1. Introduction
Avetti.com Corporation ("we," "us," "our," or "Company") is committed to protecting your privacy and personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our cybersecurity course and Avetti Security Safe Browsing Extension and App services (collectively, the "Services").
Our Commitment
We are based in Ontario, Canada, and comply with:
- Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws
- General Data Protection Regulation (GDPR) for users in the European Union
- California Consumer Privacy Act (CCPA) and other applicable US state privacy laws
Please read this Privacy Policy carefully. By using our Services, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Information You Provide to Us
Account Registration Information:
- Full name
- Email address
- Password (encrypted)
- Country/region of residence
- Company name (optional)
Payment Information:
- Payment card details (processed and stored by Stripe, not by us)
- Billing address
- Transaction history
Communication Information:
- Customer support inquiries and correspondence
- Feedback and survey responses
- Email communications with us
Profile Information:
- Course progress and completion status
- Learning preferences
- Account settings and preferences
2.2 Information Collected Automatically
Usage Data:
- Pages visited and features accessed
- Time spent on pages and in the Services
- Course modules accessed and completed
- Avetti Security Safe Browsing Extension and App usage statistics (URLs processed, sessions initiated)
- Click patterns and navigation paths
- Search queries within our platform
- Mouse movements, clicks, and scrolling behavior (via heatmaps and session recordings)
- Form interactions and input patterns (with sensitive data masked)
Important Note on Session Recordings
We use Microsoft Clarity and OpenReplay to record user sessions for improving user experience. These tools capture:
- Page navigation and interactions
- Mouse movements and clicks
- Scroll depth and patterns
Privacy Protections:
- Personally identifiable information (PII) is automatically masked
- Payment card information is never recorded
- Passwords and sensitive form fields are excluded
- Session recordings are anonymized and not linked to your identity
- You can opt out of session recording through cookie settings
Device and Browser Information:
- IP address
- Browser type and version
- Operating system
- Device type and identifiers
- Screen resolution
- Language preferences
- Time zone settings
Cookies and Tracking Technologies:
- Session cookies
- Persistent cookies
- Analytics cookies
- Preference cookies
- Security cookies
See Section 5 for detailed information about our cookie usage.
Avetti Security Safe Browsing Extension and App Specific Data:
- Remote session metadata (duration, timestamp, session ID)
- Performance metrics
- Error logs and diagnostic data
- Browser extension usage data
IMPORTANT: We do NOT collect or store:
- The actual content of URLs you process through Avetti Security Safe Browsing Extension and App
- Screenshots or recordings of your remote sessions
- Personal data from websites you visit through Avetti Security Safe Browsing Extension and App
- The content of any files or data you interact with in remote environments
2.3 Information from Third Parties
Payment Processor (Stripe):
- Payment confirmation status
- Subscription status
- Billing information
- Fraud detection signals
Analytics Providers:
- Aggregated usage statistics
- Performance metrics
- Error reports
3. How We Use Your Information
3.1 Primary Uses
We use your information to:
Provide and Maintain Services:
- Create and manage your account
- Process your subscription payments
- Deliver course content and Avetti Security Safe Browsing Extension and App access
- Authenticate your login and maintain security
- Generate and manage your registration key
- Provide customer support
Improve and Optimize Services:
- Analyze usage patterns to improve functionality
- Develop new features and services
- Conduct research and testing
- Optimize performance and user experience
- Debug and fix technical issues
Communicate with You:
- Send transactional emails (registration, payment confirmations, password resets)
- Provide customer support responses
- Send service announcements and updates
- Notify you of changes to Terms of Service or Privacy Policy
- Send educational content related to your course (if you opt in)
Security and Fraud Prevention:
- Detect and prevent fraudulent activity
- Monitor for security threats
- Enforce our Terms of Service
- Protect our legal rights and property
- Comply with legal obligations
Marketing (With Your Consent):
- Send promotional emails about new courses or features (opt-in only)
- Provide personalized recommendations
- Conduct surveys and gather feedback
You may opt out of marketing communications at any time through your account settings or by clicking "unsubscribe" in any marketing email.
