Privacy Policy

**DRAFT — NOT LEGAL ADVICE. For review by counsel before use (including FERPA, COPPA/age, and Georgia
student-data requirements). Replace bracketed items.**
Version: DRAFT-0.2 (renamed from TNP to Certainto and backup retention updated to include hourly copies, 2026-10-03) · Effective date: [date]

1. What this covers

How [Company legal name] ("Certainto") collects, uses and shares information when you use our certification practice service. The Service is intended for adults and post-secondary or professional learners; it is not directed to children under 13. [Counsel: confirm minimum age and any under-18 handling.]

2. What we collect

We do not ask what was on any real exam and do not collect payment card numbers on our own systems. [Update when payments are added.]

3. How we protect identity

Your practice records are stored under a pseudonymous ID. Your email and name are held in a separate identity store, not in the practice ledger. Reports to Institutions show the pseudonymous ID by default; an Institution can choose to see names, in which case the Institution is responsible for that choice.

4. How we use information

To run the Service, grade and coach you, correct errors, prevent abuse, keep it secure and reliable, support you, and improve it using de-identified and aggregated data. We do not sell personal information and do not use your practice data for advertising.

5. Who sees it

[Counsel: FERPA "school official" language if Institutions are educational agencies.]

6. Retention

We keep practice records while your account or your Institution's agreement is active, then [X months], unless the law requires longer. Backups are encrypted and expire on a rolling schedule: hourly copies for about 48 hours, then about 14 daily and 8 weekly copies. Records that are part of an append-only audit trail may be retained in de-identified form.

7. Your choices and rights

You may ask to access, correct or delete your data by emailing [contact]. Where your Institution controls the account, we may refer the request to it. When we delete, we remove your identity record so remaining practice records can no longer be linked to you. Backups age out on the schedule above.

8. Security

Encryption in transit and for backups, access controls, tenant separation between institutions, and monitoring. No system is perfectly secure; we will notify affected users and Institutions of a breach as required by law.

9. Cookies

We use only cookies needed to keep you signed in. No advertising or cross-site tracking cookies.

10. Changes

If we make a material change we will ask you to accept the new version before you continue.

11. Contact

[Contact email and mailing address. Suggested: a role address at certainto.com once email forwarding exists.] Governing law: State of Georgia.