1. Scope and our two roles
This policy explains how Maker’s Edge Inc. ("CERTI", "we", "us") handles personal information. CERTI provides an AI-native quality management system for food and packaging manufacturers. It applies to getcerti.com and to the CERTI platform, and it is written for the United States.
The distinction that matters most in this document is which of two roles we are in, because it determines who you should contact about your data and what rights you exercise against whom.
- We are the controller — a "business" under California law — for information about visitors to our website and people we speak to commercially: prospects, people who book a demo, and contacts at our customers and suppliers. We decide how that information is used, and this policy governs it directly.
- We are a processor — a "service provider" under California law — for everything inside a customer's CERTI workspace. When a manufacturer uploads its procedures, audit records, batch records, supplier certificates or employee training records, that manufacturer remains responsible for the data and we act on its instructions under our customer agreement. If you are an employee of one of our customers and want to exercise rights over records held in their workspace, contact your employer; we will support them in responding.
2. Information we collect
A. From our website
Our website is deliberately light. It contains no forms, no account creation and no analytics or advertising trackers of any kind. We do not set our own cookies for analytics, profiling or advertising. Three third parties are contacted when you use the site, and each necessarily receives your IP address and browser details in order to serve content:
| Third party | When | What it does |
|---|---|---|
| jsDelivr | Every page load | Serves the animation libraries the site runs on. |
| Arcade | Only when you open an interactive product demo | Hosts the demo walkthrough. It assigns a session identifier and records which steps of the demo you view, so we can see which demos are used. |
| Cal.com | Only when you book a demo | Runs our scheduling. You give it your name, email address and time zone in order to book a meeting. |
Our hosting provider also keeps standard server logs, including IP addresses, for security and abuse prevention.
B. When you deal with us commercially
- Demo and enquiry details — name, business email, company, role, and whatever you choose to tell us about your operation.
- Correspondence — email and meeting records, including notes we take about your requirements.
- Event contacts — details exchanged at trade shows and industry events.
- Prospecting contacts — business contact details we obtain in order to approach you about CERTI. See section 3C for the sources and how to stop it.
- Customer administration — billing contacts and the account details needed to run your subscription.
C. Inside a customer workspace
Here we act as a service provider and the categories are determined by our customer. In practice a workspace contains quality documents and records rather than consumer data, but personal information does appear in it, including:
- User accounts — names, work email addresses, roles and permissions, and audit trails of who viewed, edited or approved a record.
- Employee training and competency records — the most sensitive category we hold, because it is data about a customer's workforce: which staff were trained on what, when, and whether they were assessed as competent.
- Names inside documents — signatures, approvers, investigators and author names appearing in procedures, CAPAs, audit findings and batch records.
- Supplier and auditor contacts — the people named on certificates, specifications and audit reports.
We do not seek sensitive personal information, and we do not use or disclose it for any purpose that would require an opt-out under US state law. Note that occupational health or dietary information can appear incidentally in food safety records; where it does, we process it only as part of the record and on our customer's instructions.
3. How we use information
A. To provide the platform
To host and operate a customer's workspace, authenticate users, run the analysis features described in section 4, maintain audit trails, provide support and keep the service secure and available. Where we act as a service provider, we do this only on our customer's instructions and for no independent purpose of our own.
B. To run our business
To respond to enquiries, arrange and hold demos, administer subscriptions and billing, provide support, keep records, understand which parts of our website and demos are used, enforce our terms, and comply with law.
C. Marketing, including outreach you did not request
We contact people at manufacturers who we believe have a professional interest in CERTI, including where they have not previously contacted us. We want to be plain about that rather than bury it.
- Who we contact — people in quality, operations, technical and executive roles at food and packaging manufacturers, in their professional capacity, at business addresses.
- Where the details come from — publicly available professional and business sources, and third-party providers of business contact data. We do not purchase consumer data and we do not use personal email addresses.
- How to stop it — every message carries an unsubscribe link, and you can email [email protected] to be suppressed permanently. We honour requests promptly and without asking for a reason. To make sure we never contact you again we keep the minimum record needed to enforce your suppression.
D. Where you have consented
For anything else we ask for consent, which you can withdraw at any time.
4. How AI processes customer content
CERTI's value comes from analysing your documents, so it matters how that analysis actually works. We use a mix of models.
- Self-hosted models run inside our own infrastructure. Content processed by these features does not leave our environment.
- Azure OpenAI Service, provided by Microsoft, powers the remaining features. For those, the relevant excerpt of your content is sent to the service so it can return a result. Microsoft is a sub-processor and is listed in section 6.
We do not use customer content to train general-purpose or shared AI models. Azure OpenAI is a dedicated service rather than the public ChatGPT product: under Microsoft's terms, content submitted to it is not used to train or improve OpenAI's or Microsoft's models, and is not shared with OpenAI.
We use a global deployment of Azure OpenAI, which means the excerpts sent for analysis are routed to whichever Azure data centre has capacity at that moment and may be processed in any Azure region. The processing is transient and the output returns to your workspace.
Microsoft does retain prompts and responses for up to 30 days for the sole purpose of detecting and preventing abuse of the service, where they may be reviewed by authorised Microsoft personnel. They are not used for any other purpose and are then deleted.