3.2 Legal Bases for Processing (GDPR)
For users in the European Union, we process your personal data based on:
- Contract Performance: Processing necessary to provide the Services you've subscribed to
- Consent: When you've explicitly agreed to processing (e.g., marketing emails, optional cookies)
- Legitimate Interests: To improve our Services, prevent fraud, and ensure security
- Legal Obligation: To comply with applicable laws and regulations
4. How We Share Your Information
We do not sell, rent, or trade your personal information to third parties. We share information only in the following limited circumstances:
4.1 Service Providers
We share information with trusted third-party service providers who assist us in operating our Services:
Stripe (Payment Processing):
- Purpose: Process subscription payments and manage billing
- Data Shared: Name, email, payment card information, billing address
- Location: United States (Stripe is Privacy Shield certified and GDPR compliant)
- Privacy Policy: https://stripe.com/privacy
Cloud Infrastructure Providers:
- Purpose: Host our platform and remote environments
- Data Shared: Account data, usage data, technical logs
- Security: All providers are SOC 2 compliant with encryption in transit and at rest
Analytics Services:
- Purpose: Understand usage patterns and improve Services
- Data Shared: Anonymized usage data, aggregated statistics, session recordings (anonymized), heatmaps, user interactions
Tools Used:
- Google Analytics 4 (GA4): Website traffic analysis and user behavior tracking with IP anonymization enabled
- Google Tag Manager: Managing and deploying analytics and marketing tags
- Microsoft Clarity: Session replay and heatmap analysis with personally identifiable information (PII) masking
- OpenReplay: Session replay and user experience monitoring with privacy controls enabled
Privacy Measures:
IP anonymization, PII masking, cookie consent requirements, data anonymization
Third-Party Policies:
- Google Privacy Policy: https://policies.google.com/privacy
- Microsoft Privacy Statement: https://privacy.microsoft.com/privacystatement
- OpenReplay Privacy: https://openreplay.com/privacy
Email Service Provider:
- Purpose: Send transactional and marketing emails
- Data Shared: Name, email address, subscription status
- Security: TLS encryption for all email transmissions
Customer Support Tools:
- Purpose: Provide customer service
- Data Shared: Name, email, support inquiry content
- Retention: Support tickets retained per our data retention policy
All service providers are contractually obligated to:
- Use your data only for the specified purposes
- Implement appropriate security measures
- Comply with applicable privacy laws
- Delete or return data upon contract termination
4.2 Legal Requirements
We may disclose your information if required to:
- Comply with legal obligations (court orders, subpoenas, warrants)
- Enforce our Terms of Service
- Protect our rights, property, or safety
- Protect the rights, property, or safety of our users or the public
- Detect, prevent, or address fraud or security issues
We will notify you of legal requests for your information unless prohibited by law.
4.3 Business Transfers
If we are involved in a merger, acquisition, asset sale, or bankruptcy, your information may be transferred as part of that transaction. We will notify you before your information is transferred and becomes subject to a different privacy policy.
4.4 With Your Consent
We may share your information for other purposes with your explicit consent.
5. Cookies and Tracking Technologies
5.1 What Are Cookies?
Cookies are small text files stored on your device that help websites function properly and provide information to website owners.
5.2 Types of Cookies We Use
Strictly Necessary Cookies (Always Active):
- Authentication cookies (keep you logged in)
- Security cookies (prevent fraud and protect your account)
- Session management cookies
- Load balancing cookies
These cookies are essential for the Services to function and cannot be disabled.
Analytics Cookies (Requires Consent):
- Usage tracking
- Performance monitoring
- Error detection
- Feature usage statistics
Preference Cookies (Requires Consent):
- Language settings
- Display preferences
- Course progress tracking
- UI customization
Marketing Cookies (Requires Consent):
- Campaign effectiveness tracking
- Conversion tracking
- Retargeting (only with explicit consent)
5.3 Third-Party Cookies
We use the following third-party cookies:
- Stripe: Payment processing and fraud detection
- Google Analytics 4: Website usage analytics and performance tracking
- Google Tag Manager: Tag and cookie management
- Microsoft Clarity: Session recording and heatmap analysis
- OpenReplay: User experience monitoring and session replay
Each third-party service may set its own cookies. You can learn more about how these services use cookies by reviewing their respective privacy policies.
