Skip to main content

1. Introduction

Avetti.com Corporation ("we," "us," "our," or "Company") is committed to protecting your privacy and personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our cybersecurity course and Avetti Security Safe Browsing Extension and App services (collectively, the "Services").

Our Commitment

We are based in Ontario, Canada, and comply with:

  • Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws
  • General Data Protection Regulation (GDPR) for users in the European Union
  • California Consumer Privacy Act (CCPA) and other applicable US state privacy laws

Please read this Privacy Policy carefully. By using our Services, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

2.1 Information You Provide to Us

Account Registration Information:

  • Full name
  • Email address
  • Password (encrypted)
  • Country/region of residence
  • Company name (optional)

Payment Information:

  • Payment card details (processed and stored by Stripe, not by us)
  • Billing address
  • Transaction history

Communication Information:

  • Customer support inquiries and correspondence
  • Feedback and survey responses
  • Email communications with us

Profile Information:

  • Course progress and completion status
  • Learning preferences
  • Account settings and preferences

2.2 Information Collected Automatically

Usage Data:

  • Pages visited and features accessed
  • Time spent on pages and in the Services
  • Course modules accessed and completed
  • Avetti Security Safe Browsing Extension and App usage statistics (URLs processed, sessions initiated)
  • Click patterns and navigation paths
  • Search queries within our platform
  • Mouse movements, clicks, and scrolling behavior (via heatmaps and session recordings)
  • Form interactions and input patterns (with sensitive data masked)

Important Note on Session Recordings

We use Microsoft Clarity and OpenReplay to record user sessions for improving user experience. These tools capture:

  • Page navigation and interactions
  • Mouse movements and clicks
  • Scroll depth and patterns
Privacy Protections:
  • Personally identifiable information (PII) is automatically masked
  • Payment card information is never recorded
  • Passwords and sensitive form fields are excluded
  • Session recordings are anonymized and not linked to your identity
  • You can opt out of session recording through cookie settings

Device and Browser Information:

  • IP address
  • Browser type and version
  • Operating system
  • Device type and identifiers
  • Screen resolution
  • Language preferences
  • Time zone settings

Cookies and Tracking Technologies:

  • Session cookies
  • Persistent cookies
  • Analytics cookies
  • Preference cookies
  • Security cookies

See Section 5 for detailed information about our cookie usage.

Avetti Security Safe Browsing Extension and App Specific Data:

  • Remote session metadata (duration, timestamp, session ID)
  • Performance metrics
  • Error logs and diagnostic data
  • Browser extension usage data

IMPORTANT: We do NOT collect or store:

  • The actual content of URLs you process through Avetti Security Safe Browsing Extension and App
  • Screenshots or recordings of your remote sessions
  • Personal data from websites you visit through Avetti Security Safe Browsing Extension and App
  • The content of any files or data you interact with in remote environments

2.3 Information from Third Parties

Payment Processor (Stripe):

  • Payment confirmation status
  • Subscription status
  • Billing information
  • Fraud detection signals

Analytics Providers:

  • Aggregated usage statistics
  • Performance metrics
  • Error reports

3. How We Use Your Information

3.1 Primary Uses

We use your information to:

Provide and Maintain Services:

  • Create and manage your account
  • Process your subscription payments
  • Deliver course content and Avetti Security Safe Browsing Extension and App access
  • Authenticate your login and maintain security
  • Generate and manage your registration key
  • Provide customer support

Improve and Optimize Services:

  • Analyze usage patterns to improve functionality
  • Develop new features and services
  • Conduct research and testing
  • Optimize performance and user experience
  • Debug and fix technical issues

Communicate with You:

  • Send transactional emails (registration, payment confirmations, password resets)
  • Provide customer support responses
  • Send service announcements and updates
  • Notify you of changes to Terms of Service or Privacy Policy
  • Send educational content related to your course (if you opt in)

Security and Fraud Prevention:

  • Detect and prevent fraudulent activity
  • Monitor for security threats
  • Enforce our Terms of Service
  • Protect our legal rights and property
  • Comply with legal obligations

Marketing (With Your Consent):

  • Send promotional emails about new courses or features (opt-in only)
  • Provide personalized recommendations
  • Conduct surveys and gather feedback

You may opt out of marketing communications at any time through your account settings or by clicking "unsubscribe" in any marketing email.

