Avo Automation - Global Website Privacy Policy
Applicable to operations in India, Austria (EU), the United Kingdom, the United Arab Emirates, and the United States, and to all visitors and users of our Website worldwide.
|
Last Updated |
July 2026 |
|
Effective Date |
July 2026 |
1. Introduction
Avo Automation ("we," "us," "our," or the "Company") is headquartered in India and operates internationally, including in Austria, the United Kingdom, the United Arab Emirates, and the United States. We respect your privacy and are committed to protecting the personal data of everyone who interacts with us-including visitors to www.avoautomation.com (the "Website"), prospects, customers, partners, and job applicants, regardless of where you are located. This Privacy Policy ("Policy") explains what personal data we collect, why we collect it, how we use, share, and protect it, and what rights you have over it. This Policy is designed to be globally applicable and, in particular, incorporates the requirements of the jurisdictions in which we operate:
- India-The Digital Personal Data Protection Act, 2023 ("DPDPA") and its implementing rules;
- Austria and the European Union-The General Data Protection Regulation ("EU GDPR") and Austria's Datenschutzgesetz (DSG), applicable to individuals in the EU/EEA;
- United Kingdom-The UK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025, enforced by the Information Commissioner's Office (ICO);
- United Arab Emirates-Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data ("UAE PDPL"), enforced by the UAE Data Office (and, where applicable, the DIFC or ADGM data protection regimes);
- United States (California)-The California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), and the California Invasion of Privacy Act ("CIPA");
- Other applicable data protection and privacy laws in jurisdictions where we operate or where our users are located, including other U.S. state privacy laws, Brazil's LGPD, Canada's PIPEDA, and similar frameworks, to the extent they apply.
This Policy applies globally to all visitors and users of our Website, irrespective of location. Where a specific law's terminology or rights regime applies only to individuals in that jurisdiction (for example, DPDPA rights for individuals in India, or CCPA rights for California
residents), this is noted in the relevant section. As a matter of policy, however, we extend the core data protection principles and rights described in this Policy to all individuals, regardless of jurisdiction, except where doing so would conflict with applicable law.
2. Key Definitions
For clarity across jurisdictions, the following terms are used interchangeably in this Policy:
- Personal Data / Personal Information means any information that identifies, relates to, describes, or could reasonably be linked, directly or indirectly, with a particular individual.
- Sensitive Personal Data means personal data revealing financial information, health data, biometric or genetic data, sexual orientation, religious or political beliefs, government-issued identifiers, precise geolocation, or other categories treated as sensitive under applicable law.
- Processing means any operation performed on personal data, including collection, recording, storage, use, disclosure, transfer, or erasure.
- You / Data Principal / Data Subject / Consumer means the individual to whom the personal data relates.
- We / Data Fiduciary / Controller / Business means Avo Automation, which determines the purpose and means of processing your personal data.
3. Information We Collect
We collect personal data in the following ways:
3.1 Information You Provide Voluntarily
We collect information you submit directly through website forms, account registration, demo requests, customer support, surveys, or job applications, including:
- Name
- Email address
- Phone number
- Company name and job title
- Country and billing/shipping address (where applicable)
- Account credentials
- Payment information (processed via secure third-party payment processors)
- Any other information you choose to share with us
We obtain your consent before collecting form submissions where consent is the applicable legal basis. You may withdraw consent at any time, as described in Section 9 (Your Privacy Rights).
3.2 Information Collected Automatically
- When you visit our Website or use our products, we may automatically collect:
- IP address, browser type, device identifiers, and operating system
- Pages visited, time spent, click patterns, and referral/exit URLs
- Approximate location derived from IP address
- Cookie and similar tracking technology data (see Section 5)
3.3 Information from Third Parties
- We use tools such as Google Analytics and HubSpot to understand site usage and improve performance. These tools may collect browsing behavior, device metadata, and interaction statistics, subject to the consent and opt-out controls described below.
- We may receive personal data about you from business partners, data enrichment providers, publicly available sources, or social media platforms (where you interact with our content), which we combine with information collected directly from you.
4. Purpose of Processing and Lawful Basis
We process personal data only for specified, lawful purposes that are clearly communicated to you, and we do not use personal data for purposes incompatible with those communicated at the time of collection. We rely on one or more of the following lawful bases, as applicable under the relevant law:
- Consent-where you have given clear, informed, and specific consent (the default basis under DPDPA, and one of several bases under GDPR);
- Contractual necessity-to provide products or services you have requested or to fulfil a contract with you;
- Legal obligation-to comply with applicable laws, regulations, or lawful requests from authorities;
- Legitimate interests-to operate, secure, and improve our business, balanced against your rights and expectations (relied on only where permitted, e.g., under GDPR);
- Legitimate uses-in limited circumstances recognized under DPDPA, such as where you have voluntarily provided data for a specified purpose and have not indicated objection.
