Skip to main content

Enveritas Privacy & Data Ethics Notice

This Privacy & Data Ethics Notice was last updated on June 1, 2026.

Enveritas, Inc., together with its affiliates and subsidiaries (collectively, “Enveritas”, “we”, “our”, “us”) provide this Privacy & Data Ethics Notice (“Notice”) to describe how we collect, use, share, and otherwise process the Personal Data of individuals who visit our website (“Site”). In some cases, Enveritas may issue more specific privacy notices for some services or geographies. You will be informed of these notices, if they apply.

This Notice does cover job applications submitted through our Site.

This Notice does not apply to Personal Data gathered from employees. Likewise, this Notice does not apply to our processing of Personal Data provided to us for our non-public platform (“EUDR”); that Personal Data is covered under the terms of our agreement with our clients.

Enveritas believes that privacy is an important human right. We exist to improve the lives of coffee farmers, to protect the environment, and to end global poverty in the coffee sector. In doing so, we are committed to handling data, especially data about people, ethically, fairly, and transparently. We hold ourselves to a high standard of ethical data practices, consistent with our overall mission to improve the lives of the people we serve.

Who we are

Enveritas is a global not-for-profit organization that provides sustainability assurance for coffee and cocoa industries. We serve as a data controller (the entity responsible for processing your Personal Data) for processing related to this Site.

Our use of personal data

We may collect, process, store and share your Personal Data throughout the course of our relationship with you. The types of Personal Data we collect and the ways we use, store, and share that information depends on the nature and circumstances of our relationship with you.

Personal data we collect

When we refer to “Personal Data” in this Notice, we mean any information that either identifies you directly (like your name, email address, physical address, or phone number) or can be reasonably linked or combined with other information to identify you (like a device identifier or IP address). Some countries use terms like “Personal Information” or “Personally Identifiable Information” to address the same types of data. We use the term “Personal Data” to include terms like Personal Information and Personally Identifiable Information.

  • Personal contact details such as your name, telephone numbers, email, or addresses.

  • Technical information such as Internet Protocol (“IP”) address, online or device identifier, browser information, operating system, referring URL, country, language settings, and the date and time of your visit.

  • Location Information may be derived from your IP address, device, or country or location selection.

  • Contents of Communications that you submit to us via the Contact Us option or in other ways.

  • Professional, employment, and educational information associated with your application for employment. This data includes the information in your CV or resume, your job preferences, and your applicant profile. If you have a social media profile, including a LinkedIn profile, we may collect the information you share on your social media profile.

How we collect personal data

  • Information may be collected when you submit it to the Site or interact with us (e.g., when you submit a Contact Us form or email us).

  • From the devices you use to access the Site, which may provide information to us including the model, operating system and version, the name of the domain from which you access the internet, your IP address, and other unique device ID.

  • From our vendors and service providers, such as our web hosting partners and analytics providers, who may provide us with information about you or your use of the Site.

  • From publicly available information, including the information you post publicly on social media.

How we use personal data

Enveritas may use the Personal Data we collect for the purposes described below:

Purpose Legal basis
To administer, manage, deliver and promote our business and services. Our legitimate interest in offering and providing our services to our clients and operating our business.
To collect, review, and assess job applicant information, and maintain recruitment records. Your consent to the processing of personal data for recruitment purpose. Our legitimate interest in ensuring effective recruitment and hiring operations.
Providing direct marketing communications about our products and services. Your consent for purposes of email marketing.
Providing customer service and responding to your inquiries. Our legitimate interest in meeting Site visitor expectations and maintain effective communication.
To operate and maintain our Site, including monitoring performance, and security. Our legitimate interest in ensuring security, functionality, and performance of our Site.
Complying with applicable laws and regulations Necessary for compliance with our legal obligations.

How and why we share personal data

We may share your Personal Data with the following third parties:

  • Among our affiliates and subsidiaries who may use this Personal Data for the purposes described in this Notice;

  • With third-party service providers that we hire to perform a variety of services and functions for us, such as data storage and financial, legal, and marketing services. Service providers must agree by contract to use your Personal Data only to provide services to us.

    • The following are service providers we use for payment and recruitment purposes respectively:

      • Stripe: Our payments are processed through Stripe, your Personal Data will be processed in accordance with Stripe's privacy notice, found here: https://stripe.com/privacy.

      • Lever: If you use our online job board hosted by Lever, your Personal Data will also be processed according to Lever's privacy notice, found here: https://www.lever.co/privacy.

      • Greenhouse: If you use our online job board hosted by Greenhouse, your Personal Data will also be processed according to Greenhouse's privacy notice, found here: https://www.greenhouse.com/privacy-policy.

    • We utilize Hubspot for our EUDR platform, which includes our EUDR registration webform. We use a limited technical monitoring mechanism (sometimes referred to as a "pixel") in connection with our embedded EUDR registration webform. This mechanism may collect certain technical request data, such as your IP address, user agent, request headers, timestamp, and the request URL/query string. We process this information to support the rendering and reliability of our EUDR registration webform, including detecting and resolving technical errors and maintaining internal operational metrics related to the webform's performance. This functionality is implemented as a necessary technical measure to deliver and support the webform made available on our Site. It is not used for analytics, advertising, marketing, or profiling, and does not track user behavior across pages or over time, and is not used to build or infer profiles about individuals.

