Aventora Personal Data Privacy & Protection Policy
| Field | Value |
|---|---|
| Document Name | Personal Data Privacy & Protection Policy |
| Version | 1.3 |
| Effective Date | July 20, 2026 |
| Last Reviewed | July 20, 2026 |
| Owner | Aventora Security |
| Review Frequency | Annually |
| Classification | Internal / Customer Shareable |
| Approval Status | Approved for publication — see Version History |
Document Control
This policy establishes Aventora Inc. (“Aventora,” “we,” “us,” or “our”) requirements for the collection, use, disclosure, retention, protection, and disposal of personal information processed in connection with the Aventora platform and related services.
This document is intended for enterprise customers, security assessors, privacy officers, and Aventora personnel. It supports security and privacy reviews and aligns with common control themes relevant to future compliance initiatives (for example, SOC 2, ISO 27001, PIPEDA, GDPR, and UK GDPR). Aventora does not claim formal certification or attestation under any specific privacy or security framework based on this document alone. Implementation details may vary by deployment model, contractual terms, and enabled product features.
RFC 2119 Terminology
The key words “MUST,” “MUST NOT,” “REQUIRED,” “SHALL,” “SHALL NOT,” “SHOULD,” “SHOULD NOT,” “RECOMMENDED,” “MAY,” and “OPTIONAL” in this document are to be interpreted as described in RFC 2119.
Table of Contents
- Purpose
- Scope
- Definitions
- Roles and Responsibilities
- Privacy Principles
- Categories of Personal Information Processed
- Sensitive Personal Information
- Lawful Basis for Processing
- Collection of Personal Information
- Use of Personal Information
- Disclosure to Third Parties and Subprocessors
- International Data Transfers
- Data Residency
- Data Retention
- Secure Data Disposal
- Access Control
- Encryption Requirements
- Logging and Monitoring
- Authentication and Authorization
- Secure Development Practices
- Incident Response and Privacy Breach Management
- Data Subject Rights
- Customer Responsibilities
- Vendor and Subprocessor Management
- Security Awareness and Training
- Compliance with Applicable Privacy Laws
- Policy Exceptions
- Policy Review
- Version History
1. Purpose
The purpose of this Personal Data Privacy & Protection Policy is to define Aventora’s organizational commitments and operational requirements for protecting personal information throughout its lifecycle.
Aventora operates an AI-powered customer engagement platform that enables organizations to manage communications and customer interactions across channels such as voice, SMS, email, chat, and related administrative workflows. In delivering these services, Aventora processes personal information on behalf of customers and, in limited circumstances, in connection with Aventora’s own business operations.
This policy:
- Establishes privacy-by-design and security-by-design expectations for Aventora products, infrastructure, and operations;
- Defines roles, responsibilities, and minimum controls for protecting personal information;
- Provides a reference for enterprise security and privacy assessments;
- Supports alignment with applicable privacy legislation and common enterprise control frameworks without asserting certification status; and
- Communicates Aventora’s commitment that customer data is never sold and is processed only for the purposes defined by the applicable customer agreement.
2. Scope
2.1 In Scope
This policy applies to:
| Area | Description |
|---|---|
| Aventora platform services | Engagement Hub, Domain Assistant, Aventora CRM, administrative applications, mobile clients, and supporting integrations |
| Personal information processed on behalf of customers | Data submitted to, generated by, or stored within Aventora-managed environments in connection with contracted services |
| Aventora personnel | Employees, contractors, and authorized agents who access Aventora systems or customer data in the course of their duties |
| Infrastructure and hosting | Cloud and hosted environments used to operate Aventora services, including Amazon Web Services (AWS) and associated managed components |
| Third-party subprocessors | Vendors engaged by Aventora to support platform delivery, where such vendors process personal information on Aventora’s behalf |
| Development and operations | Software development, deployment, monitoring, support, backup, disaster recovery, and vendor management activities that involve personal information |
2.2 Out of Scope
Unless explicitly addressed in a written agreement, the following remain outside the scope of this policy:
- Customer-managed systems, networks, and data stores not operated by or on behalf of Aventora;
- Personal information processed by customers independently of the Aventora platform;
- Third-party services configured or operated directly by the customer outside Aventora’s control; and
- Personal information processed by Aventora for purposes unrelated to the delivery of contracted services (for example, Aventora marketing website visitors), which may be governed by separate notices and policies.
2.3 Deployment Models
This policy applies across Aventora-managed cloud deployments, customer-managed and self-hosted deployments, and hybrid configurations. Residency and hosting details for each model are described in Section 13. Customer-specific security and privacy requirements MAY be incorporated during deployment where agreed in writing. Variations from default controls MUST be documented and approved through Aventora’s exception process (see Section 27).
