Data & Privacy

Your Data is Yours

We handle your startup's most sensitive information -- financial data, legal documents, team credentials. Here is exactly what we collect, why we collect it, and how we protect it.

Our Data Principles

Six commitments we make to every founder who trusts us with their organisation's data.

Privacy by Design

Privacy is not a compliance checkbox at Orgvatar -- it is an architectural principle. Every feature is designed with data minimisation and purpose limitation as first-order constraints, not afterthoughts.

Encryption at Rest and in Transit

All startup data, consultation transcripts, and tool credentials are encrypted at rest using AES-256. All data in transit uses TLS 1.3. Credential vault secrets are encrypted before storage and never logged.

You Own Your Data

Your startup's data -- consultation history, org blueprints, tool credentials, and documents -- belongs to you. We do not sell it, share it with third parties, or use it to train models without explicit consent.

Data Minimisation

We collect only what is necessary to deliver the service. Enrichment data (LinkedIn profiles, website content) is used solely to personalise your V-Avatar consultations and is never shared externally.

Right to Deletion

You can request deletion of your account and all associated data at any time. Deletion is permanent and irreversible. We retain anonymised, aggregated usage statistics that cannot be linked back to you.

Audit Trail

Every action taken by a V-Avatar on your behalf is logged in an immutable execution log. You have full visibility into what your virtual team has done, when, and why.

What We Collect and Why

The table below is a complete inventory of every category of data Orgvatar collects, the purpose for which it is collected, and how long we retain it. There are no hidden data practices.

CategoryWhat We CollectWhyRetention
Account DataName, email address, OAuth identityAuthentication and account managementUntil account deletion
Startup ProfileCompany name, industry, stage, team size, runwayPersonalising V-Avatar consultationsUntil account deletion
Enrichment DataLinkedIn profiles, company website content (scraped)Pre-populating Ava's consultation contextUntil account deletion or manual removal
Consultation DataChat transcripts, stage outputs, confidence scoresDelivering and improving the consultation experienceUntil account deletion
Org BlueprintRecommended avatar team, job scopes, ROI analysisDeploying and configuring your virtual organisationUntil account deletion
Tool CredentialsAPI keys and OAuth tokens for connected tools (e.g., Xero, GitHub)Enabling V-Avatars to take actions in connected systemsUntil credential is removed or account deleted
Execution LogRecords of actions taken by V-Avatars in connected toolsAudit trail and founder accountability90 days rolling, then anonymised
Payment DataSubscription tier, Stripe customer ID (no card numbers)Billing and plan managementAs required by financial regulations (7 years)
Usage AnalyticsPage views, feature usage, session duration (anonymised)Product improvement24 months, anonymised

Security Architecture

Orgvatar is built on a security-first architecture. The following controls are in place for every production deployment.

Credential Encryption

Tool credentials (API keys, OAuth tokens) are encrypted with AES-256 before storage. Keys are never logged or transmitted in plaintext.

TLS 1.3 in Transit

All data between your browser and Orgvatar's servers is encrypted using TLS 1.3. HTTP connections are automatically redirected to HTTPS.

JWT Session Tokens

Authentication sessions use signed JWT tokens with short expiry windows. Tokens are rotated on every login and invalidated on logout.

Approval Gates

High-risk actions (payroll runs, infrastructure changes, payment links) require explicit founder approval via a cryptographically signed email token before execution.

Immutable Execution Log

Every action taken by a V-Avatar is written to an append-only execution log. Records cannot be modified or deleted by any user.

S3 Encrypted Storage

Generated documents (employment agreements, financial models, pitch decks) are stored in encrypted S3 buckets with access controlled by signed URLs.

Your Rights

Under GDPR, CCPA, and equivalent data protection laws, you have the following rights with respect to your personal data held by Orgvatar. To exercise any of these rights, contact us at [email protected].

Right of Access

Request a complete export of all personal data we hold about you.

Right to Rectification

Request correction of inaccurate or incomplete personal data.

Right to Erasure

Request deletion of your account and all associated data.

Right to Portability

Receive your data in a structured, machine-readable format.

Right to Restrict Processing

Request that we limit how we use your data while a dispute is resolved.

Right to Object

Object to processing of your data for direct marketing or profiling purposes.

Questions About Your Data?

Our Data Protection Officer is available at [email protected]. For the full legal text, read our Privacy Policy.