GDPR Compliance

GDPR Compliance

Last updated: August 2026

How CertiLayer approaches the GDPR — starting from an architecture that avoids personal data processing wherever the product allows it.

1. Our starting position: minimal data by architecture

CertiLayer's core detection engine was built specifically to avoid processing personal data under GDPR wherever possible. Behavioral feature vectors — timing, movement, rhythm — are, by design, not linked to an identified or identifiable natural person by CertiLayer. This isn't a policy layered on top; it's how the model inputs are structured.

Where we do process personal data — your account details as our customer, or your end users' data if you choose to correlate our session IDs with your own user records — the rest of this page explains the legal basis and your rights.

2. Roles under GDPR

For your CertiLayer account data (your name, email, billing details), we act as the Data Controller.

For behavioral signal data processed on behalf of your organization through the SDK, we act as a Data Processor, and you (our customer) are the Data Controller for your own end users. Our Data Processing Addendum at /dpa governs this relationship and is available for signature on request.

3. Legal basis for processing

Account and billing data: processed under contract (necessary to provide the Service you signed up for) and legitimate interest (fraud prevention, security).

Behavioral signal data: processed under your instructions as our customer, under the legal basis you've established with your own end users (typically legitimate interest in fraud/bot prevention, or consent, depending on your jurisdiction and use case).

4. Your rights as a data subject

If CertiLayer is the Controller of your data (i.e., you're a CertiLayer account holder), you have the right to access, correct, delete, or export your data, and to object to or restrict certain processing. Email [email protected] and we'll respond within 30 days.

If you're an end user of a CertiLayer customer's product and want to exercise your rights over behavioral data, contact that company directly — they're the Data Controller for that relationship, not CertiLayer. We'll assist our customers in fulfilling such requests where technically required to.

5. International data transfers

Where data is transferred outside the EEA/UK, we rely on Standard Contractual Clauses (SCCs) with our infrastructure sub-processors, or equivalent safeguards recognized under GDPR Chapter V.

6. Data retention

Behavioral signal data is retained per your plan's data retention window (7–365 days, see /pricing). Account data is retained for the life of your account plus a limited period for legal/accounting requirements after closure.

7. Supervisory authority

If you believe we haven't adequately addressed a concern, you have the right to lodge a complaint with your local data protection supervisory authority.