Legal

Privacy Policy

Effective date: September 29, 2026

Cerenovus Inc. (“Cerenovus,” “we,” “us”) is a Delaware corporation. We provide a business-analysis service (the “Service”): with an organization’s authorization, we connect to its business systems, analyze the data in an isolated environment, and produce a written report. This Privacy Policy explains how we handle personal information through our website at cerenovus.ai and through the Service.

We handle personal information in two roles. As a controller (Sections 1–4 and 6–11), for information about visitors to our website, people who contact us, and the business users who set up and administer engagements. As a processor or service provider (Section 5), for information contained in our customers’ systems that we analyze on their behalf (“Customer Data”). For Customer Data, our customer decides why and how it is processed, and our written agreement with that customer governs what we do.

1. Information we collect as a controller

Demo requests and correspondence. If you submit the demo-request form on our website, we collect what you enter: your name, work email, organization, role, a description of what you want to discuss, and a timing preference. If you email us, we receive whatever you choose to send.

Engagement administration. When an authorized administrator connects a business system to the Service (for example QuickBooks Online, Microsoft 365, or Google Workspace), we receive the administrator’s name, email address, and account identifier from that system, along with authorization tokens. We record who authorized each connection, when, and with what scope.

Technical information. Our hosting infrastructure records standard server logs, such as IP address, browser type, pages requested, and timestamps. We use this information to operate and secure our website and Service, including rate-limiting the demo-request form against abuse.

2. How we use it

We use the information above to:

  • respond to inquiries and schedule demos;
  • provide, operate, secure, and support the Service;
  • set up engagements and authenticate administrators;
  • communicate with you about the Service, contracts, and billing;
  • detect, investigate, and prevent security incidents and misuse;
  • comply with legal obligations and enforce our agreements.

We do not sell personal information, we do not “share” it for cross-context behavioral advertising, and we do not use it to train AI models.

Legal bases (EEA, UK, and Switzerland). Performance of a contract; our legitimate interests in responding to inquiries and in operating, securing, and providing a business-to-business service; compliance with legal obligations; and your consent where we ask for it.

3. How we share it

  • Service providers that process information on our behalf: Vercel, which hosts our website; Resend, which delivers demo-request submissions to our team as email; and the infrastructure and model providers listed in Section 5, for the Service.
  • Professional advisers, such as lawyers, accountants, auditors, and insurers, under confidentiality obligations.
  • Legal and safety: where required by law, regulation, or valid legal process, or to protect the rights, property, or safety of Cerenovus or others.
  • Business transfers: in connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to this Privacy Policy.

4. Retention

  • Demo requests and correspondence are kept as ordinary business email for as long as the conversation remains relevant. Ask us to delete a thread at any time.
  • Contract and billing records are kept for as long as the law requires.
  • Security logs are kept for up to 12 months.

5. Customer Data: information in connected business systems

Our role. A customer engages us under a written agreement and authorizes read-only access to selected business systems, such as accounting software, email, and file storage. Those systems can contain personal information about the customer’s employees, contractors, customers, vendors, and other contacts. We process that information only on our customer’s instructions, as set out in our written agreement with that customer. The customer is responsible for having a lawful basis for the processing and for providing any notices its employees and others are entitled to.

If your information may be in a system one of our customers has connected to Cerenovus, please direct privacy requests to that organization. If you contact us instead, we will forward your request to the relevant customer and help it respond.

What we access. We request read-only access wherever the connected system supports it. For example, for QuickBooks Online we request the accounting scope and only read data such as company information, accounts, customers, vendors, invoices, bills, payments, and transactions. The Service does not create, modify, or delete data in connected systems. The customer chooses which systems, entities, and date ranges are included, and we record that scope.

How Customer Data is handled:

  • Isolated environments. Each engagement runs in its own dedicated, single-tenant environment. Customer Data from different customers is never combined.
  • AI processing. We use large language models to classify, extract from, and analyze Customer Data. These models are provided by the model providers listed below, under commercial terms that prohibit them from using Customer Data to train their models.
  • Limited human access. Only authorized Cerenovus personnel access an engagement environment, and only to operate the Service, investigate errors, and review the report before delivery. That access is logged.
  • Credentials. Authorization tokens are encrypted, stored separately from other data, and deleted or revoked when the engagement ends.
  • Deletion. When an engagement ends, we delete the engagement environment, including copied source data, derived data, and credentials, within 30 days, unless the customer instructs us otherwise in writing.

No training, no sale, no advertising. We do not use Customer Data to train AI models, whether ours or anyone else’s. We do not sell Customer Data or use it for advertising. We may keep de-identified technical metrics about how the Service performed, such as processing times and error rates. These metrics contain no Customer Data content and do not identify any customer or individual.

Providers that process Customer Data. We will update this list before adding a new provider that processes Customer Data.

  • Microsoft Corporation (Azure): hosting of engagement environments, storage, and databases; United States, or another region agreed with the customer.
  • OpenAI: language-model analysis and text embeddings; United States.
  • Anthropic: language-model analysis; United States.

Intuit data. Data received from Intuit QuickBooks Online is used only to provide the Service to the customer that authorized the connection. It is handled as described in this section and is never sold or used for advertising. An administrator can disconnect Cerenovus at any time from within QuickBooks Online or by contacting us. Disconnecting stops any further access.

Google user data. Cerenovus’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

6. Cookies and analytics

Our website sets no cookies other than for the optional analytics described here. There is no sign-in and no session state on the website.

The website includes a Google tag for advertising conversion measurement. It is inactive unless we have configured a Google Ads account, and while inactive no Google script loads and no cookies are set.

The website also includes PostHog analytics. It is inactive unless we have configured a PostHog project key. When active, PostHog, Inc. processes page views, clicks, and similar usage events on our behalf in the United States, with form inputs masked.

In the European Economic Area, the United Kingdom, and Switzerland, advertising and analytics storage are off by default. You can also control cookies through your browser settings.

7. Security

We use administrative, technical, and physical safeguards appropriate to the sensitivity of the information. These include single-tenant isolation, encryption in transit and at rest, credentials stored separately from other data, and least-privilege, logged access. We are working toward a SOC 2 Type II report.

No system is perfectly secure. We will notify affected customers, and individuals and regulators where required, of a personal data breach as the law requires.

8. International transfers

We are a United States company, and information is processed in the United States unless we agree otherwise with a customer. Where we transfer personal information from the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum.

9. Your rights

Depending on where you live, you may have the right to access, correct, export, restrict, or delete your personal information, to object to certain processing, and to withdraw consent. Residents of California and other US states with privacy laws may also have the right to know what we collect and to non-discrimination for exercising their rights. Residents of the European Economic Area, the United Kingdom, and Switzerland may also lodge a complaint with their local supervisory authority.

To exercise a right over information we control, email founders@cerenovus.ai. We will verify your request and respond within the time the law requires. For Customer Data, see Section 5.

10. Children

Our website and Service are for businesses and are not directed to anyone under 16. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.

11. Changes and contact

We will post any changes on this page and update the effective date. We will notify customers of material changes to how we handle Customer Data.

Questions: founders@cerenovus.ai, or by mail at Cerenovus Inc., 23 Antwerp Street, Brighton, MA 02135, United States.