Privacy policy

This policy explains what data Certia handles, why, who it shares it with, and what you can ask us for at any time.

Last updated: 31 Jul 2026

Who handles your data

Certia is the service described on this site and is the controller of the data described here. Write to us at info@certia.one about anything to do with your data.

What data we handle

From your account: your email address, your name if you give one, your interface language, and the company or companies you belong to, with your role in each.

From your books: the purchase and sales invoices, vendors, amounts, dates and chart of accounts that Certia syncs from your accounting tool, together with the account codes proposed and applied and the record of who decided what, and when.

From your use of the service: technical logs and errors needed to keep Certia running, and the billing details handled by our payment provider. Your card details never pass through Certia and are never stored in Certia.

What we use it for

To provide the service you signed up for: reading your invoices, proposing and applying account codes, keeping the decision log, and sending your daily digest. The legal basis is performance of the contract between you and us.

To keep the service secure and running, and to charge for the subscription. The legal basis is our legitimate interest in operating the service, and compliance with our legal and accounting obligations.

Certia doesn't use your data for advertising, doesn't sell it, and doesn't train models of its own on it.

Who we share it with

Only the providers Certia needs to work, and only the data each one needs: Supabase, which hosts the database and authentication; Vercel, which hosts the application; Resend, which sends the emails; Anthropic, whose model proposes account codes from the invoice and your coding history; Stripe, which handles payments; and Sentry, which collects technical errors.

Each of them processes the data on our behalf and under contract. Some are outside the European Economic Area; in those cases the transfer relies on the standard contractual clauses approved by the European Commission.

Your accounting tool isn't a provider of ours but a service of yours: Certia connects to it with the key you enter, and you can revoke it whenever you like.

How long we keep it

For as long as your company exists in Certia. The decision log is kept intact for that whole time, because it is what keeps every coding explainable.

If you delete your company, its data is permanently deleted after the grace period shown when you confirm. We keep only what the law requires us to keep, such as billing records.

Your rights

You can ask us for access to your data, for it to be corrected or deleted, and for restriction, portability or objection. Write to info@certia.one and we'll answer within the legal time limit.

If you think we haven't handled your request properly, you can complain to the Spanish Data Protection Agency.

Cookies

Certia uses only the cookies it needs to work: the one that keeps you signed in, and the one that remembers the language you chose. There are no advertising or third-party analytics cookies, which is why you won't see a consent banner.

Changes to this policy

If we change anything material we'll update this page and the date above. If the change affects you significantly, we'll tell you by email.

How to reach us

info@certia.one