This summary is provided for convenience and is not a substitute for the full Policy below. Where the summary and the Policy differ, the Policy controls.
Avtech AI (“Avtech,” “we,” “us,” or “our”) is a global technology and business consulting firm. We provide software engineering, project and program management, cloud and infrastructure, data cybersecurity, and digital transformation services to enterprise clients. This Privacy Policy (the “Policy”) describes how we collect, use, disclose, retain, and protect personal information, and how we handle the client data our clients entrust to us.
This Policy applies to:
Where we process data on behalf of a client, that processing is governed by the written agreement between us and that client, including any master services agreement, statement of work, or data processing addendum. If any term of this Policy conflicts with such an agreement, the agreement controls with respect to that client’s data.
This Policy does not apply to third-party software, platforms, or service providers that you or your organization use alongside our Services — including systems we may configure or operate on your behalf under your own vendor agreements. Those systems are governed by their own privacy policies and by your agreements with those vendors. See Section 18.
By using the Website or receiving the Services, you acknowledge that you have read and understood this Policy. If you do not agree with it, do not use the Website.
The following terms are used throughout this Policy. Capitalized terms not defined here have the meaning given to them in the applicable client agreement.
We collect the information you choose to give us. On the Website, that is limited to the following:
When you visit the Website, our hosting infrastructure records standard server log information as a technical necessity of delivering the page. This may include your IP address, browser type and version, operating system, referring URL, the pages and resources requested, and the date and time of the request. We use this information to serve the site, maintain security, diagnose faults, and detect abuse. We do not use it to build advertising or behavioral profiles.
Our forms include a hidden field that is invisible to human visitors and is used solely to identify automated submissions. It collects no information about you.
Delivering the Services requires access to client systems and data. The scope of that access is defined in the applicable statement of work and is limited to what the engagement requires. Depending on the engagement, it may include:
Some of this data is Personnel-Identifiable Information. Section 5 sets out the specific protections that apply to it.
We do not seek, and we ask that you do not send us, Social Security numbers, government identification numbers, financial account or payment card numbers, health information, precise consumer device geolocation, information about racial or ethnic origin, religious or philosophical beliefs, union membership, sexual orientation, immigration status, or genetic data.
Delivering the Services may nonetheless bring us into contact with systems that hold categories of data we do not seek — for example health records, financial account data, or government identifiers held by a Client. Where that occurs we process such data solely as a processor, on the Client’s documented instructions and under the applicable engagement agreement and data processing addendum. We retain it only as described in Section 11 and restrict access to it as described in Section 12.
To comply with legal obligations, respond to valid legal process, establish or defend legal claims, enforce our agreements, and maintain records required by law.
We may create De-Identified Data and Aggregated Data and use it to evaluate our delivery performance, to benchmark methods across engagements, and to report on general industry trends. We do not attempt to re-identify such data, we contractually prohibit our recipients from doing so, and we do not publish aggregate figures at a granularity that would allow an individual, engagement, or Client to be singled out.
Client data is confidential, and the consequences of mishandling it fall on our clients and on their people. This section states the specific commitments that govern it.
As between Avtech and the Client, the Client owns its Client Data. With respect to that data, the Client acts as the controller or business, and Avtech acts as a service provider or processor. We process Client Data only to provide the Services, to comply with law, and otherwise on the Client’s documented instructions. We do not use Client Data for our own independent commercial purposes.
A Client may configure retention windows, attribution settings, and access roles within the limits the relevant systems allow. The Client is responsible for providing any notices to, and obtaining any consents from, its personnel, contractors, and end users that applicable law, its own policies, or an applicable collective bargaining agreement require, and for ensuring that its configuration and its instructions to us are consistent with those obligations.
Many clients run internal audit, risk, and compliance programs, and are subject to external audit and regulatory examination. Where a Client directs us to process data in support of such a program, we will honor the de-identification, access, and retention protocols the Client specifies, and we will provide evidence of the controls we operate on request. Avtech is not a substitute for any recordkeeping, reporting, or assurance program a Client is required to maintain, and our deliverables are not represented as a certified source of record.
The preceding paragraph does not limit our ability to disclose information where we believe in good faith that disclosure is necessary to prevent imminent risk of death or serious physical injury.
On termination or expiration of an engagement, the Client may request export of its Client Data in a structured, machine-readable format. Following export, or following a written deletion request during the term, we delete or de-identify the applicable Client Data within the periods stated in Section 11, subject to backup cycles and any legal hold. Credentials and access granted to Avtech personnel are revoked at engagement close as a matter of course.
