Privacy Policy
Version 1.3.1 · Effective April 22, 2026 · Last revised July 1, 2026
ATAC Anagenesis Inc. ("ATAC," "we," "us") respects your privacy. This Privacy Policy explains how we collect, use, share, and protect your personal information when you use the ATAC Global CX platform and related services (the "Services").
This Policy is designed to comply with Canadian privacy law (PIPEDA), the European Union and United Kingdom General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and, with respect to biometric information, the Illinois Biometric Information Privacy Act (BIPA). Where regional laws provide additional rights, those rights apply to residents of those regions.
1. Information We Collect
1.1 Information You Provide
- Account registration: full name, email address, password (stored as bcrypt hash)
- Mobile number (optional): if you choose to receive text messages, the mobile phone number you provide and your SMS consent status (with timestamp). See Section 11.
- Professional profile: languages spoken, years of experience, country or region, optional wallet address for blockchain credentials
- Payment information: payment card details are collected and tokenized by Stripe; ATAC does not store full card numbers
- Assessment responses: your answers, time taken, and scoring data
- Consent records: timestamps, IP addresses, and document versions when you accept our legal agreements
- Communications: messages you send us via email or support channels
1.2 Information We Collect Automatically
- Technical data: IP address, browser type, device type, operating system, referring URL
- Usage data: pages viewed, features used, time spent, assessment session duration
- Cookies: session cookies required for authentication; optional analytics cookies only with your consent
1.3 Information From Third Parties
- Employers: if your employer purchases seats on your behalf, they provide your email address to invite you
- Stripe: transaction confirmations and fraud signals (but not full payment card data)
1.4 Photo Verification (Optional)
Candidates may optionally upload a headshot or capture a selfie through our Photo Verification feature. Photo collection is opt-in: the No Photo tier requires no photo upload and remains available regardless.
- Headshot: a profile photo you upload before starting your assessment. Headshots are pinned to IPFS via Pinata and are publicly retrievable, since they appear on your public verify page and printed certificate.
- Selfie: a still image captured by your device camera at the start of your assessment and, if you opt into Biometric Identity Verification (Section 1.5), again at the start of your voice simulator. Selfies are stored only in our private database, never on a public network or third-party storage service. Selfies are accessible only to ATAC administrators and to employers on a per-request basis when verifying a credential.
Photos are captured only at the start of the assessment and, where you opt into Biometric Identity Verification, at the start of the voice simulator — never as a continuous camera feed and never during the assessment itself. Except where you opt into Biometric Identity Verification (Section 1.5), we do not perform facial recognition or comparison, and in no case do we retain a persistent biometric template or "faceprint." For full disclosures, including retention and deletion paths, see our Photo Consent Disclosure and our Biometric Consent Disclosure.
1.5 Biometric Identity Verification (Optional)
To confirm that the same individual completes each stage of certification, candidates may opt into Biometric Identity Verification. When you opt in and provide separate, explicit consent, we compare the selfie captured at the start of your written assessment and the selfie captured at the start of your voice simulator against the headshot you provided, using facial-geometry analysis. This processing constitutes biometric information.
- Purpose, and only this purpose: identity verification and credential-fraud prevention — confirming you are the same person from signup through the assessment, the simulator, and credential issuance. We do not use biometric information for marketing, advertising, profiling, surveillance, or training artificial-intelligence systems.
- How it works: comparisons are performed by Amazon Web Services (AWS) Rekognition in our Canadian region (ca-central-1) using a stateless comparison operation. AWS returns only a numerical similarity score and does not retain your images or a facial template. We store the similarity scores and your selfie images (privately, as described in Section 1.4). We do not create or retain a persistent biometric template or "faceprint."
- Opt-in and separate consent: Biometric Identity Verification is voluntary and requires your separate, explicit Biometric Consent before any facial comparison occurs. If you do not consent, no facial comparison is performed, and non-verified certification options remain available.
- Withdrawal: you may withdraw biometric consent at any time, which stops all future biometric processing. Withdrawal does not affect a credential already issued.
Legal basis (GDPR users): biometric data used to uniquely identify you is special-category data, processed solely on the basis of your explicit consent (Article 9(2)(a)). Illinois residents (BIPA): our retention-and-destruction schedule and written-release terms are set out in the Biometric Consent Disclosure. We do not sell, lease, trade, or otherwise profit from your biometric information.
