Privacy Policy
What we do with personal data in Ceertia, where it is stored, who can reach it, and the rights you have over it. Written to be read, not to be survived.
1. Who we are, and how to reach us
Ceertia is a software service operated by OrNsoft Corporation (“OrNsoft”, “we”, “us”). OrNsoft Corporation is a Florida corporation with its registered address at 10800 Biscayne Blvd #988, Miami, Florida 33161, USA.
For any question about this policy, about how your personal data is handled, or to exercise any of the rights described below, write to us at ceertia-privacy@ornsoft.com. We answer every request that reaches that address, and it is the fastest route to a person who can act on it.
If you are in the European Economic Area or the United Kingdom, you may also write to our European privacy contact at Privacy-EU@ornsoft.com. For questions about your Ceertia account that are not privacy matters, our support team is at Support@OrNsoft.com or +1 888-808-9498, 24 hours a day.
If you are in the European Economic Area, the United Kingdom, or Switzerland, you also have the right to complain to your national data protection authority. If you are in Canada, you may complain to the Office of the Privacy Commissioner of Canada or to your provincial regulator. We would prefer the chance to resolve the matter first, but nothing in this policy takes that right away from you.
OrNsoft has not yet appointed a representative under Article 27 of the GDPR. Where one is required, we will appoint one and publish the details here; in the meantime Privacy-EU@ornsoft.com is the address for EU and UK enquiries.
2. What this policy covers, and the role we play
This policy covers ceertia.com (our public website) and ceertia.app (the hosted Ceertia application) when you sign up for and use an account directly with us. It describes what we do with personal data for which OrNsoft is the controller — meaning we decide why and how it is processed.
It does not cover the situation where Ceertia is used by an organisation that has its own agreement with us and its own instructions about the data it puts into the platform. In that case OrNsoft acts as a processor on that organisation’s behalf, that organisation is the controller, and its own privacy notice — not this one — explains what happens to the data. Our obligations in that arrangement are set out in the data processing agreement we sign with the customer.
It also does not cover on-premise installations. Ceertia can be installed on a client’s own servers and served from the client’s own domain. In that arrangement the client hosts the software and holds the data, and the client is the controller under its own privacy notice. OrNsoft has no access to the documents processed there. The installation does send us a small amount of licensing and metering information, which is described in Section 7.3.
If you are unsure which of these applies to you, ask us at ceertia-privacy@ornsoft.com and we will tell you.
3. The data we collect
We collect the following categories of personal data.
- Account and identity data. Your name, work email address, password (stored only as a salted hash), company or organisation name, job title where you give it, and the country you tell us you operate from.
- Content you submit. Documents, files, images, text, and any other material you upload to Ceertia or generate within it, together with the outputs Ceertia produces from that material. This content may itself contain personal data about you or about other people — see Section 10.
- Usage records. Records of what you did in the platform: features used, jobs run, volumes processed, timestamps, and the configuration choices attached to your account or workspace.
- Payment information. Billing name, billing address, tax identifiers, plan and invoice history. Card numbers are handled by our payment processors under PCI DSS and are never stored on our systems. The current list of payment processors is available on request at ceertia-privacy@ornsoft.com.
- Support correspondence. Emails, chat messages, and tickets you send us, along with our replies and any attachments.
- Technical data. IP address, browser and device type, operating system, language settings, and the log data our servers generate when your browser or an API client connects to them.
- Cookies. Two strictly necessary cookies in the application, and Google Analytics on the website if you consent to it. See Section 14.
- Analytics data. Aggregated and pseudonymised measurements of how the website and the platform are used.
- Sensitive information received incidentally. We do not ask for special category data, but documents you submit may happen to contain it. See below.
3.1 Sensitive information
We do not solicit special category data (data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, or data concerning sex life or sexual orientation), and we do not use it to build profiles of anyone or to make decisions about them.
Where such data appears inside a document you submit, it is processed only as part of that document, for the purpose you submitted the document for, and it is deleted when the document is deleted. It is never separated out, indexed as a sensitive attribute, or used for any secondary purpose.
3.2 Age
Ceertia is a business product and accounts are for people aged 18 or over. Where we ask for a date of birth to confirm this, we check it and then discard it, keeping only the fact that the check was passed.
