Legal
Last updated: September 16, 2026 · Effective date: May 17, 2026
This Privacy Policy describes how Avenora LLC ("Avenora," "we," "us," or "our"), a Pennsylvania limited liability company, collects, uses, discloses, retains, and protects personal information in connection with the Avenora AI front desk and outbound sales coach platform (the "Service") and the avenora.ai website.
We do not sell personal information and we do not share personal information for cross-context behavioral advertising as those terms are defined under the California Consumer Privacy Act.
This Privacy Policy is incorporated into and forms part of our Terms of Service at avenora.ai/terms.
This Privacy Policy applies to:
Important — Avenora's role. When the Service processes personal information about Callers on behalf of an Account Holder, the Account Holder is generally the "business" (CCPA), "controller" (GDPR), or analogous controller of that personal information, and Avenora acts as a "Service Provider" / "processor." The Account Holder is responsible for providing required notices and obtaining required consents from Callers. Avenora processes Account Holder data (registration, billing, configuration) as a business / controller in its own right.
When you register for or use the Service as an Account Holder, we collect:
When the Service processes calls on behalf of an Account Holder, we collect:
We generate the following from inputs above:
We obtain personal information from:
On avenora.ai we use a minimal set of first-party cookies and standard server logs. We do not use third-party cross-site advertising tags, pixels, or remarketing trackers. Cookies we use are limited to:
Within the authenticated dashboard, additional functional cookies and local-storage are used for session management, preferences, and security. You can control cookies through your browser settings; doing so may impair Service functionality.
We honor the Global Privacy Control (GPC) browser signal as an opt-out from sharing where applicable; because we do not sell or share, no further action is required.
We use personal information for the following purposes:
Legal bases (where GDPR/UK GDPR applies): contract performance (provision of Service), legitimate interests (security, fraud prevention, analytics, improvement), legal obligation (regulatory compliance), and consent (where required, including SMS to wireless numbers, marketing email, optional cookies).
The Service uses Artificial Intelligence to process voice communications. This section describes what we want you to know:
When the Service sends SMS on behalf of an Account Holder to a recipient who has provided opt-in consent:
STOP, UNSUBSCRIBE, CANCEL, END, or QUIT to be removed. One final confirmation is sent.START.HELP or email support@avenora.ai.Inbound calls answered by the Service are recorded after a spoken disclosure played at the start of the call (such as "This call may be recorded for quality and training"). Recordings are stored in the Account Holder's dashboard and retained per Section 13.
Two-party-consent jurisdictions: Recording laws differ by jurisdiction. As of the Effective Date, the following U.S. states require consent from all parties to a recorded conversation (or have analogous wiretap or eavesdropping statutes): California, Connecticut, Florida, Illinois, Maryland, Massachusetts, Michigan, Montana, Nevada, New Hampshire, Oregon (in part), Pennsylvania, Vermont (in part), and Washington. Account Holders bear primary responsibility for ensuring the disclosure played by the Service satisfies all applicable requirements for any jurisdiction in which Callers are located. If you are a Caller and do not consent to recording, you may decline to continue the call.
Avenora is not a 911 substitute or a licensed emergency dispatch service. When a Caller mentions a life-safety situation during a call handled by the Service (e.g., gas leak, carbon monoxide, fire, flooding), the AI delivers a canned safety script directing the Caller to hang up and call 911 from outside the building, then creates a callback task for the Account Holder's designated emergency contact under the Account Holder's Per-Shop Emergency Protocol (Section 24.7 of the Terms of Service).
Information collected during an emergency call (Caller name, phone number, service address, problem description, recording, transcript) is processed for the purposes of (a) delivering the safety script, (b) creating the callback task, (c) notifying the Account Holder's designated emergency contact, and (d) maintaining the audit log of how the Service responded. The legal basis is the Account Holder's instructions to Avenora under the Terms of Service and the Account Holder's Per-Shop Emergency Protocol acknowledgement.
If you are a Caller and you believe you have a life-threatening emergency, hang up and call 911 immediately. Do not rely on the Service for emergency response.