3. Definitions
For the purposes of this policy, the following definitions apply:
| Term | Definition |
|---|---|
| Personal Information | Information about an identified or identifiable natural person. This includes direct identifiers (for example, name, email address, telephone number) and indirect identifiers that can reasonably be linked to an individual. |
| Sensitive Personal Information | A subset of personal information that may be subject to heightened legal or contractual protection, such as government identifiers, financial account details, precise geolocation, health-related information, biometric data, or other categories defined by applicable law or customer agreement. |
| Customer | An organization that has entered into a services agreement with Aventora for use of the platform. |
| Customer Data | Personal information and other data submitted to or processed within the Aventora platform on behalf of a Customer. |
| Data Subject | The natural person to whom personal information relates. |
| Processing | Any operation performed on personal information, including collection, recording, organization, storage, adaptation, retrieval, consultation, use, disclosure, transmission, alignment, restriction, erasure, or destruction. |
| Controller | The entity that determines the purposes and means of processing personal information. Customers are typically Controllers with respect to Customer Data. |
| Processor | The entity that processes personal information on behalf of a Controller. Aventora acts as a Processor with respect to Customer Data, except where Aventora determines purposes and means independently. |
| Subprocessor | A third party engaged by Aventora to process personal information on Aventora’s behalf in connection with the services. |
| Authorized User | An individual permitted by the Customer or Aventora to access the platform or related systems in accordance with assigned roles and permissions. |
| Privileged Access | Administrative or elevated access to production systems, infrastructure, databases, secrets, or customer environments. |
| Data Residency | The geographic region or jurisdiction where Customer Data is stored and primarily processed. |
| Privacy Incident | An event that compromises or is reasonably suspected to compromise the confidentiality, integrity, or availability of personal information, or that otherwise violates this policy or applicable law. |
| Data Minimization | The practice of limiting personal information collection, retention, and processing to what is necessary for specified purposes. |
4. Roles and Responsibilities
Aventora assigns privacy and security responsibilities across organizational functions. Specific named roles MAY vary by organization size and deployment context; however, the accountability structures below MUST be maintained.
4.1 Executive Leadership
- Approves this policy and material amendments;
- Ensures adequate resources for privacy and security program activities;
- Reviews significant privacy incidents and remediation outcomes; and
- Supports alignment with customer contractual and regulatory obligations.
4.2 Aventora Security (Policy Owner)
- Owns, maintains, and publishes this policy;
- Coordinates privacy and security control implementation across product and operations teams;
- Manages policy exceptions and tracks remediation;
- Supports customer security and privacy assessments; and
- Conducts or coordinates the annual policy review.
4.3 Engineering and Product Teams
- Implement privacy-by-design and security-by-design controls in platform components;
- Apply data minimization in product features and integrations;
- Follow secure development practices (see Section 20);
- Document data flows for new features involving personal information; and
- Remediate identified privacy and security gaps within agreed timelines.
4.4 Operations and Infrastructure Teams
- Operate hosting environments in accordance with this policy;
- Implement access controls, encryption, logging, backup, and disaster recovery procedures;
- Manage subprocessors and infrastructure configurations used in production;
- Respond to operational incidents affecting personal information; and
- Maintain deployment documentation reflecting customer-specific requirements where applicable.
4.5 Customer Success and Support
- Handle customer inquiries related to privacy, data subject requests, and incident notifications in coordination with Security and Legal;
- Ensure support personnel access Customer Data only when necessary and authorized; and
- Escalate suspected privacy incidents promptly.
4.6 Customers (Controller Responsibilities)
Customers retain responsibility for determining lawful bases, providing required notices, managing end-user consents where applicable, configuring platform permissions, and fulfilling data subject rights requests for Customer Data, subject to Aventora’s assistance obligations under applicable agreements. See Section 23.
5. Privacy Principles
Aventora adopts the following privacy principles as foundational requirements for all processing of personal information within scope of this policy. These principles align with widely recognized privacy frameworks and support future alignment with regulations such as PIPEDA, GDPR, and UK GDPR.
5.1 Lawfulness
Aventora MUST process personal information on a lawful basis appropriate to the processing context. For Customer Data, processing MUST be limited to purposes authorized by the applicable customer agreement and the Customer’s documented instructions, except where applicable law requires otherwise.
Aventora personnel MUST NOT use Customer Data for unrelated purposes, including marketing to Customer end users, model training on Customer Data unless explicitly agreed, or any commercial exploitation of Customer Data. Customer data is never sold.
5.2 Fairness
Processing MUST be conducted in a manner that is fair to data subjects and Customers. Aventora SHOULD avoid processing that is unexpected, unduly intrusive, or disproportionate to the stated purpose.
Where AI-powered features are enabled, Aventora SHOULD ensure that automated processing supports Customer-configured workflows and does not expand data use beyond contracted service purposes.
5.3 Transparency
Aventora MUST maintain accurate descriptions of its processing activities suitable for customer review, including categories of data processed, subprocessors used, and data residency options.
Customers SHOULD provide their own privacy notices to data subjects regarding their use of the Aventora platform. Aventora SHOULD make available information necessary for Customers to meet transparency obligations, including subprocessor disclosures and security documentation upon request or as contractually required.
