Aventora Privacy & Data Protection Executive Summary
| Field | Value |
|---|---|
| Document Name | Privacy & Data Protection Executive Summary |
| Version | 1.3 |
| Effective Date | July 20, 2026 |
| Last Reviewed | July 20, 2026 |
| Owner | Aventora Security |
| Review Frequency | Annually |
| Classification | Internal / Customer Shareable |
| Approval Status | Approved for publication — see Version History |
Purpose
This executive summary provides a concise overview of Aventora Inc.’s privacy and data protection practices for enterprise customers, security assessors, and privacy officers. It supports security questionnaires, vendor risk reviews, and procurement due diligence.
This document is not a certification, attestation, audit report, or legal contract. Contractual commitments are defined in the applicable services agreement and any executed data processing addendum. For full policy detail, see the Personal Data Privacy & Protection Policy.
About Aventora
Aventora operates an AI-powered customer engagement platform that helps organizations manage customer interactions across channels including voice, SMS, email, chat, and related administrative workflows. Platform components include Engagement Hub, Domain Assistant, Aventora CRM, administrative applications, and mobile clients.
Aventora processes personal information on behalf of customers to deliver contracted services. Customers typically act as Controllers (or equivalent under applicable law); Aventora acts as a Processor with respect to Customer Data.
Key Commitments
| Commitment | Summary |
|---|---|
| No sale of customer data | Aventora does not sell, rent, or license Customer Data to third parties |
| Purpose limitation | Customer Data is processed only for purposes defined in the customer agreement |
| Data minimization | Aventora processes only the minimum data necessary to provide the contracted service |
| Limited access | Aventora does not access customer systems beyond permissions explicitly granted by the customer |
| Subprocessor transparency | Subprocessors are evaluated before use, contractually bound (including re-identification, Further Subprocessor, DSR, and transfer controls), and disclosed to customers |
| No training on customer data | Customer Data is not used to train general-purpose AI models unless explicitly agreed in writing |
Data Handling Overview
Categories of personal information
Depending on enabled features and customer configuration, the platform may process:
- Identity and contact information (name, email, phone number)
- Account and authentication data for authorized users
- Communication content and metadata (messages, call/SMS records, timestamps)
- Interaction and engagement data, including AI-generated summaries where enabled
- Technical and operational logs (IP addresses, API metadata, error logs)
- Calendar and scheduling data where integrations are enabled
See Section 6 of the full policy for a complete category list.
Sensitive data
Customers are responsible for determining whether data they submit is subject to heightened legal protection (for example, health or financial data). Sensitive categories should only be processed where required for a contracted feature and permitted by agreement and applicable law.
Hosting and Data Residency
| Element | Practice |
|---|---|
| Primary hosting | Amazon Web Services (AWS) for Aventora-managed cloud deployments |
| Default managed residency | AWS Canadian regions, unless otherwise agreed in writing |
| Alternate managed regions | Available by agreement (for example, United States) |
| Customer-managed / self-hosted / on-premises | Customer-operated infrastructure; residency determined by customer configuration |
| Hybrid deployments | Mix of managed and customer-operated components per agreement |
Some enabled features (for example, global telephony routing or AI inference) may involve subprocessors operating in additional jurisdictions. Customers should evaluate enabled features against their residency requirements. See the Subprocessor Annex and Section 13 of the full policy.
Security Controls Summary
Aventora applies layered technical and organizational controls to protect personal information:
| Control area | Summary |
|---|---|
| Encryption in transit | TLS (1.2+) for production API, administrative, and customer-facing traffic |
| Encryption at rest | Provider-supported encryption for production data stores where configured |
| Access control | Role-based access control (RBAC) and least privilege across platform and operations |
| Authentication | Strong authentication; MFA required for privileged administrative access |
| Logging and monitoring | Security and operational logging implemented for production environments |
| Backups and DR | Backup and disaster recovery procedures maintained for production data |
| Secure development | Privacy-by-design and security-by-design in the development lifecycle |
| Incident response | Procedures for detection, containment, investigation, notification, and recovery |
Implementation may vary by deployment model. Aventora does not claim formal certification under SOC 2, ISO 27001, or other frameworks based on this summary alone.