4. Why we use it, on what legal basis, and for how long
| Purpose | What we use | Legal basis (GDPR / UK GDPR) | How long we keep it |
|---|---|---|---|
| Providing the Ceertia service to you | Account data, content, usage records, technical data | Performance of a contract (Art. 6(1)(b)) | For the life of the relationship and 2 years afterwards. Content is deleted earlier on your instruction, on account closure, or on the credit-lapse timetable in the Terms of Service, under which an account with expired credits is blocked after 90 days and permanently deleted after 120 |
| Operating trials and evaluations | Account data, usage records, content | Legitimate interests — assessing fit and running the trial (Art. 6(1)(f)) | Until the trial ends, then per the retention rules below |
| Detecting and preventing misuse, abuse, and unlawful use | Content, usage records, technical data | Legitimate interests — protecting the service and its users (Art. 6(1)(f)); legal obligation where applicable (Art. 6(1)(c)) | Records of a confirmed incident: 24 months |
| Security, availability, and incident investigation | Technical data, logs | Legitimate interests — securing the service (Art. 6(1)(f)) | Server and access logs: 12 months |
| Product analytics and improvement | Aggregated and pseudonymised usage data | Legitimate interests (Art. 6(1)(f)); consent where cookies are involved (Art. 6(1)(a)) | 26 months |
| Billing, invoicing, and tax records | Payment information, account data | Performance of a contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) | 7 years, as required by tax and accounting law |
| Answering support requests | Support correspondence, account data | Performance of a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) | 1 year after the ticket closes |
| Marketing communications | Name, email, marketing preferences | Consent (Art. 6(1)(a)) | Until you unsubscribe or object, and a short period afterwards to honour the request |
| Establishing, exercising, or defending legal claims | Whatever is relevant to the claim | Legitimate interests (Art. 6(1)(f)); legal obligation (Art. 6(1)(c)) | For the duration of the limitation period |
Where we rely on legitimate interests, we have weighed our interest against your rights and freedoms and concluded that the processing is proportionate. You can ask us for a summary of that assessment at any time.
Once a retention period expires, data is deleted or irreversibly anonymised. Backups are on a rolling cycle and purge deleted data within 90 days.
5. Automated analysis of accounts and content
To keep the platform safe and to operate trials sensibly, we run automated checks over signals such as usage patterns, file names, account metadata, and support messages. These checks are used to identify accounts that may be a good fit for a guided trial, and to flag content or behaviour that may breach our acceptable use terms.
An automated flag is not a decision. Where the flag concerns anything other than manifestly illegal material, a person at OrNsoft reviews it before any action is taken against an account. Automatic suspension without human review is reserved for content that is unlawful on its face.
5.1 Special category data in flags
A flag may occasionally imply something about a sensitive characteristic — for instance where the content under review concerns a protected characteristic. Where that happens in the EEA or the UK, we rely on Article 9(2)(g) (substantial public interest in preventing and detecting unlawful acts) and Article 9(2)(f) (establishing, exercising, or defending legal claims). Such records are kept separately from ordinary account data and access to them is restricted.
6. Your right to object to this analysis
You may object to the automated analysis described in Section 5 by writing to ceertia-privacy@ornsoft.com. We will exclude your account from automated evaluation and rely on manual review instead. Objecting costs you nothing: your access, your pricing, and the quality of support you receive do not change.
We may continue to run the minimum security checks required to protect the platform and to meet our legal obligations, and we will tell you which ones those are if you ask.
7. Where Ceertia runs, and where your data is stored
Ceertia is delivered in three ways, and where your data lives depends on which one applies to you.
7.1 ceertia.app — United States
Clients in the United States and the rest of the Americas are hosted on Amazon Web Services (AWS) in the us-east-1 region (Northern Virginia, United States). Content, processing, and backups stay within that region.
7.2 ceertia.app — Europe
Clients in Europe are hosted on AWS in the eu-north-1 region (Stockholm, Sweden). Their content, the processing performed on it, and its backups are stored and processed in that region and are not copied to the United States.
We should be precise about one point rather than leave it implied. The EU environment is administered by OrNsoft technical staff located in the United States. Data is not moved out of Sweden, but administrators in the US can access the environment remotely for operations, maintenance, monitoring, and support, which means they may in principle see personal data held there. Under Chapter V of the GDPR that remote access counts as a transfer. It is covered by the Standard Contractual Clauses described in Section 9, and it is restricted by role-based access controls, mandatory multi-factor authentication, and logging of administrative sessions. Access is granted on the basis of need and is reviewed periodically.