When an Account Holder completes onboarding, Avenora captures and retains an audit record consisting of the Account Holder's acceptance email, approximate IP address (derived from the HTTP headers of the acceptance request), browser user-agent string (capped at 1,000 characters), timestamp of acceptance, document version, and a snapshot of the free-form emergency protocol text the Account Holder provided. This record is retained for the duration of the subscription plus four (4) years thereafter to support TCPA / contract / regulatory defense. Account Holders may request export of their own audit records by contacting privacy@avenora.ai.
We do not sell personal information. We disclose personal information only as described below.
We engage Service Providers under contracts limiting their use of personal information to providing services to Avenora. Categories of current Subprocessors:
| Category | Provider | Purpose |
|---|---|---|
| Telephony | Twilio Inc. | Call routing, SMS delivery, recording storage |
| Conversational AI | OpenAI, OpenAI, LLC | Voice realtime AI, speech-to-text |
| Conversational AI | Anthropic PBC | Post-call analysis, summarization |
| Speech-to-text | Deepgram Inc. | Operator speech transcription |
| Payments | Stripe, Inc. | Subscription billing, payment processing |
| ActiveCampaign LLC d/b/a Postmark | Transactional email delivery | |
| Database / Auth | Supabase Inc. | Database, authentication, storage |
| Hosting (web) | Vercel Inc. | Web application hosting |
| Hosting (voice) | Railway Corp. | Voice service hosting |
| Observability | Sentry (Functional Software, Inc.), Axiom Solutions Ltd. | Error tracking, log management |
| Domain & DNS | GoDaddy.com LLC | Domain registration and DNS |
We may engage additional or alternative Subprocessors at our discretion. Material changes to the Subprocessor list affecting how personal information is processed will be reflected in updates to this Policy.
When you (as an Account Holder) connect a third-party integration via OAuth or API (e.g., Google Calendar, Jobber, HousecallPro), Avenora sends or receives data within the scope you grant. The third party's handling of the data is governed by its own privacy policy.
We may disclose personal information when we believe in good faith that disclosure is necessary to: (a) comply with applicable law, court order, subpoena, or other legal process; (b) cooperate with law enforcement; (c) enforce our Terms of Service; (d) prevent or investigate fraud, security incidents, or violations of applicable law; or (e) protect the rights, property, or safety of Avenora, our customers, Callers, or the public. Where legally permitted and reasonable, we will give the affected party notice.
If Avenora is involved in a merger, acquisition, financing, reorganization, bankruptcy, dissolution, or sale of all or a portion of its assets, personal information may be transferred to the acquiring entity with continued protection under this Policy (or an updated policy of the acquirer that provides at least equivalent protection). We will provide notice of any such transfer.
We may share personal information with third parties when you specifically direct us to do so or provide consent.
We may use, disclose, and commercialize aggregated and de-identified data that cannot reasonably be used to identify any individual or household. We commit not to attempt to re-identify such data, and we contractually prohibit recipients from re-identifying it.
Avenora is based in the United States. Personal information is processed and stored in the United States and other jurisdictions where our Subprocessors operate. If you access the Service from outside the United States, you acknowledge that your personal information is being transferred to and processed in the United States. For EU/UK data subjects, the United States may not provide the same level of data protection as your home jurisdiction; by using the Service you consent to such transfer.