We use AI-assisted tooling internally to help deliver engagements — for example in code generation, documentation, and analysis. Output from that tooling is reviewed by the Avtech personnel accountable for the deliverable before it reaches a Client, and accountability for the deliverable rests with those personnel rather than with the tool. Where a Client asks us to use, or not to use, such tooling on their engagement, we follow that instruction and record it in the statement of work.
Where we use a third-party model provider to deliver a feature, we do so under contractual terms that prohibit the provider from using our inputs or outputs to train or improve its own models, require deletion within a limited retention window, and impose confidentiality and security obligations consistent with this Policy. We will identify our current model providers to a Client on request, and we will not introduce a new provider into a Client environment without the Client’s approval.
A limited number of authorized Avtech personnel may review specific records where necessary to investigate a production incident, diagnose a defect, or validate quality. Such review is restricted to the minimum data required, is subject to confidentiality obligations, is logged, and is governed by the applicable client agreement.
Automated tooling is imperfect. Output may be incomplete, wrong, or confidently stated and still incorrect. That is precisely why every deliverable passes through review by the accountable Avtech personnel before a Client sees it, and why we do not treat tool output as a substitute for the professional judgment a Client is engaging us for.
We disclose personal information only in the circumstances described below.
We do not disclose personal information to third parties for those parties’ own marketing purposes, and we do not permit our service providers to do so.
We engage a deliberately small number of vendors. Each is engaged under a written contract that limits processing to the purposes we specify, prohibits sale of the information, prohibits retention beyond what the engagement requires, imposes confidentiality and security obligations, and requires equivalent commitments from any subprocessor it engages.
| Category | Purpose | Data involved |
|---|---|---|
| Cloud hosting and content delivery | Hosting the Website and Product infrastructure; delivery, availability, and security | Server log data; Client Data at rest and in transit |
| Transactional email delivery | Routing Website inquiries and mailing list subscriptions to our team (currently Mailgun) | Name, email address, telephone number, and message content you submit |
| Business communications and productivity | Email, document, and support tooling used to respond to inquiries and administer accounts | Business contact details and correspondence |
| Error monitoring and observability | Fault diagnosis, uptime monitoring, and security investigation | Diagnostic logs, which may include technical identifiers |
| Model and inference providers | Speech recognition and advisory generation, subject to Section 6.3 | Audio and derived text processed on a transient basis under no-training terms |
Our current list of subprocessors, including the specific entities in each category, is available to Clients and prospective Clients on request at hello@avtechai.us. Clients under contract receive advance notice of material changes to that list in accordance with their agreement.
We do not sell Client Data. We do not monetize it through advertising, data brokerage, benchmarking products offered to third parties, or any other resale arrangement. We have no advertising business, and we do not receive any consideration, monetary or otherwise, in exchange for the disclosure of personal information.
We retain personal information only for as long as necessary to fulfill the purposes described in this Policy, and we determine retention periods by reference to the duration of our relationship with you, the nature and sensitivity of the information, our legal and contractual obligations, and the need to establish or defend legal claims.
| Data | Retention period |
|---|---|
| Website inquiry submissions | Retained in our business correspondence systems while the inquiry or relationship is active, and for up to twenty-four months thereafter, unless you ask us to delete it sooner. |
| Mailing list subscriptions | Retained until you unsubscribe. We retain a minimal suppression record after unsubscribe so that we do not contact you again. |
| Server and hosting logs | Typically thirty days or less, except where a specific record is preserved for a security or abuse investigation. |
| Client Data, including Engagement Data | Retained for the term of the client agreement and in accordance with the retention window the Client configures. Absent a contrary written agreement, we delete or de-identify Client Data within thirty days of a written deletion request and within ninety days of termination. |
| Engagement working papers and deliverables | Retained for the term of the engagement and for the post-engagement period agreed in the statement of work, then returned or deleted. We keep a minimal record of the engagement itself for contractual and professional purposes. |
| Security, access, and audit logs | Retained for up to twelve months to support security assurance and incident investigation. |
| Backups | Encrypted backup copies are purged on a rolling schedule not exceeding ninety days, after which deleted records are no longer recoverable. |
| Records subject to legal hold | Retained for as long as required by the applicable obligation, notwithstanding the periods above. |
We maintain administrative, technical, and physical safeguards designed to protect personal information and Client Data against unauthorized access, disclosure, alteration, and destruction, appropriate to the nature and sensitivity of the information. Those safeguards include:
We maintain an incident response process covering detection, containment, eradication, recovery, and post-incident review. If we determine that a security incident has compromised personal information or Client Data, we will notify affected Clients without undue delay and in accordance with our contractual commitments, and we will notify individuals and regulators where applicable law requires.
