This policy describes how Avrenix Intelligence collects, uses, and protects your information.
Avrenix Intelligence provides B2B software services to energy storage operators and related businesses. These documents govern the relationship between Avrenix and its business customers. Questions: [email protected]
Avrenix collects the following categories of data in connection with the Service:
We do not collect personal financial information (payment is handled by Stripe). We do not use advertising trackers or share data with advertising networks. Claude.ai products are ad-free and Avrenix does not serve ads.
Account data is used to authenticate users, communicate about the Service, and provide customer support. We may use your company name and sector to understand our customer base in aggregate.
Operational data is used solely to deliver the Service — to run dispatch models, generate intelligence outputs, and produce analytics within your account. It is not used for any other purpose and is not used to train general-purpose AI models.
Usage data is used to monitor system health, diagnose incidents, and improve the reliability and performance of the Service. It is never used to profile individual users for advertising purposes.
We do not sell your data. We do not share your operational data with third parties except as required to deliver the Service (cloud infrastructure, as described in our sub-processor list) or as required by law.
Our current sub-processors include: Amazon Web Services (infrastructure), Stripe (payment processing), and Anthropic (AI inference for Chai). Our complete sub-processor list is available at avrenix.io/legal/sub-processors. We will notify you at least 30 days before adding new sub-processors that process operational data.
Active customer data is retained for the duration of the subscription plus 12 months. After that period, data is permanently deleted unless you request earlier deletion.
Pilot data is retained for 12 months after pilot end. You may request deletion of all your data at any time by contacting [email protected]. We will complete deletion within 30 days and confirm in writing.
Usage logs are retained for 90 days. Support communications are retained for 3 years from the date of the last message in the thread.
In addition to request-based and termination-based deletion, you may delete your own data directly in the application: you may clear an individual site's data (a scrub) or permanently delete your entire account and all associated data. In-app self-service deletion is immediate and irreversible; you are responsible for exporting any data you wish to keep beforehand. This complements, and does not replace, the request-based and termination-based deletion described here.
We apply the following controls. Sensitive recoverable fields (for example, multi-factor authentication secrets) are encrypted at the application layer using Fernet authenticated encryption (AES-128-CBC with HMAC-SHA256) under a single managed key. Encryption at rest for the broader database is provided by our managed infrastructure provider's volume-level encryption (typically AES-256), rather than application-implemented full-database encryption. Data is encrypted in transit with TLS (database connections require SSL). Authentication tokens (email verification, password reset, and email-change tokens) are stored hashed at rest.
Your data is strictly isolated on a per-tenant basis by access control: every request is scoped to the authenticated owner or organisation, and cross-tenant access is refused. We enforce role-based access controls. Our current security posture is described at avrenix.io/security.
In the event of a confirmed security incident affecting your data, we will notify you within 72 hours of discovery and provide a full incident report within 30 calendar days.
If you are located in the European Economic Area, our processing of your personal data is governed by a Data Processing Agreement available on request. We rely on Standard Contractual Clauses (2021/914/EU) for any transfers of personal data outside the EEA.
By default, all customer data is stored and processed in the United States (AWS us-east-1). Enterprise customers may request EU (Frankfurt) or APAC (Singapore) data residency.
Depending on your jurisdiction, you may have rights including: access to data we hold about you, correction of inaccurate data, deletion of your data, restriction of processing, and data portability.
To exercise any of these rights, contact [email protected] with your account email and the right you wish to exercise. We will respond within 30 days.
Data Controller: Avrenix Intelligence, Inc. Privacy enquiries: [email protected]. For EU/EEA operators, we are the data controller under GDPR.