How we protect your business and operational data.
Certiva is B2B subscription software. This policy explains what we collect, how Workforce, Retail, and DME module data is handled, and the security controls we apply to operational records.
Effective date: The date you first access or use the Certiva platform.
Certiva Tech LLC ("Certiva," "we," "us," or "our") runs certivallc.com and sells subscription software. This policy explains what we collect, how we use it, and how we protect it when you visit the site, request a demo, create an account, or use the platform.
Scope
This policy applies to business customers and authorized users of Certiva's B2B SaaS platform, including Workforce Control, Payroll Management, Retail & Stock Control, and DME Workflow Control modules.
Information we collect
Account and business information
We collect information you provide when you register, subscribe, request a demo, or contact us, including business name, authorized user names, work email addresses, phone numbers, billing contact details, and account credentials.
Operational data processed in the platform
Depending on which Certiva modules you enable, the platform may process operational records submitted by you or your authorized users, such as:
- Workforce Control & Payroll Management: employee or contractor identifiers, shift and attendance events, break and leave records, schedule metadata, approval workflows, and payroll-prep export data.
- Retail & Stock Control: store and SKU catalog data, inventory counts, stock movement events, low-stock alerts, purchase-order references, and point-of-sale integration metadata you connect.
- DME Workflow Control: case and order identifiers, equipment and serial-number records, payer references, delivery and fulfillment status, billing workflow artifacts, and documents uploaded to support operational processing.
You control what operational data is entered into Certiva. We process this data solely to provide, secure, and support the services described in your subscription.
Technical and usage information
We automatically collect standard web and application logs, including IP address, browser type, device identifiers, pages viewed, feature usage, timestamps, and diagnostic events needed to maintain service reliability and security.
Payment information
Subscription payments are processed by third-party payment processors. Certiva does not store full payment card numbers on our application servers. We may retain billing status, transaction references, and limited payment metadata required for accounting and support.
How we use information
We use collected information to:
- Provide, operate, maintain, and improve the Certiva platform
- Authenticate users and enforce role-based access controls
- Process subscriptions, invoices, and account changes
- Respond to support requests and service communications
- Monitor platform performance, prevent fraud, and investigate security incidents
- Comply with legal obligations and enforce our Terms of Service
We do not sell personal information. We do not use customer operational data for unrelated advertising profiles.
Security and compliance measures
Certiva applies administrative, technical, and organizational safeguards for business data, including:
- Encryption in transit: TLS 1.2+ for data transmitted between users and Certiva services.
- Encryption at rest: Sensitive configuration values and credentials stored in Certiva systems use application-layer encryption where supported.
- Access controls: Role-based permissions, least-privilege administrative access, and authenticated customer portal separation.
- Auditability: Timestamped activity and workflow events within Certiva modules to support operational review and accountability.
- Segregation: Customer environments are logically separated at the application and database layers.
- Monitoring: Error logging, availability monitoring, and incident response procedures for production systems.
- Vendor review: Third-party subprocessors used for hosting, email delivery, and payments are selected with security and reliability requirements appropriate to B2B SaaS operations.
No method of transmission or storage is completely secure. We continuously review controls as the platform evolves.
Module-specific data handling
Workforce and payroll-prep data
Attendance and payroll-prep records remain within your Certiva deployment for workflow, approval, and export purposes. You are responsible for obtaining any workforce notices or consents required by applicable employment and privacy laws before submitting employee-related data.
Retail and inventory data
Inventory, SKU, and store operational data is processed to provide live stock visibility, alerts, and purchasing workflows. Integration data from external POS or retail systems is used only to deliver connected inventory features you configure.
DME workflow data
DME case, equipment, billing, and fulfillment records may include sensitive operational or patient-related information depending on how your organization uses the system. You remain the controller of such data. Certiva processes it only under your instructions to deliver case-management and billing workflow functionality. Customers handling regulated health information are responsible for evaluating whether their use requires additional agreements or compliance measures beyond standard Certiva terms.
Data retention
We retain account and operational data for as long as your subscription is active and as needed to provide the service, resolve disputes, enforce agreements, and meet legal obligations. You may request deletion of your organization's data after account closure, subject to backup retention windows and legal hold requirements.
Sharing and subprocessors
We may share information with:
- Cloud hosting and infrastructure providers
- Payment processors (for example, Stripe or other configured gateways)
- Email and notification delivery providers
- Professional advisors where required by law
We require subprocessors to handle data only for contracted service purposes and apply appropriate security obligations.
Your choices and rights
Authorized account owners may access, correct, or export operational data through the Certiva application where those features are available. You may contact us to request account closure, update billing contacts, or ask questions about this policy. Depending on your jurisdiction, you or your users may have additional privacy rights; we will respond to verified requests in accordance with applicable law.
International users
Certiva is operated from the United States. If you access the service from outside the U.S., you understand that information may be processed and stored in the United States or other locations where our providers operate.
Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated effective date. Continued use of the service after changes become effective constitutes acceptance of the revised policy.
Contact
Certiva Tech LLC
24566 Jade Dr, Farmington Hills, MI 48336
Website: certivallc.com
Contact: Contact Certiva