Aventora Privacy Notice
| Field | Value |
|---|---|
| Document Title | Aventora Privacy Notice |
| Version | 1.1 |
| Effective Date | July 6, 2026 |
| Last Updated | July 6, 2026 |
| Classification | Public / Customer Shareable |
Introduction
Aventora Inc. (“Aventora,” “we,” “us,” or “our”) is an AI-powered customer engagement platform. We help organizations manage customer interactions across channels such as voice, SMS, email, chat, and related administrative workflows.
We are committed to protecting the privacy of individuals whose personal information we process. This Privacy Notice explains what information we collect, how we use it, who we share it with, and what choices you may have.
Who this notice applies to
This notice applies to:
- Visitors and users of Aventora websites, applications, and services;
- Authorized users of customer organizations that use the Aventora platform (for example, administrators, agents, and other personnel); and
- End customers and contacts whose information is processed through the platform on behalf of Aventora’s business customers.
The specific information we process depends on how you interact with Aventora and which product features your organization has enabled.
Our role
In most cases, organizations that use Aventora act as the controller of personal information relating to their customers and contacts. Aventora acts as a processor, handling that information on their instructions to deliver contracted services.
Customer data belongs to the customer. We process personal information only as needed to provide the services described in our agreements with customers, and we process only the minimum information required for those purposes.
When Aventora is the controller
For certain processing activities, Aventora acts as the controller, including:
- Website and marketing interactions — for example, when you visit our sites, request information, or subscribe to communications
- Account and billing administration — contact information for authorized users and customer personnel needed to manage accounts, contracts, and invoicing
- Support and sales inquiries — information you provide when contacting Aventora directly
When we act as controller, we determine the purposes and means of processing and respond to applicable data subject requests as described in Individual Rights.
Scope
This notice describes Aventora’s general privacy practices. Customer-specific deployments may vary based on product configuration, enabled integrations, hosting choices, and contractual terms. Enterprise customers may operate in dedicated environments with controls agreed in writing.
This notice is intended to be consistent with principles found in privacy laws such as Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA), the EU General Data Protection Regulation (GDPR), and the UK GDPR. Aventora does not claim formal certification under any specific privacy or security framework based on this notice alone.
For additional detail on security and privacy controls, enterprise customers may also review our Personal Data Privacy & Protection Policy and related security documentation.
Information We Collect
The information we collect depends on your relationship with Aventora and which services are in use. Examples include:
Information you provide directly
- Name
- Email address
- Phone number
- Company or organization name
- Job title
- Account registration and profile details
- Customer communications with Aventora (for example, support requests, sales inquiries, or feedback)
- Authentication information (for example, username, password credentials, and multi-factor authentication enrollment data for authorized users)
Information processed through the platform
When customers use Aventora to engage with their own customers and contacts, we may process:
- AI conversation content (for example, chat messages, voice transcripts, or summaries generated to support engagement)
- Quote-related information and other business content submitted or generated through enabled features
- Communication metadata (for example, timestamps, channel type, delivery status, and engagement outcomes)
- Calendar and scheduling information where integrations are enabled
Information collected automatically
When you use our websites or platform, we may collect:
- Usage information (for example, features accessed, actions taken, and session activity)
- Device and browser information (for example, browser type, operating system, and general technical identifiers)
- Log and security data (for example, IP address, API request metadata, and error diagnostics)
We aim to collect only what is reasonably necessary for the purposes described in this notice.