Clients who require that no personnel outside the EEA be able to access their environment should raise this with us before onboarding, as it may need a different arrangement.
Region assignment is set when your account or workspace is provisioned. If you need a specific region, tell us before onboarding and we will confirm what is available.
7.3 On-premise installations
Ceertia can also be installed on a client’s own infrastructure and served from the client’s own domain. In that case:
- the client chooses where the servers are and therefore where the documents reside;
- OrNsoft does not host or store the client’s documents, and has no access to their content;
- the client is responsible for the security, backup, availability, and retention of its own installation;
- Sections 7.1 and 7.2 do not apply, and the sections of this policy that describe our hosting and our access to content should be read as applying only to the hosted service;
- where an on-premise client asks us for support, any access we are given is temporary, granted by the client, and limited to what the support request requires.
What an on-premise installation does send us. Ceertia is licensed on a credit basis, with consumption measured per page, so an on-premise installation contacts OrNsoft periodically for three narrow purposes:
| What is sent | Why | What it does not include |
|---|---|---|
| Installation or licence identifier, number of pages processed, timestamp | To meter credit consumption and bill correctly | No user names, emails, or user identifiers |
| Licence identifier and status check | To confirm the licence is active | No usage content of any kind |
| Installed version number | To tell the installation whether an update is available | No usage content of any kind |
These calls carry counters and identifiers only. They never carry the documents themselves, extracts from them, file names, document metadata, the identity of the person who ran a job, or application error logs. In data protection terms this is licence administration, not processing of the client’s content, and we rely on our legitimate interest in metering and protecting our own software (Art. 6(1)(f)) together with performance of the licence agreement (Art. 6(1)(b)). Metering records are kept for as long as needed to bill and to resolve billing disputes, and in any event no longer than the 7-year accounting period in Section 4.
An on-premise client that enables an external AI model provider (Section 8) sends content directly from its own installation to that provider, under its own contract with that provider. That traffic does not pass through OrNsoft.
7.4 Our website
ceertia.com is a marketing website and is hosted separately from the application. It holds no client content. It may run on other infrastructure used by OrNsoft, including Google Cloud and Hostinger.
8. AI model providers, and what happens to your content
Ceertia uses AI models to read, classify, and extract information from the documents you submit.
Our default provider is Genius Document AI, a service operated by OrNsoft Corporation. Because Genius Document AI is our own service rather than a third party’s, your content stays within OrNsoft’s own infrastructure — the same AWS footprint described in Section 7 — for all standard processing. Content processed by Genius Document AI is not used to train models for anyone else.
Optional third-party model providers. Clients who prefer to use an external model provider may enable one, at their choice and under their control. These providers are not active unless a client turns them on, and they may include providers such as Anthropic, OpenAI, Google, Mistral AI, and models served through Amazon Bedrock. The list of providers available for activation, and the current list of all subprocessors, is available on request at ceertia-privacy@ornsoft.com.
Where a client enables a third-party provider:
- Content sent to that provider leaves OrNsoft’s infrastructure and is processed under that provider’s terms and its own security and residency arrangements, which may differ from ours;
- We contract with those providers on terms that prohibit the use of your content to train or improve their models, except where a client specifically asks us to arrange fine-tuning on their own data;
- The client’s administrator decides which provider is enabled and can turn it off again;
- We will tell you, on request, which provider is active on your workspace and where it processes data.
We give notice before adding a new subprocessor.
9. International transfers and government access
We keep data at rest in the client’s own region as described in Section 7. Transfers out of the EEA, the UK, or Switzerland nonetheless occur in three situations:
- Administration of the EU environment from the United States. As stated in Section 7.2, OrNsoft technical staff in the United States administer the eu-north-1 environment and can access it remotely. This is the transfer that affects every European client of the hosted service.
- Optional third-party AI model providers, where a client has enabled one that processes outside the EEA (Section 8).
- Support and corporate administration, where resolving a request requires it.