We state our security posture plainly rather than by implication. We do not currently hold a SOC 2 Type II attestation or an ISO/IEC 27001 certification, and we will not represent otherwise. Clients and prospective Clients may request our current security documentation, architecture overview, and subprocessor list at hello@avtechai.us.
No method of transmission or storage is completely secure. While we work to protect your information, we cannot guarantee absolute security, and you transmit information to us at your own risk.
Certain rights described in this Policy are granted by state law to residents of particular states. As a matter of policy, and regardless of where you live, we will honor the following requests concerning personal information we hold about you as a business:
Where we process Client Data as a service provider or processor, the Client directs that processing. If you are an employee, contractor, or end user of a Client that engages Avtech and you wish to exercise rights with respect to that data, please submit your request to that organization. If you contact us directly, we will, where we are able to identify the relevant Client, forward your request to that Client and assist them in responding as our agreement and applicable law require.
We will not discriminate or retaliate against you for exercising any privacy right. We will not deny you goods or services, charge you a different price, or provide a different level or quality of service because you exercised a right.
This section supplements the rest of this Policy and applies to California residents under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the “CCPA”). Terms used in this section have the meanings given to them in the CCPA.
The table below identifies the statutory categories of personal information we have collected in the twelve months preceding the effective date of this Policy.
| Statutory category | Collected | Examples |
|---|---|---|
| A. Identifiers | Yes | Name, email address, telephone number, IP address, client-issued user identifier |
| B. Client records (Cal. Civ. Code § 1798.80(e)) | Yes | Name, telephone number, and company information supplied in an inquiry |
| C. Protected classification characteristics | No | — |
| D. Commercial information | Yes | Services considered, proposal, engagement, and subscription records |
| E. Biometric information | No | We do not collect or generate biometric identifiers |
| F. Internet or other network activity | Yes | Server log data, pages requested, and application interaction events within environments we operate |
| G. Geolocation data | No | We do not collect precise device geolocation. Server logs contain IP addresses, which indicate only approximate region |
| H. Sensory or surveillance information | No | — |
| I. Professional or employment-related information | Yes | Business role, company, and the roles and permissions assigned to authorized users by the Client |
| J. Non-public education information | No | — |
| K. Inferences | No | We do not generate profiles or inferences about individuals from personal information |
| L. Sensitive personal information | Limited | Only where a Client instructs us to process it on their behalf within their own systems, as described in Section 3.5. We do not collect it through the Website |
The sources from which we collect each category are described in Section 3. The business and commercial purposes for which we collect and use each category are described in Section 4. We have disclosed the categories above for a business purpose to the categories of recipients described in Sections 7 and 8. We have not sold or shared any category of personal information.
We use and disclose sensitive personal information only for the purposes permitted by Cal. Code Regs. tit. 11, § 7027(m), namely to perform the services requested, to prevent and investigate security incidents, to resist malicious or fraudulent activity, to ensure the physical safety of natural persons, and to verify or maintain the quality and safety of our services. We do not use or disclose sensitive personal information for the purpose of inferring characteristics about an individual. Accordingly, we are not required to offer, and we do not offer, a “Limit the Use of My Sensitive Personal Information” option.
You may use an authorized agent to submit a request on your behalf. We will require written proof of the agent’s authorization, and we may require you to verify your own identity directly with us or to confirm to us that you granted the agent permission.
California Civil Code § 1798.83 permits residents to request information about disclosures of personal information to third parties for those parties’ direct marketing purposes. We do not make such disclosures.
With respect to Client Data, Avtech acts as a service provider under the CCPA. We do not retain, use, or disclose Client Data for any purpose other than performing the services specified in the client agreement, and we do not combine it with personal information received from other sources except as the CCPA permits.
Residents of states with comprehensive consumer privacy statutes, including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states as their statutes take effect, have rights to confirm whether we process their personal data and to access it, to correct inaccuracies, to delete it, to obtain a portable copy, and to opt out of targeted advertising, the sale of personal data, and profiling in furtherance of decisions producing legal or similarly significant effects. As described in Sections 4.6, 9, and 10, we do not engage in targeted advertising, do not sell personal data, and do not conduct such profiling. The remaining rights are honored as described in Sections 13 and 16.
We do not process sensitive data of website visitors within the meaning of these statutes. Where the Services process data a Client directs us to process, the Client is the controller and is responsible for establishing the lawful basis for that processing, including any consent its personnel must provide.
