Averroes Privacy Policy
Effective Date: September 2, 2026
Last Updated: September 2, 2026
Introduction
Averroes.ai, Inc. ("Averroes.ai," "we," "our," or "us") values your privacy. This Privacy Policy explains how we collect, use, share, and protect your information when you visit averroes.ai or use any product or service offered by Averroes.ai, including VisionRepo and any other current or future Averroes.ai product (collectively, the "Services"). This policy applies across all Averroes.ai products unless a product-specific privacy notice states otherwise.
Averroes.ai, Inc., 55 E 3rd Ave, San Mateo, CA 94401, USA, is the data controller for personal data collected through our website and for account, billing, and usage data. For Customer Data that our customers upload to the Services, the customer is the controller and Averroes.ai acts as a processor under the terms of our Data Processing Agreement (DPA).
1. Information We Collect
- Account Information: Name, email, organization, job title, billing details, and account credentials.
- Customer Data: Data you upload, submit, or generate in any of our Products (Input, Output, datasets, annotations, images, and models).
- Usage Data: Logs, interactions with the platform, access times, IP address, and device and browser information.
- Website and Analytics Data: Information collected through cookies, pixels, and similar technologies as described in Section 2.
- Communications: Information you provide when you contact us, request a demo, or subscribe to our newsletter.
- Third-Party Integrations: If you connect any of our Products with third-party tools (e.g., cloud storage, enterprise SSO), we collect information from those integrations.
We do not intentionally collect special categories of personal data (such as health, biometric, or political data) and ask that you do not submit such data to us.
2. Cookies, Analytics, and Tracking Technologies
We use the following third-party tools on our website and Services:
| Tool | Purpose | Data collected | Legal basis |
|---|---|---|---|
| PostHog | Product analytics | Usage events, page views, feature interactions, session information, device and browser data, IP address | Consent |
| Microsoft Clarity | Session replay and behavioral analytics (heatmaps, session recordings) | Clicks, scrolls, mouse movement, page navigation, device and browser data, IP address | Consent |
| Meta Pixel | Advertising and conversion measurement | Page views, conversion events, device data, cookie identifiers | Consent |
| LinkedIn Insight Tag | Advertising and conversion measurement | Page views, conversion events, device data, cookie identifiers | Consent |
| HubSpot | Form submissions and CRM analytics | Form data, page views, cookie identifiers | Consent (tracking); contract / legitimate interest (form processing) |
| Strictly necessary cookies | Authentication, security, session management, remembering your cookie preferences | Session identifiers, security tokens | Legitimate interest / contract |
Non-essential cookies and tracking tools (all tools listed above except strictly necessary cookies) are only set after you give consent through our cookie banner. You can withdraw or change your consent at any time through the cookie settings link in the website footer. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
Sensitive fields such as passwords and payment details are masked and are not captured in session recordings.
Microsoft's use of Clarity data is governed by the Microsoft Privacy Statement. Meta and LinkedIn act as independent controllers for data they receive through their tags, and you can manage advertising preferences directly in your Meta and LinkedIn account settings.
3. How We Use Information and Our Legal Bases
| Purpose | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Provide, maintain, and operate the Services | Account Information, Customer Data, Usage Data | Performance of a contract |
| Authenticate users and manage accounts | Account Information, Usage Data | Performance of a contract |
| Process payments and billing | Account Information, billing details | Performance of a contract; legal obligation |
| Security, fraud prevention, and system monitoring | Usage Data, Account Information | Legitimate interest (protecting the Services and our users) |
| Respond to support requests and communicate about updates | Account Information, Communications | Performance of a contract; legitimate interest |
| Product analytics and improving user experience | Website and Analytics Data, Usage Data | Consent |
| Marketing emails and newsletters | Account Information, Communications | Consent (you may unsubscribe at any time) |
| Advertising measurement | Website and Analytics Data | Consent |
| Train and improve our AI models | Customer Data in anonymized, aggregated, or de-identified form only | Legitimate interest; governed by the DPA for enterprise customers |
| Comply with legal obligations | Any category as required | Legal obligation |
Where we rely on legitimate interest, we have assessed that our interests are not overridden by your rights and freedoms. You may object to legitimate-interest processing at any time (see Section 9).
We do not use Customer Data to train models in a form that identifies you, your organization, or any individual. Enterprise customers may exclude their Customer Data from model training entirely under the DPA.
We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects.