For all three we rely on the European Commission’s Standard Contractual Clauses, together with the UK Addendum or the UK International Data Transfer Agreement where applicable, supported by a transfer impact assessment and by technical measures including encryption in transit and at rest, role-based access control, multi-factor authentication, and logging of administrative access.
We are candid about one point: as a company with United States operations, we may be subject to US legal process, including the CLOUD Act. If we receive a government or law enforcement request for data, we check that it is valid and lawful, we narrow it to the minimum that must be produced, we challenge it where there are grounds to, and we notify the affected customer unless we are legally prohibited from doing so.
10. People named in the content you submit
Documents submitted to Ceertia often mention people who are not our users — a signatory, an employee, a counterparty. Those people are data subjects too, and this policy applies to them.
We hold no data about such a person beyond what appears in the material an account holder submitted. We do not enrich it from other sources, we do not build profiles, and we do not contact them. Requests for access or deletion are usually best directed to the organisation that submitted the document, because it controls the content, but if you write to ceertia-privacy@ornsoft.com we will help you reach the right party and act on anything within our own control.
11. Organisations and their members
Where an account belongs to an organisation, the organisation controls it. Administrators can see the content in the workspace, the usage records attached to it, and the members of the workspace, and they can add or remove members. If you use Ceertia through your employer, your employer’s policies govern what it does with that access.
Your individual right to object to automated analysis under Section 6 is yours alone and is not overridden by your organisation’s administrative rights.
12. US state privacy rights
If you live in a US state with a consumer privacy law — including California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Nebraska, and others as they come into effect — you have the rights set out in this section, to the extent that law applies to you.
You may ask us to tell you what personal data we hold about you and where it came from, to correct it, to delete it, to give you a portable copy, and to opt out of targeted advertising, of the sale or sharing of personal data, and of profiling that produces legal or similarly significant effects. We do not discriminate against anyone for exercising these rights.
12.1 Do not sell or share my personal information
We do not sell personal data, and we do not share it for cross-context behavioural advertising. There is no advertising pixel, no conversion tag, and no advertising identifier on ceertia.com or in the Ceertia application. The only third-party technology on the website is Google Analytics, used to measure traffic, and it runs only if you accept analytics cookies.
Google Signals and the Google Analytics advertising features are switched off in our Google Analytics property, so no advertising identifiers are collected or transmitted.
If you would nonetheless like us to record an opt-out against your account, reject analytics cookies in the banner, send a Global Privacy Control signal from your browser, or email ceertia-privacy@ornsoft.com.
12.2 Your rights, and how to appeal
Write to ceertia-privacy@ornsoft.com. We respond within 45 days and may extend once by a further 45 days where a request is complex, telling you why. We verify identity before acting on a request, in proportion to how sensitive the data is.
If we refuse, you may appeal by replying to our decision. A different person reviews the appeal and answers within 45 days (60 days in some states). If the appeal fails, we will tell you how to contact your state Attorney General.
12.3 Global Privacy Control
We honour the Global Privacy Control signal as a valid opt-out of sale and sharing, both in the browser that sent it and, where we can associate it with an account, in our own records.
12.4 Sensitive information and health data
We do not use or disclose sensitive personal information for purposes beyond those permitted without an opt-out under applicable state law. Ceertia is not a health product and we do not collect consumer health data for our own purposes. Where health information happens to appear inside a document a client submits, it is handled as described in Section 3.1: processed only as part of that document, for the purpose the document was submitted for, and never used to infer anything about a person’s health.
Where a client intends to use Ceertia to process health information at scale, we handle that under a separate agreement with that client rather than under this policy — for example a Business Associate Agreement where HIPAA applies, or a dedicated consumer health data notice where a state health privacy law such as the Washington My Health My Data Act applies. Clients who need such an arrangement should contact us at ceertia-privacy@ornsoft.com before onboarding.
12.5 Which laws apply, and when that changes
Some state privacy laws apply only above certain revenue or volume thresholds, and OrNsoft may not currently meet all of them. We extend the rights described above to residents of every state with a comprehensive privacy law regardless of whether the threshold is met, so you do not have to work out which law covers you.
13. The UK and other countries
If you are in the United Kingdom, the UK GDPR applies to you and the rights in Section 17 are yours in full. Comparable rights apply if you are in Switzerland (revFADP), Brazil (LGPD), Canada (PIPEDA and provincial law, including Quebec’s Law 25), or Australia (Privacy Act 1988). Where local law gives you more than this policy sets out, local law wins.
