Export, PA 15632. We will verify your request by matching the information you provide to information we already hold and, where appropriate, by requesting additional confirmation. Authorized agents may submit requests on your behalf with written, signed permission and verification of identity. We will respond within the time required by applicable law (generally 45 days, extendable as permitted).
11. California “Shine the Light”
California residents may request, once per calendar year, information about categories of personal information (if any) we disclosed to third parties for their direct marketing purposes. We do not disclose personal information to third parties for their direct marketing purposes.
12. Nevada residents
Nevada residents may direct us not to sell their personal information. We do not sell personal information as defined under Nevada law, but you may submit a verified request to privacy@verdacert.com to confirm.
13. Children’s privacy
The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, contact us and we will delete it.
14. Third-party links
The Services may link to third-party websites or services. We are not responsible for their privacy practices. Their use of your information is governed by their own policies.
15. Data-breach notification
If we determine that a security incident has resulted in the unauthorized acquisition of unencrypted personal information, we will notify affected individuals and regulators as required by applicable law. Nothing in this Policy constitutes a waiver of any rights or remedies otherwise available under applicable breach-notification laws.
16. Changes to this Policy
We may update this Policy from time to time. The version posted on this page is the current version and supersedes prior versions. We will notify you of material changes by email, by a prominent notice in the Services, or both, at least 14 days before they take effect, except where a shorter period is required by law or by a security incident.
17. Contact us
Verdacert LLC, Attn: Privacy, 4112 Manor Oaks Ct, Export, PA 15632. Email: privacy@verdacert.com. For EEA/UK individuals: where required, our designated contact for data-protection inquiries is the privacy email above.
