The operational commitments we make to clients and candidates on how personal information is handled.
Verification is a business built entirely on other people's personal information. We treat that as the defining obligation of the service rather than an administrative formality.
This statement sets out the operational commitments we make to clients and to the candidates whose records we verify. It sits alongside our Privacy Policy, which explains our legal position in full.
When a client instructs us to verify a candidate, that client determines what is checked and for what purpose. They are the controller. Authenticatin acts as a processor and works only on documented instructions.
We do not repurpose candidate data. We do not use it to build databases, to market to candidates, or for any purpose beyond completing the instructed case.
This is not negotiable. Every case must be accompanied by an authorisation signed by the candidate, covering the specific checks requested. Where an authorisation is missing, expired or does not cover the requested check, we decline the case and tell the client why.
The authorisation is also what protects the specialist attending the institution. It is the document they present to establish that the enquiry is legitimate.
Every verification specialist we engage is bound before receiving any case by written obligations covering:
| Area | Measure |
|---|---|
| Transmission | Case material is transferred over encrypted connections |
| Storage | Access-controlled storage with permissions limited by role |
| Access | Need-to-know only, per case; access revoked at case closure |
| Devices | Specialists are prohibited from storing case material on personal devices beyond the case duration |
| Review | Access rights reviewed when an engagement ends |
Case data is retained for as long as the instructing client requires it, and by default no longer than twelve months from case completion.
Clients may instruct deletion of any case at any time in writing. We confirm deletion in writing once completed. Candidates may also request deletion; where we act as processor we will pass the request to the instructing client and support them in responding.
Confirming a credential issued in one country for an employer in another necessarily involves cross-border transfer. Where personal data leaves the EEA or the UK we rely on Standard Contractual Clauses and on contractual confidentiality obligations with every party in the chain.
We will tell a client in advance where a specific market involves an unusual transfer arrangement or a local restriction that affects how data may be handled.
We engage a limited number of service providers, including hosting, email and secure file storage. Each is bound by contract to protection standards consistent with those we offer our clients.
Clients may request a current list of sub-processors at any time. We will give reasonable notice of any material change.
If you are an individual whose credentials have been verified, you may ask us:
Because the instructing client determines the purpose of the check, some requests must be directed to them. Contact us and we will identify the correct party and forward your request. We respond within 30 days.
For any data protection question, or to make a request:
Authenticatin LLC
Email: contact@authenticatin.com