Privacy notice
Effective date: 26 September 2026
Last updated: 26 September 2026
At a glance
This summary gives you the key points. The full details follow in the numbered sections below.
| Question | Short answer |
|---|---|
| Who are we? | Aventruks DOOEL Skopje ("Aventrux"), a company registered in North Macedonia that builds and operates Certinuity |
| What is Certinuity? | Software that keeps supplier certificates, insurance and declarations in date: it reminds suppliers by email, collects their uploads and produces the audit register |
| What does this notice cover? | The website certinuity.com, and the Certinuity platform at platform.certinuity.com |
| Who decides what happens to the data? | We do for website visitors, trial and demo requests, customer accounts and billing. Our customers do for the supplier records they keep in Certinuity; we process those on their behalf |
| What do we collect on the website? | What you type into the trial or demo form, the campaign parameters of the link that brought you here, and your IP address and browser for abuse prevention. Analytics only runs if you accept it |
| Do we sell your data? | No. Never |
| Who else sees it? | A small number of service providers, listed in section 8. Names and emails are never sent to analytics |
| Where is data stored? | On Aventrux's own servers in Skopje, North Macedonia (in Europe, outside the EU/EEA) |
| How long do we keep it? | As long as it is needed, with fixed periods in section 10. Trial data that is not continued is deleted after 60 days. Invoices are kept for 7 years, as the law requires |
| What are your rights? | Access, correction, deletion, restriction, portability and objection. Write to info@certinuity.com |
| Who is the DPO? | Martin Mihailovski - martin@aventrux.com - +389 71 333 194 |
1. Who we are
Certinuity is operated by:
Aventruks DOOEL Skopje Mateja Matevski 22, Skopje, North Macedonia Email: info@certinuity.com Phone: +389 71 333 194
When this notice says "Certinuity", "we", "us" or "our", it means Aventruks DOOEL Skopje.
We process personal data under the Law on Personal Data Protection of the Republic of North Macedonia (Official Gazette no. 42/2020) and, where it applies to you (for example because you are in the European Union and we offer you our service), the General Data Protection Regulation (EU) 2016/679 ("GDPR"). The two laws are closely aligned, and this notice refers to GDPR articles for clarity.
2. Who this notice applies to
This notice applies to:
- Website visitors who browse certinuity.com
- People who request a trial or a demo through the forms on the website
- Customer users: the owners, admins, reviewers and read-only auditors who sign in to the Certinuity platform on behalf of their organisation
- Supplier contacts: people at a customer's suppliers who receive reminder emails and upload documents through a personal link. They do not have an account. Section 6 is written for them
If your employer gave you access to Certinuity, your employer may have its own privacy notice that also applies to you.
3. Our role: controller or processor
Who is responsible for your data depends on the situation.
When we are the controller
We decide why and how data is processed when:
- You visit the website, request a trial or book a demo
- You sign up to receive product updates
- We run a customer account: sign-in, security, support, invoices and payments
- We process data for our own business purposes, such as keeping the service secure and meeting legal obligations
When we are the processor
The customer organisation decides why and how data is processed when it uses Certinuity to:
- Keep a list of its suppliers and their contact people
- Request, receive, review and approve supplier documents
- Keep an audit trail and produce the audit register
In these cases the customer is the controller and we process the data only on its instructions, under our Data Processing Agreement. This covers supplier contacts, the documents suppliers upload, and the content that customer users create inside the platform.
What this means for you: if you are a supplier contact, or a user whose account belongs to an organisation, some requests (such as deleting a supplier record) need to go to that organisation. If you write to us, we will pass your request on or tell you who to contact.
