Skip to main content

Aventora Personal Data Privacy & Protection Policy

FieldValue
Document NamePersonal Data Privacy & Protection Policy
Version1.3
Effective DateJuly 20, 2026
Last ReviewedJuly 20, 2026
OwnerAventora Security
Review FrequencyAnnually
ClassificationInternal / Customer Shareable
Approval StatusApproved for publication — see Version History

Document Control

This policy establishes Aventora Inc. (“Aventora,” “we,” “us,” or “our”) requirements for the collection, use, disclosure, retention, protection, and disposal of personal information processed in connection with the Aventora platform and related services.

This document is intended for enterprise customers, security assessors, privacy officers, and Aventora personnel. It supports security and privacy reviews and aligns with common control themes relevant to future compliance initiatives (for example, SOC 2, ISO 27001, PIPEDA, GDPR, and UK GDPR). Aventora does not claim formal certification or attestation under any specific privacy or security framework based on this document alone. Implementation details may vary by deployment model, contractual terms, and enabled product features.

RFC 2119 Terminology

The key words “MUST,” “MUST NOT,” “REQUIRED,” “SHALL,” “SHALL NOT,” “SHOULD,” “SHOULD NOT,” “RECOMMENDED,” “MAY,” and “OPTIONAL” in this document are to be interpreted as described in RFC 2119.


Table of Contents

  1. Purpose
  2. Scope
  3. Definitions
  4. Roles and Responsibilities
  5. Privacy Principles
  6. Categories of Personal Information Processed
  7. Sensitive Personal Information
  8. Lawful Basis for Processing
  9. Collection of Personal Information
  10. Use of Personal Information
  11. Disclosure to Third Parties and Subprocessors
  12. International Data Transfers
  13. Data Residency
  14. Data Retention
  15. Secure Data Disposal
  16. Access Control
  17. Encryption Requirements
  18. Logging and Monitoring
  19. Authentication and Authorization
  20. Secure Development Practices
  21. Incident Response and Privacy Breach Management
  22. Data Subject Rights
  23. Customer Responsibilities
  24. Vendor and Subprocessor Management
  25. Security Awareness and Training
  26. Compliance with Applicable Privacy Laws
  27. Policy Exceptions
  28. Policy Review
  29. Version History

1. Purpose

The purpose of this Personal Data Privacy & Protection Policy is to define Aventora’s organizational commitments and operational requirements for protecting personal information throughout its lifecycle.

Aventora operates an AI-powered customer engagement platform that enables organizations to manage communications and customer interactions across channels such as voice, SMS, email, chat, and related administrative workflows. In delivering these services, Aventora processes personal information on behalf of customers and, in limited circumstances, in connection with Aventora’s own business operations.

This policy:

  • Establishes privacy-by-design and security-by-design expectations for Aventora products, infrastructure, and operations;
  • Defines roles, responsibilities, and minimum controls for protecting personal information;
  • Provides a reference for enterprise security and privacy assessments;
  • Supports alignment with applicable privacy legislation and common enterprise control frameworks without asserting certification status; and
  • Communicates Aventora’s commitment that customer data is never sold and is processed only for the purposes defined by the applicable customer agreement.

2. Scope

2.1 In Scope

This policy applies to:

AreaDescription
Aventora platform servicesEngagement Hub, Domain Assistant, Aventora CRM, administrative applications, mobile clients, and supporting integrations
Personal information processed on behalf of customersData submitted to, generated by, or stored within Aventora-managed environments in connection with contracted services
Aventora personnelEmployees, contractors, and authorized agents who access Aventora systems or customer data in the course of their duties
Infrastructure and hostingCloud and hosted environments used to operate Aventora services, including Amazon Web Services (AWS) and associated managed components
Third-party subprocessorsVendors engaged by Aventora to support platform delivery, where such vendors process personal information on Aventora’s behalf
Development and operationsSoftware development, deployment, monitoring, support, backup, disaster recovery, and vendor management activities that involve personal information

2.2 Out of Scope

Unless explicitly addressed in a written agreement, the following remain outside the scope of this policy:

  • Customer-managed systems, networks, and data stores not operated by or on behalf of Aventora;
  • Personal information processed by customers independently of the Aventora platform;
  • Third-party services configured or operated directly by the customer outside Aventora’s control; and
  • Personal information processed by Aventora for purposes unrelated to the delivery of contracted services (for example, Aventora marketing website visitors), which may be governed by separate notices and policies.

2.3 Deployment Models

This policy applies across Aventora-managed cloud deployments, customer-managed and self-hosted deployments, and hybrid configurations. Residency and hosting details for each model are described in Section 13. Customer-specific security and privacy requirements MAY be incorporated during deployment where agreed in writing. Variations from default controls MUST be documented and approved through Aventora’s exception process (see Section 27).


