Privacy at Certova
Certova holds an agency's book of business: its accounts, the policies in force, the documents that prove what was issued, and the messages exchanged with clients and carriers. This page says what we collect, what we do with it, what we will never do with it, and what you can require us to do.
Two different relationships run through this page, and they are worth separating. For the agency's own staff we are the company deciding what happens to their account data. For everything the agency loads about its clients we are a service provider acting on the agency's written instruction — the agency decides, and we execute. When those two roles imply different answers below, we say which one applies.
Last updated August 25, 2026. We post the date every time the text changes, and we tell account owners by email before a change that narrows their rights takes effect.
What we hold, and why
Four categories, each with the reason it exists. Nothing here is collected because it might be useful later.
The agency's own people
Name, work email, phone, role, licence number where the work requires one, and the record of when each person signed in and what they approved. The approval record is not optional: an agency that cannot show who authorised a certificate cannot defend it, so we keep it for as long as the account exists and for the retention period afterwards.
The book the agency loads
Accounts, contacts, policies, coverages, endorsements, claims, certificates, holders, commissions and every document filed against them. This is the agency's data, loaded on the agency's instruction, and we process it to run the product the agency is paying for — not for any purpose of our own.
Messages and documents
Email, WhatsApp messages, uploaded files and call notes filed against an account. Inbound messages arrive as untrusted input and are treated as such throughout: they are quarantined, scanned and never executed as instructions, because a document that can talk to the system is a document that can be used against it.
Visitors to this website
On your first visit this site sets one cookie of its own, certova-attribution, which records how you arrived — the campaign parameters on the link, the referring site and the page you landed on — and lasts a year, so that a walkthrough request months later still tells us which channels are worth paying for. It holds no name and no contact detail. If you then ask for a walkthrough we keep what you typed into the form. We measure how this site is used with Vercel Web Analytics, which sets no cookie and stores no identifier that follows you: it records the page, the language, how far down you read, and whether you moved the pricing slider or opened the walkthrough. Nothing you type reaches it. We load no advertising script, we sell nothing to anyone, and we build no profile of you across other people's websites.
What we will not do with it
These are commitments in the contract, not preferences on a page. If one of them is ever untrue, the contract has been broken.
It does not train a model
Your data does not train a model — not ours, and not a provider's. Every model call leaves through a single internal gateway that removes identifiers such as tax, bank-account and driver-licence numbers before the request goes out, and the no-training term is written into the agreement rather than only described here.
It is not sold or brokered
We do not sell personal information, and we do not share it for cross-context behavioural advertising. There is no data-broker relationship to disclose because there is no data-broker relationship.
No quiet access by us
There is no support account with a master key into your records. Support staff hold no read access to an agency's book at all. Every staff read requires a stated purpose and is written to our internal audit log, and acting inside your account — impersonation — additionally requires a time-boxed grant that the database refuses to issue open-ended, and appears in your own audit log where you can see it.
It does not leak between agencies
One agency cannot read another's rows. The database itself enforces it, the application account is not the owner of the tables and cannot switch it off, and an adversarial two-agency test suite has to pass before any change reaches production.
What you can require us to do
Rights are worth what it costs to exercise them. Here each one is a button or an email, not a negotiation.
Take everything, at any time, free
A complete export of accounts, policies, documents, messages and history in documented open formats, on demand, at no charge, including on the day you leave. Competitors charge for this; one agency reported a fee of fifteen hundred dollars to get its own records out. We put it in the contract instead.
Correct it, or have it deleted
Ask us to correct or delete personal information and we will, unless a retention schedule or a live legal hold requires us to keep it — in which case we tell you which one, and when it lifts. Insurance records carry statutory retention periods, and a system that silently ignores them is not doing you a favour.
Stop the messages, provably
Texts and WhatsApp messages go only to contacts who opted in, and we store the proof of that opt-in. Withdraw it and the withdrawal is recorded against that contact and checked again on every single send, so a later campaign cannot quietly reach them. Consent is held per contact rather than per agency, and where a contact has quiet hours set, the send path holds the message until the window opens rather than trusting someone to remember the hour.
Ask, even if you are not our customer
If you are an agency's client rather than its staff, the agency is the one holding your file and your request goes to the agency first. Send it to us and we will route it to them and help them answer it — we will not quietly answer on their behalf about records that are theirs to govern.
Who else touches the data
Running this product means using other companies: somewhere to host the database, a model provider behind the gateway that strips identifiers, a payment processor, and the email and messaging networks that carry what you send. Each one is bound by contract to the same restrictions we accept, and each is used for one stated purpose. Ask us for the current list and we will send it, and we give notice before adding one that handles personal information.
Your records are stored in the United States, and the production service is configured for geographically redundant backups restorable to a point in time — which is what makes a bad afternoon recoverable rather than final. Retention is recorded against each document when it is filed, by category and by the jurisdiction whose rules apply, because Florida does not ask the same of a claim file as it does of a marketing email.
Mailboxes and messaging accounts you connect
An agency can connect a Google or Microsoft mailbox and a WhatsApp Business number so that inbound requests are filed against the right account automatically. Connecting one is a deliberate act by someone at the agency, it is authorised through the provider's own consent screen, and it can be disconnected from the same screen at any time.
What we do with that access is narrow and worth stating exactly. We read messages and their attachments in order to file them against the correct account, policy and line of business, to extract the request the message is making, and to draft a reply for a licensed person to approve. We store the message, its attachments and that filing decision as part of the agency's record, because an agency that cannot show the request behind a certificate cannot defend the certificate.
What we do not do with it: we do not use mailbox or messaging content to train models, we do not use it for advertising, we do not sell it, and we do not transfer it to anyone except the subprocessors needed to provide the feature. Use of data from Google APIs follows Google's Limited Use requirements, and human beings read that data only where you have asked us to, where security or the law requires it, or where the data has been aggregated and de-identified. Disconnect the mailbox and we stop collecting; ask us to delete what was collected and we will, subject only to the retention rules described above.
If something goes wrong
If personal information is exposed, we investigate, contain it, and notify affected account owners without unreasonable delay and within the timeframe Florida's information protection statute requires. Notice says what happened, what data was involved, what we have done and what you should do — written to be useful, not written to shield us in a later dispute.
Questions about anything on this page, requests about your own information, or a security report all go to hola@certova.co and reach a person, not a queue. Security reports are welcome and we do not threaten people who send them.