Privacy Policy

Last updated: [DATE] · Draft for legal review — not yet finalised
This is a starting draft, written to be legally reasonable and GDPR-aware — it is not a substitute for review by a qualified lawyer before publishing. Every bracketed [PLACEHOLDER] must be filled in before this goes live, and the whole document should be checked against your actual data flows before publication.

1. Who we are

Avercentris ("we", "us", "our") provides an AI-assisted customer operations platform for businesses. This policy explains how we collect, use, and protect personal data when you visit our website, use our platform, or interact with an AI assistant powered by Avercentris on one of our customers' websites.

Data controller: Avercentris, [LEGAL ENTITY NAME], [REGISTERED ADDRESS], Ireland. Contact: info@avercentris.com.

2. Two roles: when we're the controller, and when we're the processor

This distinction matters and applies differently depending on how you're interacting with us:

If you're a visitor chatting with an AI assistant on one of our customers' websites, that business's own privacy policy governs how your data is used — this page describes how Avercentris, as their processor, handles it on their behalf.

3. What data we collect

CategoryExamples
Contact dataName, email address, phone number
Conversation dataMessages sent to the AI assistant or a human agent, timestamps
Technical dataIP address, browser type, device information
Account data (our own customers)Billing details, login credentials, usage and configuration data

4. Why we process this data (legal basis)

5. AI processing — what you should know

When you interact with an Avercentris-powered assistant, your message is processed by an AI language model to generate a response. We use third-party AI infrastructure providers (see Section 6) to do this. Conversations are grounded in a knowledge base configured by the business you're speaking with — the AI does not have general internet access and is instructed not to invent information outside that knowledge base.

You are always entitled to know you're speaking with an AI system, and to request a human at any point in the conversation.

If you send a file through the chat, it's automatically checked for security threats — such as embedded malicious code — before it's added to the conversation. Files that don't pass this check are rejected rather than stored or shared.

6. Who else sees this data (sub-processors)

We use the following categories of sub-processor to operate the platform. An up-to-date, named list is available on request at info@avercentris.com.

PurposeProvider (example)Location
AI language model inference[OpenRouter / underlying model providers]USA — DPF-certified or SCCs in place
Text embeddings for knowledge retrieval[OpenAI]USA — DPF-certified or SCCs in place
Email delivery[Mailgun][EU/USA — confirm]
Hosting & infrastructure[Hostinger][Confirm data centre region]
Internal team notifications[Telegram][Confirm — Telegram's data handling should be reviewed separately]

Where a sub-processor is located outside the EEA, we rely on the EU–US Data Privacy Framework where the provider is certified, or Standard Contractual Clauses where it is not. [This section must be verified against each provider's current certification status before publishing — these change over time.]

7. How long we keep data

[PLACEHOLDER — define retention periods, e.g.: Conversation data is retained for 12 months after the last interaction, then automatically deleted, unless a longer period is required by the business we're processing data for, or by law. Account data for our own customers is retained for the duration of the contract plus [X] years for accounting/legal purposes.]

8. Your rights

Under GDPR, you have the right to:

To exercise any of these rights, contact info@avercentris.com. If your request concerns a conversation with a specific business using our platform, we may need to direct you to that business first, since they are the data controller for that conversation.

9. Security

[PLACEHOLDER — briefly describe technical/organisational measures once finalised: encryption in transit, access controls, API key rotation policy, etc.]

10. Changes to this policy

We may update this policy from time to time. Material changes will be noted on this page with an updated "last updated" date.

11. Contact

Questions about this policy or how your data is handled: info@avercentris.com