3. Definitions

For the purposes of this policy, the following definitions apply:

TermDefinition
Personal InformationInformation about an identified or identifiable natural person. This includes direct identifiers (for example, name, email address, telephone number) and indirect identifiers that can reasonably be linked to an individual.
Sensitive Personal InformationA subset of personal information that may be subject to heightened legal or contractual protection, such as government identifiers, financial account details, precise geolocation, health-related information, biometric data, or other categories defined by applicable law or customer agreement.
CustomerAn organization that has entered into a services agreement with Aventora for use of the platform.
Customer DataPersonal information and other data submitted to or processed within the Aventora platform on behalf of a Customer.
Data SubjectThe natural person to whom personal information relates.
ProcessingAny operation performed on personal information, including collection, recording, organization, storage, adaptation, retrieval, consultation, use, disclosure, transmission, alignment, restriction, erasure, or destruction.
ControllerThe entity that determines the purposes and means of processing personal information. Customers are typically Controllers with respect to Customer Data.
ProcessorThe entity that processes personal information on behalf of a Controller. Aventora acts as a Processor with respect to Customer Data, except where Aventora determines purposes and means independently.
SubprocessorA third party engaged by Aventora to process personal information on Aventora’s behalf in connection with the services.
Authorized UserAn individual permitted by the Customer or Aventora to access the platform or related systems in accordance with assigned roles and permissions.
Privileged AccessAdministrative or elevated access to production systems, infrastructure, databases, secrets, or customer environments.
Data ResidencyThe geographic region or jurisdiction where Customer Data is stored and primarily processed.
Privacy IncidentAn event that compromises or is reasonably suspected to compromise the confidentiality, integrity, or availability of personal information, or that otherwise violates this policy or applicable law.
Data MinimizationThe practice of limiting personal information collection, retention, and processing to what is necessary for specified purposes.

4. Roles and Responsibilities

Aventora assigns privacy and security responsibilities across organizational functions. Specific named roles MAY vary by organization size and deployment context; however, the accountability structures below MUST be maintained.

4.1 Executive Leadership

  • Approves this policy and material amendments;
  • Ensures adequate resources for privacy and security program activities;
  • Reviews significant privacy incidents and remediation outcomes; and
  • Supports alignment with customer contractual and regulatory obligations.

4.2 Aventora Security (Policy Owner)

  • Owns, maintains, and publishes this policy;
  • Coordinates privacy and security control implementation across product and operations teams;
  • Manages policy exceptions and tracks remediation;
  • Supports customer security and privacy assessments; and
  • Conducts or coordinates the annual policy review.

4.3 Engineering and Product Teams

  • Implement privacy-by-design and security-by-design controls in platform components;
  • Apply data minimization in product features and integrations;
  • Follow secure development practices (see Section 20);
  • Document data flows for new features involving personal information; and
  • Remediate identified privacy and security gaps within agreed timelines.

4.4 Operations and Infrastructure Teams

  • Operate hosting environments in accordance with this policy;
  • Implement access controls, encryption, logging, backup, and disaster recovery procedures;
  • Manage subprocessors and infrastructure configurations used in production;
  • Respond to operational incidents affecting personal information; and
  • Maintain deployment documentation reflecting customer-specific requirements where applicable.

4.5 Customer Success and Support

  • Handle customer inquiries related to privacy, data subject requests, and incident notifications in coordination with Security and Legal;
  • Ensure support personnel access Customer Data only when necessary and authorized; and
  • Escalate suspected privacy incidents promptly.

4.6 Customers (Controller Responsibilities)

Customers retain responsibility for determining lawful bases, providing required notices, managing end-user consents where applicable, configuring platform permissions, and fulfilling data subject rights requests for Customer Data, subject to Aventora’s assistance obligations under applicable agreements. See Section 23.


5. Privacy Principles

Aventora adopts the following privacy principles as foundational requirements for all processing of personal information within scope of this policy. These principles align with widely recognized privacy frameworks and support future alignment with regulations such as PIPEDA, GDPR, and UK GDPR.

5.1 Lawfulness

Aventora MUST process personal information on a lawful basis appropriate to the processing context. For Customer Data, processing MUST be limited to purposes authorized by the applicable customer agreement and the Customer’s documented instructions, except where applicable law requires otherwise.

Aventora personnel MUST NOT use Customer Data for unrelated purposes, including marketing to Customer end users, model training on Customer Data unless explicitly agreed, or any commercial exploitation of Customer Data. Customer data is never sold.

5.2 Fairness

Processing MUST be conducted in a manner that is fair to data subjects and Customers. Aventora SHOULD avoid processing that is unexpected, unduly intrusive, or disproportionate to the stated purpose.

Where AI-powered features are enabled, Aventora SHOULD ensure that automated processing supports Customer-configured workflows and does not expand data use beyond contracted service purposes.

5.3 Transparency

Aventora MUST maintain accurate descriptions of its processing activities suitable for customer review, including categories of data processed, subprocessors used, and data residency options.

