Privacy notice

Clear about your data.

This notice explains what personal data Aventa uses, why it is needed, who receives it and the choices available to you.

Last updated 28 September 2026

Aventa Advisory Limited, trading as Aventa Technology Solutions, is committed to using personal data lawfully, fairly and transparently. We do not sell personal data.

1. Who we are and when this notice applies

Aventa Advisory Limited (company number 17033995), trading as Aventa Technology Solutions (“Aventa”, “we”, “us” or “our”), is registered at 15 Hadley Gardens, Newport, Wales, NP10 9QA.

This notice applies when you visit our public website, contact us, ask for a walkthrough, subscribe for updates, or use an Aventa account or workspace. It also covers the limited service, security and usage information we process to operate and improve the platform.

Controller and processor roles

For our website, enquiries, marketing preferences, account administration, security and our own business records, Aventa is normally the controller: we decide why and how the personal data is used.

Where an organisation uses Aventa to manage its project information, that organisation normally decides what information is uploaded and why. For personal data within that customer content, the organisation is normally the controller and Aventa acts as its processor under a contract. Requests about customer-controlled project content should usually be made to the organisation that provided or uploaded it. We will support that organisation in responding.

2. Personal data we may use

We only seek information that is relevant to providing, protecting and improving Aventa. Depending on how you interact with us, this may include:

  • Identity and contact data: name, work email address, organisation, role, telephone number and communication preferences.
  • Account and access data: user identifier, workspace membership, permissions, invitations, sign-in events and authentication/session information.
  • Enquiry and relationship data: messages, walkthrough requests, meeting notes, support requests and records of our relationship with you or your organisation.
  • Customer and project content: project context, sources, activities, evidence, findings, approvals, outputs, comments and files uploaded to a workspace.
  • AI feature data: prompts, source excerpts, generated responses, review actions, usage events and, if dictation is used, audio submitted for transcription and the resulting transcript.
  • Technical and security data: IP address, device and browser information, timestamps, diagnostic events, audit history and records used to prevent misuse and investigate incidents.
  • Marketing data: subscription status, consent wording and timestamp, source of consent, campaign delivery events and unsubscribe or objection records.

We obtain data directly from you; from your employer, client or workspace administrator; from other authorised project participants; and automatically when you use the service. We may also receive limited business contact information from public professional sources where the law permits.

Please keep personal data proportionate. Do not upload special-category data, criminal-offence data, children’s data or unrelated personal information unless it is genuinely necessary, lawful, authorised by the relevant controller and suitable safeguards are in place.

3. How we use personal data and our lawful bases

UK data protection law requires us to have a lawful basis for each purpose. The basis depends on the context and our relationship with you.

PurposeTypical dataLawful basis
Respond to enquiries, arrange walkthroughs and take steps towards a service agreement.Contact, organisation, role and enquiry details.Steps requested before entering a contract; and our legitimate interests in responding to and developing business relationships.
Create accounts, control access and provide the platform.Identity, account, permissions, activity and support data.Performance of a contract where you contract with us; otherwise our legitimate interests and those of your organisation in providing the service securely.
Host and process project information for a customer.Customer and project content, including any personal data a customer chooses to include.We normally act on the customer controller’s documented instructions as its processor. The customer determines the lawful basis.
Provide AI-assisted validation, drafting, guidance, transcription and connected outputs.Prompts, relevant project context, source excerpts, audio where used, outputs and review actions.Contract and legitimate interests in providing requested product functions. Where we are a processor, the customer determines the lawful basis.
Send essential service messages and provide support.Contact, account, service and support records.Contract, legitimate interests in supporting users and, where relevant, legal obligations.
Send optional product updates and marketing.Contact details, consent and engagement records.Consent where required. We use legitimate interests to maintain a suppression record and demonstrate that choices are respected.
Protect Aventa, prevent misuse, maintain auditability and establish or defend legal claims.Technical, security, access, audit and relevant content records.Legitimate interests in service security and accountability; and legal obligations where they apply.
Improve the service and produce research or usage insights.Feature usage and performance data, preferably aggregated or de-identified.Legitimate interests in improving the service. We will seek consent where identifiable data is requested for optional research beyond normal service improvement.

Where we rely on legitimate interests, we consider the necessity of the processing, its benefit and its potential impact on individuals. We do not rely on that basis where your rights and interests override ours.

4. AI-assisted features and professional review

Aventa uses AI to assist with tasks such as analysing supplied information, identifying potential gaps, drafting responses, providing guidance and transcribing dictated input. Relevant content is sent only when needed to provide the requested feature.

  • Aventa is designed to support—not replace—professional judgement.
  • Users are expected to review and validate generated material before relying on it or issuing it.
  • Aventa does not use AI to make solely automated decisions about individuals that produce legal or similarly significant effects.
  • OpenAI states that data submitted through its business API is not used to train its models by default unless the customer explicitly opts in. Relevant API safety logs may be retained for a limited period under OpenAI’s applicable terms and controls.