5.4 Your Cookie Choices
Managing Cookies:
- Use our Cookie Consent Manager (available at the bottom of every page)
- Adjust settings in your browser preferences
- Install browser extensions to block specific cookies
Browser Controls:
- Most browsers allow you to view, delete, and block cookies
- Blocking all cookies may prevent some features from working properly
Withdrawing Consent:
European users can withdraw cookie consent at any time through our Cookie Consent Manager. This will not affect the lawfulness of processing before withdrawal.
5.5 Do Not Track
Some browsers have "Do Not Track" (DNT) features. We currently do not respond to DNT signals, as there is no industry consensus on how to interpret them.
6. Data Security
6.1 Security Measures
We implement industry-standard security measures to protect your information:
Technical Safeguards:
- TLS/SSL encryption for all data in transit
- AES-256 encryption for data at rest
- Secure password hashing (bcrypt with salt)
- Regular security audits and penetration testing
- Firewall and intrusion detection systems
- Isolated remote environments for Avetti Security Safe Browser Extension and App
Administrative Safeguards:
- Employee background checks
- Confidentiality agreements for all staff
- Role-based access controls
- Security awareness training
- Incident response procedures
Physical Safeguards:
- Secure data center facilities (SOC 2 certified)
- 24/7 monitoring and surveillance
- Redundant power and network systems
6.2 Data Breach Notification
In the event of a data breach affecting your personal information, we will:
- Notify you within 72 hours (as required by GDPR)
- Inform relevant supervisory authorities
- Provide details about the breach and our response
- Offer guidance on protective measures you can take
6.3 Your Responsibility
You are responsible for:
- Maintaining the confidentiality of your password
- Using a strong, unique password
- Logging out after using shared devices
- Keeping your contact information up to date
- Notifying us immediately of any unauthorized access
IMPORTANT: No security system is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
7. Data Retention
7.1 Retention Periods
We retain your personal information only as long as necessary for the purposes described in this Privacy Policy:
Active Accounts:
- Account data: Retained while your subscription is active
- Course progress: Retained while your subscription is active
- Usage data: Retained for 24 months
- Technical logs: Retained for 12 months
Cancelled Accounts:
- Account data: Deleted 30 days after subscription ends
- Payment history: Retained for 7 years (tax and accounting requirements)
- Anonymized usage data: May be retained indefinitely for analytics
Customer Support:
- Support tickets: Retained for 3 years
- Communication records: Retained for 3 years
Legal Requirements:
- Data required by law: Retained as legally required
- Data subject to legal holds: Retained until hold is lifted
7.2 Deletion Process
Upon account deletion:
- Your registration key is immediately deactivated
- Access to Services is terminated at end of billing period
- Personal data is scheduled for deletion within 30 days
- Payment history is anonymized (kept for tax purposes only)
- Backups containing your data are deleted within 90 days
7.3 Right to Request Deletion
You may request deletion of your account and personal data at any time. See Section 9 for details on exercising your rights.
8. International Data Transfers
8.1 Transfer Mechanisms
We are based in Ontario, Canada. Your information may be transferred to and processed in:
- Canada (our primary location)
- United States (Stripe payment processing, cloud infrastructure)
- Other countries where our service providers operate
8.2 Safeguards for International Transfers
For European Users:
We ensure adequate protection for data transferred outside the EU through:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Service providers certified under EU-US Data Privacy Framework
- Adequacy decisions (e.g., Canada has adequacy status for commercial organizations under PIPEDA)
For All Users:
All international transfers are protected by:
- Contractual obligations requiring equivalent protection
- Technical security measures (encryption, access controls)
- Regular compliance audits
9. Your Privacy Rights
9.1 Rights for All Users
Regardless of location, you have the right to:
- Access your personal information
- Correct inaccurate information
- Request deletion of your account
- Opt out of marketing communications
- Update your communication preferences
- Export your course progress data
9.2 European Union Users (GDPR Rights)
EU users have additional rights:
- Right to Access: Request a copy of all personal data we hold about you
- Right to Rectification: Correct inaccurate or incomplete personal data
- Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data (subject to legal retention requirements)
- Right to Restrict Processing: Limit how we use your personal data in certain circumstances
- Right to Data Portability: Receive your data in a structured, machine-readable format and transfer it to another controller
- Right to Object: Object to processing based on legitimate interests or for direct marketing
- Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent
- Right Not to Be Subject to Automated Decision-Making: We do not use automated decision-making or profiling that produces legal or similarly significant effects
- Right to Lodge a Complaint: File a complaint with your national supervisory authority
Find your authority at: https://edpb.europa.eu/about-edpb/board/members_en
9.3 Canadian Users (PIPEDA Rights)
Canadian users have the right to:
- Access personal information we hold about you
- Challenge the accuracy and completeness of your information
- Withdraw consent (subject to legal or contractual restrictions)
- File a complaint with the Privacy Commissioner of Canada: https://www.priv.gc.ca
9.4 United States Users
California Residents (CCPA/CPRA):
- Right to know what personal information is collected
- Right to know if personal information is sold or shared (we do not sell information)
- Right to deletion
- Right to correct inaccurate information
- Right to opt-out of the sale of personal information (not applicable)
- Right to limit use of sensitive personal information
- Right to non-discrimination for exercising your rights
Other US States:
Users in Virginia, Colorado, Connecticut, Utah, and other states with privacy laws have similar rights. Contact us for details specific to your state.
