Legal

How Cortena handles your data.

This privacy policy is split into two parts: the Cortena product, and Cortena browser extensions. Each part covers collection, handling, storage, and sharing. Your data is hosted in the EU and handled in line with the GDPR.

Privacy policy · last reviewed July 2026

How this policy is organized

Cortena B.V. ("Cortena", "we", "us") provides finance operations software. This policy covers personal and sensitive user data for two separate surfaces:

Part 1 · Cortena product: Cortena Payables at app.cortena.ai, this website, and related product services (accounts, invoices, integrations, support).

Part 2 · Browser extensions: Cortena Payables Sync and future browser extensions (Chrome today, Firefox later) that sync invoices from billing portals into Cortena Payables.

If you use Cortena under a customer agreement, we typically act as your processor for customer content and follow your documented instructions. Rights and contact details at the end of this page apply to both parts.

Part 1

Cortena product

This part covers the Cortena web product and website only. It does not describe browser-extension behavior. See Part 2 for extensions.

Data we collect

Account and identity data: name, work email, company details, role, authentication information, and session data when you sign in (including via Google, Microsoft, email magic link, or other supported identity providers).

Customer content you provide or connect: invoices and related PDFs or documents, supplier and payment details needed for bookkeeping, bank and accounting connection data when you enable an integration, and messages you send to support or our forms.

Technical and security data: IP address, browser and device information, application logs, and diagnostic events needed to run, secure, and troubleshoot the service.

We do not sell personal data. We do not use your finance content for advertising.

How we handle and use data

We use personal data to provide and operate Cortena, authenticate users, process invoices and related finance workflows, support integrations you enable, keep the service secure, meet legal and bookkeeping obligations, and respond to support requests.

Customer content is processed to deliver the features you use (capture, coding, approvals, reconciliation, exports to your ledger, and related workflows). Where AI features help prepare bookings or extract fields, they operate on data needed for that purpose inside the Cortena product.

We limit use of product user data to providing, securing, and improving Cortena. We do not use that data for unrelated profiling or ads.

How we store data

Cortena product data (accounts, invoices, documents, and related records) is stored on Cortena systems hosted in the European Union, including application databases and object storage for documents such as invoice PDFs.

Data in transit to Cortena services is transmitted over HTTPS. Access is controlled by authentication, tenant permissions, and operational access controls.

How we share data

We share personal data only as needed to provide Cortena: with subprocessors that host or operate parts of the service (for example EU cloud hosting, email delivery, error monitoring), and with third-party integrations you connect (for example accounting, banking, or expense tools) when you enable those connections.

We may disclose data if required by law, to protect against abuse or security threats, or in connection with a merger or acquisition with appropriate notice where required.

We do not sell personal data to data brokers or advertising platforms.

A current subprocessors list is published publicly. A data processing agreement is available from compliance@cortena.ai.

How long we keep data

We keep account and product data while your account is active and as needed for legal, tax, and bookkeeping retention (including GoBD where applicable).

On request and where the law allows, we delete or return customer data according to your agreement and applicable retention rules.

Part 2

Browser extensions

This part covers Cortena browser extensions that help sync invoices from vendor billing portals into Cortena Payables. Today that means the Cortena Payables Sync extension for Google Chrome. The same practices will apply to a Firefox extension when we ship one, unless we publish an update to this part.

Extensions use your existing signed-in session on app.cortena.ai. They do not create a separate extension login. Product account data itself is described in Part 1.

Data we collect

When you click Sync invoices: invoice PDF files downloaded from the billing provider and uploaded to Cortena Payables for your selected tenant.

When you click Report invoice page: page URL, title, and a sanitized HTML snapshot (scripts and inline event handlers removed), plus capture diagnostics needed to review the page. This happens only when you explicitly report a page.

On matching billing pages: invoice numbers used to show sync status. Locally cached extraction rules, synced invoice numbers, and tenant preferences in browser extension storage.

We do not capture full page DOM content unless you click Report invoice page. We do not track browsing history outside the extension's disclosed billing-sync purpose. We do not sell extension user data or use it for advertising.

How we handle and use data

Synced PDFs are handled as invoice intake in Cortena Payables under your tenant permissions, so the invoices appear in your Cortena workspace.

Site reports are handled by Cortena only to review unsupported billing portals and to build or maintain extraction rules.

The extension periodically downloads signed extraction-rule configuration from Cortena. Rules are declarative configuration, not remote executable code, and do not include personal data in the rules request itself.

Permissions such as storage, tabs, scripting, alarms, activeTab, and webNavigation (and equivalent permissions on other browsers) are used only to operate the disclosed sync and reporting features.

How we store data

Invoice uploads and site reports from the extension are stored in Cortena EU-hosted systems, alongside your Payables tenant data.

Limited caches live in browser extension storage on your device (for example rules, synced invoice numbers, and tenant preferences). Transmission to Cortena uses HTTPS.

How we share data

Extension data is shared with Cortena as the provider of Payables so we can process synced invoices and review optional page reports.

It is not sold, not used for advertising, and not shared with advertising platforms or data brokers.

If a synced invoice becomes part of your Cortena workspace, further sharing follows Part 1 (for example integrations you enable).

How long we keep data

Synced invoices follow the same retention rules as other Payables documents in Part 1.

Local extension caches can be cleared by removing the extension or clearing extension storage.

Site reports are retained as needed to investigate and improve portal support, then deleted or minimized when no longer required.

Chrome Web Store Limited Use

Cortena's use of information received from Google APIs and Chrome extension user data adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.

User data obtained through Cortena Payables Sync is used only to provide or improve the extension's disclosed single purpose: syncing invoices into Cortena Payables and, when you choose, reporting unsupported billing pages so we can improve extraction support. We do not transfer that data for advertising, credit scoring, or sale to data brokers.

Your rights

Under the GDPR and similar laws, you may have the right to access, correct, delete, or export personal data, and to object to or restrict certain processing.

If Cortena processes customer content as a processor, we support the customer (controller) in responding to requests about that content. For privacy requests about your own account or this policy, contact dpo@cortena.ai.

How to reach us

Controller / provider: Cortena B.V. Website: cortena.ai. Product: app.cortena.ai.

Data protection officer: dpo@cortena.ai. Contracts and data processing agreements: compliance@cortena.ai. Product support: support@cortena.ai.

Contracts and DPA

For a data processing agreement (AVV) or contract questions, contact compliance. The current subprocessors list is published publicly. For privacy and data protection questions, reach our appointed DPO.

This privacy policy is provided for transparency and is not legal advice. We may update it when our practices change. The current version is always published on this page.

Talk to us about how Cortena handles your data.

Book a demo, or reach compliance@cortena.ai for contracts and dpo@cortena.ai for privacy questions.

Book a demo

Takes 30 seconds. We tailor the demo to what you send.