2. How We Use Your Information
We use your personal information for the following purposes:
- Providing the Services: account creation, authentication, delivering assessments, issuing credentials, sending platform emails
- Payment processing: charging you for services you purchase, handling refunds, responding to disputes
- Identity verification and fraud prevention: detecting suspicious activity, investigating violations of our Terms, enforcing credential integrity, and — where you opt in and consent — confirming through Biometric Identity Verification that the same person completes each stage of certification
- Legal compliance: complying with tax, anti-money-laundering, consumer protection, and other applicable laws
- Service improvement: understanding how the Services are used to improve features (aggregated/anonymized where practical)
- Communications: responding to your inquiries, sending transactional emails (required), marketing emails (only with your consent), and, if you opt in, text messages (see Section 11)
Legal basis (GDPR users): We process your personal information on the basis of (a) performance of our contract with you (Terms of Service); (b) compliance with legal obligations; (c) your consent (for optional marketing, analytics, public registry name display, text messaging, and — as explicit consent for special-category data — Biometric Identity Verification); and (d) legitimate interests (fraud prevention, service improvement).
3. How We Share Your Information
We share your personal information only as described here. We do not sell your personal information.
3.1 Service Providers (Subprocessors)
We share personal information with third-party service providers who process it on our behalf under written agreements:
| Provider | Purpose | Data Location |
|---|---|---|
| Railway | Application and database hosting | USA |
| Vercel | Frontend hosting | USA (global edge) |
| Stripe | Payment processing | USA |
| Postmark (ActiveCampaign) | Transactional email delivery | USA |
| Twilio | Text message (SMS) delivery and opt-out (STOP/HELP) management | USA |
| Alchemy | Blockchain RPC and indexing | USA |
| Pinata | Credential metadata pinning and headshot pinning (IPFS) | USA |
| Amazon Web Services (AWS) Rekognition | Stateless facial comparison for optional Biometric Identity Verification (no image or template retained by AWS) | Canada (ca-central-1) |
| GoHighLevel | Community onboarding and marketing automation | USA |
3.2 Employers
If you are invited to the platform by an employer, we share your certification status (not your answers or detailed scores beyond what you consent to share) with that employer. This is a necessary part of the service they purchased. If you selected the Verified Identity tier when earning your credential, employers may request access to your selfie on a per-credential-verification basis as part of their fraud-prevention review. We do not share your biometric similarity scores or any facial-comparison data with employers.
3.3 Legal Requirements
We may disclose your personal information when required by law, court order, or to protect our rights, property, or safety, or that of our users or the public.
3.4 Business Transfers
If ATAC is involved in a merger, acquisition, or asset sale, personal information may be transferred. We will notify you before any transfer that changes how your personal information is handled.
3.5 Public Credential Registry
We maintain a public credential registry on our website so that credentials issued by ATAC can be seen to be real, current, and verifiable. The registry supports the public, verifiable nature of an ATAC credential.
What is shown by default. Each active credential is listed in a de-identified form. The listing shows the credential ID, the program (for example, CRSA), the credential status, the country or region, the issue date, and the holder's initials. The listing does not include your full name, email address, assessment answers, scores, or any photo or biometric data.
Optional display of your name. With your opt-in consent, the registry additionally displays your first name and last initial next to your credential (for example, "Jordan M."). We display your name only where you have given this specific consent. You can manage this at any time from your candidate dashboard, or by contacting privacy@atacglobalcx.com. When the display is off, your name is removed from the registry and your listing returns to the de-identified form.
A credential can also be confirmed through its public verify page, which employers and other parties use to check that a credential is valid. Legal basis (GDPR users): we display your name in the registry on the basis of your consent.
4. Blockchain Records
When you earn a credential, a minimum record is written permanently to the blockchain. This record includes credential ID, program code, score band, issue and expiry dates, and your optional wallet address if provided. Your name, email, assessment answers, photos, and biometric data are NOT written to the blockchain.
Blockchain records are public and cannot be deleted. See our Blockchain Credential Disclosure for full details.
5. International Data Transfers
ATAC is headquartered in Canada. Some of our service providers are located in the United States and other jurisdictions. Biometric facial comparison is performed within Canada (AWS ca-central-1). When we transfer personal information across borders, we use appropriate safeguards including standard contractual clauses and reliance on adequacy decisions where available.
6. Data Retention
We retain your personal information only as long as necessary:
- Account data: while your account is active, plus 7 years after closure for tax, audit, and legal compliance
- Assessment data: while your credential is valid, plus 7 years for credential verification and fraud investigation
- Photo verification data: headshots and selfies are retained for the lifetime of your credential. Deletion may be requested via support@atacglobalcx.com; selfies are deleted from our database within 30 days of request, headshot IPFS pins are best-effort unpinned but may persist on the wider IPFS network. See our Photo Consent Disclosure for full details.