Customers SHOULD provide their own privacy notices to data subjects regarding their use of the Aventora platform. Aventora SHOULD make available information necessary for Customers to meet transparency obligations, including subprocessor disclosures and security documentation upon request or as contractually required.

5.4 Data Minimization

Aventora MUST process only the minimum customer data necessary to provide the contracted service. Product and engineering teams SHOULD design features to avoid unnecessary collection of personal information and SHOULD prefer pseudonymization or aggregation where full identifiers are not required.

Integration configurations MUST limit data exchange to fields required for the enabled feature. Aventora MUST NOT access customer systems beyond the permissions explicitly granted by the customer.

5.5 Purpose Limitation

Personal information MUST be collected and used for specified, explicit, and legitimate purposes consistent with the customer agreement and MUST NOT be further processed in a manner incompatible with those purposes.

Changes to processing purposes that materially affect Customer Data MUST be communicated to affected Customers and implemented only where permitted by contract and applicable law.

5.6 Accuracy

Aventora SHOULD take reasonable steps to maintain accurate personal information where Aventora is responsible for data entry or synchronization, and SHOULD enable Customers to review, correct, or delete Customer Data through platform functionality where available.

Customers remain responsible for the accuracy of data they submit or configure within the platform.

5.7 Storage Limitation

Personal information MUST NOT be retained longer than necessary for the purposes for which it was processed, unless a longer retention period is required or permitted by law or contract. Retention schedules MUST be defined and applied consistently (see Section 14).

5.8 Integrity and Confidentiality

Aventora MUST implement appropriate technical and organizational measures to protect personal information against unauthorized or unlawful processing and against accidental loss, destruction, or damage.

These measures include access controls, encryption in transit, logging and monitoring, secure development practices, vendor management, and incident response procedures described in this policy.

5.9 Accountability

Aventora MUST demonstrate compliance with this policy through documented controls, assigned ownership, periodic review, and remediation of identified gaps.

Privacy and security obligations MUST be reflected in contracts with Customers, personnel, and subprocessors where applicable.


6. Categories of Personal Information Processed

The categories of personal information processed by Aventora depend on enabled product features, customer configuration, and integrations. The table below describes common categories. This list is illustrative and not exhaustive.

CategoryExamplesTypical Source
Identity and contact informationName, email address, telephone number, job title, organization nameCustomer upload, CRM sync, web forms, chat intake, email intake
Account and authentication dataUsernames, role assignments, password hashes, session tokens, API key metadataCustomer administrators, Authorized Users, platform authentication services
Communication content and metadataMessage body, call recordings or transcripts where enabled, SMS content, email headers, timestamps, channel identifiersEngagement workflows, telephony providers, messaging integrations
Interaction and engagement dataConversation history, engagement status, routing decisions, AI-generated summaries or responses where enabledPlatform processing during customer interactions
Technical and usage dataIP addresses, device or browser identifiers, API request metadata, error logsPlatform operations, security monitoring, support diagnostics
Calendar and scheduling dataAppointment details, availability, meeting links where calendar integrations are enabledOAuth-connected calendar providers (for example, Google, Microsoft)
Configuration and business metadataTenant settings, workflow rules, template content, domain configurationCustomer administrators
Billing and commercial dataAccount identifiers, subscription tier, usage metrics (typically organization-level)Aventora commercial systems

Aventora SHOULD maintain an internal data inventory mapping product components and data stores to these categories to support privacy impact assessments and customer inquiries.


7. Sensitive Personal Information

7.1 Definition and Handling

Sensitive personal information SHOULD NOT be collected or processed through the Aventora platform unless required for a contracted feature and permitted by the customer agreement and applicable law.

Where sensitive personal information is processed:

  • Processing MUST be limited to the minimum necessary for the enabled function;
  • Access MUST be restricted through role-based access control and least privilege;
  • Additional safeguards SHOULD be applied where required by law or customer contract (for example, enhanced encryption, restricted subprocessors, or regional residency);
  • Personnel access MUST be logged and limited to authorized support or engineering activities; and
  • Customers SHOULD classify data appropriately in their own policies and configure integrations to avoid transmitting sensitive categories not required for the service.

7.2 Prohibited Uses

Unless explicitly agreed in writing and permitted by law, Aventora MUST NOT:

  • Use Customer Data to train general-purpose AI models for unrelated commercial purposes;
  • Sell, rent, or license Customer Data to third parties; or
  • Combine Customer Data across customers for profiling or marketing purposes.

7.3 Customer Determination of Sensitivity

Customers are responsible for determining whether data they submit qualifies as sensitive under applicable law (for example, health information, financial data, or children’s data) and for ensuring that their use of the platform complies with restrictions applicable to such data.