4. Data we collect on the website
4.1 Trial and demo forms
| Data | Form | Why we need it |
|---|---|---|
| Full name | Trial, demo | To address you and set up your account or demo |
| Work email | Trial, demo | To send your sign-in details or agree a demo time |
| Company | Trial, demo | To set up your organisation and prepare the demo |
| Number of suppliers (band) | Trial, demo | To suggest a plan and prepare the demo |
| Country | Trial | To set up your organisation, time zone and billing |
| Plan after the trial | Trial | To know which plan you are interested in |
| Acceptance of the Terms and DPA | Trial | To record that you accepted them |
| Product updates opt-in | Trial | To know whether you want product update emails |
| Role | Demo | To tailor the demo |
| Number of facilities (band) | Demo | To tailor the demo |
| Message (optional) | Demo | Anything you want us to know before the call |
Campaign parameters: utm_source, utm_medium, utm_campaign, utm_term, utm_content, gclid and the first page you landed on |
Trial, demo | To understand which campaigns and pages bring people to us |
| IP address and browser (user agent) | Trial, demo | To prevent abuse, spam and automated submissions |
The forms also contain checks that stop automated submissions. Submissions that fail them are discarded and not stored.
Form data is stored on our own servers in Skopje, North Macedonia. New submissions are posted to a private channel in our internal Slack workspace so that our team can follow up. The Slack message contains the form fields and the campaign source, not your IP address or browser.
4.2 Browsing the website
When you browse the website, our web server processes your IP address and the pages requested, as any web server does, in order to deliver the pages and keep the site secure.
If you accept analytics cookies, Google Analytics 4 measures how the site is used: pages viewed, buttons and forms used, the campaign that brought you, approximate location, device and browser. Until you accept, analytics and marketing storage stay denied. Google may still receive cookieless signals without identifiers while consent is denied, which it uses for aggregate modelling. We never send names, email addresses, company names or form text to analytics. The website also sets one first-party cookie, cn_hero, which decides which of two homepage headlines you see. It contains no personal data. See the Cookie policy for the full list.
5. Data we process in the platform
5.1 Account and sign-in data (we are controller)
| Data | Why we need it |
|---|---|
| Name, email address, job title (optional) | To identify you in the platform and show your name on your actions, such as approvals |
| Interface language | To show the platform in your language |
| Organisation memberships, role and facilities | To control what you can see and do. Roles limit each person to their own facilities |
| Access end date (read-only auditors) | To end an auditor's access automatically |
| Password and one-time codes sent by email | To sign you in securely. You sign in with your email address and password, which is stored only as a one-way hash. If you switch on two-step sign-in, you also enter a one-time code we email you, valid for 10 minutes |
| Signed-in devices (device and browser, IP address, last active) | So you can see and sign out your devices, and for security monitoring |
| Last sign-in time | Security monitoring |
5.2 Organisation and billing data (we are controller)
| Data | Why we need it |
|---|---|
| Organisation name, country, domain, time zone | To run the account and show dates correctly |
| Owner of the account | To know who may manage billing, transfer ownership or delete the account |
| Plan, supplier limit, trial and subscription dates, status | To provide the plan you chose |
| VAT number and its validation result | To issue correct invoices |
| Invoices (number, period, amounts in EUR and MKD, exchange rate) | Billing and accounting |
| Payment references from cPay, and the card brand, last four digits and expiry | To reconcile payments, charge the saved card each period and warn you before a card expires |
We never receive or store full card numbers or security codes. Card details are entered on the payment page of cPay (CaSys International, Skopje), which returns only a payment reference, a token for recurring charges and the details listed above.
5.3 Customer data (we are processor)
Customer data is what the organisation and its users put into Certinuity, including:
- Facilities, the document catalogue, supplier sets and workflows
- Suppliers: name, country, contact name, contact email, language and internal notes
- Requirements, statuses, exceptions (with their reason and end date) and review decisions (with reject reasons and notes)
- Files uploaded by suppliers or users, with their dates, scope notes and history
- The audit trail: who did what, and when
- Records of emails sent to suppliers, and whether they were opened or the upload link was used
Uploaded documents such as certificates and insurance schedules can themselves contain personal data, such as the names and signatures of auditors, signatories or company officers. We process that data as part of the file, on the customer's instructions.
