Privacy Policy
Version: 1.0 · Last updated: 1 July 2026 · Effective date: 1 July 2026
1. Who we are
Certo is the controller for the personal data described in this policy. You can reach us here:
- Certo
- Schiedamse Vest 154, 3011 BH Rotterdam, Netherlands
- Legal and privacy email: legal@certo.chat
Certo is a fintech app operating under the General Data Protection Regulation (GDPR) and other applicable EU and Dutch law. This policy explains what data we process, why we process it, the legal basis, who receives it, how long we keep it and what rights you have.
2. Our starting point
Certo combines end-to-end encrypted communication with a non-custodial crypto wallet. We apply data minimisation: we collect what is needed to provide, secure and comply with the Service, and we do not collect private keys or your recovery phrase.
We do not run advertising or behavioural analytics, do not track you across other services and do not sell personal data. We do not use personal data to build advertising profiles.
3. Data we process on the website
Our website uses no cookies, analytics, tracking pixels or contact forms. We process:
- Language preference. If you pick a language, we save that choice in your browser's localStorage. This stays on your device and is never sent to us. You can delete it at any time via your browser settings.
- Hosting and security logs. The host may record an IP address, browser and device information, requested page, time and security events. We use this for a secure and functioning website (legal basis: legitimate interests). We keep these logs for the short period set by our host's security and operations policy, then delete or aggregate them.
There is no website account, newsletter or form. If you email us, we process the email address, message and any attachment to answer you (legal basis: taking steps at your request and our legitimate interest in handling correspondence).
4. Account, verification and profile data
- Account data. Your @handle, phone number, account settings, login and security events. We use this to create and secure your account and to let other users find and pay you (legal basis: performance of our contract and legitimate interests in security).
- Phone verification. Every user must complete phone verification through Didit. We use the result to protect the Service and reduce abuse (legal basis: performance of our contract and legitimate interests).
- Full KYC. Selling and other higher-trust features require an identity document and liveness check through Didit. The resulting KYC record is encrypted. Liveness information may qualify as biometric data under the GDPR; where that applies, we process it only under the applicable GDPR Article 9 condition and for verification, compliance and security. The legal basis is compliance with applicable legal obligations and, where permitted, legitimate interests in preventing abuse. Verification lowers risk but does not eliminate it.
- Reduced verified name. Other users see only your initials and surname as a reduced verified display name. This is necessary to provide the trust feature you use (legal basis: performance of our contract and legitimate interests).
- Profile and trust data. If you create a public profile, we process the profile information, follows, likes, reviews and buyer reputation you provide. Buyer reputation is private and shown only to Sellers as described in the Service. Public profile data is visible to other users because that is the purpose of the feature (legal basis: performance of our contract).
5. Spaces, marketplace and user content
Spaces can contain public profiles, posts, photos, videos, comments, likes, follows and reviews. We process the Content and related metadata you provide to publish, display, secure, moderate and remove it, and to respond to reports (legal basis: performance of our contract and legitimate interests). Other users may copy or retain content they can lawfully access.
For marketplace listings we process listing content, seller and buyer account identifiers, delivery and dispute information, reviews, reputation and transaction metadata. We use this to show listings, support communication, prevent prohibited goods and meet legal duties. Certo is not a party to the sale and does not receive or hold the purchase price.
If you provide personal data about another person, such as a contact, you must have a lawful basis to do so and must not share more than needed.
6. Encrypted communications and calls
Messages, group chats, shared files, locations and voice or video call content are end-to-end encrypted. The keys are on participants' devices. Certo cannot read the plaintext, use it for advertising or provide it in response to a request because we do not have it.
We do process limited service metadata needed to deliver and secure communications, such as account identifiers, recipients, delivery status, timestamps, device and network information, abuse reports and technical errors. WebRTC calls use peer-to-peer transport with DTLS-SRTP where technically possible. Metadata processing is based on performance of the contract, security and legal obligations.
A participant may voluntarily report or share a specific item of encrypted content for safety or legal review.
7. Wallet, payments and blockchain data
The wallet is strictly non-custodial. Private keys and the 12-word recovery phrase are generated and stored only on your device and are never sent to Certo. We do not know, receive or store them.
On-chain activity is public by nature. Depending on the network and feature, we may process or display public wallet addresses, transaction hashes, token and network, amount, fee, timestamp, status and the @handle or contact used to start a payment. We use this to show payment status, support security and meet legal duties. This data may remain on the public blockchain independently of account deletion.