If we decline to act on your request, you may appeal that decision within a reasonable period by replying to our response or by writing to hello@avtechai.us with the subject line “Privacy Request Appeal.” We will respond in writing within forty-five days of receipt, and will explain the reasons for our decision. If your appeal is denied, you may contact your state attorney general to submit a complaint.
Nevada residents have the right to direct a covered operator not to sell certain covered information. We do not sell covered information as defined by Nevada Revised Statutes Chapter 603A, and we have no plans to do so.
We do not collect, process, or share consumer health data within the meaning of the Washington My Health My Data Act, the Nevada consumer health data law, or similar statutes.
Send your request to hello@avtechai.us with the subject line “Privacy Request.” Please tell us the right you wish to exercise, the state in which you reside, and enough information for us to locate your records, such as the email address you used to contact us or the Client you work for.
To protect your information, we will verify your identity before acting on a request. Verification is typically accomplished by matching the information in your request against records we already hold, and by corresponding with you at the email address associated with those records. For requests seeking specific pieces of personal information, we apply a higher standard of certainty. We will not require you to create an account in order to make a request, and we will use any information you provide for verification only for that purpose.
We will acknowledge receipt of your request within ten business days and will respond substantively within forty-five days. Where reasonably necessary, we may extend that period by an additional forty-five days and will inform you of the extension and the reason for it within the initial period. We do not charge a fee to respond, unless your request is manifestly unfounded or excessive, in which case we will tell you why and what the fee would be before proceeding.
We may decline a request, in whole or in part, where an exception under applicable law applies, including where retention is necessary to complete a transaction, to detect or prevent security incidents or fraudulent or illegal activity, to comply with a legal obligation or legal hold, to exercise or defend legal claims, or where the information is not reasonably linkable to you. Where we decline, we will explain why and will tell you how to appeal.
The Website and the Services are intended for business use by adults. They are not directed to children. We do not knowingly collect personal information from any individual under the age of sixteen, and we do not sell or share the personal information of individuals under sixteen.
If we learn that we have collected personal information from a child under thirteen in violation of the Children’s Online Privacy Protection Act, or from any individual under sixteen without a lawful basis, we will delete it promptly. A parent or guardian who believes we hold such information may contact us at hello@avtechai.us.
Where we build or operate a system that serves a Client’s own end users, that system may process information about minors under the Client’s instructions — for example a patient portal or a public sector service. In those cases the Client is the controller, is responsible for obtaining any parental or guardian consent that applicable law requires, and is responsible for confirming that its instructions to us are consistent with that consent.
The Website may link to third-party sites, and the systems we build or operate for a Client routinely integrate with cloud platforms, software vendors, data services, and other systems that you or your organization select. We do not control those third parties, we are not responsible for their privacy practices, and this Policy does not apply to them — including where we configure or administer such a system on your behalf under your own vendor agreement. Information you provide to a third party, or that a third party collects through its own integration with you, is governed by that party’s privacy policy. We encourage you to review the policies of any service in your estate.
Avtech operates in the United States. Personal information and Client Data we collect are processed and stored on infrastructure located in the United States. The Website and the Services are directed to users in the United States and are not intended for individuals located in jurisdictions whose laws would require additional disclosures or transfer mechanisms.
If you access the Website from outside the United States, you understand that your information will be transferred to, processed in, and stored in the United States, where data protection laws may differ from those of your jurisdiction. If we begin offering the Services to individuals outside the United States, we will update this Policy and provide the additional disclosures and safeguards that the applicable laws require.
We may update this Policy to reflect changes in our practices, our technology, or the law. When we do, we will revise the effective date and the version number at the top of this page. Prior versions are available on request.
Where a change is material, we will provide notice before it takes effect. Notice will be given by posting a prominent statement on the Website at least ten days before the new version becomes effective, and, where we hold your contact information as a Client or subscriber, by email. Changes affecting Client Data are additionally governed by the notice provisions of the applicable client agreement.
Your continued use of the Website or the Services after a revised Policy takes effect constitutes your acknowledgment of the revised Policy.
Questions, requests, and complaints regarding this Policy or our handling of personal information should be directed to us in writing. We answer every message. We aim to acknowledge privacy correspondence within one business day.
| Purpose | Contact | Subject line |
|---|---|---|
| Privacy questions and data rights requests | hello@avtechai.us | Privacy Request |
| Appeal of a declined request | hello@avtechai.us | Privacy Request Appeal |
| Security reports and vulnerability disclosure | hello@avtechai.us | Security |
| Security documentation and subprocessor list | hello@avtechai.us | Security Documentation |
You may also reach us through the contact page. If you are a employee or contractor of a Client that engages Avtech, please see Section 13.2 before submitting a request.