Auvra Labs
Privacy Policy
Version 2026-08-11 · effective 2026-08-11
Auvra Labs Privacy Policy
Version 2026-08-11
1. Who we are. This policy is published by 1001537887 Ontario Inc., operating as Auvra Labs ("Auvra," "we"). It covers auvralabs.com, the Auvra console, and our support and billing operations. Privacy contact: hello@auvralabs.com.
2. Our two roles. For our own website, accounts, authentication, security, billing, and support records, Auvra is the organization responsible for the data. For data that clients import or connect to their workspace ("client data"), Auvra processes it on the client's documented instructions under a signed Data Processing Agreement; the client is responsible for that data, and requests about it are routed to the client (section 10).
3. What we collect. Account basics (name, business email, role); workspace data clients import or connect (companies, contacts, CRM records, notes); product activity (screens used, actions, tasks, outcomes); error diagnostics, scrubbed before they leave the app (no request bodies, cookies, or secrets); security events (sign-ins, permission denials, privileged actions); billing records; and support communications.
4. Where data comes from. Directly from you and your workspace; from first-party product activity; from reviewed public and business sources used for company research; and from external organization-data suppliers that provide company-level facts. Company-level evidence is never treated as a person's consent, relationship, or intent.
5. How we use data. To provide, secure, support, evaluate, and bill for the service: building research and review queues, scoring and ranking companies, showing usage and results, keeping tenants isolated, preventing abuse, and keeping accounts secure. We do not sell personal information. We do not use one client's private data to serve another client. We do not use identifiable client data to train general-purpose AI models without express written agreement.
6. AI and automated processing. Auvra uses AI-assisted methods for research, classification, ranking, summarization, and drafting. Outputs are reviewed by people before consequential external use; we do not make automated decisions that produce legal or similarly significant effects about individuals without human involvement.
7. Who receives data. We use a small set of service providers: authentication, database, and storage (currently Supabase, United States); application hosting and delivery (currently Vercel, United States); and scrubbed error telemetry (currently Sentry, vendor-managed locations). Some providers run only when a workspace's configuration enables them, such as AI inference or transactional email. Payment records go to our payment processor when one is used. Providers receive only what their job needs. The current list, purposes, and locations are on our subprocessors page. Clients' own destination systems — their CRM, mailbox, or cloud tenant — are controlled by the client, not by Auvra.
8. International processing. We are a Canadian company. Data is processed in the United States and other disclosed vendor-managed locations under contractual safeguards. Contact us with questions about cross-border processing.
9. Retention and deletion. We keep data while an account or contract is active and as needed for security, billing, tax, legal, and dispute obligations. After a verified deletion request or the end of a contract, we delete client personal data from live systems within 60 days, subject to identity verification, legal holds, records we are required to keep, and operational safety; backup copies age out on our providers' backup cycles. Deletion is a controlled, recorded process.
10. Your rights. You can ask to access, correct, or delete personal data about you, or raise a question or complaint, at hello@auvralabs.com. We verify identity before acting on a request. If your data lives in a client's workspace, we notify that client and assist them in responding. We aim to answer ordinary access requests within 30 days and will confirm the timeline that applies to your request. You may also complain to the privacy regulator that applies to you, including the Office of the Privacy Commissioner of Canada.
11. Cookies. The site and console use first-party cookies and local browser storage needed to run the product: authentication and session state, your selected workspace (kept up to one year), and theme preference. We do not use advertising or third-party analytics cookies. Because only necessary and functional first-party storage is used, no separate cookie-preference center is offered; if that changes, this policy and the appropriate controls will be updated first.
12. Security. Data is encrypted in transit and at rest through our infrastructure providers. Access is limited by workspace, role, and server-side authorization; security-relevant actions are recorded; secrets are kept out of logs and telemetry; and we operate an incident-response process. If a personal-data incident affects a client's data, we notify that client without undue delay in line with our agreements and applicable law.
13. Children. The service is for business use and is not directed to children; we do not knowingly collect children's personal information.
14. Changes. Material changes to this policy are posted here with a new version date; account holders are notified in the console or by email.
15. Contact. hello@auvralabs.com — 1001537887 Ontario Inc., operating as Auvra Labs.