AVbuilder

AVbuilder

Legal

Privacy Policy

Last Updated: 2025-08-31

Summary

This Privacy Policy describes how AVBuilder processes personal data when you use our Services. We act as a processor for Customer Data that organizations upload to their workspace and as a controller for account, usage, and marketing data.

2.1 Categories of Information We Collect

  • Identifiers: name, business email, phone, employer, role, display name, user ID.
  • Account & Commercial: plan, purchases, transaction history, subscription status.
  • Professional & Project Data: room templates, BOMs, drawings/specs, vendor rules, proposal content, evaluation datasets.
  • Usage & Device: app interactions, logs, IP address, user agent, cookie IDs, coarse location; crash/diagnostic data.
  • Payment: billing address, last‑4, and tokenized payment info via processors (e.g., Stripe). We do not store full card numbers.
  • Communications & Support: messages, tickets, surveys, webinar registrations.
  • Inferences: preferences derived from settings and feedback; model metrics and performance analytics.
  • Audio/Voice (optional): recordings if you use voice features.

2.2 Sources

We collect data directly from you, automatically via the Services, from your organization/administrators, and from service providers/partners (e.g., CRM, analytics, cloud hosting), as well as publicly available business information to improve quality and security.

2.3 Purposes of Use

We use information to:

  1. Provide, maintain, secure, and troubleshoot the Services; process transactions; authenticate; prevent fraud/abuse.
  2. Operate AI features; train, evaluate, and improve models and classifiers (with safeguards and, for Customer Data, only as permitted by your admin settings or agreement).
  3. Analyze usage; develop new features; personalize experiences; deliver onboarding and support.
  4. Communicate about updates, security, and marketing (you can opt out of marketing).
  5. Comply with law, enforce Terms, and protect safety and rights.

2.4 Processing Roles

  • Controller: AVBuilder for account, usage, website, and marketing data.
  • Processor: AVBuilder for Customer Data ingested into your workspace; we process under your instructions and applicable DPA.

2.5 Disclosures to Third Parties

We disclose data to: (a) vendors/processors (e.g., cloud hosting, analytics, payments, email/SMS, error monitoring, CRM); (b) integration partners at your direction; (c) professional advisors; (d) affiliates; (e) authorities where required by law; and (f) in connection with corporate transactions. We do not sell personal data for money. We may “share” identifiers and internet activity with advertising/analytics providers where allowed by law; see Your Privacy Choices.

2.6 Cookies

We use authentication cookies to keep you signed in (Supabase session) and a minimal set of analytics cookies to understand usage. We do not use advertising or cross-site tracking cookies. For a full list of cookies, their purposes, and how to manage them, see our Cookie Policy.

2.7 International Transfers

We may transfer data to the U.S. and other countries with different laws. Where required, we use appropriate safeguards (e.g., SCCs/UK IDTA) and ensure vendors provide adequate protection.

2.8 Data Retention

We keep data for as long as necessary for the purposes described, subject to contractual and legal obligations. Admins can configure workspace retention for Customer Data. We may anonymize/aggregate data for analytics.

2.9 Security

We maintain administrative, technical, and physical safeguards appropriate to the data we process, including encryption in transit, access controls, logging, and vulnerability management. No system is 100% secure.

2.10 Your Rights & Choices

Depending on your location, you may have rights to access, correct, delete, port, or opt out of certain processing (e.g., targeted ads, sale/share, profiling). You can: (a) manage settings in the app; (b) use footer links (“Do Not Sell or Share My Personal Information”); (c) send requests to privacy@avbuilder.ai; or (d) have your admin submit a workspace request. We will verify your request and respond as required by law. Authorized agents may act where permitted.

2.11 Children

AVBuilder is for professionals and is not directed to children. Do not submit children’s data.

2.12 Third‑Party Links

Our Services may contain links to third‑party sites whose practices are not ours. Review their policies.

2.13 Changes to This Policy

We may update this Policy and will post the revision date. Material changes will be announced via the Services or email.

2.14 Contact

AVBuilder Privacy — privacy@avbuilder.ai; Mailing Address: [Address].


Regional Privacy Disclosures

These regional notices supplement the Privacy Policy for residents of specific jurisdictions.

4.1 U.S. State Privacy Notice (e.g., CA, CO, CT, UT, VA, etc.)

  • Categories Collected: identifiers; commercial information; internet/network activity; geolocation (coarse); professional information; inferences.
  • Sources & Purposes: as described in §§2.2–2.3.
  • Disclosures for Business Purposes: to processors/providers (cloud, analytics, payments, CRM, communications, error monitoring), affiliates, and as required by law.
  • “Sale”/“Sharing”: We do not sell personal information for money. We may “share” identifiers and internet activity with advertising/analytics partners to deliver or measure ads. You may opt out via Your Privacy Choices links and by enabling a browser Global Privacy Control (GPC) signal, which we treat as a valid opt‑out where required.
  • Sensitive Data: We do not use sensitive personal information to infer characteristics. If we ever process sensitive data, we will do so with notice and limitations required by law.
  • Retention: per §2.7.
  • Rights: access, delete, correct, portability, and opt‑out of sale/share/targeted ads and certain profiling. Submit at privacy@avbuilder.ai or via in‑app controls. Non‑discrimination: we will not discriminate for exercising rights, but certain features may require data processing to function.

4.2 European Economic Area & United Kingdom (GDPR/UK GDPR)

  • Controller/Representative: AVBuilder, Inc.; EU/UK representative (if appointed): [Name/Contact].
  • Legal Bases: performance of a contract, legitimate interests (security, analytics, product improvement, marketing to business contacts), consent (where required), and legal obligations.
  • Data Subject Rights: access, rectification, erasure, restriction, portability, objection (including to direct marketing), and withdrawal of consent. Contact privacy@avbuilder.ai. You may lodge a complaint with your local supervisory authority.
  • International Transfers: SCCs/UK IDTA and other safeguards.

4.3 Canada (PIPEDA)

  • Purposes: as described in §§2.3; consent or other lawful bases as permitted by law. Contact us to access or correct your information.

Your Privacy Choices (US States)

This notice explains how to exercise opt‑out rights available in certain U.S. states.

5.1 Options to Opt Out of “Sale/Share” and Targeted Advertising

  • In‑App/Account Settings: Navigate to Settings → Data & Privacy → Your Privacy Choices to manage advertising and analytics preferences.
  • Site Footer Links: “Do Not Sell or Share My Personal Information.”
  • Global Privacy Control (GPC): If your browser sends a GPC signal, we treat it as a valid opt‑out for that browser.

5.2 Verification & Scope

We may need to verify your request (e.g., email confirmation, signed agent authorization). Opt‑outs apply to the device/browser and account you use and may not persist across devices unless you are logged in.

5.3 What Opting Out Changes

We will stop sharing personal information with third parties for targeted advertising and will limit analytics accordingly. Some features may still require essential cookies or service providers’ processing.

5.4 Contact

Questions? privacy@avbuilder.ai.


Data Processing Addendum (Enterprise)

Enterprise customers can request our Data Processing Addendum (DPA), which describes how AVbuilder processes Customer Personal Data on your behalf, including sub-processors, technical and organizational measures, international transfer safeguards (EU SCCs / UK IDTA), and audit rights.

To request the DPA: email privacy@avbuilder.ai with your organization name and use case.