Certo is not a bank, custodian or electronic money institution and does not hold client funds.
8. Device, permissions and third parties
We process the minimum device and technical information needed to operate the App, such as operating-system version, app version, device and network diagnostics, security events and crash information where available. We do not use it for advertising or cross-service tracking.
If you enable push notifications, Apple or Google may process a delivery token and notification data under their own terms. If you grant camera, microphone, contacts, photo or notification permission, the App uses that access only for the feature you selected and respects the device permission. You can withdraw optional permissions in your device settings, although the related feature may stop working.
Our processors and service providers may include Didit for verification, hosting and infrastructure providers, and blockchain or RPC providers needed to submit or read transactions. They may process data only under our instructions and contractual confidentiality and security duties. We do not use advertising networks, analytics SDKs or third-party AI to profile you.
9. Purposes and legal bases
We use personal data only for these purposes: create and operate accounts; verify phone numbers and identities; provide chat, calls, Spaces, marketplace and payments; show reduced verified names; prevent fraud, abuse, money laundering and sanctions breaches; moderate and investigate reports; provide support; secure, troubleshoot and improve the Service; comply with legal obligations; and establish, exercise or defend legal claims.
The legal basis is, depending on the purpose, performance of our contract with you, compliance with a legal obligation, our legitimate interests in security, fraud prevention and service operation, or your consent for an optional feature. Where we rely on legitimate interests, we balance those interests against your rights. Where processing is based on consent, you can withdraw it at any time without affecting earlier lawful processing.
10. Retention and deletion
We keep data only as long as needed for the purpose collected, then delete or anonymise it unless a longer period is required by law, needed for a legal claim, or technically necessary for a short backup cycle.
- Website language preference: stored locally on your device until you remove it.
- Website security logs: a short period set by security and operations needs, then deleted or aggregated.
- Account, profile and support data: while the account or support matter exists, then deleted or anonymised within a reasonable operational period.
- Public Content and blockchain records: may remain visible or immutable after you or another user has shared or confirmed them; account deletion cannot erase the blockchain or copies held lawfully by others.
- Encrypted KYC records: for the statutory retention period applicable to the relationship and financial-crime obligations. After that period, we delete or anonymise them unless another legal duty requires longer retention.
You can request account deletion in the App. Deletion does not override mandatory KYC retention, legal holds, fraud investigations or records that we must keep.
11. Sharing and international transfers
We do not sell or rent personal data. We share it only with processors and providers needed for the purposes above, other users when a feature is public or you choose to share, and authorities when a valid legal obligation or lawful request requires it.
We keep data in the European Economic Area where reasonably possible. If a provider or network processes data outside the EEA, we use an adequacy decision, Standard Contractual Clauses or another lawful GDPR transfer mechanism and apply appropriate safeguards. You can contact us for information about the relevant safeguard.
Processors must provide protection appropriate to this policy and the GDPR. We remain responsible for our processing decisions.
12. Security and incidents
We use encryption in transit and at rest for data we hold, end-to-end encryption for supported content, access controls, least-privilege access, logging, data minimisation and security reviews appropriate to the risk. No service can promise absolute security.
If a personal-data breach creates a risk to your rights, we will assess and notify the competent supervisory authority and affected people where the GDPR requires it.
13. Your GDPR rights
Subject to legal limits, you can ask us to access, correct, delete or restrict use of your personal data, object to processing based on legitimate interests, receive portable data, and withdraw consent where consent is the basis. You can also object to direct marketing, although we do not send advertising marketing.
You have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, unless a GDPR exception applies. We do not make solely automated decisions of that kind for the Service. Safety tools may use automated signals, but material account or content actions have human review and an appeal route.
Email legal@certo.chat. We may ask for information to verify your identity before responding. We normally respond within one month, with an extension of up to two further months for complex requests, and we explain any delay. Requests are free unless they are manifestly unfounded or excessive.
14. Complaints and supervisory authority
Please contact us first so we can resolve the issue. You also have the right to complain to the Autoriteit Persoonsgegevens, the Dutch data-protection authority, at https://autoriteitpersoonsgegevens.nl/. You may also contact the supervisory authority in the EU country where you live, work or believe an infringement occurred.
15. Changes to this policy
We may update this policy when the Service, our processing or the law changes. We show the version, effective date and last-updated date at the top. For material changes, we give clear advance notice in the App or on the website where required and explain any consent choice.