How Ceribro™ collects, uses, stores, and protects your personal information.
Account Information: Name, email address, phone number, company name, billing address, and payment details provided during registration and subscription management.
Usage Data: Log data, feature usage analytics, session duration, IP address, browser type, and device information. This data is collected to improve the Platform and troubleshoot issues.
Business Data: All data you enter into Ceribro™ modules, including employee records, financial transactions, customer information, and project data. You retain full ownership of this data.
Cookies: We use essential cookies for authentication and session management, and optional analytics cookies to understand usage patterns. See our Cookie Policy for details.
We do not sell your personal data. We share data only with: (a) service providers who process data on our behalf under strict contractual obligations (e.g. payment processors, hosting providers); (b) law enforcement when required by valid legal process; (c) during a business transfer such as a merger or acquisition, with advance notice to you.
We implement industry-standard security measures including: AES-256 encryption at rest, TLS 1.3 encryption in transit, role-based access control, multi-factor authentication, regular penetration testing, SOC 2 Type II certified infrastructure, and ISO 27001 aligned processes.
We retain your account data for the duration of your subscription plus 30 days. After cancellation, all data is permanently deleted within 30 days unless a longer retention period is required by law. You may request data export at any time.
Under POPIA, GDPR, and applicable privacy laws, you have the right to:
Your data may be processed in data centres located in South Africa, the European Union, or the United States. All transfers are protected by appropriate safeguards including Standard Contractual Clauses and adequacy decisions.
Ceribro™ is not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware of such collection, we will delete the data promptly.
For privacy-related enquiries, contact our DPO at privacy@ceribro.io. You also have the right to lodge a complaint with the Information Regulator of South Africa or the relevant supervisory authority in your jurisdiction.
We may update this Privacy Policy from time to time. Material changes will be communicated via email and/or a prominent notice on the Platform at least 30 days before they take effect.