Subprocessors
Aventora engages third-party subprocessors to deliver infrastructure and optional features. Common subprocessors include:
| Subprocessor | Typical use |
|---|---|
| Amazon Web Services (AWS) | Cloud hosting, compute, storage, networking |
| OpenAI | AI language model inference (enabled features) |
| Twilio | Telephony and SMS |
| Calendar, identity, or communication integrations (where enabled) | |
| Microsoft | Calendar, identity, or communication integrations (where enabled) |
Additional feature-dependent subprocessors (for example, alternative telephony, speech synthesis, or alternate AI inference) may apply. See the Subprocessor Annex for the authoritative list.
Aventora requires vendors and subprocessors that handle personal information to accept standard contractual terms covering purpose limitation, security, breach notification, no unauthorized re-identification, Further Subprocessor authorization, data subject rights assistance, international transfer controls, and return or destruction of data. See the Vendor Management Policy.
Privacy Principles
Aventora’s processing aligns with widely recognized privacy principles:
- Lawfulness — Processing on an appropriate lawful basis; Customer Data used only as instructed
- Fairness — Processing that is proportionate and not unduly intrusive
- Transparency — Documentation available for customer review and assessment
- Data minimization — Collection limited to what is necessary for the service
- Purpose limitation — No incompatible further processing
- Accuracy — Reasonable steps to maintain data quality where Aventora is responsible
- Storage limitation — Retention aligned with contractual and legal requirements
- Integrity and confidentiality — Appropriate safeguards throughout the lifecycle
- Accountability — Documented controls, ownership, and periodic review
Data Subject Rights
Customers, as Controllers, are primarily responsible for responding to data subject requests regarding Customer Data. Aventora provides reasonable assistance where technically feasible and as required by agreement, including access, correction, deletion, restriction, objection, portability, and export through platform functionality where available.
Where Aventora is Controller, individuals may lodge a complaint with a supervisory authority or privacy regulator in their jurisdiction, where applicable under local law, in addition to contacting privacy@aventora.ai.
Incident and Breach Notification
Aventora maintains incident response procedures covering detection, containment, investigation, recovery, and notification. Where a privacy incident affects Customer Data, Aventora will notify affected customers without undue delay where required by agreement or applicable law and will cooperate with customers in fulfilling regulatory notification obligations where Aventora acts as Processor.
Regulatory Alignment
Aventora designs its privacy program to support alignment with applicable laws and common enterprise frameworks, including:
- PIPEDA (Canada)
- GDPR and UK GDPR (where applicable)
- U.S. state privacy laws (where applicable)
This summary does not constitute a compliance attestation. Sector-specific frameworks (for example, HIPAA, PCI DSS) apply only where explicitly agreed in writing.
Customer Responsibilities
Customers are responsible for:
- Establishing lawful bases and providing required notices to data subjects
- Configuring roles, permissions, integrations, and enabled features
- Specifying residency and transfer requirements during contracting
- Managing credentials and endpoints under customer control
- Cooperating during security and privacy incidents
Related Documents
| Document | Description |
|---|---|
| Personal Data Privacy & Protection Policy | Full enterprise policy |
| Vendor Management Policy | Vendor/subprocessor contractual requirements and approval checklists |
| Subprocessor Annex | Current subprocessor list and details |
| Data Processing Addendum Appendix | DPA-aligned contractual appendix |
| Security Overview | Platform security commitments |
Contact
| Purpose | Contact |
|---|---|
| Legal entity | Aventora Inc. |
| Address | Toronto, Ontario, Canada |
| Privacy inquiries | privacy@aventora.ai |
| Security assessments and subprocessor inquiries | security@aventora.ai |
| Commercial inquiries | sales@aventora.ai |
Version History
| Version | Date | Summary |
|---|---|---|
| 1.3 | July 20, 2026 | Linked Vendor Management Policy; noted standard vendor/subprocessor contractual controls for questionnaires |
| 1.2 | July 6, 2026 | Added standardized legal entity address; expanded data subject rights to include complaint process |
| 1.1 | July 6, 2026 | Clarified deployment models and residency; aligned contact channels with privacy policy |
| 1.0 | July 6, 2026 | Initial release |
This document is provided for informational purposes and does not constitute legal advice.