How We Collect Information
We collect personal information through several methods:
- Directly from you — when you create an account, contact us, subscribe to communications, or otherwise interact with Aventora
- From our customers — when a customer organization uploads, syncs, or enters information into the platform, or when their end users interact with Aventora-powered experiences
- Through integrations — when a customer connects third-party services (for example, calendar, identity, CRM, or communication providers). Customer-requested integrations determine which third parties process data for that deployment
- Through cookies and similar technologies — on our websites and certain applications, where applicable and subject to your choices (see Cookies)
- Through automated logging — as part of operating, securing, and maintaining our services
Why We Collect Information
We collect and process personal information for purposes such as:
- Delivering contracted services to our customers
- Powering AI-enabled customer engagement features configured by customers
- Providing customer support and responding to inquiries
- Authenticating users and managing access to the platform
- Protecting security and preventing fraud or misuse
- Improving and maintaining our products and infrastructure
- Meeting legal obligations, including record-keeping and responding to lawful requests
We do not use personal information for purposes that are incompatible with these goals without appropriate notice or consent where required by law.
How Information Is Used
Depending on context, we use personal information to:
- Deliver services — operate the platform, route communications, and fulfill customer agreements
- Support AI processing — generate responses, summaries, routing decisions, and related engagement outputs configured by customers
- Provide reporting and analytics — where enabled, to help customers understand engagement activity and outcomes
- Communicate with you — about accounts, service updates, security notices, and support matters
- Monitor security — detect suspicious activity, investigate incidents, and protect platform integrity
- Support compliance — with applicable laws, contractual commitments, and internal policies
Customer Data is not used to train general-purpose AI models unless explicitly agreed in writing with the relevant customer.
Information Sharing
Aventora does not sell, rent, or license personal information.
We may share personal information only in limited circumstances:
Service providers
We may share information with authorized service providers (subprocessors) that help us operate the platform, but only as necessary to provide services.
The authoritative list of subprocessors that may process personal information on Aventora’s behalf — including infrastructure, telephony, AI inference, speech, identity, and operational providers — is maintained in our Subprocessor Annex. Which subprocessors apply to a specific deployment depends on enabled product features, deployment model, and contractual configuration.
Customer-configured integrations with third-party systems (for example, CRM or payment providers) are directed by the customer and are described in the Subprocessor Annex under customer-directed integrations.
Other disclosures
We may also disclose information where:
- Required by law — such as in response to a valid legal process or regulatory request
- Necessary to protect rights and safety — to investigate misuse, enforce agreements, or protect individuals and systems
- Part of a business transaction — such as a merger, acquisition, or asset sale, subject to appropriate safeguards
- Authorized by the customer — where a customer directs us to share information with a third party
We require service providers to handle personal information appropriately and to use it only for the purposes for which it was shared.
International Data Transfers
Primary hosting for Aventora-managed deployments is on AWS in Canada. AWS Canadian regions are the default deployment for data residency in managed cloud environments, unless otherwise agreed in writing.
Some integrations and subprocessors — particularly those related to global telephony, AI inference, or customer-selected productivity tools — may process information outside Canada depending on customer configuration and the providers involved.
Where personal information is transferred across borders, we use appropriate contractual safeguards where required by applicable law, such as standard contractual clauses or equivalent measures agreed with customers and subprocessors.
Enterprise customers with specific residency requirements should discuss deployment options, including dedicated environments, with their Aventora account team.
Data Security
We apply technical and organizational measures designed to protect personal information against unauthorized access, loss, misuse, or alteration. These measures include:
- Encryption in transit — TLS is used to protect data transmitted over public networks
- Access controls — role-based access and least-privilege principles for platform and operational access
- Multi-factor authentication (MFA) — required for privileged administrative access
- Monitoring and logging — security and operational logging to support detection, investigation, and service reliability
- AWS security — use of cloud provider security capabilities for infrastructure hosted on AWS
No method of transmission or storage is completely secure. We work to maintain safeguards appropriate to the nature of the information we process and the services we provide. Implementation details may vary by deployment model.
Data Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this notice, including:
- Customer agreements — retention periods defined in contracts, data processing addenda, or customer instructions
- Legal obligations — where law or regulation requires us to keep certain records
- Operational requirements — such as maintaining backups, resolving disputes, enforcing agreements, or supporting security investigations
Retention periods may differ by data type, product feature, and deployment configuration. Customers may have additional retention settings within the platform where supported.
See Data Retention for category-level retention practices.