5.4 Technical data
| Data | Why we need it |
|---|---|
| IP address, browser and device | Security, rate limiting and diagnosing problems |
| Server and application logs | To keep the platform running and investigate errors or abuse |
6. If you are a supplier contact
A customer of ours (the organisation named in the email you received) has added you as the contact person for your company, so that it can collect the documents it needs from you. That organisation is the controller of your data. We send the emails and run the upload page on its behalf.
What is processed about you:
- Your name, email address and preferred language, as entered by the organisation, plus any notes it keeps about your company
- The emails sent to you (requests, reminders, accepted and rejected notices), and whether each was opened or its link was used. We detect this with a small image in the email and with the link itself
- What you upload through the personal link: the file, any expiry date you type, your optional note, and the page language you used
- Your IP address and browser when you use the upload page, for security and rate limiting
You do not need an account, and no password is involved. The link is personal to your company: anyone who has it can upload documents for your company, so please do not forward it outside your company. The organisation can reset the link at any time.
For questions or requests about your data, contact the organisation that emailed you. The reply-to address of its emails goes to that organisation. If you write to us at info@certinuity.com, we will pass your request to the organisation and help it respond.
7. Why we process your data and our legal basis
To answer your trial or demo request
Legal basis: steps at your request before entering into a contract (Article 6(1)(b) GDPR)
This covers setting up your trial, sending your sign-in details, agreeing a demo time and following up on your request, including sharing it with our team through Slack.
To provide the platform to customers
Legal basis: performance of a contract (Article 6(1)(b) GDPR)
- Creating and running accounts, organisations and memberships
- Providing the features of the plan, including emails to users and suppliers
- Billing, invoicing and recurring card payments through cPay
- Service emails: invitations, sign-in codes, export links, billing notices and account deletion notices
- Customer support
To keep the website and platform secure
Legal basis: legitimate interest (Article 6(1)(f) GDPR)
Our legitimate interest is a secure, reliable service that cannot easily be abused:
- Rate limiting and spam checks on forms, sign-in and upload pages
- Logging, monitoring and investigating suspicious activity
- Showing and revoking signed-in devices
Balancing test: these measures use the minimum data needed, are expected by people using a business service, and protect them as much as us.
To understand and improve our marketing
Legal basis: legitimate interest (Article 6(1)(f) GDPR) for campaign parameters attached to a form submission; consent (Article 6(1)(a) GDPR) for analytics cookies
Knowing which campaign or page led to a trial or demo request helps us spend our marketing budget sensibly. Analytics cookies are set only after you accept them.
To send product updates
Legal basis: consent (Article 6(1)(a) GDPR)
Only if you ticked the product updates box. We send them at most once a month, and every email has an unsubscribe link.
To meet legal obligations
Legal basis: legal obligation (Article 6(1)(c) GDPR)
- Keeping invoices and accounting records for 7 years, as required by tax and accounting law
- Responding to lawful requests from authorities
Customer data
When we process customer data as a processor, the customer determines the legal basis. We process it only to provide the service, on the customer's documented instructions, as set out in the Data Processing Agreement.
You can withdraw consent at any time, through Cookie settings in the website footer or the unsubscribe link in our emails. Withdrawing consent does not affect processing that took place before.
8. Who we share data with
We do not sell, rent or trade personal data.
8.1 Service providers
These providers help us run the website and the platform. We share only the data each one needs.
| Provider | What they do | Data they process | Where |
|---|---|---|---|
| Aventrux's own servers (operated by us, not a third party) | Host the website, the platform, its database and uploaded files, and the backups | All website and platform data | Skopje, North Macedonia |
| Slack (Slack Technologies) | Internal notification of new trial and demo requests to our team | Form fields and campaign source (no IP address or browser) | United States |
| Google Analytics (Google Ireland Limited) | Website analytics, only after you accept analytics cookies | Pseudonymous identifiers, pages and events, approximate location, device and browser | EU, with transfers to the United States |
| cPay (CaSys International) | Card payments for subscriptions | Payment amount and currency, payment references, recurring payment token. Card details are entered on cPay, never with us | North Macedonia |
| Microsoft 365 (Microsoft Ireland Operations Limited) | Sends platform emails to users and suppliers through Exchange Online, from Aventrux's own Microsoft 365 tenant | Recipient name and email address, email content | EU, with possible transfers to the United States |
We do not use advertising networks, social media trackers or error-tracking services. The cookie banner has a Marketing option, but no marketing tags are in use today. If we add any, we will list them here and in the Cookie policy first.