5.4 Data Minimization
Aventora MUST process only the minimum customer data necessary to provide the contracted service. Product and engineering teams SHOULD design features to avoid unnecessary collection of personal information and SHOULD prefer pseudonymization or aggregation where full identifiers are not required.
Integration configurations MUST limit data exchange to fields required for the enabled feature. Aventora MUST NOT access customer systems beyond the permissions explicitly granted by the customer.
5.5 Purpose Limitation
Personal information MUST be collected and used for specified, explicit, and legitimate purposes consistent with the customer agreement and MUST NOT be further processed in a manner incompatible with those purposes.
Changes to processing purposes that materially affect Customer Data MUST be communicated to affected Customers and implemented only where permitted by contract and applicable law.
5.6 Accuracy
Aventora SHOULD take reasonable steps to maintain accurate personal information where Aventora is responsible for data entry or synchronization, and SHOULD enable Customers to review, correct, or delete Customer Data through platform functionality where available.
Customers remain responsible for the accuracy of data they submit or configure within the platform.
5.7 Storage Limitation
Personal information MUST NOT be retained longer than necessary for the purposes for which it was processed, unless a longer retention period is required or permitted by law or contract. Retention schedules MUST be defined and applied consistently (see Section 14).
5.8 Integrity and Confidentiality
Aventora MUST implement appropriate technical and organizational measures to protect personal information against unauthorized or unlawful processing and against accidental loss, destruction, or damage.
These measures include access controls, encryption in transit, logging and monitoring, secure development practices, vendor management, and incident response procedures described in this policy.
5.9 Accountability
Aventora MUST demonstrate compliance with this policy through documented controls, assigned ownership, periodic review, and remediation of identified gaps.
Privacy and security obligations MUST be reflected in contracts with Customers, personnel, and subprocessors where applicable.
6. Categories of Personal Information Processed
The categories of personal information processed by Aventora depend on enabled product features, customer configuration, and integrations. The table below describes common categories. This list is illustrative and not exhaustive.
| Category | Examples | Typical Source |
|---|---|---|
| Identity and contact information | Name, email address, telephone number, job title, organization name | Customer upload, CRM sync, web forms, chat intake, email intake |
| Account and authentication data | Usernames, role assignments, password hashes, session tokens, API key metadata | Customer administrators, Authorized Users, platform authentication services |
| Communication content and metadata | Message body, call recordings or transcripts where enabled, SMS content, email headers, timestamps, channel identifiers | Engagement workflows, telephony providers, messaging integrations |
| Interaction and engagement data | Conversation history, engagement status, routing decisions, AI-generated summaries or responses where enabled | Platform processing during customer interactions |
| Technical and usage data | IP addresses, device or browser identifiers, API request metadata, error logs | Platform operations, security monitoring, support diagnostics |
| Calendar and scheduling data | Appointment details, availability, meeting links where calendar integrations are enabled | OAuth-connected calendar providers (for example, Google, Microsoft) |
| Configuration and business metadata | Tenant settings, workflow rules, template content, domain configuration | Customer administrators |
| Billing and commercial data | Account identifiers, subscription tier, usage metrics (typically organization-level) | Aventora commercial systems |
Aventora SHOULD maintain an internal data inventory mapping product components and data stores to these categories to support privacy impact assessments and customer inquiries.
7. Sensitive Personal Information
7.1 Definition and Handling
Sensitive personal information SHOULD NOT be collected or processed through the Aventora platform unless required for a contracted feature and permitted by the customer agreement and applicable law.
Where sensitive personal information is processed:
- Processing MUST be limited to the minimum necessary for the enabled function;
- Access MUST be restricted through role-based access control and least privilege;
- Additional safeguards SHOULD be applied where required by law or customer contract (for example, enhanced encryption, restricted subprocessors, or regional residency);
- Personnel access MUST be logged and limited to authorized support or engineering activities; and
- Customers SHOULD classify data appropriately in their own policies and configure integrations to avoid transmitting sensitive categories not required for the service.
7.2 Prohibited Uses
Unless explicitly agreed in writing and permitted by law, Aventora MUST NOT:
- Use Customer Data to train general-purpose AI models for unrelated commercial purposes;
- Sell, rent, or license Customer Data to third parties; or
- Combine Customer Data across customers for profiling or marketing purposes.
7.3 Customer Determination of Sensitivity
Customers are responsible for determining whether data they submit qualifies as sensitive under applicable law (for example, health information, financial data, or children’s data) and for ensuring that their use of the platform complies with restrictions applicable to such data.
8. Lawful Basis for Processing
8.1 Customer Data
For Customer Data, Aventora generally processes personal information as a Processor acting on documented instructions from the Customer (Controller). The lawful basis for processing is determined by the Customer in accordance with applicable law. Aventora MUST process Customer Data only as necessary to:
- Provide, maintain, and support the contracted services;
- Implement security, fraud prevention, and abuse detection controls;
- Comply with applicable legal obligations; and
- Perform other processing explicitly authorized in the customer agreement or documented instructions.