  • In the context of an actual or prospective business transaction involving all or part of our company, including mergers, acquisitions, consolidations or divestitures;

  • With law enforcement or governmental agencies to comply with a court order, law, or legal process, including responding to any government or regulatory request; and

  • When we believe, in good faith, that disclosure is necessary to protect our rights, the integrity of our work, or the safety of others, or to detect, prevent, or respond to fraud, intellectually property infringement violations of our terms of use, or violations of law.

Things we don’t do: sell or share personal data, process sensitive information for inference, or profile

We do not sell Personal Data for monetary or other valuable consideration. We also do not share Personal Data for behavioral advertising purposes, including cross-context behavioral advertising. We do not use sensitive Personal Data for inferring characteristics about individuals. We do not use automated processing of Personal Data for profiling purposes.

International data transfers

Enveritas is a global company and uses global vendors, subcontractors, systems, and applications. As a result, your Personal Data that we collect and process about you may be transferred, stored, or accessed in a destination outside of your country that may not offer a level of data protection equivalent to that in your country, which may have less strict or no data protection laws when compared to the laws in your country. Any transfers of Personal Data to Enveritas affiliates or third parties outside your local country will be conducted in compliance with the international data transfer restrictions that apply under applicable data protection laws.

We take legally required measures to ensure that adequate safeguards are in place (e.g., standard contractual clauses, data transfer agreements) to protect your Personal Data in accordance with applicable privacy laws and this Notice. For Personal Data exports out of the European Union (“EU”) or European Economic Area (“EEA”), Enveritas enters the European Commission’s Standard Contractual Clauses with the recipient to ensure compliance with the special requirements on transfers of Personal Data out of such countries. Where necessary, Enveritas will take appropriate supplementary measures to ensure an essentially equivalent level of data protection to that guaranteed in the EEA, in accordance with European Data Protection Board (“EDPB”) recommendations.

How we secure personal data

We will take reasonable steps to ensure that Personal Data is accurate, complete, current, secure, and reliable for its intended uses. We employ procedural and technological security measures that are designed to protect your Personal Data from loss, unauthorized access, disclosure, alteration, or destruction. However, please remember that no method of transmission over the internet or method of electronic storage is perfectly secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security.

How long we keep personal data

We will keep your Personal Data for as long as is reasonably necessary for the purpose of the processing or as otherwise required by law.

No kids, please

We hope children are excited by our mission and grow up to be agents for good in the world. However, this website is not intended to collect information from kids under 18. We kindly ask kids who are curious about Enveritas to ask their parents, teachers, or guardians to communicate with us on their behalf.

Your rights

We strive to honor individual rights with respect to your Personal Data. These include the right to:

  • Request to access or obtain a copy of your Personal Data collected by Enveritas;

  • Request we disclose the categories and specific pieces of personal data we have collected, the categories of sources, the business or commercial purposes for collection, and the categories of third parties with whom we share Personal Data;

  • Request that we correct inaccurate Personal Data about you;

  • Object to or opt-out of Enveritas’ processing of your Personal Data for direct marketing;

  • Object to processing based on our legitimate interest for reasons relating to your situation.

  • Request the restriction of the processing of your Personal Data, including sensitive Personal Data; and

  • Lodge a complaint with your local Data Protection Authority or regulator if you have concerns about our data practices.

We are committed to honoring your data protection rights. In some cases, we may need to deny or limit a request if permitted by law, but we will explain our decision.

Only you or someone legally authorized to act on your behalf may make requests regarding your data protection rights. To exercise these rights, please send an email to privacy@enveritas.org with the details of your request.

Changes to this notice

We may update this Notice from time to time to reflect changes in legal requirements, operational practices, or due to other factors. When required by applicable law, we will notify you of such changes to this Notice by posting a notice on this page before any changes take effect or in another appropriate manner. You can see when this Notice was last updated by checking the “Last Updated” date displayed at the top of this Notice.

Contact information and DPO

All questions, complaints, or comments about this Privacy Notice or Enveritas’ data protection practices can be emailed to Enveritas at privacy@enveritas.org. Enveritas has appointed Amy R. Worley at Berkeley Research Group, LLC (“BRG”) as its Data Protection Officer (“DPO”). You may reach our DPO at privacy@enveritas.org, or by calling the number for your country below and following the prompts.

Country Phone number
Bolivia +591 50721019
Brazil +55 1131644951
CIV +225 0566770865
Colombia +57 6016659545
Costa Rica +506 46009295
Ecuador +593 96 336 0430
El Salvador +503 2230 5302
Ethiopia +251 800861942
Ghana +233 596992960
Guatemala +502 23140937
Honduras +504 22620106
India +91 8071279081
Indonesia +62 21 50918403
Kenya +254 203894274
Laos +856 20 94 106 733
Mexico +52 9619800522
Nicaragua +505 7517 8140
Panama +507 839 2828
Peru +51 17068435
Thailand +66 2 460 6612
Uganda +256 800113529
United States +1 855 810 8885
Vietnam +84 12032390