Privacy Policy
Updated 7 October 2026. Covers the website, application and expert-service enquiries.
Controller and contact
Inovasense s.r.o., Karpatské námestie 7770/10A, 831 06 Bratislava, Slovakia, company ID 50 288 172, operates Cenitia. See the company details. Contact privacy@cenitia.com for privacy requests.
Purposes, data and lawful bases
- Account and organisation administration: email, authentication/session data, profile, membership and role. Necessary for the service contract (Article 6(1)(b) GDPR); business-contact administration and access security also involve legitimate interests under Article 6(1)(f).
- Document drafting and management: product and manufacturer details, uploaded engineering records, document content, AI prompts/responses, evidence references and review decisions. Used for the requested service. Personal data processed on customer instructions is addressed separately below.
- Signing and verification: signatory name, role, email, signature image/text, timestamp, IP, user-agent, review notes and document/PDF integrity records. Used to record issuance and prevent unauthorised changes (service provision and legitimate interests in security and proof of issuance).
- Billing: subscription, customer/payment-provider identifiers and transaction/invoice information. Contract and applicable accounting/tax obligations (Article 6(1)(c)). Stripe handles card payments; the app does not store a full card number.
- Support and operational messages: contact details, messages, delivery status and service lifecycle records. Requested support, account notices and reliable service (contract/legitimate interests).
- Lead/notification forms: email, voluntarily submitted details, form source and technical context. Used to respond to requests; optional marketing communications require the relevant consent, which can be withdrawn.
- Hosting logs, rate limits and diagnostics: request/device context, error traces and identifiers. Security and fault resolution under legitimate interests. Optional widgets and diagnostics depend on enabled integrations and browser settings.
Expert-service projects
Enquiries and engagements contain business-contact details, product scope, confidential evidence, quotations, service terms, approvals, payment references and project messages. We use them to answer the request, perform the agreed engagement and maintain proof of instructions (pre-contract steps/contract where applicable, legitimate interests for corporate contacts and records, and applicable legal obligations). The verified requesting account and authorised Cenitia staff access the private project; internal journal notes are restricted to staff. This portal does not automatically index project files for AI drafting.
External laboratories or specialist providers receive only the material needed for the separately agreed work, after the customer approves that scope and disclosure. Applicable confidentiality, controller/processor roles and contractual arrangements must be established before transfer. Submitting an enquiry is not consent to marketing.
Service orders and representative records are independent of a software subscription. Account closure removes login access but does not automatically erase records needed for an engagement, legally required availability, accounting or claims. Staff must assess and document the applicable retention and handover basis, minimise retained personal data and arrange deletion when that basis ends. Request an expert-project export or closure review through the project or privacy contact; organisation exports do not currently include these separate service records.
Customer content and AI
Customers determine the purposes of personal data in their product files and documents. Where Inovasense processes it on their behalf, the customer is controller and Inovasense is processor under documented instructions and an Article 28 data-processing agreement. Request the applicable DPA at the privacy contact before uploading personal/confidential material requiring contractual approval. Do not upload unnecessary personal or special-category data.
Selected file text and product/document context may be sent to the configured AI service for embeddings, retrieval and drafting. Cenitia does not make an automated legal decision about a person or certify conformity. Human review is required. Provider training, retention and processing-location restrictions depend on applicable agreements/settings; this notice does not claim independent certification of them.
Recipients and public verification
The app integrates Supabase (database/authentication/storage), Vercel (hosting), Mistral (AI), Stripe (billing) and Resend (email). Sentry diagnostics and Crisp support apply when enabled. Authorised organisation members access records according to roles. Public verification URLs disclose issuance, product/manufacturer identity, signatory name/role and legislation; published signed PDFs expose their declaration content. Avoid confidential personal data in public declarations. QR verification records issuance; it is not a conformity certificate.
We do not sell personal data. Disclosure may also be necessary under a binding legal request or to establish, exercise or defend legal claims.
International transfers
Hosting region alone does not establish where every provider processes billing, support, diagnostics or AI data. Processing may involve locations outside the EEA. Applicable provider arrangements must identify recipients, locations and a valid mechanism, such as adequacy or standard contractual clauses with necessary supplementary measures. Contact us for applicable provider/transfer information or a copy of safeguards. Provider contracts and enabled production settings remain subject to operator verification; there is no EU-only processing guarantee.
Retention, export and closure
Active-account records support service provision. Account deletion has a 30-day cancellation period before processing can start. Download JSON and, for files/PDFs, ZIP exports from organisation settings before closure; large exports may need separate downloads. Failed storage deletion is queued for retry and errors do not count as successful deletion.
Shared-organisation business records may remain with other authorised members. Signed records require a specific retention/export decision before organisation purge. Assess retention against actual customer instructions, applicable product-law/accounting duties and necessary legal-claim periods; every personal record is not retained forever. Provider logs and backups have separately configured lifecycles requiring operator confirmation; this notice does not invent a universal deletion period.
Your rights and required information
Request access, correction, erasure, restriction and, where applicable, portability; object to legitimate-interest processing; withdraw consent without affecting earlier lawful processing. Identity/authority verification may be necessary and statutory exceptions may apply. We respond within GDPR time limits. Complaints can be made to the Slovak data-protection authority or your competent local authority.
Required authentication/billing information is necessary for the corresponding service; optional fields are identified in forms. Cenitia is intended for professional compliance work. Material processing changes will be reflected here and communicated through appropriate account channels.