If a customer enables or directs AI processing within its workspace, the customer remains responsible for ensuring that the submitted content is appropriate and that users and affected individuals receive any additional information required by law.

5. Marketing choices

We will not add you to optional email updates without a valid basis. Where consent is required, the request will be separate, specific and based on a clear positive action. We record when, where and how consent was given so that we can demonstrate and respect your choice.

You can withdraw consent or object to direct marketing at any time by using the unsubscribe link in an email or contacting us. We may keep a minimal suppression record so that we do not contact you again against your wishes.

6. Cookies and similar technologies

The signed-in platform uses strictly necessary session and authentication technologies to keep accounts secure and remember an active session. We do not currently use advertising cookies or third-party behavioural advertising on the public website. If we introduce optional analytics or other non-essential technologies, we will update this notice and provide appropriate choices before they are used.

7. Who receives personal data

We disclose personal data only where necessary and under appropriate contractual or legal controls. Recipients may include:

  • Vercel for website and application hosting and delivery;
  • Supabase for database and authentication services;
  • Microsoft Azure for secure file storage;
  • OpenAI for enabled AI and transcription functions;
  • Resend for service and, where permitted, marketing email delivery;
  • authorised members and administrators of the relevant customer workspace;
  • professional advisers, insurers, auditors, potential business transaction parties and public authorities where genuinely necessary or legally required.

We require service providers to protect personal data, use it only for agreed purposes and support applicable data protection obligations. We do not permit them to use customer content for their own advertising.

International transfers

Some suppliers may process data outside the United Kingdom, including in the United States or European Economic Area. Where UK personal data is transferred to a country without UK adequacy regulations, we use an appropriate safeguard such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with supplementary safeguards where required. You may ask us for further information about the relevant mechanism, subject to lawful confidentiality restrictions.

8. How long we keep personal data

We keep personal data only for as long as it is needed for the stated purpose, the customer contract, security, auditability and applicable legal, accounting or claims requirements. Our current retention approach is:

RecordRetention approach
Enquiries and walkthrough requestsNormally up to 24 months after the last meaningful contact, unless a contract begins or a longer period is needed for a dispute or legal obligation.
Account and commercial recordsFor the account or contract term, then normally up to six years where needed for contractual, tax, accounting or legal claims.
Customer project contentIn accordance with the customer agreement, workspace settings and documented instructions. Export, return and deletion arrangements are agreed with the customer at service closure.
Marketing and consent recordsWhile subscribed. Evidence of consent, withdrawal or objection and a minimal suppression record may be kept for up to six years after the last relevant communication to demonstrate compliance and honour the choice.
Security and diagnostic recordsNormally up to 12 months, unless a longer period is reasonably necessary to investigate an incident, prevent misuse or establish a legal claim.
AI inputs and outputsIf saved into a project record, they follow the customer-content retention rules. Temporary provider-side processing is governed by the relevant provider terms and our contractual controls.

We may retain data longer where the law requires it, a legal hold applies, or it is necessary to establish, exercise or defend a legal claim. When identifiable data is no longer needed, we delete it or irreversibly anonymise it.

9. How we protect personal data

We use proportionate technical and organisational measures including access controls, workspace and role separation, encryption in transit, managed infrastructure safeguards, audit records, restricted administrative access and secure development practices. No online service can guarantee absolute security, so users should also protect credentials and share only information appropriate for the workspace.

10. Your data protection rights

Depending on the circumstances, you may have the right to:

  • ask for access to your personal data and information about its use;
  • ask us to correct inaccurate or incomplete data;
  • ask for deletion or restriction of processing;
  • object to processing based on legitimate interests and always object to direct marketing;
  • receive certain data in a portable format;
  • withdraw consent at any time, without affecting earlier lawful processing; and
  • complain to the Information Commissioner’s Office.

These rights are not absolute and may be subject to lawful exemptions. We may ask for information needed to verify your identity and understand the request. We do not charge a fee in ordinary cases. If Aventa is acting only as processor for a customer, we will refer or relay the request to that customer controller.

11. Children

Aventa is a business service for professional users and is not directed to children. We do not knowingly invite children to create accounts or subscribe for updates.

12. Contact, complaints and changes

For privacy questions or to exercise a right, contact:

Aventa Advisory Limited
15 Hadley Gardens
Newport, Wales, NP10 9QA
hello@aventaadvisory.co.uk

Please write “Privacy request” in the subject line. We aim to acknowledge requests promptly and respond within the period required by law.

You may also complain to the UK supervisory authority, the Information Commissioner’s Office. We would appreciate the opportunity to address your concern first, but you do not have to contact us before approaching the ICO.

We will update this notice when our processing, suppliers or legal obligations materially change. The date at the top identifies the current version. Where a change materially affects how existing data is used, we will provide a more prominent notice where reasonably practicable.