14. Cookies and similar technologies
Ceertia uses very few cookies, and the application uses none for tracking.
14.1 The Ceertia application (ceertia.app and on-premise)
The application sets two cookies, both strictly necessary. Neither one tracks you, profiles you, or is shared with anyone.
| Cookie | Purpose | Category | Duration |
|---|---|---|---|
| ceertia_session | Keeps you signed in and links your browser to your authenticated session. Encrypted. | Strictly necessary | Session — expires when the session lifetime ends or you sign out |
| XSRF-TOKEN | Protects against cross-site request forgery by verifying that a request came from the Ceertia interface. Encrypted. | Strictly necessary | Session — same lifetime as above |
Because both are strictly necessary to deliver a service you have asked for, they are set without consent, and there is no cookie banner in the application. There are no analytics, advertising, or third-party cookies in the Ceertia application.
14.2 The Ceertia website (ceertia.com)
The website uses strictly necessary cookies, and Google Analytics to measure traffic, with Google Signals and the advertising features disabled. Google Analytics is set only after you opt in through our consent banner. Refusing is as easy as accepting: the banner offers both in a single click, and you can change your mind at any time through the cookie settings link in the footer. There are no advertising cookies on the website.
15. Children
Ceertia is a business product, is not directed at children, and is not for anyone under 18. We do not knowingly collect personal data from anyone under 16 in any circumstances, and Ceertia accounts require you to be 18 or over. If we learn that an account belongs to a minor, we close it and delete the associated data. If you believe a child has given us personal data, write to ceertia-privacy@ornsoft.com and we will remove it.
16. How we protect your data
We encrypt data in transit and at rest, restrict access to personnel who need it for their role, log administrative access, require multi-factor authentication for internal systems, segregate environments, and review our security arrangements periodically. Our staff are bound by confidentiality obligations. OrNsoft holds ISO 9001 and ISO 27001 certification.
These measures describe the hosted service. In an on-premise installation, the security of the servers, the network, and the backups is the client’s responsibility; we document our recommended configuration and will advise on it, but we cannot enforce it on infrastructure we do not run.
No system is perfectly secure. Where a personal data breach is likely to result in a risk to your rights, we notify the competent supervisory authority within 72 hours of becoming aware of it and notify affected individuals without undue delay where the risk is high.
17. Your rights under the GDPR and UK GDPR
If the GDPR or UK GDPR applies to you, you have the right to:
- obtain confirmation of whether we process your data, and a copy of it;
- have inaccurate data corrected and incomplete data completed;
- have your data erased where one of the grounds in Article 17 applies;
- have processing restricted while a dispute about accuracy or legitimate interests is resolved;
- object to processing based on legitimate interests, and to object to direct marketing at any time and unconditionally;
- receive the data you gave us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible;
- withdraw consent at any time, without affecting processing already carried out on that basis;
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects — see Sections 5 and 6.
Write to ceertia-privacy@ornsoft.com. We answer within one month and may extend by two further months for complex requests, telling you within the first month if we do. There is no charge unless a request is manifestly unfounded or excessive. We may decline or defer part of a request where doing otherwise would prejudice an active fraud or abuse investigation, or where another person’s rights would be infringed; we will explain the reason when we do.
18. Marketing
We send marketing email only to people who have opted in — the box at sign-up is unticked and stays that way unless you tick it. Every marketing message has a one-click unsubscribe link, and unsubscribing takes effect immediately.
Messages about your account, your invoices, security matters, and changes to this policy are service messages, not marketing, and you receive them for as long as you have an account. Notifications about the end of a trial or the results of an evaluation are treated as marketing and require consent.
19. Changes to this policy
We update this policy when the service or the law changes. The version in force is always the one published at ceertia.com, with the effective date at the top. Where a change materially affects how we use your personal data, we tell you by email or in the platform before it takes effect, and where the change requires your consent we ask for it.
20. Contact
Questions, requests, and complaints: ceertia-privacy@ornsoft.com
European and UK enquiries: Privacy-EU@ornsoft.com
Support: Support@OrNsoft.com · +1 888-808-9498 (24/7)
OrNsoft Corporation, 10800 Biscayne Blvd #988, Miami, Florida 33161, USA.