3.2 Legal Bases for Processing (GDPR)

For users in the European Union, we process your personal data based on:

  • Contract Performance: Processing necessary to provide the Services you've subscribed to
  • Consent: When you've explicitly agreed to processing (e.g., marketing emails, optional cookies)
  • Legitimate Interests: To improve our Services, prevent fraud, and ensure security
  • Legal Obligation: To comply with applicable laws and regulations

4. How We Share Your Information

We do not sell, rent, or trade your personal information to third parties. We share information only in the following limited circumstances:

4.1 Service Providers

We share information with trusted third-party service providers who assist us in operating our Services:

Stripe (Payment Processing):

  • Purpose: Process subscription payments and manage billing
  • Data Shared: Name, email, payment card information, billing address
  • Location: United States (Stripe is Privacy Shield certified and GDPR compliant)
  • Privacy Policy: https://stripe.com/privacy

Cloud Infrastructure Providers:

  • Purpose: Host our platform and remote environments
  • Data Shared: Account data, usage data, technical logs
  • Security: All providers are SOC 2 compliant with encryption in transit and at rest

Analytics Services:

  • Purpose: Understand usage patterns and improve Services
  • Data Shared: Anonymized usage data, aggregated statistics, session recordings (anonymized), heatmaps, user interactions
Tools Used:
  • Google Analytics 4 (GA4): Website traffic analysis and user behavior tracking with IP anonymization enabled
  • Google Tag Manager: Managing and deploying analytics and marketing tags
  • Microsoft Clarity: Session replay and heatmap analysis with personally identifiable information (PII) masking
  • OpenReplay: Session replay and user experience monitoring with privacy controls enabled
Privacy Measures:

IP anonymization, PII masking, cookie consent requirements, data anonymization

Third-Party Policies:

Email Service Provider:

  • Purpose: Send transactional and marketing emails
  • Data Shared: Name, email address, subscription status
  • Security: TLS encryption for all email transmissions

Customer Support Tools:

  • Purpose: Provide customer service
  • Data Shared: Name, email, support inquiry content
  • Retention: Support tickets retained per our data retention policy

All service providers are contractually obligated to:

  • Use your data only for the specified purposes
  • Implement appropriate security measures
  • Comply with applicable privacy laws
  • Delete or return data upon contract termination

4.2 Legal Requirements

We may disclose your information if required to:

  • Comply with legal obligations (court orders, subpoenas, warrants)
  • Enforce our Terms of Service
  • Protect our rights, property, or safety
  • Protect the rights, property, or safety of our users or the public
  • Detect, prevent, or address fraud or security issues

We will notify you of legal requests for your information unless prohibited by law.

4.3 Business Transfers

If we are involved in a merger, acquisition, asset sale, or bankruptcy, your information may be transferred as part of that transaction. We will notify you before your information is transferred and becomes subject to a different privacy policy.

4.4 With Your Consent

We may share your information for other purposes with your explicit consent.

5. Cookies and Tracking Technologies

5.1 What Are Cookies?

Cookies are small text files stored on your device that help websites function properly and provide information to website owners.

5.2 Types of Cookies We Use

Strictly Necessary Cookies (Always Active):

  • Authentication cookies (keep you logged in)
  • Security cookies (prevent fraud and protect your account)
  • Session management cookies
  • Load balancing cookies

These cookies are essential for the Services to function and cannot be disabled.

Analytics Cookies (Requires Consent):

  • Usage tracking
  • Performance monitoring
  • Error detection
  • Feature usage statistics

Preference Cookies (Requires Consent):

  • Language settings
  • Display preferences
  • Course progress tracking
  • UI customization

Marketing Cookies (Requires Consent):

  • Campaign effectiveness tracking
  • Conversion tracking
  • Retargeting (only with explicit consent)

5.3 Third-Party Cookies

We use the following third-party cookies:

  • Stripe: Payment processing and fraud detection
  • Google Analytics 4: Website usage analytics and performance tracking
  • Google Tag Manager: Tag and cookie management
  • Microsoft Clarity: Session recording and heatmap analysis
  • OpenReplay: User experience monitoring and session replay

Each third-party service may set its own cookies. You can learn more about how these services use cookies by reviewing their respective privacy policies.