8.2 Aventora Operational Data
Where Aventora acts as a Controller (for example, processing contact information of Customer personnel for account management or billing), Aventora MUST identify and document an appropriate lawful basis under applicable law, such as contract performance, legitimate interests, consent, or legal obligation.
8.3 Special Categories and Consent
Where processing of special categories of personal information is in scope, Customers MUST ensure an appropriate lawful basis exists under applicable law. Aventora SHOULD assist Customers in configuring the platform to support consent or restriction requirements where technically feasible and contractually agreed.
9. Collection of Personal Information
9.1 Collection Methods
Personal information MAY be collected through:
- Direct submission by Customers or Authorized Users via administrative interfaces;
- End-user interactions with customer-configured channels (voice, SMS, email, chat, web forms);
- Synchronized data from customer-connected systems (for example, CRM records, calendar events);
- Automated intake workflows (for example, email polling, webhook receivers, API integrations); and
- Operational telemetry generated during platform use.
9.2 Collection Limitations
Aventora MUST configure default product behavior to support data minimization. Engineering teams SHOULD:
- Require explicit customer configuration before enabling integrations that expand data collection;
- Avoid collecting fields not needed for the enabled workflow;
- Document data fields collected by each integration; and
- Provide Customers with configuration options to limit retention and visibility where feasible.
9.3 Customer-Controlled Collection
Customers MUST ensure that their collection of personal information from data subjects complies with applicable notice and consent requirements. Aventora MUST NOT access customer-owned systems or data repositories beyond permissions explicitly granted by the Customer.
10. Use of Personal Information
10.1 Permitted Uses
Personal information MUST be used only for purposes consistent with this policy and the applicable customer agreement, including:
| Purpose | Description |
|---|---|
| Service delivery | Operating engagement workflows, AI-assisted responses where enabled, routing, notifications, and reporting |
| Platform administration | Account provisioning, authentication, authorization, configuration, and support |
| Security and integrity | Detecting abuse, investigating incidents, maintaining audit logs, and enforcing access controls |
| Improvement and reliability | Debugging, performance monitoring, and service improvement using aggregated or de-identified data where possible |
| Legal compliance | Responding to lawful requests and meeting regulatory obligations |
10.2 AI-Powered Processing
Where AI features are enabled (for example, natural language understanding, summarization, or automated response generation), personal information MAY be transmitted to AI subprocessors only as necessary to perform the customer-configured function. AI processing MUST remain within the scope of the contracted service and MUST NOT expand to unrelated purposes.
Customers SHOULD review enabled AI features and subprocessors as part of their own privacy assessments.
10.3 Personnel Access
Aventora personnel MAY access Customer Data only when:
- Access is necessary to provide support, perform maintenance, or investigate a security or operational issue;
- Access is authorized by the Customer where required by agreement;
- Access follows least privilege and is logged where technically feasible; and
- Personnel are bound by confidentiality obligations.
Routine browsing of Customer Data MUST NOT occur.
11. Disclosure to Third Parties and Subprocessors
11.1 General Requirements
Aventora MUST NOT disclose Customer Data to third parties except:
- To subprocessors engaged to support delivery of the services, subject to contractual protections;
- To integration providers enabled by the Customer;
- Where required by applicable law or valid legal process; or
- With the Customer’s documented authorization.
Customer data is never sold. Disclosure for advertising, data brokerage, or unrelated commercial purposes MUST NOT occur.
11.2 Subprocessors
Aventora uses third-party subprocessors to provide infrastructure and optional features. Subprocessors process personal information only as directed by Aventora and in accordance with written agreements requiring appropriate security and confidentiality obligations.
Depending on enabled features and deployment configuration, subprocessors MAY include:
| Subprocessor | Typical Processing Activity |
|---|---|
| Amazon Web Services (AWS) | Cloud hosting, compute, storage, networking, backup infrastructure |
| OpenAI | AI language model inference for enabled conversational features |
| Twilio | Telephony, SMS, and related communication delivery |
| Calendar integration, identity, or communication services where enabled | |
| Microsoft | Calendar integration, identity, or communication services where enabled |
Additional feature-dependent subprocessors (for example, alternative telephony, speech synthesis, or alternate AI inference providers) MAY apply depending on enabled product features and deployment configuration. The authoritative, deployment-specific subprocessor list is maintained in the Subprocessor Annex and SHOULD be reviewed as part of customer privacy assessments.
11.3 Customer-Enabled Integrations
Where Customers configure integrations with third-party systems, data MAY be disclosed to those providers according to Customer instructions and the integration’s technical design. Such disclosures are directed by the Customer; Customers remain responsible for their relationship with those third parties.
11.4 Legal Disclosure
If Aventora receives a request from law enforcement or other authority for Customer Data, Aventora SHOULD redirect the request to the Customer where permitted and SHOULD notify the Customer unless prohibited by law. Aventora MUST disclose only the minimum information required by valid legal process.
