Who this policy covers
Certi5 Technologies LLC ("Certi5", "we", "us") provides XpressInspect, a digital inspection and audit platform for vertical transportation equipment such as elevators, escalators and moving walks.
This policy applies to the XpressInspect mobile applications for iOS and Android, the XpressInspect web application at xpressinspect.certi5tech.com, and the Certi5 website at certi5tech.com. It explains what we collect, why we collect it, who we share it with, and the choices available to you.
XpressInspect is a professional tool. In almost every case, accounts are created and managed by the inspection agency, building owner or authority having jurisdiction that employs or contracts you.
Our role in your data
Our responsibilities differ depending on the type of information.
Inspection data belongs to your agency. When an inspector records an inspection, the resulting records belong to the organization that subscribes to XpressInspect. That organization decides what is collected, who may see it, and how long it is kept. We process that data on their instructions under our agreement with them. If you want inspection records corrected or removed, contact your organization's administrator first.
For account registration, billing, website enquiries and our own communications with you, we decide how the information is used and we are directly responsible for it.
Information we collect
Account and profile information
Name, work email address, employer or agency, assigned role (administrator, reviewer or inspector), phone number, and professional licence and certification details such as a QEI certification number. This information is normally entered by your organization's administrator rather than by you, and the licence and certification details are held because they appear on inspection reports and are relied on by accreditation bodies.
Inspection records you create
- Equipment identifiers, unit numbers and equipment type
- Building or site name and address where the equipment is located
- Checklist responses, pass and fail results, deficiencies and notes
- Photographs and attachments captured during an inspection
- Inspector and witness signatures
- Date, time and duration of the inspection, and the inspector it is attributed to
Device and technical information
Device model, operating system version, app version, language setting, IP address, and diagnostic information generated by our Amazon Web Services infrastructure when the platform reports an error. We use this to keep the service running and to reproduce faults you report.
Website and enquiries
If you email us from certi5tech.com, we receive the contact details and the message you send.
What we do not collect
Some of what we do not do matters as much as what we do. As at the effective date of this policy:
- The XpressInspect mobile applications do not collect device location or GPS data.
- We do not use any website or in-app analytics tool. Our only diagnostic source is error reporting from our AWS infrastructure.
- We do not use advertising identifiers, and we do not track users across other companies' apps or websites.
- We do not sell personal information, and we will not sell it.
If this changes, we will update this policy and the App Store privacy disclosures before the change takes effect.
How we use information
- To provide the inspection platform and sync records between devices and the cloud
- To authenticate users and enforce role-based access within an organization
- To generate inspection reports and accreditation documentation for your agency
- To administer subscriptions and billing, which Certi5 handles directly with each customer
- To provide support, investigate faults and respond to your questions
- To secure the service, detect misuse and maintain the audit trail
- To meet legal, regulatory and contractual obligations
Where the law requires a legal basis for processing, we rely on performance of our contract with your organization, our legitimate interest in operating and securing the service, and compliance with legal obligations.
Who we share it with
We use a small number of service providers, and we name each of them. We do not share personal information with anyone else except as set out below.
| Recipient | Purpose | Location |
|---|---|---|
| Your organization | Administrators and reviewers in your organization can see the inspection records and activity of users in that organization. | Your location |
| Amazon Web Services | Cloud hosting, storage, database infrastructure and platform error reporting. | United States |
| PAPL Corp India Private Limited | Product development and technical support for the XpressInspect platform, under contract to Certi5. Personnel may access production data where necessary to develop, maintain and support the service. | Chennai, India |
| PAPL Corp India Private Limited | Operations and customer support services, under contract to Certi5. | Chennai, India |
| Email delivery for transactional and service messages. | United States | |
| Legal and safety | Where required by law, regulation, subpoena or court order, or to protect the rights and safety of people and property. | As required |
| Business transfer | If Certi5 is involved in a merger, acquisition or sale of assets, information may transfer as part of that transaction. | As applicable |
We do not currently use a payment processor. If we introduce one, we will name it in this policy before it begins processing any information.