We retain personal information for the following periods, unless a longer period is required by law or a legal hold:
| Data type | Retention | Basis |
|---|---|---|
| Outbound coach call recordings | 4 years | TCPA / regulatory recordkeeping |
| Inbound receptionist call recordings (standard) | 1 year (365 days) | Operational / dispute resolution |
| Inbound receptionist call recordings (emergency) | 7 years | Liability / safety recordkeeping |
| Setup and support call recordings (calls between Avenora and an Account Holder) | 4 years | Contract formation / terms acceptance record |
| Call transcripts | Retained for the life of the Account; deleted on verified request or at Account closure | Operational |
| SMS message logs (sent, replies, delivery) | 18 months | TCPA / carrier defense |
| Opt-in / opt-out records (the number, the exact wording agreed to, and the date given or withdrawn) | 4 years (or longer if required by law). Retained through a deletion request — see below | TCPA defense; honoring a STOP permanently |
| Account registration and billing records | 7 years | Tax / audit compliance |
| Support inquiries | 3 years | Operational |
| Web analytics (anonymized) | Indefinite | Aggregate trend analysis |
| Server logs | 90 days (operational), up to 1 year (security) | Operational / security |
The periods above are the maximum periods we have set for each type of record. Automatic deletion at the end of a period is switched on for a record type only after that period has been confirmed with counsel. As of the "Last updated" date above it is not yet running for any record type, and no call recording we hold has yet reached the end of its period. Until it is switched on, a record is deleted when we receive a verified request (see below and Section 16), when an Account is closed (next paragraph), or when Avenora deletes it — and a call recording that has been deleted is purged from storage within 30 days. We will update this section when automatic deletion is switched on.
Upon closure of an Account, personal information is deleted or anonymized in accordance with the retention schedule above, except as required to be retained by law, contract, or to support a legal hold.
When an individual asks a shop to delete their information, we erase the call transcript in full and strip their name, phone number, email and service address from the remaining records. Four things deliberately survive, and we say so rather than leave it to be discovered:
This list is also read back to the person when a deletion is carried out, so the published policy and what they are told are the same list.
We employ administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, alteration, disclosure, or destruction, including:
No method of transmission or storage is 100% secure. We cannot guarantee absolute security. You use the Service at your own risk and should not transmit information you do not want to be subject to the inherent risks of internet transmission.
Subject to your jurisdiction and the type of relationship you have with us, you may have rights to:
How to submit: email privacy@avenora.aiwith subject line "Privacy Request" and include: (a) the right you wish to exercise; (b) sufficient information to verify your identity (your account email if an Account Holder; the phone number associated with your call records and approximate call date if a Caller; or such other information as we reasonably request); (c) your jurisdiction of residence (so we can apply the correct framework); and (d) a clear, specific description of the request.
Verification: we may ask for additional information or a sworn declaration to verify your identity, particularly for sensitive requests like deletion. We will not make decisions based on automated processing of your verification information.
Authorized agents: California consumers may use an authorized agent. We require written, signed authorization, verification of the agent's identity, and verification of the consumer's identity.
Timing: we will acknowledge your request within 10 business days and substantively respond within 45 calendar days (extendable by another 45 days with notice).
Fees: there is no fee for the first request in a 12-month period; subsequent requests in the same period that are excessive, repetitive, or unfounded may incur a reasonable administrative fee or be denied.
Appeals: if we deny a request, you may appeal by replying to our response email with the subject line "Privacy Request — Appeal." We will respond to the appeal within 60 days.
Caller requests: if you are a Caller (not an Account Holder), your communications and recordings reside in the Account Holder's account. We will route your request to the Account Holder where reasonable; the Account Holder, not Avenora, is responsible for substantive response, with Avenora's cooperation as a Service Provider.
This Section applies to California residents and supplements Section 15.
In the 12 months preceding the Effective Date, we have collected the following categories of personal information (as enumerated under Cal. Civ. Code § 1798.140):
We have disclosed these categories to the categories of Service Providers and third parties described in Section 11 of this Policy for the business purposes described in Section 7.
You have the right to:
Avenora does not sell personal information and does not share personal information for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA. No action by you is required to opt out, because opt-out is the default.
Avenora uses sensitive personal information (such as the contents of communications captured in call recordings and transcripts) only as reasonably necessary to perform the Service and for the limited purposes permitted by CPRA § 1798.121(a). We do not use sensitive personal information to infer characteristics about you for marketing or for any purpose outside those permitted business purposes.
California residents may submit requests by emailing privacy@avenora.ai with subject line "California Privacy Request" following the procedure in Section 16.
California Civil Code § 1798.83 permits California residents to request certain information regarding our disclosure of personal information to third parties for the third parties' direct marketing purposes in the preceding calendar year. Avenora does not disclose personal information to third parties for their direct marketing purposes. California residents may still email privacy@avenora.ai with subject line "Shine the Light" to confirm.