12. International Data Transfers
Personal information MAY be transferred across borders where necessary to provide the services, including transfers to subprocessors or support personnel in jurisdictions other than the data subject’s country of residence.
Where required by applicable law (for example, GDPR Chapter V or UK GDPR transfer rules), Aventora SHOULD implement appropriate transfer mechanisms such as:
- Standard contractual clauses or equivalent contractual protections;
- Customer-approved deployment and residency configurations that limit transfers; or
- Other lawful transfer tools recognized under applicable law.
Customers SHOULD specify residency and transfer requirements during contracting. Aventora SHOULD document transfer locations relevant to each deployment.
13. Data Residency
Data residency depends on deployment model, contractual terms, and enabled product features. The table below distinguishes how personal information is stored and primarily processed.
13.1 Deployment Models and Residency
| Deployment model | Description | Typical data residency |
|---|---|---|
| Aventora-managed cloud (default) | Aventora-operated environments on Amazon Web Services (AWS) | AWS Canadian regions, unless otherwise agreed in writing |
| Aventora-managed cloud (alternate region) | Aventora-operated managed environments in a customer-selected or contractually agreed region (for example, United States) | As specified in the applicable agreement |
| Customer-managed / self-hosted / on-premises | Customer-operated infrastructure (for example, VPS, private cloud, or on-premises) using published deployment options | Determined by the customer’s infrastructure, configuration, and applicable law |
| Hybrid | Combination of Aventora-managed and customer-managed components as agreed in writing | As documented and approved for the specific deployment |
Unless otherwise agreed in writing, default Aventora-managed deployments use AWS Canadian regions to support data residency preferences for Canadian customers and alignment with PIPEDA expectations. Customer-specific security and privacy requirements, including residency, MAY be incorporated during deployment where documented and approved.
13.2 Subprocessor Locations
Even where compute and storage are located in a specified region, subprocessors used for enabled features (for example, AI inference or global telephony routing) MAY process data in other jurisdictions. Customers SHOULD evaluate enabled features against their residency requirements. See the Subprocessor Annex.
14. Data Retention
14.1 Retention Principles
Personal information MUST be retained only for as long as necessary to:
- Provide the contracted services;
- Meet legal, regulatory, or contractual obligations;
- Resolve disputes and enforce agreements; and
- Maintain security logs and backup integrity for defined periods.
14.2 Retention Schedules
Aventora SHOULD define and maintain retention schedules by data category and product component. Retention periods SHOULD consider:
- Customer-configured settings where available;
- Contractual minimums and maximums;
- Operational requirements (for example, backup rotation); and
- Applicable legal requirements.
Upon contract termination or Customer request, Aventora MUST delete or return Customer Data in accordance with the applicable agreement, subject to legal retention obligations and secure backup expiry cycles.
14.3 Legal Hold
Where litigation, investigation, or regulatory inquiry requires preservation of data, Aventora SHOULD suspend routine deletion for affected data sets upon direction by Aventora Security or Legal and SHOULD document the scope and duration of the hold.
15. Secure Data Disposal
When personal information is no longer required, Aventora MUST dispose of it securely.
15.1 Disposal Methods
Disposal SHOULD include one or more of the following, appropriate to the media and environment:
- Cryptographic erasure where encryption keys are destroyed;
- Secure deletion from active databases and application stores;
- Expiration and purging of backups according to defined retention cycles; and
- Secure destruction or wiping of physical media where applicable.
15.2 Subprocessor Disposal
Contracts with subprocessors SHOULD require return or deletion of personal information upon termination of the subprocessing relationship, except where retention is required by law.
15.3 Verification
Aventora SHOULD periodically verify that deletion routines and backup expiry processes operate as intended and SHOULD maintain records of deletion upon customer offboarding where contractually required.
16. Access Control
Access to systems and personal information MUST be restricted based on business need and assigned responsibilities.
16.1 Role-Based Access Control
Aventora MUST apply role-based access control (RBAC) across platform and administrative systems. Permissions MUST be assigned according to job function and MUST be reviewed periodically.
Platform authorization MUST enforce server-side access decisions. Client applications MUST NOT be relied upon as the sole enforcement mechanism.
16.2 Least Privilege
The principle of least privilege MUST be applied to:
- Production infrastructure and databases;
- Administrative consoles and deployment tools;
- API keys, service accounts, and integration credentials; and
- Support and engineering access to Customer Data.
Default-deny access models SHOULD be used where feasible.
16.3 Access Reviews
Aventora SHOULD conduct periodic reviews of privileged accounts, production access, and outstanding authorization grants. Access MUST be revoked promptly upon role change or termination.
16.4 Customer Access Control
Customers MUST manage Authorized User accounts, roles, and integration permissions within their tenant. Customers SHOULD disable unused accounts and apply MFA for administrative users where supported.
