Skip to main content

Aventora Privacy & Data Protection Executive Summary

FieldValue
Document NamePrivacy & Data Protection Executive Summary
Version1.3
Effective DateJuly 20, 2026
Last ReviewedJuly 20, 2026
OwnerAventora Security
Review FrequencyAnnually
ClassificationInternal / Customer Shareable
Approval StatusApproved for publication — see Version History

Purpose

This executive summary provides a concise overview of Aventora Inc.’s privacy and data protection practices for enterprise customers, security assessors, and privacy officers. It supports security questionnaires, vendor risk reviews, and procurement due diligence.

This document is not a certification, attestation, audit report, or legal contract. Contractual commitments are defined in the applicable services agreement and any executed data processing addendum. For full policy detail, see the Personal Data Privacy & Protection Policy.


About Aventora

Aventora operates an AI-powered customer engagement platform that helps organizations manage customer interactions across channels including voice, SMS, email, chat, and related administrative workflows. Platform components include Engagement Hub, Domain Assistant, Aventora CRM, administrative applications, and mobile clients.

Aventora processes personal information on behalf of customers to deliver contracted services. Customers typically act as Controllers (or equivalent under applicable law); Aventora acts as a Processor with respect to Customer Data.


Key Commitments

CommitmentSummary
No sale of customer dataAventora does not sell, rent, or license Customer Data to third parties
Purpose limitationCustomer Data is processed only for purposes defined in the customer agreement
Data minimizationAventora processes only the minimum data necessary to provide the contracted service
Limited accessAventora does not access customer systems beyond permissions explicitly granted by the customer
Subprocessor transparencySubprocessors are evaluated before use, contractually bound (including re-identification, Further Subprocessor, DSR, and transfer controls), and disclosed to customers
No training on customer dataCustomer Data is not used to train general-purpose AI models unless explicitly agreed in writing

Data Handling Overview

Categories of personal information

Depending on enabled features and customer configuration, the platform may process:

  • Identity and contact information (name, email, phone number)
  • Account and authentication data for authorized users
  • Communication content and metadata (messages, call/SMS records, timestamps)
  • Interaction and engagement data, including AI-generated summaries where enabled
  • Technical and operational logs (IP addresses, API metadata, error logs)
  • Calendar and scheduling data where integrations are enabled

See Section 6 of the full policy for a complete category list.

Sensitive data

Customers are responsible for determining whether data they submit is subject to heightened legal protection (for example, health or financial data). Sensitive categories should only be processed where required for a contracted feature and permitted by agreement and applicable law.


Hosting and Data Residency

ElementPractice
Primary hostingAmazon Web Services (AWS) for Aventora-managed cloud deployments
Default managed residencyAWS Canadian regions, unless otherwise agreed in writing
Alternate managed regionsAvailable by agreement (for example, United States)
Customer-managed / self-hosted / on-premisesCustomer-operated infrastructure; residency determined by customer configuration
Hybrid deploymentsMix of managed and customer-operated components per agreement

Some enabled features (for example, global telephony routing or AI inference) may involve subprocessors operating in additional jurisdictions. Customers should evaluate enabled features against their residency requirements. See the Subprocessor Annex and Section 13 of the full policy.


Security Controls Summary

Aventora applies layered technical and organizational controls to protect personal information:

Control areaSummary
Encryption in transitTLS (1.2+) for production API, administrative, and customer-facing traffic
Encryption at restProvider-supported encryption for production data stores where configured
Access controlRole-based access control (RBAC) and least privilege across platform and operations
AuthenticationStrong authentication; MFA required for privileged administrative access
Logging and monitoringSecurity and operational logging implemented for production environments
Backups and DRBackup and disaster recovery procedures maintained for production data
Secure developmentPrivacy-by-design and security-by-design in the development lifecycle
Incident responseProcedures for detection, containment, investigation, notification, and recovery

Implementation may vary by deployment model. Aventora does not claim formal certification under SOC 2, ISO 27001, or other frameworks based on this summary alone.