5.4 Your Cookie Choices

Managing Cookies:

  • Use our Cookie Consent Manager (available at the bottom of every page)
  • Adjust settings in your browser preferences
  • Install browser extensions to block specific cookies

Browser Controls:

  • Most browsers allow you to view, delete, and block cookies
  • Blocking all cookies may prevent some features from working properly

Withdrawing Consent:

European users can withdraw cookie consent at any time through our Cookie Consent Manager. This will not affect the lawfulness of processing before withdrawal.

5.5 Do Not Track

Some browsers have "Do Not Track" (DNT) features. We currently do not respond to DNT signals, as there is no industry consensus on how to interpret them.

6. Data Security

6.1 Security Measures

We implement industry-standard security measures to protect your information:

Technical Safeguards:

  • TLS/SSL encryption for all data in transit
  • AES-256 encryption for data at rest
  • Secure password hashing (bcrypt with salt)
  • Regular security audits and penetration testing
  • Firewall and intrusion detection systems
  • Isolated remote environments for Avetti Security Safe Browser Extension and App

Administrative Safeguards:

  • Employee background checks
  • Confidentiality agreements for all staff
  • Role-based access controls
  • Security awareness training
  • Incident response procedures

Physical Safeguards:

  • Secure data center facilities (SOC 2 certified)
  • 24/7 monitoring and surveillance
  • Redundant power and network systems

6.2 Data Breach Notification

In the event of a data breach affecting your personal information, we will:

  • Notify you within 72 hours (as required by GDPR)
  • Inform relevant supervisory authorities
  • Provide details about the breach and our response
  • Offer guidance on protective measures you can take

6.3 Your Responsibility

You are responsible for:

  • Maintaining the confidentiality of your password
  • Using a strong, unique password
  • Logging out after using shared devices
  • Keeping your contact information up to date
  • Notifying us immediately of any unauthorized access

IMPORTANT: No security system is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

7. Data Retention

7.1 Retention Periods

We retain your personal information only as long as necessary for the purposes described in this Privacy Policy:

Active Accounts:

  • Account data: Retained while your subscription is active
  • Course progress: Retained while your subscription is active
  • Usage data: Retained for 24 months
  • Technical logs: Retained for 12 months

Cancelled Accounts:

  • Account data: Deleted 30 days after subscription ends
  • Payment history: Retained for 7 years (tax and accounting requirements)
  • Anonymized usage data: May be retained indefinitely for analytics

Customer Support:

  • Support tickets: Retained for 3 years
  • Communication records: Retained for 3 years

Legal Requirements:

  • Data required by law: Retained as legally required
  • Data subject to legal holds: Retained until hold is lifted

7.2 Deletion Process

Upon account deletion:

  1. Your registration key is immediately deactivated
  2. Access to Services is terminated at end of billing period
  3. Personal data is scheduled for deletion within 30 days
  4. Payment history is anonymized (kept for tax purposes only)
  5. Backups containing your data are deleted within 90 days

7.3 Right to Request Deletion

You may request deletion of your account and personal data at any time. See Section 9 for details on exercising your rights.

8. International Data Transfers

8.1 Transfer Mechanisms

We are based in Ontario, Canada. Your information may be transferred to and processed in:

  • Canada (our primary location)
  • United States (Stripe payment processing, cloud infrastructure)
  • Other countries where our service providers operate

8.2 Safeguards for International Transfers

For European Users:

We ensure adequate protection for data transferred outside the EU through:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Service providers certified under EU-US Data Privacy Framework
  • Adequacy decisions (e.g., Canada has adequacy status for commercial organizations under PIPEDA)

For All Users:

All international transfers are protected by:

  • Contractual obligations requiring equivalent protection
  • Technical security measures (encryption, access controls)
  • Regular compliance audits

9. Your Privacy Rights

9.1 Rights for All Users

Regardless of location, you have the right to:

  • Access your personal information
  • Correct inaccurate information
  • Request deletion of your account
  • Opt out of marketing communications
  • Update your communication preferences
  • Export your course progress data

9.2 European Union Users (GDPR Rights)

EU users have additional rights:

  • Right to Access: Request a copy of all personal data we hold about you
  • Right to Rectification: Correct inaccurate or incomplete personal data
  • Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data (subject to legal retention requirements)
  • Right to Restrict Processing: Limit how we use your personal data in certain circumstances
  • Right to Data Portability: Receive your data in a structured, machine-readable format and transfer it to another controller
  • Right to Object: Object to processing based on legitimate interests or for direct marketing
  • Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent
  • Right Not to Be Subject to Automated Decision-Making: We do not use automated decision-making or profiling that produces legal or similarly significant effects
  • Right to Lodge a Complaint: File a complaint with your national supervisory authority