8. Lawful Basis for Processing

8.1 Customer Data

For Customer Data, Aventora generally processes personal information as a Processor acting on documented instructions from the Customer (Controller). The lawful basis for processing is determined by the Customer in accordance with applicable law. Aventora MUST process Customer Data only as necessary to:

  • Provide, maintain, and support the contracted services;
  • Implement security, fraud prevention, and abuse detection controls;
  • Comply with applicable legal obligations; and
  • Perform other processing explicitly authorized in the customer agreement or documented instructions.

8.2 Aventora Operational Data

Where Aventora acts as a Controller (for example, processing contact information of Customer personnel for account management or billing), Aventora MUST identify and document an appropriate lawful basis under applicable law, such as contract performance, legitimate interests, consent, or legal obligation.

Where processing of special categories of personal information is in scope, Customers MUST ensure an appropriate lawful basis exists under applicable law. Aventora SHOULD assist Customers in configuring the platform to support consent or restriction requirements where technically feasible and contractually agreed.


9. Collection of Personal Information

9.1 Collection Methods

Personal information MAY be collected through:

  • Direct submission by Customers or Authorized Users via administrative interfaces;
  • End-user interactions with customer-configured channels (voice, SMS, email, chat, web forms);
  • Synchronized data from customer-connected systems (for example, CRM records, calendar events);
  • Automated intake workflows (for example, email polling, webhook receivers, API integrations); and
  • Operational telemetry generated during platform use.

9.2 Collection Limitations

Aventora MUST configure default product behavior to support data minimization. Engineering teams SHOULD:

  • Require explicit customer configuration before enabling integrations that expand data collection;
  • Avoid collecting fields not needed for the enabled workflow;
  • Document data fields collected by each integration; and
  • Provide Customers with configuration options to limit retention and visibility where feasible.

9.3 Customer-Controlled Collection

Customers MUST ensure that their collection of personal information from data subjects complies with applicable notice and consent requirements. Aventora MUST NOT access customer-owned systems or data repositories beyond permissions explicitly granted by the Customer.


10. Use of Personal Information

10.1 Permitted Uses

Personal information MUST be used only for purposes consistent with this policy and the applicable customer agreement, including:

PurposeDescription
Service deliveryOperating engagement workflows, AI-assisted responses where enabled, routing, notifications, and reporting
Platform administrationAccount provisioning, authentication, authorization, configuration, and support
Security and integrityDetecting abuse, investigating incidents, maintaining audit logs, and enforcing access controls
Improvement and reliabilityDebugging, performance monitoring, and service improvement using aggregated or de-identified data where possible
Legal complianceResponding to lawful requests and meeting regulatory obligations

10.2 AI-Powered Processing

Where AI features are enabled (for example, natural language understanding, summarization, or automated response generation), personal information MAY be transmitted to AI subprocessors only as necessary to perform the customer-configured function. AI processing MUST remain within the scope of the contracted service and MUST NOT expand to unrelated purposes.

Customers SHOULD review enabled AI features and subprocessors as part of their own privacy assessments.

10.3 Personnel Access

Aventora personnel MAY access Customer Data only when:

  • Access is necessary to provide support, perform maintenance, or investigate a security or operational issue;
  • Access is authorized by the Customer where required by agreement;
  • Access follows least privilege and is logged where technically feasible; and
  • Personnel are bound by confidentiality obligations.

Routine browsing of Customer Data MUST NOT occur.


11. Disclosure to Third Parties and Subprocessors

11.1 General Requirements

Aventora MUST NOT disclose Customer Data to third parties except:

  • To subprocessors engaged to support delivery of the services, subject to contractual protections;
  • To integration providers enabled by the Customer;
  • Where required by applicable law or valid legal process; or
  • With the Customer’s documented authorization.

Customer data is never sold. Disclosure for advertising, data brokerage, or unrelated commercial purposes MUST NOT occur.

11.2 Subprocessors

Aventora uses third-party subprocessors to provide infrastructure and optional features. Subprocessors process personal information only as directed by Aventora and in accordance with written agreements requiring appropriate security and confidentiality obligations.

Depending on enabled features and deployment configuration, subprocessors MAY include:

SubprocessorTypical Processing Activity
Amazon Web Services (AWS)Cloud hosting, compute, storage, networking, backup infrastructure
OpenAIAI language model inference for enabled conversational features
TwilioTelephony, SMS, and related communication delivery
GoogleCalendar integration, identity, or communication services where enabled
MicrosoftCalendar integration, identity, or communication services where enabled

Additional feature-dependent subprocessors (for example, alternative telephony, speech synthesis, or alternate AI inference providers) MAY apply depending on enabled product features and deployment configuration. The authoritative, deployment-specific subprocessor list is maintained in the Subprocessor Annex and SHOULD be reviewed as part of customer privacy assessments.

11.3 Customer-Enabled Integrations

Where Customers configure integrations with third-party systems, data MAY be disclosed to those providers according to Customer instructions and the integration’s technical design. Such disclosures are directed by the Customer; Customers remain responsible for their relationship with those third parties.