17. Encryption Requirements
17.1 Encryption in Transit
Encryption MUST be used for data in transit. Production API, administrative, and customer-facing traffic MUST be protected using TLS (TLS 1.2 or higher). Connections to databases, subprocessors, and integration endpoints SHOULD use encrypted channels where supported by the provider.
Unencrypted transmission of personal information over public networks in production environments MUST NOT occur.
17.2 Encryption at Rest
Aventora SHOULD enable encryption at rest for production data stores using provider-supported mechanisms (for example, AWS volume and database encryption). Application-level encryption SHOULD be applied to highly sensitive fields where warranted by risk assessment or customer requirements.
Encryption key management SHOULD follow provider best practices and SHOULD restrict key access to authorized personnel and services.
17.3 Secrets Management
API keys, passwords, tokens, and other secrets MUST NOT be stored in plaintext in source code or unsecured configuration repositories. Secrets MUST be supplied through secure configuration mechanisms appropriate to the deployment environment.
18. Logging and Monitoring
18.1 Logging Requirements
Logging and monitoring MUST be implemented for production environments to support security, operational reliability, and incident investigation.
Logs SHOULD capture relevant security events, including:
- Authentication successes and failures;
- Authorization denials;
- Administrative actions;
- Integration and API errors affecting data processing; and
- Infrastructure and application health indicators.
18.2 Log Protection
Logs that MAY contain personal information MUST be protected against unauthorized access and SHOULD be retained according to defined schedules. Log content SHOULD be minimized and redacted where feasible to reduce exposure of credentials, tokens, and unnecessary personal information.
18.3 Monitoring and Alerting
Aventora SHOULD monitor production systems for anomalies indicative of security events or service degradation and SHOULD escalate suspected incidents in accordance with Section 21.
Centralized log aggregation and immutable archival MAY be implemented based on deployment scale and customer requirements.
19. Authentication and Authorization
19.1 Authentication Requirements
Strong authentication MUST be enforced for access to production systems and sensitive platform functions. Supported mechanisms include API keys, JWT-based sessions, OAuth integrations, and password-based authentication with stored password hashes.
19.2 Multi-Factor Authentication
MFA is required for privileged administrative access to Aventora production systems and administrative interfaces, including:
- Cloud provider accounts (for example, AWS);
- Source code and deployment platforms;
- Production hosting and database administration; and
- Administrative application access where MFA is supported and enabled.
Customers SHOULD enable MFA for their administrative users where the platform supports it.
19.3 Credential Management
Passwords and API keys MUST be stored using industry-standard hashing or tokenization appropriate to the credential type. API keys SHOULD be scoped to minimum permissions and rotated upon compromise or personnel change.
20. Secure Development Practices
Aventora MUST integrate privacy and security into the software development lifecycle.
20.1 Requirements
Development teams MUST:
- Apply server-side input validation and authorization checks on sensitive routes;
- Avoid logging secrets, credentials, or excessive personal information;
- Use dependency management and vulnerability remediation processes;
- Conduct code review for changes affecting authentication, authorization, or data handling; and
- Document security-relevant configuration for new features.
20.2 Privacy by Design
New features SHOULD be assessed for personal information impact before release. Data fields SHOULD be justified against data minimization and purpose limitation principles.
20.3 Change Management
Material changes affecting personal information processing SHOULD follow Aventora’s change management practices, including testing, approval, and rollback planning. See the Application Change Management Policy.
20.4 Testing and Release
Security-relevant functionality SHOULD be tested before production release. Emergency changes MUST be documented and reviewed post-implementation.
21. Incident Response and Privacy Breach Management
21.1 Incident Response Program
Aventora MUST maintain procedures to detect, respond to, and recover from security and privacy incidents affecting personal information. Procedures SHOULD address:
| Phase | Activities |
|---|---|
| Detection and reporting | Monitoring, employee reporting channels, customer notifications of suspected issues |
| Triage and classification | Severity assessment, identification of affected data and customers |
| Containment | Access revocation, credential rotation, service isolation as needed |
| Investigation | Root cause analysis, evidence preservation, log review |
| Notification | Customer notification and regulatory notification where required by law or contract |
| Recovery | Restoration of services, validation of control effectiveness |
| Post-incident review | Lessons learned, remediation tracking, policy updates |
21.2 Privacy Breach Management
Where a privacy incident involves unauthorized access, disclosure, or loss of personal information, Aventora MUST:
- Investigate promptly and document findings;
- Notify affected Customers without undue delay where required by agreement or law;
- Cooperate with Customers in fulfilling data subject and regulator notifications where Aventora acts as Processor; and
- Implement corrective measures to reduce recurrence risk.
Notification timelines and content SHOULD align with applicable legal requirements (for example, GDPR 72-hour reporting to supervisory authorities where Aventora is Controller, or customer-directed timelines where Aventora is Processor).
21.3 Backup and Disaster Recovery
Backups and disaster recovery procedures MUST be maintained for production environments to support availability and recovery of personal information following operational failures or disasters.