4. Sharing of Information
We do not sell your personal information. We may share information with:
- Service Providers: Vendors who process data on our behalf to support hosting and infrastructure (Amazon Web Services), storage, analytics (PostHog, Microsoft Clarity), advertising measurement (Meta, LinkedIn), customer relationship management and email (HubSpot, MailerLite), payments, and security. These providers are bound by contracts that restrict their use of your data.
- Sign-in Providers: If you sign in or submit a form using Google or Microsoft, those providers receive information about your use of that feature under their own privacy policies.
- Legal/Regulatory: Where required by law, regulation, court order, or legal process, or to protect our rights, safety, or property.
- Business Transfers: In case of merger, acquisition, financing, or sale of assets, in which case we will notify you before your data becomes subject to a different privacy policy.
- With your consent: For any other purpose you direct.
5. Data Ownership & Access
- You own your Customer Data.
- You control access to your datasets and Output.
- Averroes.ai may restrict downloading or exporting Customer Data if subscription fees are unpaid or the subscription has lapsed.
- You may request deletion of your Customer Data, subject to legal or backup retention requirements.
6. Data Retention
We retain personal data only as long as necessary for the purposes described in this policy:
- Account Information: For the duration of your account plus up to 90 days after closure, unless a longer period is required by law.
- Customer Data: While your account is active. Deleted within 90 days of account termination or upon request, except for backup copies which are purged on a rolling basis within 180 days.
- Usage and security logs: Up to 12 months.
- Billing and transaction records: 7 years, as required by tax and accounting laws.
- Analytics data: PostHog and Microsoft Clarity data is retained according to each tool's configured retention period, not exceeding 12 months.
- Marketing data: Until you unsubscribe or withdraw consent.
When we delete data, we do so securely and consistent with NIST 800-88 standards.
7. Data Security
- We use industry-standard encryption in transit and at rest.
- We implement access controls, monitoring, and logging.
- We require our service providers to maintain appropriate security measures.
- No system is completely secure; we cannot guarantee absolute security.
- In the event of a personal data breach that is likely to result in a risk to your rights, we will notify the relevant supervisory authority and affected individuals as required by law.
- Users are responsible for maintaining backups of their Customer Data.
8. International Data Transfers
We are based in the United States, and your information may be processed in the United States and other countries where we or our service providers operate.
If you are located in the EU, EEA, UK, or Switzerland, we transfer your personal data using one or more of the following safeguards:
- Standard Contractual Clauses approved by the European Commission (and the UK International Data Transfer Addendum where applicable), which are incorporated into our Data Processing Agreement.
- Transfer mechanisms maintained by our service providers, including Microsoft, PostHog, Meta, and LinkedIn.
You may request a copy of the relevant safeguards by contacting us.
9. Your Rights
If you are in the EU, EEA, UK, or Switzerland, you have the following rights under the GDPR and UK GDPR:
- Access: Obtain a copy of the personal data we hold about you.
- Rectification: Correct inaccurate or incomplete personal data.
- Erasure: Request deletion of your personal data in certain circumstances.
- Restriction: Request that we limit processing of your personal data.
- Objection: Object to processing based on legitimate interest, including direct marketing.
- Portability: Receive your personal data in a structured, commonly used, machine-readable format.
- Withdraw consent: Withdraw consent at any time where processing is based on consent, without affecting prior processing.
- Complaint: Lodge a complaint with your local supervisory authority. A list of EU authorities is available at edpb.europa.eu. In the UK, the authority is the Information Commissioner's Office (ico.org.uk).
If you are a California resident, you have similar rights under the CCPA/CPRA, including the right to know, delete, correct, and opt out of the sale or sharing of personal information. We do not sell personal information. Our use of advertising tags may be considered "sharing" under the CPRA; you can opt out through the cookie settings link or by contacting us. We do not discriminate against you for exercising your rights.
To exercise any of these rights, contact us at legal@averroes.ai. We will respond within one month (or 45 days for CCPA requests) and may extend this period where permitted by law. We may need to verify your identity before responding. If you are an employee or user of one of our enterprise customers and your request concerns Customer Data, we may refer your request to that customer as the controller.
10. Children's Privacy
- The Services are not directed to individuals under 18.
- We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, contact us and we will delete it.
11. Changes to Privacy Policy
- We may update this Privacy Policy from time to time.
- Updates will be posted on our website with a revised "Last Updated" date.
- For material changes, we will notify you by email or through a prominent notice on the Services before the changes take effect.
12. Contact Us
For privacy-related questions or to exercise your rights, contact:
- Averroes.ai, Inc.
- 55 E 3rd Ave
- San Mateo, CA 94401, USA
- Email: legal@averroes.ai