We sell data about organizations, not people.
No Certvas product contains natural-person data. The only personal data we handle is the contact information you choose to give us — to buy, to trial, or to get in touch. This page explains what we collect, why, and who processes it.
Last updated: August 2026.
No personal data in the products.
Every published Certvas dataset (AF-FUND, AF-TENDER, AF-MACRO) contains organization-level and public-statistical data only. In procurement data, party records are classified and natural persons are excluded in the model layer — a structural rule, enforced in code and checked in CI. We do not collect, store, or sell personal data as part of any data product, and we never build profiles of individuals.
What we collect, and why.
Contact details
If you email us, request a sample, or buy, we hold your name, email and company — used only to reply, fulfil your order, issue your API key, and answer follow-ups. We don’t send marketing you didn’t ask for.
Purchase & billing
Checkout is handled by our merchant of record, Polar. They process your payment and billing details — we never see your card number. We receive only the order record (product, amount) needed to fulfil and account for the sale.
Site analytics
We use Cloudflare Web Analytics — privacy-first, aggregate traffic stats with no cookies and no cross-site tracking. We can’t and don’t identify individual visitors.
API & delivery
When you request free sample access or subscribe, we email your API key via Resend and provision the key in our system. Your email is used only to deliver the key and reply to you — never added to any product. We also record your organization type and use-case as anonymous demand signal, and measure whether a new key makes its first query (activation) using a pseudonymous key identifier that is not linked to you except through our internal records.
Who we share operational data with.
We do not sell personal data, and we don’t share it beyond the service providers needed to run the business: Polar (payments / merchant of record), Cloudflare (hosting and privacy-first analytics), Google Workspace (our email), and Resend (transactional email such as API-key delivery). Each processes only what its function requires, under its own terms.
Your rights & how long we keep data.
You can ask us to access, correct, or delete the contact information we hold about you — just email [email protected] and we’ll action it. We keep operational data only as long as needed to provide the service and meet legal or accounting obligations, then delete it. Because our products contain no personal data, there is nothing about individuals to access or erase in the datasets themselves.
Questions about this policy? Reach us any time at [email protected].
Ownership and data controller. Certvas is a sole proprietorship owned and operated by Rebaone Theo Mandase of Francistown, Botswana, who is the data controller for the purposes of this policy. Certvas is a trading name; it is not a separately incorporated company. The Certvas Ontology and Certvas ID are released under CC0 1.0.