If Aventora receives a request from law enforcement or other authority for Customer Data, Aventora SHOULD redirect the request to the Customer where permitted and SHOULD notify the Customer unless prohibited by law. Aventora MUST disclose only the minimum information required by valid legal process.


12. International Data Transfers

Personal information MAY be transferred across borders where necessary to provide the services, including transfers to subprocessors or support personnel in jurisdictions other than the data subject’s country of residence.

Where required by applicable law (for example, GDPR Chapter V or UK GDPR transfer rules), Aventora SHOULD implement appropriate transfer mechanisms such as:

  • Standard contractual clauses or equivalent contractual protections;
  • Customer-approved deployment and residency configurations that limit transfers; or
  • Other lawful transfer tools recognized under applicable law.

Customers SHOULD specify residency and transfer requirements during contracting. Aventora SHOULD document transfer locations relevant to each deployment.


13. Data Residency

Data residency depends on deployment model, contractual terms, and enabled product features. The table below distinguishes how personal information is stored and primarily processed.

13.1 Deployment Models and Residency

Deployment modelDescriptionTypical data residency
Aventora-managed cloud (default)Aventora-operated environments on Amazon Web Services (AWS)AWS Canadian regions, unless otherwise agreed in writing
Aventora-managed cloud (alternate region)Aventora-operated managed environments in a customer-selected or contractually agreed region (for example, United States)As specified in the applicable agreement
Customer-managed / self-hosted / on-premisesCustomer-operated infrastructure (for example, VPS, private cloud, or on-premises) using published deployment optionsDetermined by the customer’s infrastructure, configuration, and applicable law
HybridCombination of Aventora-managed and customer-managed components as agreed in writingAs documented and approved for the specific deployment

Unless otherwise agreed in writing, default Aventora-managed deployments use AWS Canadian regions to support data residency preferences for Canadian customers and alignment with PIPEDA expectations. Customer-specific security and privacy requirements, including residency, MAY be incorporated during deployment where documented and approved.

13.2 Subprocessor Locations

Even where compute and storage are located in a specified region, subprocessors used for enabled features (for example, AI inference or global telephony routing) MAY process data in other jurisdictions. Customers SHOULD evaluate enabled features against their residency requirements. See the Subprocessor Annex.


14. Data Retention

14.1 Retention Principles

Personal information MUST be retained only for as long as necessary to:

  • Provide the contracted services;
  • Meet legal, regulatory, or contractual obligations;
  • Resolve disputes and enforce agreements; and
  • Maintain security logs and backup integrity for defined periods.

14.2 Retention Schedules

Aventora SHOULD define and maintain retention schedules by data category and product component. Retention periods SHOULD consider:

  • Customer-configured settings where available;
  • Contractual minimums and maximums;
  • Operational requirements (for example, backup rotation); and
  • Applicable legal requirements.

Upon contract termination or Customer request, Aventora MUST delete or return Customer Data in accordance with the applicable agreement, subject to legal retention obligations and secure backup expiry cycles.

Where litigation, investigation, or regulatory inquiry requires preservation of data, Aventora SHOULD suspend routine deletion for affected data sets upon direction by Aventora Security or Legal and SHOULD document the scope and duration of the hold.


15. Secure Data Disposal

When personal information is no longer required, Aventora MUST dispose of it securely.

15.1 Disposal Methods

Disposal SHOULD include one or more of the following, appropriate to the media and environment:

  • Cryptographic erasure where encryption keys are destroyed;
  • Secure deletion from active databases and application stores;
  • Expiration and purging of backups according to defined retention cycles; and
  • Secure destruction or wiping of physical media where applicable.

15.2 Subprocessor Disposal

Contracts with subprocessors SHOULD require return or deletion of personal information upon termination of the subprocessing relationship, except where retention is required by law.

15.3 Verification

Aventora SHOULD periodically verify that deletion routines and backup expiry processes operate as intended and SHOULD maintain records of deletion upon customer offboarding where contractually required.


16. Access Control

Access to systems and personal information MUST be restricted based on business need and assigned responsibilities.

16.1 Role-Based Access Control

Aventora MUST apply role-based access control (RBAC) across platform and administrative systems. Permissions MUST be assigned according to job function and MUST be reviewed periodically.

Platform authorization MUST enforce server-side access decisions. Client applications MUST NOT be relied upon as the sole enforcement mechanism.

16.2 Least Privilege

The principle of least privilege MUST be applied to:

  • Production infrastructure and databases;
  • Administrative consoles and deployment tools;
  • API keys, service accounts, and integration credentials; and
  • Support and engineering access to Customer Data.

Default-deny access models SHOULD be used where feasible.

16.3 Access Reviews

Aventora SHOULD conduct periodic reviews of privileged accounts, production access, and outstanding authorization grants. Access MUST be revoked promptly upon role change or termination.