Data Deletion
When personal information is no longer needed, we take steps to delete or anonymize it in accordance with our retention practices and applicable law.
You may request deletion in the following circumstances:
- Customer requests — organizations using Aventora may submit deletion requests on behalf of their users or contacts, subject to their agreement with us
- Individual requests — where you contact us directly and we are responsible for the processing, or where we can direct your request to the relevant customer organization
- Account closure — when an authorized user or customer account is closed, associated personal information is handled according to contractual terms and operational procedures
Legal retention exceptions may apply. We may retain certain information where required by law, to resolve disputes, enforce agreements, or protect security — even after a deletion request.
When deletion is performed, we use secure deletion methods appropriate to the storage medium and environment, consistent with our data disposal practices.
Individual Rights
Depending on your location and relationship with Aventora, you may have rights regarding your personal information. These may include the right to:
- Access — request confirmation of whether we process your personal information and obtain a copy where applicable
- Correction — request correction of inaccurate or incomplete information
- Deletion — request deletion of personal information, subject to legal and contractual limitations
- Restriction — request that we limit certain processing in specific circumstances
- Objection — object to certain processing based on legitimate interests, where applicable
- Data portability — receive certain information in a structured, commonly used format where technically feasible and required by law
- Withdrawal of consent — where processing is based on consent, withdraw that consent at any time (without affecting prior lawful processing)
- Complaint — lodge a complaint with a supervisory authority or privacy regulator in your jurisdiction, where applicable under local law
If Aventora processes your information on behalf of a customer organization, we may need to refer your request to that organization, which acts as the controller of your information. We will assist customers in responding to requests as required by our agreements and applicable law.
If you have concerns about our handling of your personal information, we encourage you to contact us first using the details in Contact Information so we can address your inquiry. We may need to verify your identity before responding.
Cookies
Our websites and some applications may use cookies and similar technologies (such as local storage or pixels) to:
- Keep you signed in and maintain session state
- Remember preferences
- Understand how our sites and services are used
- Support security and fraud prevention
Where required by law, we will provide cookie choices and obtain consent for non-essential cookies.
You can manage cookies through your browser settings. Disabling certain cookies may affect site functionality.
Children's Privacy
Aventora services are intended for use by businesses and authorized adults. Our platform is not directed at children under the age of 16 (or the applicable age of digital consent in your jurisdiction).
We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us and we will take appropriate steps to investigate and address the matter.
Changes to This Notice
We may update this Privacy Notice from time to time to reflect changes in our practices, services, legal requirements, or operational needs.
When we make material changes, we will post the updated notice on our website and update the Last Updated date at the top of this document. Where required by law, we will provide additional notice or seek consent.
We encourage you to review this notice periodically.
Contact Information
If you have questions about this Privacy Notice, our privacy practices, or wish to exercise your rights, please contact:
| Legal entity | Aventora Inc. |
| Address | Toronto, Ontario, Canada |
| Privacy inquiries and data subject requests | privacy@aventora.ai |
| Security assessments and subprocessor inquiries | security@aventora.ai |
For enterprise security and privacy reviews, additional documentation is available in our Security section, including our Privacy & Data Protection Executive Summary and Subprocessor Annex.
Related Documents
| Document | Description |
|---|---|
| Personal Data Privacy & Protection Policy | Detailed privacy and protection requirements for enterprise review |
| Privacy & Data Protection Executive Summary | Concise overview for vendor questionnaires |
| Subprocessor Annex | Third-party service providers that may process personal information |
| Data Retention | Storage components and category-level retention practices |
| Data Processing Addendum Appendix | Contractual processing terms reference |
Changelog
| Date | Change |
|---|---|
| 2026-07-06 | v1.1: Clarified controller vs. processor roles; subprocessor list now references authoritative annex; added complaint right, security contact, and Data Retention cross-link; aligned no-sale language with Security Overview. |
| 2026-07-06 | Initial publication of Privacy Notice v1.0. |