8.2 Inside a customer organisation
Users of a customer organisation see each other's names and roles where the work requires it, for example on approvals, workflows and the audit register. Organisation admins can see the users, roles and facility access of their organisation. No organisation can see another organisation's data.
Read-only users, such as the customer's external auditor, can see the suppliers, documents and register for the facilities they were given, until their access ends.
8.3 Our own staff
A small number of Aventrux staff can access customer accounts where needed to provide support, investigate a problem or meet a legal obligation. Where we open an account as an organisation admin to help, that access is time-limited and every action taken is recorded in the audit trail with the staff member's identity.
8.4 Legal requirements
We may disclose personal data if the law, a regulator or a court order requires it, or to protect the rights, property or safety of our users, the public or us. We check that requests are lawful, and where we are allowed to, we tell the person or customer affected.
8.5 Business transfers
If Aventruks DOOEL Skopje is involved in a merger, acquisition or sale of assets, personal data may pass to the successor. We will tell you before your data becomes subject to a different privacy notice.
9. International data transfers
We are established in North Macedonia, and the website, the platform and all their data are hosted on our own servers in Skopje. North Macedonia is in Europe but is not a member of the EU or EEA, and has no adequacy decision of the European Commission. If you are in the EU, EEA or United Kingdom, sending data to us is a transfer to a third country. We protect those transfers as follows:
- Website requests and customer accounts: we collect this data from you directly to answer your request or perform our contract with you (Article 49(1)(b) GDPR, where it applies), and we apply the protections in this notice and the law of North Macedonia, which closely follows the GDPR
- Customer data we process as a processor: the safeguards are set out in the Data Processing Agreement
- Slack, Google and Microsoft: where data goes to the United States, these providers rely on the EU-U.S. Data Privacy Framework and the European Commission's Standard Contractual Clauses
For details of the safeguards for a specific transfer, write to info@certinuity.com.
10. How long we keep your data
| Data | How long | Why |
|---|---|---|
| Trial and demo requests that do not become a customer | 24 months from our last contact with you, including the copy in our Slack channel | To follow up and handle a later return |
| Rate-limit records for forms | A hashed IP address, used only within a 10-minute window | Abuse prevention |
| Product update consent | Until you unsubscribe | So we only email people who asked |
| Trial account not continued | Kept for 60 days after the trial ends, then deleted | So you can still choose a plan without losing your work |
| Cancelled subscription | Full access until the end of the paid period, then read-only for 60 days, then deleted | To allow export or a change of mind |
| Account deletion requested by the Owner | Deleted 14 days after the request, unless cancelled in that time | To allow a mistaken request to be undone |
| Customer data during the subscription | Until the customer deletes it or the account ends | The customer decides |
| Audit trail | As long as the account exists; it cannot be edited or deleted by users | The audit register depends on it |
| Invoices and payment records | 7 years from issue | Tax and accounting law |
| Invitations | Valid 7 days | Security |
| Data export download links | Valid 7 days | Security |
| One-time sign-in codes | 10 minutes | Security |
| Signed-in device sessions | Until you sign out or revoke the device | Security |
| Google Analytics data | 2 months | Aggregate reporting |
| Backups | Daily copies kept for 5 days, weekly for 3 weeks and monthly for 2 months, then overwritten | Recovery from failures and mistakes |
After these periods, data is permanently deleted or irreversibly anonymised.