If you are a resident of Colorado (CPA), Connecticut (CTDPA), Virginia (VCDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), Iowa (ICDPA), Tennessee (TIPA), Delaware (DPDPA), New Jersey (NJDPA), Florida (FDBR), or another U.S. state with a comprehensive consumer-privacy law, you may have rights similar to the California rights described in Section 17, including (subject to state-specific scope and exceptions): right to access, right to correct, right to delete, right to portability, right to opt out of sale, right to opt out of targeted advertising, right to opt out of profiling with legal or significant effects, and right to appeal a denial.
Avenora does not sell personal information, does not engage in targeted advertising, and does not engage in profiling with legal or similarly significant effects. No action is required for these opt-outs.
To exercise other rights, email privacy@avenora.aiwith the subject line "[Your State] Privacy Request" per the procedure in Section 16. We will apply the framework most protective of your rights where state laws overlap.
Avenora is a U.S.-based business targeting U.S. HVAC contractors and does not intentionally market to or solicit data from EU or UK residents. If we receive personal data from EU or UK data subjects in the ordinary course (for example, a Caller traveling abroad), we process it on the legal bases described in Section 7. You have rights under the GDPR or UK GDPR including access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. You may exercise these rights by emailing privacy@avenora.ai or by lodging a complaint with your local supervisory authority.
Personal data is transferred to the United States. We rely on (where required) Standard Contractual Clauses or other appropriate safeguards with our Subprocessors. You may request more information at the email above.
If you are a Canadian resident, you have rights under PIPEDA including access and correction. We do not sell personal information. To exercise rights, email privacy@avenora.ai. Complaints may be directed to the Office of the Privacy Commissioner of Canada.
The Service is a B2B platform and is not directed at children under 16. We do not knowingly collect personal information from children under 13 (the U.S. COPPA threshold) or under 16 (the GDPR-K threshold). If you believe a child has provided personal information to the Service, please contact privacy@avenora.ai and we will delete it promptly upon verification.
We may incidentally collect Sensitive Personal Information when a Caller discusses health, financial, or other sensitive matters during a call. We use Sensitive Personal Information only for the limited business purposes permitted by applicable law (operating the Service requested by the Account Holder, preventing fraud, ensuring security, and complying with law), and we do not use it to infer characteristics for marketing.
Avenora is not HIPAA-compliant. The Service is not designed for the processing of Protected Health Information (PHI). Account Holders must not use the Service for PHI processing.
Avenora does not make solely-automated decisions that produce legal effects or similarly significant effects concerning you. Where AI assists in routing (e.g., emergency classification) or scheduling (e.g., proposed appointment slots), the AI output is a recommendation reviewed by a human (the Account Holder, on-call technician, or your representative) before any consequential action is taken.
Avenora does not offer any financial incentive program (such as discounts in exchange for personal information) within the meaning of CCPA § 1798.125(b).
Avenora does not track users across third-party websites and does not use third-party advertising trackers. We honor the Global Privacy Control browser signal as an opt-out where applicable.
The Service and avenora.ai may contain links to or integrate with third-party websites and services. Avenora is not responsible for the privacy practices of third parties. Review their privacy policies before providing personal information.
If you have a disability and need assistance with privacy choices, contact privacy@avenora.ai for reasonable accommodation.
If you are an employee or contractor of an Account Holder and interact with the Service in that capacity, your use of the dashboard is subject to your employer's policies, which we are not responsible for.
We may update this Policy from time to time. The "Last updated" date will change. For material changes affecting how we use personal information, we will provide notice via email or in-app at least 14 days before the change takes effect, where reasonably practical. Continued use of the Service after the effective date indicates acceptance.
Avenora LLC
Attention: Privacy Officer
502 W 7th St STE 100
Erie, PA 16502, USA
Email: privacy@avenora.ai
Support: support@avenora.ai
Legal: legal@avenora.ai
Where required by state law (e.g., California for businesses meeting certain thresholds), Avenora will publish annual metrics regarding privacy-request volume in this Section. Avenora is below applicable thresholds for the current reporting period.