Recovery objectives SHOULD be defined per deployment. Restoration procedures SHOULD be tested periodically. Backup retention MUST align with Section 14 and SHOULD protect backup confidentiality consistent with production controls.
22. Data Subject Rights
Data subjects MAY have rights under applicable privacy laws, which may include access, correction, deletion, restriction, portability, objection, withdrawal of consent, and the right to lodge a complaint with a supervisory authority or privacy regulator where applicable under local law.
22.1 Customer Data
For Customer Data, the Customer as Controller is primarily responsible for responding to data subject requests. Aventora MUST provide reasonable assistance to Customers in fulfilling such requests where technically feasible and as required by the customer agreement, including:
- Accessing, exporting, correcting, or deleting data within the platform where functionality exists;
- Identifying subprocessors relevant to the request; and
- Implementing documented instructions from the Customer within agreed timelines.
22.2 Aventora Operational Data
Where Aventora is Controller, Aventora MUST establish a process to receive and respond to data subject requests in accordance with applicable law. Requests MAY be submitted to privacy@aventora.ai or through the contact channels in Section Contact.
22.3 Request Verification
Aventora SHOULD verify the identity of requestors and the authority of Customer personnel initiating requests before disclosing or modifying personal information.
23. Customer Responsibilities
Customers MUST fulfill responsibilities appropriate to their role as Controller (or equivalent) under applicable law, including:
| Responsibility | Description |
|---|---|
| Lawful collection | Ensuring a lawful basis exists for personal information submitted to the platform |
| Transparency | Providing privacy notices to data subjects regarding use of the platform and enabled channels |
| Configuration | Managing roles, permissions, integrations, and feature enablement consistent with privacy commitments |
| Data quality | Maintaining accurate data submitted to the platform |
| Instructions | Providing documented processing instructions where required by agreement |
| Security | Protecting credentials, API keys, and endpoints under Customer control |
| Residency and transfers | Specifying residency and transfer requirements during contracting |
| Incident cooperation | Cooperating with Aventora during security and privacy incidents affecting Customer Data |
| Subprocessor review | Evaluating Aventora subprocessors and enabled integrations as part of their vendor risk program |
Customers MUST NOT submit personal information to the platform in violation of applicable law or in a manner inconsistent with Aventora’s acceptable use expectations.
24. Vendor and Subprocessor Management
Operational procedures, due-diligence and contract-review checklists, and the full set of Standard Vendor and Subprocessor Contractual Requirements are defined in the Vendor Management Policy. This section summarizes the privacy-policy requirements; in the event of conflict regarding vendor contracting detail, the Vendor Management Policy controls for vendor lifecycle procedures, and the executed vendor agreement controls for that vendor relationship.
24.1 Vendor Evaluation (Internal Aventora Procedure)
Vendors MUST be evaluated before use and monitored throughout the relationship. Before a vendor that will handle personal information is approved for production use, Aventora MUST complete the Vendor Due Diligence Checklist and Contract Review Checklist in the Vendor Management Policy. Evaluation MUST consider:
- Security and privacy practices;
- Data processing locations and international transfer safeguards;
- Subcontracting and Further Subprocessor authorization practices;
- Incident notification commitments;
- Compliance with the Standard Vendor and Subprocessor Contractual Requirements; and
- Business continuity capabilities.
24.2 Contractual Requirements (Obligations Imposed on Vendors)
Agreements with vendors and subprocessors that process personal information MUST include obligations appropriate to the sensitivity and volume of personal information processed. At a minimum, such agreements MUST require the vendor to:
- Comply with applicable privacy laws;
- Process personal information only on documented instructions and for the contracted purpose;
- Not sell or make unauthorized disclosures of personal information;
- Implement appropriate security safeguards;
- Provide security incident and breach notification without undue delay;
- Obtain Aventora’s prior written authorization before engaging a new Further Subprocessor where required by contract or applicable law (general written authorization via advance notice and opportunity to object is permitted);
- Flow down data protection obligations to Further Subprocessors that are no less protective than those owed to Aventora;
- Not attempt to re-identify de-identified, anonymized, aggregated, or pseudonymized data unless expressly authorized in writing by Aventora and permitted by applicable law;
- Promptly assist Aventora with data subject rights requests, including access, correction, deletion, restriction, portability, objection, and related requests, to the extent required by applicable privacy law;
- Not transfer personal information outside the agreed processing locations or jurisdictions without Aventora’s prior written approval, and where an international transfer is approved, implement all legally required safeguards (including Standard Contractual Clauses, transfer impact assessments, supplementary measures, or equivalent lawful transfer mechanisms);
- Return or securely destroy personal information upon termination or request; and
- Provide audit evidence and cooperation where applicable under the agreement or law.
The authoritative contract-ready wording of these requirements is set out in Section 6 of the Vendor Management Policy.
24.3 Ongoing Monitoring (Internal Aventora Procedure)
Aventora SHOULD periodically review subprocessors for continued suitability, including review of security documentation, incident notifications, and material changes to processing activities, locations, or Further Subprocessors.