Model output is a draft. CERTI proposes, and a named person at your organisation reviews and approves before anything becomes a controlled record. No decision about an individual is made solely by automated means.
A current list of which features use which category of model is available on request, and we give customers advance notice of material changes.
5. How we share information
- Sub-processors — the vendors in section 6, under contract, limited to what they need.
- Within a customer's workspace — with the users and administrators that customer authorises.
- Professional advisers — auditors, lawyers and accountants under confidentiality obligations.
- Legal requirements — where we must comply with law or valid legal process, or to protect rights and safety. We will tell affected customers unless legally prohibited.
- Corporate transactions — in a merger, acquisition or asset sale, subject to this policy continuing to apply.
We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use it for targeted advertising.
6. Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Microsoft Azure | Platform hosting and storage | Sweden Central (European Union) |
| Microsoft Azure OpenAI Service | AI analysis features (section 4) | Global deployment — requests may be processed in any Azure region |
| Cal.com | Demo scheduling on our website | — |
| Arcade | Interactive product demos on our website | — |
| jsDelivr | Website asset delivery | Global CDN |
We will give customers advance notice before adding or replacing a sub-processor that handles workspace content, so there is an opportunity to object.
7. Where your data is stored
All customer workspace content is hosted in the European Union, in Microsoft Azure's Sweden Central region. This is the case for every customer, including US customers: your workspace content is stored in the EU rather than in the United States. We mention it because it is the opposite of what most buyers assume.
Maker’s Edge Inc. is a United States company, so our personnel access that environment from the United States in order to operate and support the service. As described in section 4, excerpts sent for AI analysis may be processed in an Azure region elsewhere. In all of these cases the information is protected by encryption in transit and at rest, least-privilege access controls, and logging of administrative access.
If the location of processing matters to your organisation, tell us before you contract and we will confirm what we can offer.
8. Your rights and choices
If you live in California, Virginia, Colorado, Connecticut, Utah, Texas or another state with comprehensive privacy legislation, you have the right to:
- know what personal information we hold about you and how we use and disclose it;
- access a copy of it, and receive it in a portable form;
- correct information that is inaccurate;
- delete it, subject to exceptions the law allows;
- opt out of sale, targeted advertising and certain profiling.
On that last right there is nothing to opt out of. We do not sell personal information, we do not share it for cross-context behavioural advertising, we do not use it for targeted advertising, and we do not profile people in ways that produce legal or similarly significant effects. We therefore have no opt-out mechanism to offer and no need to act on Global Privacy Control signals for those purposes — but we honour access, correction and deletion requests in full.
The categories of information we collect, our purposes, the categories of third party we disclose to, the categories of source, and our retention approach are set out in sections 2, 3, 5, 6 and 9.
To exercise a right, email [email protected]. We respond within the period the applicable law requires and will tell you if we need longer. We may need to verify your identity before we act. You may use an authorised agent. We will not discriminate against you for exercising a right. If you disagree with our decision you can appeal by replying to our response, and a different reviewer will consider it.
If your data sits in a customer's workspace, contact that customer first. They are responsible for that data and decide the outcome; we assist them.
California: we do not disclose personal information to third parties for their own direct marketing purposes, so there is nothing to report under California's "Shine the Light" law. Nevada: we do not sell covered information as Nevada law defines it.
9. Retention
We keep information only as long as needed for the purpose it was collected for, then delete or anonymise it.
Customer workspace content is different, and deliberately so. Quality records exist to prove what happened, and retention is driven by your certification scheme and by law rather than by us. Customers configure retention for their workspace, and we retain content for the term of the agreement plus the wind-down period it specifies. On termination we delete or return workspace content as instructed, subject to backup cycles and any legal hold.
Where we have not set a fixed period, we decide how long to keep information by weighing:
- how long we still need it for the purpose in section 3;
- whether a certification scheme, tax, employment or other law requires us to keep it;
- whether it is needed to establish, exercise or defend a legal claim;
- the sensitivity of the information and the risk of keeping it.
In practice: website server logs are kept short-term for security only; demo and enquiry records are kept while there is a live commercial relationship and for a reasonable period after; suppression records for marketing objections are kept indefinitely, because deleting them is what would let us contact you again by mistake.
You can ask us at any time how long we hold a particular category of information.
10. Security
We encrypt personal information in transit and at rest, restrict access on a least-privilege basis, log administrative access, separate customer workspaces, review our sub-processors, and maintain incident response procedures. Where a breach is likely to present a risk we notify affected customers and regulators as required, and without undue delay.
No system is perfectly secure, so we do not claim otherwise. Please tell us at [email protected] if you believe you have found a vulnerability.
11. Children
CERTI is a business tool that is not directed to children, and we do not knowingly collect personal information from anyone under 13. If you believe a child's information has reached us, contact [email protected] and we will delete it.
12. Changes to this policy
When we change this policy we update the date at the top. For changes that materially affect how we handle personal information we give notice before they take effect — by email to customers, or by a notice on this page. The previous version is available on request.
13. Contact us
Maker’s Edge Inc.
1401 Pennsylvania Ave., Suite 105
Wilmington, DE 19806, United States
[email protected]
If you are an employee of one of our customers asking about records held in their CERTI workspace, please contact your employer first — they are responsible for that data and we act on their instructions.
Back to home