Find your authority at: https://edpb.europa.eu/about-edpb/board/members_en

9.3 Canadian Users (PIPEDA Rights)

Canadian users have the right to:

  • Access personal information we hold about you
  • Challenge the accuracy and completeness of your information
  • Withdraw consent (subject to legal or contractual restrictions)
  • File a complaint with the Privacy Commissioner of Canada: https://www.priv.gc.ca

9.4 United States Users

California Residents (CCPA/CPRA):

  • Right to know what personal information is collected
  • Right to know if personal information is sold or shared (we do not sell information)
  • Right to deletion
  • Right to correct inaccurate information
  • Right to opt-out of the sale of personal information (not applicable)
  • Right to limit use of sensitive personal information
  • Right to non-discrimination for exercising your rights

Other US States:

Users in Virginia, Colorado, Connecticut, Utah, and other states with privacy laws have similar rights. Contact us for details specific to your state.

9.5 How to Exercise Your Rights

Email:

  • Send requests to [email protected]
  • Include your full name, email address, and specific request

Mail:

Avetti.com Corporation
Attention: Privacy Officer
92 Caplan Avenue, Suite 206
Barrie, Ontario, L4N 9J2
Canada

Response Time:

  • We will respond to requests within 30 days (GDPR, CCPA)
  • We may extend by 30 days if requests are complex (with notice)
  • We will verify your identity before processing requests

No Fee: We do not charge a fee for processing requests unless they are manifestly unfounded or excessive.

10. Children's Privacy

Our Services are not intended for children under 18 years of age (or the age of majority in your jurisdiction).

We do not knowingly collect information from children:

  • We do not knowingly collect personal information from anyone under 18
  • We do not knowingly allow children to create accounts
  • If we discover we have collected information from a child, we will delete it immediately

Parents/Guardians: If you believe your child has provided us with personal information, please contact us immediately at [email protected].

11. Third-Party Links and Services

11.1 Third-Party Websites

Our Services may contain links to third-party websites. This Privacy Policy does not apply to those websites. We are not responsible for:

  • The privacy practices of third-party websites
  • The content of third-party websites
  • Security of third-party websites

We encourage you to read the privacy policies of any third-party sites you visit.

11.2 Avetti Security Safe Browsing Extension and App and External Content

When using Avetti Security Safe Browsing Extension and App to access external websites:

  • We do not track or monitor the content you view
  • We do not store URLs you access through remote environments
  • External websites may collect their own data according to their privacy policies
  • Remote environments are isolated and temporary

12. California Shine the Light Law

California residents who have provided personal information may request information about our disclosure of certain categories of personal information to third parties for direct marketing purposes. We do not share personal information with third parties for their direct marketing purposes.

13. Changes to This Privacy Policy

13.1 Updates

We may update this Privacy Policy from time to time to reflect:

  • Changes in our practices
  • Changes in applicable laws
  • New features or services
  • Feedback from users or regulators

13.2 Notification

We will notify you of material changes by:

  • Posting the updated policy on our website with a new "Last Updated" date
  • Sending an email to your registered email address (for significant changes)
  • Displaying a prominent notice on our platform

13.3 Acceptance

Continued use of the Services after changes become effective constitutes acceptance of the updated Privacy Policy. If you do not agree to the changes, please discontinue use and contact us to delete your account.

14. Contact Information

14.1 Privacy Officer

For questions, concerns, or requests regarding this Privacy Policy or your personal information:

Avetti.com Corporation
Attention: Privacy Officer
92 Caplan Avenue, Suite 206
Barrie, Ontario, L4N 9J2
Canada

Email: [email protected]

14.2 Data Protection Officer (EU Users)

Data Protection Officer
Email: [email protected]

14.3 Supervisory Authorities

European Users:

You have the right to lodge a complaint with your local supervisory authority. Find your authority at: https://edpb.europa.eu/about-edpb/board/members_en

Canadian Users:

Office of the Privacy Commissioner of Canada
Website: https://www.priv.gc.ca
Phone: 1-800-282-1376

California Users:

California Attorney General's Office
Website: https://oag.ca.gov/privacy

Last Updated: November 10, 2025

By using our Services, you acknowledge that you have read and understood this Privacy Policy and agree to its terms.