Customers SHOULD be notified of material subprocessor changes in accordance with contractual terms and the Subprocessor Annex.
25. Security Awareness and Training
Aventora personnel with access to personal information or production systems MUST receive security and privacy awareness training appropriate to their role.
Training SHOULD cover:
- This policy and related security standards;
- Phishing and social engineering awareness;
- Secure handling of Customer Data;
- Incident reporting obligations;
- Password, MFA, and secrets hygiene; and
- Acceptable use of AI tools where relevant to customer data handling.
Training SHOULD be provided upon hire and refreshed at least annually or upon material policy changes.
Personnel MUST acknowledge confidentiality obligations as a condition of access to Customer Data.
26. Compliance with Applicable Privacy Laws
Aventora MUST process personal information in compliance with applicable privacy and data protection laws in jurisdictions where Aventora operates or where Customers direct processing, including where relevant:
| Framework | Relevance |
|---|---|
| PIPEDA (Canada) | Personal information protection in commercial activities; accountability, consent, limiting collection, safeguards, openness, individual access |
| GDPR (EU) | Processing of personal data of individuals in the EU; lawfulness, data subject rights, processor obligations, transfer mechanisms |
| UK GDPR | UK equivalent requirements for personal data processing |
| U.S. state privacy laws | Where applicable to Aventora’s operations or Customer configurations |
| Sector-specific regulations | Where explicitly in scope under customer agreement (for example, HIPAA, PCI DSS) — Aventora makes no general claim of compliance with sector-specific frameworks unless explicitly agreed in writing |
This policy SHOULD be interpreted alongside customer agreements, data processing addenda, and applicable law. Where conflicts arise, the stricter requirement applicable to the processing activity SHOULD prevail unless prohibited by law.
Aventora SHOULD maintain readiness to support future formal assurance initiatives (for example, SOC 2 or ISO 27001) through documented controls and evidence collection, without representing that certification has been achieved unless explicitly stated in a valid attestation report.
27. Policy Exceptions
Exceptions to this policy MAY be granted only where:
- A legitimate business or technical requirement exists;
- Compensating controls are documented;
- The exception is approved in writing by Aventora Security or designated authority;
- The exception is time-bound and reviewed at least annually; and
- Material customer-facing exceptions are disclosed or agreed with affected Customers where required by contract.
Exception records SHOULD include the control waived, justification, approver, effective dates, and remediation plan if applicable.
28. Policy Review
Aventora Security MUST review this policy at least annually and upon material changes to:
- Product architecture or data flows;
- Hosting regions, subprocessors, or transfer practices;
- Applicable privacy laws or regulatory guidance;
- Significant security or privacy incidents; or
- Customer contractual obligations affecting privacy requirements.
Review outcomes SHOULD be documented, including approved revisions, open remediation items, and assigned owners.
29. Version History
| Version | Date | Author / Owner | Summary of Changes |
|---|---|---|---|
| 1.3.1 | July 27, 2026 | Aventora Security | Linked Information Security Risk Management Policy and Risk Assessment and Treatment Procedure |
| 1.3 | July 20, 2026 | Aventora Security | Expanded Section 24 with standard vendor/subprocessor contractual requirements (re-identification prohibition, Further Subprocessor authorization, data subject rights assistance, international transfer controls); linked Vendor Management Policy as authoritative source for checklists and contract-ready wording |
| 1.2 | July 6, 2026 | Aventora Security | Added standardized legal entity address; expanded data subject rights to include complaint process |
| 1.1 | July 6, 2026 | Aventora Security | Clarified deployment models and data residency; strengthened subprocessor annex reference; added privacy contact and Last Reviewed date |
| 1.0 | July 6, 2026 | Aventora Security | Initial release of Personal Data Privacy & Protection Policy; linked executive summary, subprocessor annex, and DPA appendix |
Related Documents
- Customer Security Package
- Vendor Management Policy
- Information Security Risk Management Policy
- Risk Assessment and Treatment Procedure
- Data Classification and Handling Policy
- Privacy & Data Protection Executive Summary
- Subprocessor Annex
- Data Processing Addendum Appendix
- Security Overview
- API Security Policy
- Application Change Management Policy
- Data Retention
- Incident Response
- Compliance Mapping Notes
Contact
| Purpose | Contact |
|---|---|
| Legal entity | Aventora Inc. |
| Address | Toronto, Ontario, Canada |
| Privacy inquiries and data subject requests (where Aventora is Controller) | privacy@aventora.ai |
| Security assessments and subprocessor information | security@aventora.ai or your designated account representative |
| Contracted services | Contact channels specified in your services agreement |
For Customer Data where the Customer is Controller, data subject requests SHOULD be directed to the Customer; Aventora SHOULD assist Customers as described in Section 22.
This document is provided for informational and contractual support purposes. It does not constitute legal advice. Customers should consult qualified legal counsel regarding their obligations under applicable privacy laws.