Legal
Effective date: September 29, 2026
Cerenovus Inc. (“Cerenovus,” “we,” “us”) is a Delaware corporation. We provide a business-analysis service (the “Service”): with an organization’s authorization, we connect to its business systems, analyze the data in an isolated environment, and produce a written report. This Privacy Policy explains how we handle personal information through our website at cerenovus.ai and through the Service.
We handle personal information in two roles. As a controller (Sections 1–4 and 6–11), for information about visitors to our website, people who contact us, and the business users who set up and administer engagements. As a processor or service provider (Section 5), for information contained in our customers’ systems that we analyze on their behalf (“Customer Data”). For Customer Data, our customer decides why and how it is processed, and our written agreement with that customer governs what we do.
Demo requests and correspondence. If you submit the demo-request form on our website, we collect what you enter: your name, work email, organization, role, a description of what you want to discuss, and a timing preference. If you email us, we receive whatever you choose to send.
Engagement administration. When an authorized administrator connects a business system to the Service (for example QuickBooks Online, Microsoft 365, or Google Workspace), we receive the administrator’s name, email address, and account identifier from that system, along with authorization tokens. We record who authorized each connection, when, and with what scope.
Technical information. Our hosting infrastructure records standard server logs, such as IP address, browser type, pages requested, and timestamps. We use this information to operate and secure our website and Service, including rate-limiting the demo-request form against abuse.
We use the information above to:
We do not sell personal information, we do not “share” it for cross-context behavioral advertising, and we do not use it to train AI models.
Legal bases (EEA, UK, and Switzerland). Performance of a contract; our legitimate interests in responding to inquiries and in operating, securing, and providing a business-to-business service; compliance with legal obligations; and your consent where we ask for it.
Our role. A customer engages us under a written agreement and authorizes read-only access to selected business systems, such as accounting software, email, and file storage. Those systems can contain personal information about the customer’s employees, contractors, customers, vendors, and other contacts. We process that information only on our customer’s instructions, as set out in our written agreement with that customer. The customer is responsible for having a lawful basis for the processing and for providing any notices its employees and others are entitled to.
If your information may be in a system one of our customers has connected to Cerenovus, please direct privacy requests to that organization. If you contact us instead, we will forward your request to the relevant customer and help it respond.
What we access. We request read-only access wherever the connected system supports it. For example, for QuickBooks Online we request the accounting scope and only read data such as company information, accounts, customers, vendors, invoices, bills, payments, and transactions. The Service does not create, modify, or delete data in connected systems. The customer chooses which systems, entities, and date ranges are included, and we record that scope.
How Customer Data is handled:
No training, no sale, no advertising. We do not use Customer Data to train AI models, whether ours or anyone else’s. We do not sell Customer Data or use it for advertising. We may keep de-identified technical metrics about how the Service performed, such as processing times and error rates. These metrics contain no Customer Data content and do not identify any customer or individual.
Providers that process Customer Data. We will update this list before adding a new provider that processes Customer Data.
Intuit data. Data received from Intuit QuickBooks Online is used only to provide the Service to the customer that authorized the connection. It is handled as described in this section and is never sold or used for advertising. An administrator can disconnect Cerenovus at any time from within QuickBooks Online or by contacting us. Disconnecting stops any further access.
Google user data. Cerenovus’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Our website sets no cookies other than for the optional analytics described here. There is no sign-in and no session state on the website.
The website includes a Google tag for advertising conversion measurement. It is inactive unless we have configured a Google Ads account, and while inactive no Google script loads and no cookies are set.
The website also includes PostHog analytics. It is inactive unless we have configured a PostHog project key. When active, PostHog, Inc. processes page views, clicks, and similar usage events on our behalf in the United States, with form inputs masked.
In the European Economic Area, the United Kingdom, and Switzerland, advertising and analytics storage are off by default. You can also control cookies through your browser settings.
We use administrative, technical, and physical safeguards appropriate to the sensitivity of the information. These include single-tenant isolation, encryption in transit and at rest, credentials stored separately from other data, and least-privilege, logged access. We are working toward a SOC 2 Type II report.
No system is perfectly secure. We will notify affected customers, and individuals and regulators where required, of a personal data breach as the law requires.
We are a United States company, and information is processed in the United States unless we agree otherwise with a customer. Where we transfer personal information from the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum.
Depending on where you live, you may have the right to access, correct, export, restrict, or delete your personal information, to object to certain processing, and to withdraw consent. Residents of California and other US states with privacy laws may also have the right to know what we collect and to non-discrimination for exercising their rights. Residents of the European Economic Area, the United Kingdom, and Switzerland may also lodge a complaint with their local supervisory authority.
To exercise a right over information we control, email founders@cerenovus.ai. We will verify your request and respond within the time the law requires. For Customer Data, see Section 5.
Our website and Service are for businesses and are not directed to anyone under 16. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.
We will post any changes on this page and update the effective date. We will notify customers of material changes to how we handle Customer Data.
Questions: founders@cerenovus.ai, or by mail at Cerenovus Inc., 23 Antwerp Street, Brighton, MA 02135, United States.