1. Introduction
ADVINTIS Inc. ("we," "us," or "our") is committed to protecting the privacy of our users. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the ADVINTIS platform ("the Service"). By using the Service, you consent to the practices described in this policy.
2. Information We Collect
2.1 Account Information
- Name, email address, and organization name
- Authentication credentials (managed via secure third-party providers)
- Billing information (processed by our payment provider)
- Role and permission settings within your organization
2.2 Usage Data
- Conversations and messages processed through the platform
- AI interaction logs and resolution metrics
- Dashboard activity and feature usage patterns
- Device information, IP addresses, and browser type
2.3 Third-Party Integration Data
- OAuth tokens from connected services (Meta, Slack, Microsoft, Google, TikTok)
- Channel-specific identifiers (page IDs, workspace IDs, etc.)
- Messages received through connected channels
3. How We Use Your Information
- Service Delivery: To provide, maintain, and improve the ADVINTIS platform.
- AI Processing: To power autonomous AI agents, sentiment analysis, and smart routing.
- Analytics: To generate dashboards, reports, and performance metrics for your organization.
- Communication: To send service updates, security alerts, and billing notifications.
- Improvement: To train and improve AI models using anonymized, aggregated data.
- Security: To detect, prevent, and respond to security incidents.
4. Data Isolation & Multi-Tenancy
ADVINTIS operates as a multi-tenant platform with strict data isolation:
- Each organization's data is logically isolated using unique tenant identifiers.
- No data is shared between organizations under any circumstances.
- OAuth credentials, conversation data, and configurations are tenant-scoped.
- Administrative access is role-based and audit-logged.
5. Data Sharing & Disclosure
We do not sell your personal data. We may share information only in these circumstances:
- Service Providers: Trusted partners who assist in operating the platform (hosting, payment processing, email delivery).
- Legal Compliance: When required by law, court order, or governmental authority.
- Business Transfer: In connection with a merger, acquisition, or sale of assets, with appropriate notice.
- Your Consent: When you explicitly authorize sharing with a third party.
6. Data Security
- All data is encrypted in transit (TLS 1.3) and at rest (AES-256).
- OAuth tokens are stored encrypted and scoped per tenant.
- CSRF protection is implemented on all authentication flows.
- Regular security audits and penetration testing.
- Role-based access control (RBAC) with comprehensive audit logging.
- SOC 2 and HIPAA-ready architecture.
7. Data Retention
- Account data is retained for the duration of your subscription.
- Upon account deletion, data is permanently removed within 30 days.
- Conversation logs may be retained per your organization's configured retention policy (30–365 days).
- Anonymized, aggregated analytics data may be retained indefinitely for service improvement.
8. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access: Request a copy of your personal data.
- Correction: Request correction of inaccurate data.
- Deletion: Request deletion of your data ("right to be forgotten").
- Portability: Export your data in a machine-readable format.
- Objection: Object to certain processing activities.
- Restriction: Request restriction of processing in certain circumstances.
To exercise these rights, contact us at privacy@advintis.com. We will respond within 30 days.
9. GDPR Compliance (EEA/UK Users)
- We process data under lawful bases: contract performance, legitimate interest, and consent.
- Data transfers outside the EEA use Standard Contractual Clauses (SCCs).
- You may lodge a complaint with your local Data Protection Authority.
- Our Data Protection Officer can be reached at dpo@advintis.com.
10. CCPA Compliance (California Users)
- We do not sell personal information as defined by the CCPA.
- California residents have the right to know, delete, and opt-out.
- We do not discriminate against users who exercise their CCPA rights.
11. Cookies & Tracking
- Essential Cookies: Required for authentication and core platform functionality.
- Analytics Cookies: Used to understand usage patterns and improve the service.
- You can manage cookie preferences through your browser settings.
- We do not use cookies for advertising purposes.
12. Children's Privacy
The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware of such collection, we will delete the information promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or platform notification at least 30 days before taking effect. The "Last updated" date at the top reflects the most recent revision.