11. How we protect your data
- Encryption in transit: the website and the platform are served over HTTPS only
- Network and server protection: the production server runs in its own isolated network segment, behind a firewall that allows only web traffic and administrator access; administrator access is by SSH key only, repeated failed attempts are blocked automatically, and security updates are installed automatically
- Backups: Backups of the servers are taken automatically every day at 03:00, as consistent snapshots, compressed, and kept on a separate disk pool of the same server infrastructure in Skopje. Five daily, three weekly and two monthly copies are kept, and older copies are deleted automatically
- Private storage: the database and uploaded files are stored on our own servers in Skopje, on a private disk that is not reachable from the internet. Files are never stored on a public address
- Tenant isolation: every query in the platform is limited to the signed-in user's organisation, and every supplier query to the user's facilities. Both are covered by automated tests across organisations and facilities
- Roles: Owner, Admin, Reviewer and Read-only, each limited to a list of facilities; auditor access can end on a set date
- Sign-in protection: passwords are stored only as one-way hashes; optional two-step sign-in adds a one-time code by email that expires after 10 minutes and allows 5 attempts; sign-in, sign-in codes and upload pages are rate-limited; you can see and sign out your devices
- Files: served only to authorised users or through short-lived preview links (5 minutes). File types are checked on the server, and web page and SVG files are refused
- Supplier links: long random tokens, stored as a hash; an unknown or reset link shows a neutral page that reveals nothing
- Audit trail: decisions and changes are recorded and cannot be edited or deleted through the platform
- Payments: card details stay with cPay
- People: access to production systems is limited to the staff who need it, and every staff visit to a customer account as admin is audited
12. Your privacy rights
You have the following rights, wherever you are:
- Access (Article 15 GDPR): ask whether we process your data and get a copy
- Rectification (Article 16 GDPR): ask us to correct or complete your data. Users can update most of their details in My profile
- Erasure (Article 17 GDPR): ask us to delete your data, unless we must keep it, for example invoices for 7 years
- Restriction (Article 18 GDPR): ask us to pause processing while a dispute is resolved
- Portability (Article 20 GDPR): get your data in a structured, machine-readable format. Customer admins can export all organisation data from Settings
- Objection (Article 21 GDPR): object to processing based on our legitimate interests
- Automated decisions (Article 22 GDPR): Certinuity does not make decisions about people based solely on automated processing. Documents are approved or rejected by people
- Withdraw consent: at any time, without affecting earlier processing
How to exercise your rights
- Email: info@certinuity.com
- Post: Aventruks DOOEL Skopje, Mateja Matevski 22, Skopje, North Macedonia
- DPO: Martin Mihailovski, martin@aventrux.com, +389 71 333 194
We acknowledge requests within 7 days and reply within 30 days. For a complex request we may extend this by up to 60 more days, and we will tell you why. We may need to confirm your identity first. If the request concerns customer data, we will pass it to the customer and help it respond.
Right to complain
You can complain to a supervisory authority:
Agency for Personal Data Protection of North Macedonia (Agencija za zashtita na lichnite podatoci) Bul. Goce Delchev 18, 1000 Skopje, North Macedonia Website: https://azlp.mk
You can also complain to the supervisory authority in the EU member state where you live or work, or in the United Kingdom to the Information Commissioner's Office.
13. Cookies
The website uses a small number of cookies and browser storage items, and analytics only after you accept. The platform uses browser storage to keep you signed in. The Cookie policy lists every item. You can change your choice at any time with Cookie settings in the website footer.
14. Children's data
Certinuity is a business service. It is not directed at children under 16 and we do not knowingly collect their data. If you believe we have, write to info@certinuity.com and we will delete it.
15. Changes to this notice
We may update this notice when our service, providers or the law change:
- Minor updates (clarifications, formatting): we change the "Last updated" date
- Material changes (new data, new providers, changes to your rights): we tell customers by email or in the platform at least 30 days before they apply, and ask for consent again where the law requires
Earlier versions are available on request.
16. How to contact us
Aventruks DOOEL Skopje Mateja Matevski 22, Skopje, North Macedonia Email: info@certinuity.com Phone: +389 71 333 194
Data Protection Officer Martin Mihailovski Email: martin@aventrux.com Phone: +389 71 333 194
Contact the DPO to exercise your rights, ask how we handle your data, report a concern or request a signed copy of the Data Processing Agreement.
This notice is provided in English. If a translated version is made available and differs, the English version prevails.