[bracket] before publishing at avowa.ai/privacy, then remove this banner.[Avowa legal entity] ("Avowa", "we") provides an AI-trust assurance platform. We are the controller of the personal data described here. Our Data Protection Officer / privacy lead can be reached at privacy@avowa.ai or [postal address]. [If applicable: our EU/UK representative is [name/contact].]
| Who | What |
|---|---|
| Account users | Name, work email, role, authentication data (stored hashed), and audit logs of activity in the platform. |
| Prospects & website visitors | Name, work email, company, role; demo/contact requests; website and usage analytics. |
| Customer-uploaded content | Where a customer uploads documents or connects systems, we process the resulting metadata as a processor — by design we read configuration and metadata, not our customers' end-customer content or source code. |
We do not seek special-category (sensitive) personal data and ask customers not to upload it.
| Purpose | Lawful basis (GDPR) |
|---|---|
| Providing and administering the service | Performance of a contract |
| Security, fraud prevention, audit logging | Legitimate interests; legal obligation |
| Sales outreach and marketing | Legitimate interests or consent (by channel/region) |
| Support and communications | Contract; legitimate interests |
| Complying with law | Legal obligation |
We operate a US ⇄ India delivery model and use providers in the United States, so your data may be transferred internationally. Where we transfer personal data from the EEA, UK, or Switzerland to a country without an adequacy decision, we rely on the Standard Contractual Clauses (with the UK Addendum / Swiss amendments as applicable) and appropriate supplementary measures. India transfers are handled in line with the DPDPA. You can request a copy of the relevant safeguards at privacy@avowa.ai.
We keep personal data only as long as needed for the purposes above: account data for the life of the account plus [X] days; prospect/marketing data for [e.g. 24 months] from last engagement; and as otherwise required by law. Backups are overwritten on a rolling [X]-day cycle.
Depending on where you are, you may have the right to access, correct, delete, restrict or object to processing, data portability, and to withdraw consent (GDPR/UK GDPR). Under India's DPDPA you may access, correct, and erase your data and raise a grievance. Under the CCPA/CPRA (California) you may know, delete, and correct your data and opt out of sale/sharing — though we do not sell or share it.
To exercise a right, email privacy@avowa.ai. We'll respond within the time the law allows (generally one month under GDPR). If your data is held because a customer uses Avowa to assess a vendor, we'll route your request to that customer as the controller and assist them.
Please contact us first at privacy@avowa.ai. You also have the right to complain to a supervisory authority — in the EEA, your local Data Protection Authority; in the UK, the ICO; in India, the Data Protection Board.
We may update this notice; we'll post the new version here with a revised effective date and, where appropriate, notify you. This version is effective [DATE].