At CertoFlow, we are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered project quoting software.
2. How We Use Your Information
We use the information we collect for the following purposes:
- Service Provision: To provide, maintain, and improve our quoting software
- Account Management: To create and manage your account, process payments, and provide customer support
- Communication: To send you important updates, service notifications, and respond to your inquiries
- Security: To protect against fraud, unauthorized access, and other security threats
- Analytics: To understand how our service is used and improve user experience
- Legal Compliance: To comply with applicable laws and regulations
3. Data Sharing and Disclosure
Your business data is never shared, sold, or used for any purpose other than providing you with our service. We may share your information only in the following limited circumstances:
- Service Providers: With trusted third-party vendors who assist us in operating our platform (such as authentication services, payment processors, email delivery services, and hosting providers). These providers are bound by contractual obligations to keep your data secure and use it only to provide services to us.
- Legal Requirements: When required by law or to protect our rights and the safety of our users
- Business Transfers: In connection with a merger, acquisition, or sale of assets (with notice to users)
- Consent: When you explicitly consent to sharing your information
4. Data Security and Protection
We implement comprehensive security measures to protect your information:
- Encryption in transit using industry-standard TLS protocols and at rest through our secure cloud infrastructure
- Regular security audits and vulnerability assessments
- Multi-factor authentication and access controls
- Enterprise-grade cloud infrastructure with physical and logical security measures
- Regular automated backups and disaster recovery procedures
- Strict internal policies on data protection and privacy
While we strive to protect your information, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security but are committed to using industry-standard practices.
5. Data Retention
We retain your information for as long as necessary to provide our services and fulfill the purposes outlined in this policy:
- Account Data: Retained while your account is active and for a reasonable period after closure
- Business Data: Retained until you delete it or close your account
- Usage Data: Retained for analytics and service improvement purposes
- Legal Requirements: Some data may be retained longer to comply with legal obligations
6. Your Rights and Choices
You have the following rights regarding your personal information:
- Access: Request access to your personal information
- Correction: Update or correct inaccurate information
- Deletion: Request deletion of your personal information
- Portability: Export your data in a machine-readable format
- Opt-out: Unsubscribe from marketing communications
- Restriction: Limit how we process your information
To exercise these rights, contact us at support@certoflow.com or use the settings in your account.
7. Cookies and Tracking Technologies
We use cookies and similar technologies to enhance your experience:
- Essential Cookies: Necessary for website functionality
- Analytics Cookies: Help us understand website usage
- Preference Cookies: Remember your settings and preferences
You can manage cookies through your browser settings. For more detailed information, see our Cookie Policy.
8. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place to protect your information during such transfers, in accordance with applicable data protection laws and utilizing appropriate legal mechanisms such as standard contractual clauses where required.
9. Children's Privacy
Our service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If we become aware that we have collected such information, we will take steps to delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on our website and updating the "Last Updated" date. We encourage you to review this policy periodically.
Last updated: October 2025