16.4 Customer Access Control

Customers MUST manage Authorized User accounts, roles, and integration permissions within their tenant. Customers SHOULD disable unused accounts and apply MFA for administrative users where supported.


17. Encryption Requirements

17.1 Encryption in Transit

Encryption MUST be used for data in transit. Production API, administrative, and customer-facing traffic MUST be protected using TLS (TLS 1.2 or higher). Connections to databases, subprocessors, and integration endpoints SHOULD use encrypted channels where supported by the provider.

Unencrypted transmission of personal information over public networks in production environments MUST NOT occur.

17.2 Encryption at Rest

Aventora SHOULD enable encryption at rest for production data stores using provider-supported mechanisms (for example, AWS volume and database encryption). Application-level encryption SHOULD be applied to highly sensitive fields where warranted by risk assessment or customer requirements.

Encryption key management SHOULD follow provider best practices and SHOULD restrict key access to authorized personnel and services.

17.3 Secrets Management

API keys, passwords, tokens, and other secrets MUST NOT be stored in plaintext in source code or unsecured configuration repositories. Secrets MUST be supplied through secure configuration mechanisms appropriate to the deployment environment.


18. Logging and Monitoring

18.1 Logging Requirements

Logging and monitoring MUST be implemented for production environments to support security, operational reliability, and incident investigation.

Logs SHOULD capture relevant security events, including:

  • Authentication successes and failures;
  • Authorization denials;
  • Administrative actions;
  • Integration and API errors affecting data processing; and
  • Infrastructure and application health indicators.

18.2 Log Protection

Logs that MAY contain personal information MUST be protected against unauthorized access and SHOULD be retained according to defined schedules. Log content SHOULD be minimized and redacted where feasible to reduce exposure of credentials, tokens, and unnecessary personal information.

18.3 Monitoring and Alerting

Aventora SHOULD monitor production systems for anomalies indicative of security events or service degradation and SHOULD escalate suspected incidents in accordance with Section 21.

Centralized log aggregation and immutable archival MAY be implemented based on deployment scale and customer requirements.


19. Authentication and Authorization

19.1 Authentication Requirements

Strong authentication MUST be enforced for access to production systems and sensitive platform functions. Supported mechanisms include API keys, JWT-based sessions, OAuth integrations, and password-based authentication with stored password hashes.

19.2 Multi-Factor Authentication

MFA is required for privileged administrative access to Aventora production systems and administrative interfaces, including:

  • Cloud provider accounts (for example, AWS);
  • Source code and deployment platforms;
  • Production hosting and database administration; and
  • Administrative application access where MFA is supported and enabled.

Customers SHOULD enable MFA for their administrative users where the platform supports it.

19.3 Credential Management

Passwords and API keys MUST be stored using industry-standard hashing or tokenization appropriate to the credential type. API keys SHOULD be scoped to minimum permissions and rotated upon compromise or personnel change.


20. Secure Development Practices

Aventora MUST integrate privacy and security into the software development lifecycle.

20.1 Requirements

Development teams MUST:

  • Apply server-side input validation and authorization checks on sensitive routes;
  • Avoid logging secrets, credentials, or excessive personal information;
  • Use dependency management and vulnerability remediation processes;
  • Conduct code review for changes affecting authentication, authorization, or data handling; and
  • Document security-relevant configuration for new features.

20.2 Privacy by Design

New features SHOULD be assessed for personal information impact before release. Data fields SHOULD be justified against data minimization and purpose limitation principles.

20.3 Change Management

Material changes affecting personal information processing SHOULD follow Aventora’s change management practices, including testing, approval, and rollback planning. See the Application Change Management Policy.

20.4 Testing and Release

Security-relevant functionality SHOULD be tested before production release. Emergency changes MUST be documented and reviewed post-implementation.


21. Incident Response and Privacy Breach Management

21.1 Incident Response Program

Aventora MUST maintain procedures to detect, respond to, and recover from security and privacy incidents affecting personal information. Procedures SHOULD address:

PhaseActivities
Detection and reportingMonitoring, employee reporting channels, customer notifications of suspected issues
Triage and classificationSeverity assessment, identification of affected data and customers
ContainmentAccess revocation, credential rotation, service isolation as needed
InvestigationRoot cause analysis, evidence preservation, log review
NotificationCustomer notification and regulatory notification where required by law or contract
RecoveryRestoration of services, validation of control effectiveness
Post-incident reviewLessons learned, remediation tracking, policy updates

21.2 Privacy Breach Management

Where a privacy incident involves unauthorized access, disclosure, or loss of personal information, Aventora MUST:

  • Investigate promptly and document findings;
  • Notify affected Customers without undue delay where required by agreement or law;
  • Cooperate with Customers in fulfilling data subject and regulator notifications where Aventora acts as Processor; and
  • Implement corrective measures to reduce recurrence risk.

