00Legal

Privacy policy.

Last updated: 11 October 2026

Certeza Systems Ltd is registered in England and Wales, company number 17457692. Our registered office is 128 City Road, London, EC1V 2NX. We are registered with the Information Commissioner’s Office under number ZC248143. You can contact us about this policy at enquiries@certeza.co.uk.

This policy covers two situations. The first is people who visit our website or deal with us as a business. The second is businesses whose records we process as a service.

Visitors and contacts

1. Visitors, enquirers and business contacts

We are the controller of this information.

What we holdWhy we hold itLawful basisHow long we keep it
Name, contact details and message from an email or the contact formTo reply to youLegitimate interests2 years from our last contact, unless it leads to an engagement
Business contact details of client and supplier staffTo set up and run an engagementContract, or steps before oneThe engagement plus 6 years
Names, email addresses and signing records when a document is signed electronicallyTo keep a reliable record of what was agreedContractThe engagement plus 6 years
Billing contacts, invoices and paymentsTo keep our accountsLegal obligation6 years from the end of the financial year concerned

We do not advertise and we do not sell personal data.

This website uses only the cookies it needs to work. It has no analytics or advertising cookies. If that changes, we will update this policy and ask for your consent first.

Clients

2. Businesses using Certeza

When a business uses our service, that business is the controller. It decides what is captured and why. We are its processor. We act only on its written instructions, under a data processing agreement with each client.

What we process

Communications and records from the systems a client connects, such as email, files, messages and call transcripts. These can include personal data about the client’s staff, customers, suppliers and anyone else who writes to them.

How we get access

We never ask for, receive or store a client’s passwords. The client grants access itself. Access is read-only, visible in the client’s own account, and the client can withdraw it at any time.

Where it is stored

Each client has its own database with its own credentials, hosted by Supabase in London (AWS eu-west-2). There is no shared store. Data is encrypted in transit and at rest, and it is stored in the UK. Some of our providers’ support staff outside the UK may have limited access to system logs or support data. Where they do, the access is covered by the safeguards in section 3.

AI processing

When the system reads, sorts or drafts from a record, the relevant material is sent to one of our AI providers, Anthropic or TypeSafe, for processing outside the UK. The provider processes it and returns the result. Neither uses it to train models. Each retains it no longer than its commercial terms allow. These transfers are covered by the providers’ data processing terms and the safeguards in section 3.

Training

Any AI provider we use must contractually exclude training on client data. That is a condition of using it, not a preference, and it applies whichever model runs.

How long we keep it

For as long as the engagement lasts. Backups are taken daily, kept for seven days and stored in the same region. When an engagement ends, the client can take its records in an open format, such as standard database exports with each item’s date, source and integrity check. We then delete the client’s database within 30 days, unless the client asks us to keep it longer, and the backups expire seven days later.

Processors

3. Who we share data with

The service runs on the providers below. Each acts under its own data processing terms. We tell clients before we add or replace one.

ProviderWhat it does in the serviceWhere data is held
SupabaseHosts each client’s databaseLondon
DigitalOceanRuns the service that captures client recordsLondon
AnthropicAI processingUnited States
TypeSafeAI processing, through its own sub-processors AWS, Modal, Nebius and CoreWeaveOutside the UK
DopplerStores system credentials, no client contentUnited States
HealthchecksConfirms scheduled jobs ran, no client contentEuropean Union

To run our own business we also use providers for email, document storage, electronic signatures, accounting and video calls. They hold enquiries and business contact details, not the client records the service captures.

Where personal data leaves the UK, it is protected in one of three ways. The country has UK adequacy regulations, as the European Union does. Or the provider is certified under the UK Extension to the EU-US Data Privacy Framework. Or the transfer uses the UK International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses.

Security

4. Security

Every administrative account we use is protected by two-factor authentication. System credentials are held in a dedicated secrets manager, never in code or email. The service that captures client records runs with the narrowest access it needs.

Rights and complaints

5. Your rights

If your information sits in a client’s records, please contact that client. It is the controller, and we will help it respond.

For information we hold as controller, you can ask us to give you a copy, correct it, delete it, restrict how we use it, object to how we use it, or move it to another provider. Email enquiries@certeza.co.uk. We will reply within one month.

You can complain to the Information Commissioner’s Office at ico.org.uk. We would appreciate the chance to put things right first.

Changes

6. Changes

We will update the date at the top when this policy changes. We will tell our clients about any material change before it takes effect.