CCPA · United States

Privacy Policy

How AVA-X, Inc. collects, uses, and protects personal information under U.S. privacy law, including the California Consumer Privacy Act (CCPA) as amended by the CPRA.

AVA-X, Inc.

1. Controller and Contact

The business responsible for the personal information described in this Privacy Policy is:

AVA-X, Inc.

United States

Delaware

United States

Privacy contact

Enquiries relating to this Privacy Policy, consumer privacy requests, or U.S. privacy compliance should be directed to:

Postal: AVA-X, Inc., attn. Privacy, Delaware, United States.

2. Applicable Law

This Privacy Policy is issued for AVA-X, Inc. under applicable United States privacy law, including where relevant the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), other comprehensive state privacy laws, and sector or biometric laws that may apply to our products (such as Illinois BIPA where biometric identifiers are processed).

Where our processing affects individuals in other jurisdictions, we also take account of applicable foreign data protection laws (including the EU GDPR and Swiss data protection law) to the extent they apply to AVA-X, Inc..

AVA-X, Inc. processes personal information in a manner consistent with notice, purpose limitation, security, and consumer-rights obligations under U.S. privacy law.

3. Personal Information We Collect

We generally process personal information that you provide to us, that is generated through use of our website or services, or that is collected in the course of our business relationships—always for a defined, lawful purpose.

3.1 Identity and contact data

  • Name, organization, job title, postal or physical address, email address, and telephone number
  • Contract documents, billing and payment information (for example bank details and invoice data)
  • Other information you provide when communicating with us (including demo or contact form submissions)

3.2 Technical and usage data

  • IP address, browser type, operating system, device type, and access times
  • Log data when using our website, portals, or cloud-connected services

3.3 Publicly available information

Information from official registers or generally accessible sources, where necessary for business purposes, due diligence, or identification—processed only as permitted by law.

3.4 Customer / end-user operational data

Where we supply video analytics, access control, or related systems to customers, the customer is typically the controller (or “business”) for personal information processed in their environment. We may act as a service provider / processor under written instructions and appropriate agreements.

4. How We Use Personal Information

We use personal information only for the purposes set out below, and as otherwise disclosed at collection or permitted by U.S. privacy law.

Contract and service delivery

  • Entering into and performing contracts for our products and services (delivery, installation, support, licensing)
  • Customer service, communication, and invoicing

Basis: performance of a contract; legitimate business purposes where applicable.

Legal obligations

  • Compliance with statutory retention, tax, and company-law requirements
  • Responding to lawful requests from U.S. authorities and regulators

Basis: compliance with legal obligations.

Business operations and security

  • Operating, securing, and improving our website and services (including IT security and fraud prevention)
  • Establishing, exercising, or defending legal claims

Basis: legitimate business interests, balanced against your privacy rights.

Consent / marketing

  • Marketing communications (newsletters, campaigns) where consent or another lawful basis is required
  • Non-essential analytics or tracking technologies on our website

Basis: consent where required; you may opt out of marketing at any time.

5. Biometric and Sensitive Information

U.S. state laws may treat biometric identifiers (such as facial templates used for recognition) and other sensitive personal information as categories requiring heightened notice, purpose limitation, and safeguards—including under the CCPA/CPRA and, where applicable, laws such as Illinois BIPA.

Where we process biometric or other sensitive personal information in connection with our products or services (for example facial recognition or video analytics), we do so only as permitted by applicable law, with appropriate technical and organizational safeguards, and—where we act as a service provider—under customer instructions and agreements.

Customers deploying AVA-X technology remain responsible for ensuring their own compliance with applicable U.S. privacy and biometric laws in respect of individuals in their environments (including notice, consent or other required authorizations, and retention limits).

6. Service Providers and Third Parties

We only share personal information with third parties where this is necessary and lawful, including where:

  • required for contract performance (for example payment providers or logistics partners),
  • required to comply with a legal obligation (for example regulators or law-enforcement agencies),
  • provided to service providers under written agreements that impose privacy and security duties consistent with U.S. privacy law, or
  • you have consented to the disclosure.

We do not sell personal information as “sale” is commonly understood in everyday language. Where “sale” or “sharing” for cross-context behavioral advertising is defined under the CCPA/CPRA, we will disclose that practice and offer required opt-out mechanisms if applicable.

Typical recipients include:

  • U.S. authorities and regulators where required by law
  • IT, hosting, cloud, and communications service providers
  • Banks and payment processors
  • Professional advisers (legal, accounting, insurance)

7. International Transfers

Personal information collected in the United States may be processed by AVA-X, Inc. and affiliated entities or service providers in other countries. Where transfers occur, we implement appropriate contractual and technical safeguards.

