Privacy Policy

Effective Date: March 2026

1. Introduction

Welcome to CertFile ("we", "our", or "us"). We are committed to protecting your privacy and ensuring the secure handling of your technical documentation, installation data, and personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our web application, mobile application, and related services (collectively, the "Platform").

2. Information We Collect

We collect structural and operational data to facilitate compliance generation and system functionality:

  • Account Information: Name, business email, company entity, and authentication credentials.
  • Site & Project Data: Installation addresses, homeowner consent forms, U-Value technical specifications, and generated PDFs.
  • Media & Diagnostics: Site photographs uploaded for technical review, pre-survey documentation, and structural imagery. (Note: These are backed up securely via enterprise cloud networks including Dropbox).
  • Usage Metrics: Interaction data regarding which components are heavily utilized to refine our platform algorithms.

3. How We Use Your Information

The primary mandate of CertFile is to act as your technical co-pilot. As such, data is utilized exclusively for:

  • Generating legally binding and formatted compliance documents automatically.
  • Facilitating secure audits and reviews by System Owners (e.g., Baumit Administrators).
  • Transmitting notifications pertaining to changes in document status and workflow transitions.
  • Providing secure historical archives of past installations for warranty verifications.

4. Third-Party Sharing and Integrations

CertFile does not sell your data. Data is shared strictly to fulfill operational mandates:

  • Cloud Service Providers: Technical infrastructure (Google Cloud/Firebase) and media archiving (Dropbox APIs).
  • Payment Processors: We utilize trusted providers (e.g., Stripe) to handle financial transactions. We do not store raw card numbers on our servers.
  • System Administrators: Installers operating under specific system mandates (e.g., Baumit) inherently consent to sharing that project's compliance data with their affiliated System Administrator for auditing purposes.

5. Data Security & Cryptography

CertFile implements rigorous, industry-standard authentication protocols and cryptographic measures to protect against unauthorized access, alteration, disclosure, or destruction of your compliance documentation. Document signatures and metadata are inextricably linked to secure backend records to ensure legal immutability.

6. Your Rights (GDPR & Data Protection)

Depending on your jurisdiction, you have the right to request access, correction, or deletion of your personal data residing on CertFile. However, due to the legal necessity of compliance archiving, requests to delete finalized warranty or compliance documentation may be subject to legal retention obligations.

7. Contact Us

If you have structural questions regarding our data architecture or Privacy Policy, please contact our compliance team at privacy@certfile.com.