Where data is stored and accessed
Platform data is stored on Amazon Web Services infrastructure in a United States region. The mobile applications also hold inspection data on your device so that you can work offline in machine rooms and shafts, and that data syncs to the cloud when a connection returns.
Access from India. Certi5's product development, technical support and operations teams are provided by PAPL Corp India Private Limited in Chennai, India. Personnel in India can access production data, including inspection records and account information, where necessary to develop, maintain and support the platform. Data remains stored in the United States; this is remote access rather than a transfer of storage. Access is limited to personnel who require it, is subject to the same role-based controls and audit logging as all other access, and is governed by contractual confidentiality and data protection obligations between Certi5 and PAPL Corp India Private Limited.
How long we keep it
Inspection records are kept for as long as your organization's subscription is active, and afterwards in line with our agreement with that organization. Inspection and accreditation records frequently carry statutory retention periods set by the authority having jurisdiction, and your organization may direct us to retain records for that reason.
Customer and account records are retained for five years after an account is deleted. We hold them for this period because inspection reports are legal records that may be examined during an accreditation review, an insurance claim or a jurisdictional audit, and the identity and certification status of the inspector who signed a report must remain verifiable for that period.
Diagnostic data is retained for 180 days.
Security
We encrypt data in transit and at rest, restrict access on a least-privilege basis through the platform's three-tier role architecture, and log administrative activity. Every inspection entry is timestamped and attributed to the inspector who captured it. The platform's inspection workflow and reporting structure are aligned to ISO/IEC 17020:2012.
No system is perfectly secure. If a breach affects your information, we will notify affected organizations and individuals as required by applicable law.
Your rights and choices
Depending on where you live, you may have the right to access, correct, delete, restrict or object to the processing of your personal information, to receive a copy in portable form, and to withdraw consent where we rely on it. California residents have additional rights under the CCPA, including the right not to be discriminated against for exercising them. We do not sell personal information or share it for cross-context behavioural advertising.
Because most information in XpressInspect is held on behalf of your organization, we will usually refer your request to them and support them in answering it. To make a request directly, contact us using the details below. We will not charge you for exercising these rights, and we will respond within the period required by applicable law.
Deleting an account
You can have your XpressInspect account and its associated personal data deleted at any time. There are three routes.
Delete your own account
You can delete your own account yourself, without contacting an administrator or Certi5. Open your dashboard at xpressinspect.certi5tech.com/inspector_dashboard and select Deactivate Account. You are asked to confirm the request, and on confirmation your account is deleted and your access to the platform ends.
Through your organization's administrator
Administrators can delete accounts directly in the XpressInspect web application:
- To delete an individual user, open xpressinspect.certi5tech.com/list_all_users and remove the user from the list.
- To delete an entire organization and all of its users, open xpressinspect.certi5tech.com/view-organization and delete the organization.
By request to Certi5
If you can no longer sign in, or you would rather we handle it, email admin@certi5tech.com from your registered address and ask us to delete your account. We complete deletion within 24 hours of receiving the request.
However the request is made, the user profile is removed and the individual loses all access to the platform. Inspection records that belong to your organization are retained and the personal profile behind them is closed, because a signed inspection report is a legal record that the agency and its accreditation body continue to rely on. Account records are then held for the five-year period described above and deleted at the end of it.
Children
XpressInspect is a workplace tool intended for professional users aged 18 and over. We do not knowingly collect personal information from children. If we learn that we have, we will delete it.
Changes to this policy
We update this policy when our practices change. The effective date at the top of this page shows the current version. For material changes we will notify subscribing organizations directly and, where appropriate, in the application.
Contact us
For any privacy question or request, reach us at:
Certi5 Technologies LLC
8296 Flagg View Dr
Powell, OH 43065
United States
admin@certi5tech.com
certi5tech.com