CertCueBack to CertCue

Privacy policy

Controller and contact

CertCue is operated by AGENTIC SYSTEMS S.R.L., registered office at Bulevardul Pipera 84D, Voluntari, Ilfov County, Romania, CUI 55009198, Trade Register no. J2026041331006, EUID ROONRC.J2026041331006, telephone +40 728 254 395. For account, billing, security, support, and product-usage data, AGENTIC SYSTEMS S.R.L. is the data controller. Privacy requests can be sent to support@cert-cue.com or made by telephone at +40 728 254 395.

Customer workspace roles

A customer organization decides which vendor and document data to place in its workspace and is normally the controller of that data. CertCue processes it to provide the service. Customers are responsible for having a lawful basis to upload vendor and contact information and for answering their data subjects' requests.

Data we process

We process account identity and work email, organization and team membership, vendor and document records, reminder and activity data, subscription and billing references, support and setup requests, short-lived abuse-prevention identifiers, and limited error and product-usage events. Stripe receives payment details directly; CertCue does not store full card or bank details.

Purposes and legal bases

We use data to provide and secure the contracted service, authenticate users, process subscriptions, respond to requests, prevent abuse, diagnose failures, meet legal duties, and improve the workflow. The legal bases are contract performance, steps requested before a contract, legitimate interests in service security and improvement, legal obligations, and consent where consent is required.

Workspace storage and controls

Signed-in workspaces use an organization-scoped Supabase database and private file storage. The sample workspace remains in the browser on the user's device. Workspace exports, backup and restore, and clear-data controls are available in Settings. Account-level access or deletion requests can also be sent to support.

Service providers and transfers

CertCue uses Cloudflare for website delivery and abuse prevention, Supabase for authentication, database, functions, and storage, Stripe for subscriptions and billing, and transactional email providers for account and service messages. The primary application database is configured in the European Union. Some providers may process data outside the EEA under their contractual transfer safeguards and applicable adequacy mechanisms.

Retention

Rate-limit records are deleted after 3 days; analytics and client-error events after 90 days; expired vendor-upload requests after 30 days; and support, guided-setup, and minimal Stripe webhook records after 24 months. Workspace data remains while the customer account is active or until an authorized user clears it. Provider backups expire on their own schedules. Billing and accounting records may be kept longer where law requires.

Browser storage and analytics

CertCue uses storage needed for authentication, workspace continuity, preferences, and security. First-party product events use an in-memory session identifier and are sent without a persistent analytics identifier. Optional third-party analytics and Google Ads conversion measurement do not load without a recorded consent. CertCue does not use remarketing, Customer Match, or personalized advertising. You can grant or withdraw optional measurement through Privacy choices; withdrawal removes CertCue-set optional measurement cookies from the browser. Cloudflare Turnstile processes security signals when a protected public form is used.

Your rights

Depending on applicable law, individuals may request access, correction, deletion, restriction, portability, or objection, and may withdraw consent without affecting earlier processing. Requests can be sent to support. Individuals may also complain to the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) or their local supervisory authority.

Security and sensitive data

CertCue uses organization-scoped access controls, private storage, HTTPS, signed upload links, rate limits, and human-verification checks. No service can promise absolute security. Do not send passwords, private magic links, API keys, payment credentials, bank details, or unnecessary sensitive personal data through support, CSV imports, or setup notes.