Notification timelines and content SHOULD align with applicable legal requirements (for example, GDPR 72-hour reporting to supervisory authorities where Aventora is Controller, or customer-directed timelines where Aventora is Processor).

21.3 Backup and Disaster Recovery

Backups and disaster recovery procedures MUST be maintained for production environments to support availability and recovery of personal information following operational failures or disasters.

Recovery objectives SHOULD be defined per deployment. Restoration procedures SHOULD be tested periodically. Backup retention MUST align with Section 14 and SHOULD protect backup confidentiality consistent with production controls.


22. Data Subject Rights

Data subjects MAY have rights under applicable privacy laws, which may include access, correction, deletion, restriction, portability, objection, withdrawal of consent, and the right to lodge a complaint with a supervisory authority or privacy regulator where applicable under local law.

22.1 Customer Data

For Customer Data, the Customer as Controller is primarily responsible for responding to data subject requests. Aventora MUST provide reasonable assistance to Customers in fulfilling such requests where technically feasible and as required by the customer agreement, including:

  • Accessing, exporting, correcting, or deleting data within the platform where functionality exists;
  • Identifying subprocessors relevant to the request; and
  • Implementing documented instructions from the Customer within agreed timelines.

22.2 Aventora Operational Data

Where Aventora is Controller, Aventora MUST establish a process to receive and respond to data subject requests in accordance with applicable law. Requests MAY be submitted to privacy@aventora.ai or through the contact channels in Section Contact.

22.3 Request Verification

Aventora SHOULD verify the identity of requestors and the authority of Customer personnel initiating requests before disclosing or modifying personal information.


23. Customer Responsibilities

Customers MUST fulfill responsibilities appropriate to their role as Controller (or equivalent) under applicable law, including:

ResponsibilityDescription
Lawful collectionEnsuring a lawful basis exists for personal information submitted to the platform
TransparencyProviding privacy notices to data subjects regarding use of the platform and enabled channels
ConfigurationManaging roles, permissions, integrations, and feature enablement consistent with privacy commitments
Data qualityMaintaining accurate data submitted to the platform
InstructionsProviding documented processing instructions where required by agreement
SecurityProtecting credentials, API keys, and endpoints under Customer control
Residency and transfersSpecifying residency and transfer requirements during contracting
Incident cooperationCooperating with Aventora during security and privacy incidents affecting Customer Data
Subprocessor reviewEvaluating Aventora subprocessors and enabled integrations as part of their vendor risk program

Customers MUST NOT submit personal information to the platform in violation of applicable law or in a manner inconsistent with Aventora’s acceptable use expectations.


24. Vendor and Subprocessor Management

Operational procedures, due-diligence and contract-review checklists, and the full set of Standard Vendor and Subprocessor Contractual Requirements are defined in the Vendor Management Policy. This section summarizes the privacy-policy requirements; in the event of conflict regarding vendor contracting detail, the Vendor Management Policy controls for vendor lifecycle procedures, and the executed vendor agreement controls for that vendor relationship.

24.1 Vendor Evaluation (Internal Aventora Procedure)

Vendors MUST be evaluated before use and monitored throughout the relationship. Before a vendor that will handle personal information is approved for production use, Aventora MUST complete the Vendor Due Diligence Checklist and Contract Review Checklist in the Vendor Management Policy. Evaluation MUST consider:

  • Security and privacy practices;
  • Data processing locations and international transfer safeguards;
  • Subcontracting and Further Subprocessor authorization practices;
  • Incident notification commitments;
  • Compliance with the Standard Vendor and Subprocessor Contractual Requirements; and
  • Business continuity capabilities.

24.2 Contractual Requirements (Obligations Imposed on Vendors)

Agreements with vendors and subprocessors that process personal information MUST include obligations appropriate to the sensitivity and volume of personal information processed. At a minimum, such agreements MUST require the vendor to:

  1. Comply with applicable privacy laws;
  2. Process personal information only on documented instructions and for the contracted purpose;
  3. Not sell or make unauthorized disclosures of personal information;
  4. Implement appropriate security safeguards;
  5. Provide security incident and breach notification without undue delay;
  6. Obtain Aventora’s prior written authorization before engaging a new Further Subprocessor where required by contract or applicable law (general written authorization via advance notice and opportunity to object is permitted);
  7. Flow down data protection obligations to Further Subprocessors that are no less protective than those owed to Aventora;
  8. Not attempt to re-identify de-identified, anonymized, aggregated, or pseudonymized data unless expressly authorized in writing by Aventora and permitted by applicable law;
  9. Promptly assist Aventora with data subject rights requests, including access, correction, deletion, restriction, portability, objection, and related requests, to the extent required by applicable privacy law;
  10. Not transfer personal information outside the agreed processing locations or jurisdictions without Aventora’s prior written approval, and where an international transfer is approved, implement all legally required safeguards (including Standard Contractual Clauses, transfer impact assessments, supplementary measures, or equivalent lawful transfer mechanisms);
  11. Return or securely destroy personal information upon termination or request; and
  12. Provide audit evidence and cooperation where applicable under the agreement or law.

