Privacy policy
How Acerto handles account information, uploaded documents, extracted data, and AI processing, and who is responsible for what.
Contents
Last updated: July 7, 2026
This Privacy Policy explains how Connective Solutions Studio LLC (“Connective Solutions”, “we”, “us”) handles personal information and customer data in connection with Acerto, our invoice reconciliation service (the “Service”).
Two kinds of data, two roles
Customer Content. The documents your organization uploads and the data the Service extracts from them often contain personal information about people at your business partners, such as names, email addresses, and phone numbers that appear on invoices and receipts. Your organization decides what to upload, who in the organization can see it, and when it is deleted. We process Customer Content on your organization's behalf and under its instructions, as a service provider. If someone whose information appears in your organization's documents contacts us about it, we will refer the request to your organization and assist where required.
Account and operational data. Information about you as a user and about how the Service runs. We are directly responsible for this data.
What we collect
- Account information: name, email address, organization membership, and role. Passwords are stored in hashed form by our authentication provider; we cannot read them.
- Customer Content: uploaded documents and the data extracted from them, including business partner details, seal numbers, weights, prices, totals, and line items.
- Activity and audit records: actions taken in the app, such as uploads, edits, corrections, approvals, escalations, and notes. The audit trail records who did what and when; it is part of the product.
- Technical data: IP address, browser and device information, pages and features used, timestamps, and error reports. In-app usage analytics are recorded under a pseudonymous account identifier, not your name or email address.
- Support communications: messages you send us.
How AI processing works
When your organization uploads a document:
- The document is stored in private storage that belongs to your organization. It is never visible to other customers.
- Each page is converted to an image, and the images are sent to an AI model for reading. We do not run your documents through consumer or free AI tools.
- Your organization's own configuration, such as known business partner names, aliases, and extraction hints, may be included to help the model interpret the document.
- The model's suggestions are stored with confidence scores and shown to your team for review.
- Your team reviews, corrects, approves, escalates, or rejects the results. Nothing is approved or marked paid automatically.
- Key actions are recorded in an audit trail.
AI models sometimes misread documents, especially poor scans, handwriting, or unusual layouts. Acerto is designed around that reality: extracted values carry confidence scores, mismatches are flagged, and documents move through an explicit review workflow. Your team makes the decisions. Acerto tracks reconciliation status, including a “Paid” status your team sets for record keeping; Acerto never connects to bank accounts, never initiates payments, and never moves money.
AI training and reuse
- We do not use your documents or data to train Acerto-owned AI models.
- We do not permit AI providers to use your content to train their models. We access models only through paid, business-grade APIs and provider settings selected to exclude training use, and we review these settings when we change providers.
- Your team's corrections improve extraction for your organization only. They become organization-scoped configuration such as aliases, extraction hints, and mapping rules, and improvements are queued as suggestions for your team to accept, not applied silently.
- Our error monitoring does not record document content or model outputs. Authorized staff may review specific documents and AI results when needed to diagnose problems and improve extraction quality, and any tool we use for this is a service provider under this policy.
What we do not do
We do not sell or rent personal information. We do not use it for advertising. We do not share one customer's documents or identifiable records with another customer.
Who processes your data
We use a small number of service providers to run the Service: cloud application hosting, database and private document storage, AI model providers that read document images, error monitoring, and usage analytics. Each provider processes customer data only as needed to provide its service to us, under agreements that restrict how it may use that data. Customers can request the current named provider list at support@connectivesolutions.ai.
International processing
Our service providers operate in multiple regions, so data may be stored or processed outside your country. We rely on our agreements with these providers, and the safeguards in them, when data crosses borders.
Retention
We keep data while your organization uses the Service. Deleted document files are removed from active storage on a delayed cleanup cycle. Audit records and security logs are kept as long as needed for integrity, security, and legal purposes. After offboarding, your organization has 30 days to request an export; we then delete or de-identify Customer Content within a reasonable period, generally within 90 days, except encrypted backups that are removed on a rolling schedule and records we are required to keep.
Security
Access to customer data requires authentication. Customer data is separated by organization and enforced at the database layer, with role-based permissions on top. Uploaded documents are stored in private storage and served through short-lived access links. Data is encrypted in transit, and our infrastructure providers encrypt data at rest. Key actions are recorded in an audit trail. Our staff access customer data only when needed for support, maintenance, security, extraction quality review, or legal compliance.
No system is completely secure. If a breach affects your organization's data, we will notify affected customers without undue delay.
Your rights and choices
You can view and update your account information in the app or by contacting us. Depending on where you live, you may have legal rights to access, correct, delete, export, or object to the processing of your personal information. To exercise them, contact support@connectivesolutions.ai. If your information appears in another organization's documents, we will refer your request to that organization, which controls that content.
If your organization needs a data processing agreement, contact us at support@connectivesolutions.ai.
Children
The Service is a business tool for adults. It is not directed to children, and users must be at least 18.
Changes and contact
We will update this policy as the Service evolves and update the date above. For material changes, we will notify customers in the app or by email. Privacy questions: support@connectivesolutions.ai.