Aveexia · legal information
Privacy Policy
Last updated: 8 september 2026 · v2026-09-08
Controller identity
For Aveexia website, account and contact data, Aveexia is normally the controller. When Aveexia processes personal data in a customer's AI receptionist on the customer's instructions, the customer is normally controller and Aveexia processor. See the DPA.
Purposes and legal bases
- provide accounts, support and contracted services: contract or legitimate interest
- handle security, incidents and abuse: legitimate interest and legal obligation
- send marketing: consent where required, otherwise an applicable lawful basis with an opt-out
- optional analytics and marketing tools: consent before loading where consent is required.
Categories and recipients
This may include contact, account, usage, support, integration, message, voice and technical log data. The customer must not submit more information than necessary.
Providers and roles are described in the subprocessor register. We do not describe a provider as verified without checking the active configuration, region and contract.
Storage, transfers and deletion
Retention periods are described in the retention matrix and may be affected by contracts, backups, legal requirements and provider deletion windows. Current regions and transfer mechanisms must be verified for each active provider; we therefore make no blanket EU-only or zero-retention claim here.
Your rights
You may request access, rectification, erasure, restriction, data portability and object to processing where the applicable rules provide that right. Send requests to privacy@aveexia.com. We may need to verify identity and coordinate with the customer where Aveexia acts as processor.
You have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY).
Version
Version 2026-09-08. This policy is complemented by the cookie policy, DPA and the internal DSAR runbook.