Our product architecture emphasizes on-premises and sovereign deployment options so that customer operational data can remain within the United States or another chosen jurisdiction.

8. Cookies and Tracking

We use cookies and similar technologies (for example local storage) on our website to:

  • ensure essential functionality and security of the site, and
  • measure usage or support marketing where you have consented or where otherwise permitted.

Essential cookies are required for the website to operate and cannot be disabled through our consent tools.

Restricting cookies in your browser may affect site functionality. You can change or withdraw optional cookie consent at any time via our cookie banner controls where available.

9. Security Safeguards

We implement appropriate, reasonable technical and organizational measures to protect personal information against loss, damage, unauthorized access, and unlawful processing. These include:

  • Encryption of data in transit (for example HTTPS/TLS)
  • Role-based access controls and multi-factor authentication where appropriate
  • Regular security reviews, backups, updates, and testing
  • Hosting and deployment options designed for data residency and auditability

No method of transmission or storage is completely secure. We will provide breach notifications as required by applicable U.S. federal and state law.

10. Automated Processing

Where we use personal information for analytics or profiling in connection with our website or marketing, we do so as permitted by applicable law (typically consent or legitimate business purposes).

We do not make decisions with legal or similarly significant effects based solely on automated processing of personal information without appropriate human involvement. Where our products assist customers with automated analysis (for example video analytics), those customers remain responsible for ensuring human oversight and lawful use in their deployments.

11. Retention

We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, or as required by U.S. law (including tax and company records obligations). Thereafter, information is destroyed, deleted, or de-identified in a manner that prevents reconstruction in ordinary course.

Where information is needed for more than one purpose, access is restricted to the purpose still requiring retention until all applicable periods expire.

12. Your Privacy Rights

Depending on your state of residence, you may have rights that include (as applicable and subject to lawful limitations):

Access and know

You may request confirmation of whether we hold personal information about you, and request a copy or categories of that information.

Correction and deletion

You may request that we correct inaccurate personal information, or delete personal information we hold about you, subject to legal exceptions (for example records we must retain).

Opt-out of sale / sharing

Where the CCPA/CPRA or similar laws apply, you may opt out of the “sale” or “sharing” of personal information, and limit the use of sensitive personal information, as those terms are defined by law.

Withdraw consent / marketing

Where processing is based on consent, you may withdraw consent at any time. You may also opt out of electronic marketing communications; we will honour unsubscribe requests.

Exercising your rights

To exercise these rights, contact us at privacy@ava-x.us. We may request reasonable proof of identity before actioning a request, to prevent unauthorized disclosure. Authorized agents may submit requests where permitted by law.

13. California Privacy Rights (CCPA/CPRA)

If you are a California resident, the CCPA/CPRA provides additional rights, including the right to know, delete, correct, opt out of sale/sharing, and limit use of sensitive personal information, as well as non-discrimination for exercising those rights.

Categories of personal information we may collect are described in Section 3 and may include identifiers, commercial information, internet / electronic activity, professional information, and—in customer deployments—biometric information. We collect this information for the business purposes described in Section 4.

To submit a California consumer request, email privacy@ava-x.us. We will respond within the timeframes required by California law.

14. Complaints

If you believe that your personal information has been processed unlawfully, please contact us first so we can attempt to resolve the matter. Depending on your state, you may also have the right to lodge a complaint with a state attorney general or privacy regulator. California residents may contact the California Privacy Protection Agency:

California Privacy Protection Agency

Sacramento, California, United States

Website: cppa.ca.gov

15. Changes to this Policy

We may update this Privacy Policy from time to time to reflect legal, operational, or product changes. The current version is always published on this page with the "Last updated" date. Material changes will be communicated in an appropriate manner (for example by notice on our website or by email where we hold a current address for that purpose).

16. Questions and Contact

For questions, suggestions, or requests regarding privacy at AVA-X, Inc., please contact:

Privacy contact

AVA-X, Inc.

Email: privacy@ava-x.us

Postal correspondence:

attn. Privacy
Delaware, United States

Related: Privacy, CCPA & AI Ethics

Closing note

This Privacy Policy explains how we handle personal information and reflects our commitment to responsible processing under United States privacy law.

Unless otherwise stated, applicable U.S. federal and state privacy laws—including CCPA/CPRA where relevant—govern the processing described here.

© 2026 AVA-X, Inc. — All rights reserved.