Skip to content
avertari
How it works Trust Contact Become a design partner

Legal

Privacy policy

Effective 24 September 2026

On this page

  1. Who we are
  2. Our two roles
  3. What we collect and why
  4. Cookies
  5. Who we share it with
  6. International transfers
  7. How long we keep it
  8. How we protect it
  9. Your rights
  10. Complaints
  11. Changes to this policy
Draft. This document is being reviewed by our legal advisers and may change before general availability. Questions: legal@avertari.io.

Who we are

Avertari is operated by to be confirmed, a company registered in to be confirmed under company number to be confirmed, with its registered office at to be confirmed ("Avertari", "we", "us"). We're registered with the UK Information Commissioner's Office under registration number to be confirmed.

For any question about this policy or your personal data, contact privacy@avertari.io.

Our two roles

Data protection law treats us differently depending on whose data it is:

  • We're a controller for personal data about visitors to this website, people who contact us, and the people at our customers who manage their Avertari account. This policy covers that data.
  • We're a processor for the workforce data our customers connect to Avertari: their employees', contractors' and former staff's identity, employment and access records. For that data the customer (usually your employer) is the controller. We process it only on their instructions, under our data processing agreement. If you're an employee of one of our customers, contact your employer first. We'll help them respond to you.

What we collect and why

DataWhy we use itLawful basis
Website visits: IP address, browser details and requested URL, handled by our hosting providerDelivering the site, and protecting it from attacks and abuseLegitimate interests (keeping the site available and secure)
Messages you send us: name, email address, organisation and whatever you writeReplying to you, and keeping a record of the conversationLegitimate interests (responding to enquiries); steps before a contract, where relevant
Customer account contacts: name, work email, role, and sign-in and audit recordsProviding the service, securing accounts, billing and supportPerformance of our contract with your organisation; legitimate interests
Security and vulnerability reportsInvestigating and fixing issues, and crediting researchersLegitimate interests (keeping our service secure)

We don't sell personal data, use it for advertising or make decisions about you based only on automated processing.

Cookies

This website sets no cookies. It uses no analytics or tracking scripts and loads no content from third parties: fonts and assets are served from our own domain. Our hosting provider, Cloudflare, may process connection data to protect the site from attacks, as described above. If this ever changes, we'll update this section before it happens.

Who we share it with

We share personal data only with service providers who help us run Avertari, under contracts that limit them to our instructions. They're listed, with their location and purpose, on our subprocessors page. We may also disclose data where the law requires it, or to protect the rights and safety of our users or others.

International transfers

Customer data in the Avertari platform is stored and processed in the United Kingdom (Google Cloud, europe-west2 London). Some providers, such as Cloudflare, operate internationally and may process website or email data outside the UK. When personal data leaves the UK we rely on an appropriate safeguard: an adequacy regulation, the UK Extension to the EU–US Data Privacy Framework where the recipient is certified, or the UK International Data Transfer Agreement or Addendum.

How long we keep it

  • Website connection logs: kept by our hosting provider for a short period for security purposes, typically no more than a few days.
  • Correspondence: up to 2 years after our last contact, unless it becomes part of a customer relationship.
  • Customer account data: for the life of the contract, then deleted within 30 days of termination, except where we must keep records (for example invoices) for legal or tax reasons.
  • Customer workforce data: as set out in our data processing agreement. This means deletion within 30 days of termination, made irreversible by destroying the customer's encryption key.

How we protect it

We use encryption in transit and at rest, per-customer encryption keys, strict access controls and audit logging. Details are in our trust centre.

Your rights

Under UK data protection law you have the right to:

  • access the personal data we hold about you
  • have inaccurate data corrected
  • have your data erased
  • restrict or object to how we process it, including where we rely on legitimate interests
  • receive your data in a portable format, where applicable

To exercise any of these, email privacy@avertari.io. We'll respond within one month, and there's normally no charge. We may need to confirm your identity first.

Complaints

If you're unhappy with how we've handled your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office (ico.org.uk).

Changes to this policy

We'll post any changes on this page and update the effective date. If a change materially affects how we use data we already hold, we'll tell affected customers directly before it takes effect.

avertari

Joiner, mover and leaver intelligence for the tools you already run.

Product

How it works Joiners, movers, leavers Trust centre

Company

Contact Design partners hello@avertari.io

Legal

Privacy policy Terms of service Data processing Subprocessors security.txt

© 2026 Avertari. Company details

This site sets no cookies and loads nothing from third parties.