9.5 How to Exercise Your Rights
Email:
- Send requests to [email protected]
- Include your full name, email address, and specific request
Mail:
Avetti.com Corporation
Attention: Privacy Officer
92 Caplan Avenue, Suite 206
Barrie, Ontario, L4N 9J2
Canada
Response Time:
- We will respond to requests within 30 days (GDPR, CCPA)
- We may extend by 30 days if requests are complex (with notice)
- We will verify your identity before processing requests
No Fee: We do not charge a fee for processing requests unless they are manifestly unfounded or excessive.
10. Children's Privacy
Our Services are not intended for children under 18 years of age (or the age of majority in your jurisdiction).
We do not knowingly collect information from children:
- We do not knowingly collect personal information from anyone under 18
- We do not knowingly allow children to create accounts
- If we discover we have collected information from a child, we will delete it immediately
Parents/Guardians: If you believe your child has provided us with personal information, please contact us immediately at [email protected].
11. Third-Party Links and Services
11.1 Third-Party Websites
Our Services may contain links to third-party websites. This Privacy Policy does not apply to those websites. We are not responsible for:
- The privacy practices of third-party websites
- The content of third-party websites
- Security of third-party websites
We encourage you to read the privacy policies of any third-party sites you visit.
11.2 Avetti Security Safe Browsing Extension and App and External Content
When using Avetti Security Safe Browsing Extension and App to access external websites:
- We do not track or monitor the content you view
- We do not store URLs you access through remote environments
- External websites may collect their own data according to their privacy policies
- Remote environments are isolated and temporary
12. California Shine the Light Law
California residents who have provided personal information may request information about our disclosure of certain categories of personal information to third parties for direct marketing purposes. We do not share personal information with third parties for their direct marketing purposes.
13. Changes to This Privacy Policy
13.1 Updates
We may update this Privacy Policy from time to time to reflect:
- Changes in our practices
- Changes in applicable laws
- New features or services
- Feedback from users or regulators
13.2 Notification
We will notify you of material changes by:
- Posting the updated policy on our website with a new "Last Updated" date
- Sending an email to your registered email address (for significant changes)
- Displaying a prominent notice on our platform
13.3 Acceptance
Continued use of the Services after changes become effective constitutes acceptance of the updated Privacy Policy. If you do not agree to the changes, please discontinue use and contact us to delete your account.
14. Contact Information
14.1 Privacy Officer
For questions, concerns, or requests regarding this Privacy Policy or your personal information:
Avetti.com Corporation
Attention: Privacy Officer
92 Caplan Avenue, Suite 206
Barrie, Ontario, L4N 9J2
Canada
Email: [email protected]
14.2 Data Protection Officer (EU Users)
Data Protection Officer
Email: [email protected]
14.3 Supervisory Authorities
European Users:
You have the right to lodge a complaint with your local supervisory authority. Find your authority at: https://edpb.europa.eu/about-edpb/board/members_en
Canadian Users:
Office of the Privacy Commissioner of Canada
Website: https://www.priv.gc.ca
Phone: 1-800-282-1376
California Users:
California Attorney General's Office
Website: https://oag.ca.gov/privacy
Last Updated: November 10, 2025
By using our Services, you acknowledge that you have read and understood this Privacy Policy and agree to its terms.