- Biometric verification data: selfie images used for Biometric Identity Verification and their numerical comparison scores are retained for the lifetime of your credential, and in no case longer than three (3) years after your last interaction with ATAC, whichever occurs first, after which the selfie images are permanently deleted. They are also deleted upon withdrawal of biometric consent or upon request via privacy@atacglobalcx.com. We do not retain a persistent biometric template. See our Biometric Consent Disclosure.
- SMS consent and mobile number: retained while you remain opted in to text messages; after you opt out (reply STOP), retained only as necessary to honor your opt-out and to keep a record of consent as required by law
- Consent records: retained for the duration required by consumer protection and contract law (minimum 6 years from last interaction)
- Blockchain records: permanent; cannot be deleted
- Marketing consent records: until you withdraw consent, then deleted within 30 days
7. Your Rights
7.1 All Users
You have the right to:
- Access the personal information we hold about you
- Correct inaccurate personal information
- Request deletion of your account and associated personal information (subject to retention exceptions)
- Withdraw consent for optional processing (for example, marketing emails, text messages, public registry name display, or Biometric Identity Verification), which you can manage from your dashboard or by contacting us
- Lodge a complaint with your local privacy regulator
7.2 Residents of the European Union / United Kingdom (GDPR)
In addition to the above, you have the right to data portability, to object to processing based on legitimate interests, and to request restriction of processing. Where we process special-category biometric data for optional Biometric Identity Verification, we do so only with your explicit consent, which you may withdraw at any time without affecting a credential already issued. Your regulator is your national data protection authority (in the UK, the Information Commissioner's Office).
7.3 Residents of California (CCPA/CPRA)
In addition to the rights above, California residents have the right to know what categories of personal information we collect, the sources, the business purposes, and the categories of third parties with whom we share it. Biometric information is treated as sensitive personal information, used only for the identity-verification purpose disclosed above. You have the right to opt out of the sale or sharing of your personal information (we do not sell or share your personal information for cross-context behavioural advertising).
7.4 Exercising Your Rights
Submit privacy requests to privacy@atacglobalcx.com. We will respond within 30 days (CCPA/PIPEDA) or one month (GDPR). We may verify your identity before fulfilling requests.
8. Security
We use reasonable technical and organizational measures to protect your personal information: encryption in transit (TLS), encryption at rest for databases, bcrypt password hashing, role-based access controls, and regular security reviews. Selfie images and biometric comparison scores are stored in our private database and are not exposed publicly. No system is perfectly secure; we cannot guarantee absolute security.
If we become aware of a data breach affecting your personal information, we will notify you and relevant regulators as required by applicable law.
9. Children
The Services are not directed to children under 18. We do not knowingly collect personal information from children under 18. If you believe we have collected information from a child, please contact us and we will delete it.
10. Cookies
We use strictly necessary cookies for authentication and session management. We use optional analytics cookies only with your consent. See our cookie banner for controls.
11. Text Messaging (SMS)
If you provide your mobile number and opt in, ATAC Global CX sends you account and lifecycle text messages. Providing your mobile number and consenting to texts is optional and is not a condition of registration or purchase.
- Messages we send: a welcome/onboarding text, reminders to complete your assessment and meet deadlines, notifications to finish enrollment or payment for your credential, and related offers about your ATAC credential.
- How you opt in: by checking the optional, unchecked SMS-consent box on our registration form (or from your candidate dashboard). We record your consent, including timestamp and the number provided.
- Frequency and cost: message frequency varies. Message and data rates may apply, depending on your mobile carrier and plan.
- Opting out and help: reply STOP to any message to unsubscribe at any time, or reply HELP for assistance. You can also manage SMS preferences in your candidate dashboard or by emailing privacy@atacglobalcx.com. After you opt out, we send no further marketing or lifecycle texts, other than a single confirmation of your opt-out.
- Delivery provider: text messages are delivered through Twilio, our SMS subprocessor (see Section 3.1).
No sharing of your mobile number or SMS consent. We do not sell, rent, lease, or share your mobile phone number or your SMS/text-messaging opt-in (consent) information with third parties or affiliates for their own marketing or promotional purposes. Your SMS opt-in data is used solely to deliver the messages described above and is shared only with Twilio to the extent necessary to send them.
Legal basis (GDPR users): we send lifecycle and marketing text messages on the basis of your consent, which you may withdraw at any time by replying STOP.
12. Changes to This Policy
We may update this Privacy Policy. Material changes will be announced with a version bump and, where required by law, affirmative re-consent from existing users.
Attn: Privacy Officer
Oshawa, Ontario, Canada
Email: privacy@atacglobalcx.com
Canadian users: you may also contact the Office of the Privacy Commissioner of Canada at priv.gc.ca.