The authoritative contract-ready wording of these requirements is set out in Section 6 of the Vendor Management Policy.

24.3 Ongoing Monitoring (Internal Aventora Procedure)

Aventora SHOULD periodically review subprocessors for continued suitability, including review of security documentation, incident notifications, and material changes to processing activities, locations, or Further Subprocessors.

Customers SHOULD be notified of material subprocessor changes in accordance with contractual terms and the Subprocessor Annex.


25. Security Awareness and Training

Aventora personnel with access to personal information or production systems MUST receive security and privacy awareness training appropriate to their role.

Training SHOULD cover:

  • This policy and related security standards;
  • Phishing and social engineering awareness;
  • Secure handling of Customer Data;
  • Incident reporting obligations;
  • Password, MFA, and secrets hygiene; and
  • Acceptable use of AI tools where relevant to customer data handling.

Training SHOULD be provided upon hire and refreshed at least annually or upon material policy changes.

Personnel MUST acknowledge confidentiality obligations as a condition of access to Customer Data.


26. Compliance with Applicable Privacy Laws

Aventora MUST process personal information in compliance with applicable privacy and data protection laws in jurisdictions where Aventora operates or where Customers direct processing, including where relevant:

FrameworkRelevance
PIPEDA (Canada)Personal information protection in commercial activities; accountability, consent, limiting collection, safeguards, openness, individual access
GDPR (EU)Processing of personal data of individuals in the EU; lawfulness, data subject rights, processor obligations, transfer mechanisms
UK GDPRUK equivalent requirements for personal data processing
U.S. state privacy lawsWhere applicable to Aventora’s operations or Customer configurations
Sector-specific regulationsWhere explicitly in scope under customer agreement (for example, HIPAA, PCI DSS) — Aventora makes no general claim of compliance with sector-specific frameworks unless explicitly agreed in writing

This policy SHOULD be interpreted alongside customer agreements, data processing addenda, and applicable law. Where conflicts arise, the stricter requirement applicable to the processing activity SHOULD prevail unless prohibited by law.

Aventora SHOULD maintain readiness to support future formal assurance initiatives (for example, SOC 2 or ISO 27001) through documented controls and evidence collection, without representing that certification has been achieved unless explicitly stated in a valid attestation report.


27. Policy Exceptions

Exceptions to this policy MAY be granted only where:

  • A legitimate business or technical requirement exists;
  • Compensating controls are documented;
  • The exception is approved in writing by Aventora Security or designated authority;
  • The exception is time-bound and reviewed at least annually; and
  • Material customer-facing exceptions are disclosed or agreed with affected Customers where required by contract.

Exception records SHOULD include the control waived, justification, approver, effective dates, and remediation plan if applicable.


28. Policy Review

Aventora Security MUST review this policy at least annually and upon material changes to:

  • Product architecture or data flows;
  • Hosting regions, subprocessors, or transfer practices;
  • Applicable privacy laws or regulatory guidance;
  • Significant security or privacy incidents; or
  • Customer contractual obligations affecting privacy requirements.

Review outcomes SHOULD be documented, including approved revisions, open remediation items, and assigned owners.


29. Version History

VersionDateAuthor / OwnerSummary of Changes
1.3.1July 27, 2026Aventora SecurityLinked Information Security Risk Management Policy and Risk Assessment and Treatment Procedure
1.3July 20, 2026Aventora SecurityExpanded Section 24 with standard vendor/subprocessor contractual requirements (re-identification prohibition, Further Subprocessor authorization, data subject rights assistance, international transfer controls); linked Vendor Management Policy as authoritative source for checklists and contract-ready wording
1.2July 6, 2026Aventora SecurityAdded standardized legal entity address; expanded data subject rights to include complaint process
1.1July 6, 2026Aventora SecurityClarified deployment models and data residency; strengthened subprocessor annex reference; added privacy contact and Last Reviewed date
1.0July 6, 2026Aventora SecurityInitial release of Personal Data Privacy & Protection Policy; linked executive summary, subprocessor annex, and DPA appendix


Contact

PurposeContact
Legal entityAventora Inc.
AddressToronto, Ontario, Canada
Privacy inquiries and data subject requests (where Aventora is Controller)privacy@aventora.ai
Security assessments and subprocessor informationsecurity@aventora.ai or your designated account representative
Contracted servicesContact channels specified in your services agreement

For Customer Data where the Customer is Controller, data subject requests SHOULD be directed to the Customer; Aventora SHOULD assist Customers as described in Section 22.


This document is provided for informational and contractual support purposes. It does not constitute legal advice. Customers should consult qualified legal counsel regarding their obligations under applicable privacy laws.