Subprocessors

Aventora engages third-party subprocessors to deliver infrastructure and optional features. Common subprocessors include:

SubprocessorTypical use
Amazon Web Services (AWS)Cloud hosting, compute, storage, networking
OpenAIAI language model inference (enabled features)
TwilioTelephony and SMS
GoogleCalendar, identity, or communication integrations (where enabled)
MicrosoftCalendar, identity, or communication integrations (where enabled)

Additional feature-dependent subprocessors (for example, alternative telephony, speech synthesis, or alternate AI inference) may apply. See the Subprocessor Annex for the authoritative list.

Aventora requires vendors and subprocessors that handle personal information to accept standard contractual terms covering purpose limitation, security, breach notification, no unauthorized re-identification, Further Subprocessor authorization, data subject rights assistance, international transfer controls, and return or destruction of data. See the Vendor Management Policy.


Privacy Principles

Aventora’s processing aligns with widely recognized privacy principles:

  1. Lawfulness — Processing on an appropriate lawful basis; Customer Data used only as instructed
  2. Fairness — Processing that is proportionate and not unduly intrusive
  3. Transparency — Documentation available for customer review and assessment
  4. Data minimization — Collection limited to what is necessary for the service
  5. Purpose limitation — No incompatible further processing
  6. Accuracy — Reasonable steps to maintain data quality where Aventora is responsible
  7. Storage limitation — Retention aligned with contractual and legal requirements
  8. Integrity and confidentiality — Appropriate safeguards throughout the lifecycle
  9. Accountability — Documented controls, ownership, and periodic review

Data Subject Rights

Customers, as Controllers, are primarily responsible for responding to data subject requests regarding Customer Data. Aventora provides reasonable assistance where technically feasible and as required by agreement, including access, correction, deletion, restriction, objection, portability, and export through platform functionality where available.

Where Aventora is Controller, individuals may lodge a complaint with a supervisory authority or privacy regulator in their jurisdiction, where applicable under local law, in addition to contacting privacy@aventora.ai.


Incident and Breach Notification

Aventora maintains incident response procedures covering detection, containment, investigation, recovery, and notification. Where a privacy incident affects Customer Data, Aventora will notify affected customers without undue delay where required by agreement or applicable law and will cooperate with customers in fulfilling regulatory notification obligations where Aventora acts as Processor.


Regulatory Alignment

Aventora designs its privacy program to support alignment with applicable laws and common enterprise frameworks, including:

  • PIPEDA (Canada)
  • GDPR and UK GDPR (where applicable)
  • U.S. state privacy laws (where applicable)

This summary does not constitute a compliance attestation. Sector-specific frameworks (for example, HIPAA, PCI DSS) apply only where explicitly agreed in writing.


Customer Responsibilities

Customers are responsible for:

  • Establishing lawful bases and providing required notices to data subjects
  • Configuring roles, permissions, integrations, and enabled features
  • Specifying residency and transfer requirements during contracting
  • Managing credentials and endpoints under customer control
  • Cooperating during security and privacy incidents

DocumentDescription
Personal Data Privacy & Protection PolicyFull enterprise policy
Vendor Management PolicyVendor/subprocessor contractual requirements and approval checklists
Subprocessor AnnexCurrent subprocessor list and details
Data Processing Addendum AppendixDPA-aligned contractual appendix
Security OverviewPlatform security commitments

Contact

PurposeContact
Legal entityAventora Inc.
AddressToronto, Ontario, Canada
Privacy inquiriesprivacy@aventora.ai
Security assessments and subprocessor inquiriessecurity@aventora.ai
Commercial inquiriessales@aventora.ai

Version History

VersionDateSummary
1.3July 20, 2026Linked Vendor Management Policy; noted standard vendor/subprocessor contractual controls for questionnaires
1.2July 6, 2026Added standardized legal entity address; expanded data subject rights to include complaint process
1.1July 6, 2026Clarified deployment models and residency; aligned contact channels with privacy policy
1.0July 6, 2026Initial release

This document is provided for informational purposes and does not constitute legal advice.