Privacy-first, with explicit boundaries.
This policy distinguishes browser-local financial processing from the hosted identity, authority, billing and service data needed to operate Certanexa safely.
Consent version: privacy-2026-07-10 · Last operational review: August 14, 2026
Controlled-launch summary: supported CSV/XLSX reconciliation is browser-local by design; account identity and access authority are hosted; hidden AI/OCR/integration modules are not part of the default launch data path. See the Customer Trust & Data Processing page for retention, deletion, subprocessors, browser storage and current limits.
Core launch financial-file processing
The controlled-launch reconciliation path supports two same-currency CSV/XLSX ledgers and is designed to process those financial files in the user's browser. Browser-local processing reduces unnecessary transfer of raw financial files to hosted services.
A browser-local architecture is not the same as a 'no servers' promise. Authentication, tenant/workspace authority, consent records, billing state and service operations use hosted infrastructure.
Browser-local storage
Certanexa can use IndexedDB, OPFS/DuckDB-backed storage, localStorage and sessionStorage for supported application state. Different storage mechanisms serve different purposes, including workspace data, preferences, short-lived signup/OAuth intent and safe return-to state.
Clearing Certanexa site data in the browser can remove browser-local workspace state and may sign the user out. Signing out alone does not promise deletion of every local reconciliation artifact.
Hosted account and service data
Certanexa uses hosted services for authentication and server-authoritative account/workspace controls. Hosted records can include account identity, organization/workspace binding, accepted Terms/Privacy version, subscription and billing state, security-relevant metadata, support records and operational diagnostics.
These controls are intentionally server-authoritative so a browser user cannot grant themselves tenant, role or paid-tier authority by editing local state.
Hidden AI, OCR and integration modules
The wider codebase includes AI/PowerBot, OCR/PDF and integration work, but those capabilities are not part of the default controlled-launch reconciliation path while their release gates remain closed.
Core launch CSV/XLSX reconciliation does not silently send financial files to an AI model, OCR provider or ERP integration merely because related internal code exists.
If Certanexa later releases a feature that sends customer content to an additional provider, the customer-facing data-handling and subprocessor disclosures must be reviewed before that feature is represented as available.
Marketing, support and communications
When you submit an early-access, demo, contact, support or newsletter form, Certanexa may store the contact details and business context you provide so the request can be handled.
Limited attribution such as campaign values, landing path, referrer context and a random marketing-session identifier may be retained when implemented. Marketing/support forms are not intended for raw financial files, passwords, payment-card data, access tokens or government identifiers.
Transactional account email can be delivered through Certanexa's configured email infrastructure. Billing records are also processed by the configured payment provider when paid billing is used.
Security, telemetry and diagnostics
Certanexa may process security and operational telemetry needed to protect accounts, investigate defects, enforce abuse controls and understand service reliability. We do not describe those records as anonymous if they can reasonably be associated with an account, session, request or incident.
The controlled-launch application does not use advertising telemetry as a reason to upload raw reconciliation files. Error and security evidence should be minimized and redacted where practical.
Retention, subprocessors and deletion
Current retention targets, deletion boundaries and the production subprocessor list are maintained on the Customer Trust & Data Processing page. Those operational disclosures are reviewed alongside this policy when the launch architecture changes.
Your rights and controls
- Access or correction: ask what hosted personal/account data is associated with your account and correct inaccurate account information.
- Deletion: request deletion or de-identification of hosted account/workspace data, subject to identity verification and required security, billing or legal retention.
- Local deletion: clear the workspace in-product where supported or clear Certanexa site data in the browser to remove browser-local state for that profile.
- Portability: export supported reconciliation evidence/results through released product export functions where available.
- Questions or complaints: contact privacy@certanexa.com; legal rights provided by applicable law remain unaffected.
Privacy questions: privacy@certanexa.com
Security reports: security@certanexa.com