We use personal data to:
- Respond to inquiries and demo requests
- Provide, maintain, and improve our products, services, and technical support
- Process transactions and send related communications
- Send marketing communications, only with your consent or as otherwise permitted by law, and always with an easy opt-out
- Conduct website and product analytics and performance improvement
- Detect, prevent, and investigate fraud, security incidents, or unlawful activity
- Comply with legal, regulatory, and contractual obligations
5. Cookies, Tracking Technologies, and CIPA Compliance
We implement strict controls over tracking technologies to comply with the California Invasion of Privacy Act (CIPA) and similar laws globally:
- No Session Replay or High-Risk Tracking Tools-We do not use session replay software, keystroke logging, or other high-risk interception technologies without disclosure and consent.
- Consent-Gated Analytics-We use Google Analytics and HubSpot only after receiving consent in jurisdictions that require opt-in consent. In jurisdictions that permit opt-out models, we provide a clear mechanism to opt out (see Section 9).
- Cookie Consent Banner-We have deployed a cookie consent management platform (e.g., Cookiebot/OneTrust) that allows you to actively select, manage, and withdraw your cookie preferences at any time.
- Blocked by Default-Non-essential analytics, marketing, and tracking cookies are blocked until you affirmatively opt in, where required by applicable law.
A dedicated Cookie Policy, available on our Website, lists all cookies in use, their purpose, duration, provider, and whether each is essential or optional.
6. How We Share Your Information
We do not sell your personal data for monetary consideration. We may share personal data with:
- Service providers and processors-such as Google Analytics, HubSpot, cloud hosting, customer support, and payment processing vendors, who process data on our behalf under contractual confidentiality and data protection obligations;
- Affiliates and group companies-for internal business operations, consistent with this Policy;
- Professional advisors-such as auditors, lawyers, and insurers, where necessary;
- Regulators and authorities-where required by law, legal process, or to protect our rights, property, or safety, or that of others;
- Business transferees-in connection with a merger, acquisition, financing, or sale of assets, subject to confidentiality protections.
Where required under CCPA/CPRA, we identify whether any sharing constitutes a "sale" or "sharing" of personal information (including for cross-context behavioral advertising) and provide an opt-out mechanism described in Section 9.3.
7. Data Security
We maintain administrative, technical, and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration, or destruction. We are ISO 27001:2022 certified and SOC 2 Type II compliant, and we maintain:
- Strict access controls and role-based permissions
- Encryption of data in transit and, where appropriate, at rest
- Preserved audit logs and system configurations
- Regular security audits, vulnerability assessments, and penetration testing
- Documented incident response and breach notification procedures
No method of transmission or storage is completely secure. If we become aware of a personal data breach likely to result in risk to your rights, we will notify affected individuals and the relevant supervisory authority-such as the Data Protection Board of India, the Austrian Datenschutzbehörde or other EU supervisory authority, the UK Information Commissioner's Office, or the UAE Data Office-without undue delay and in accordance with applicable law and statutory timelines in the relevant jurisdiction.
8. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including for satisfying any legal, accounting, or reporting requirements, or to establish, exercise, or defend legal claims. In determining retention periods, we consider:
- The amount, nature, and sensitivity of the personal data
- The purpose for which we process it and whether that purpose can be achieved through other means
- Applicable legal, regulatory, tax, or accounting retention requirements
Where you withdraw consent or your data is no longer necessary for the purpose for which it was collected, and there is no other legal basis or legal requirement to retain it, we will erase or anonymize your personal data within a reasonable period, consistent with DPDPA's erasure requirements and similar obligations under GDPR and CCPA/CPRA.
9. Your Privacy Rights
Depending on your location, you have certain rights over your personal data. We honor these rights for all users globally as a matter of policy, regardless of jurisdiction, except where limited by law.
9.1 Rights for All Users
- Right to Access-Know what personal data we hold about you and how it is processed.
- Right to Correction-Request correction of inaccurate or incomplete personal data.
- Right to Erasure/Deletion-Request deletion of your personal data, subject to legal retention requirements.
- Right to Withdraw Consent-Withdraw consent at any time, as easily as you gave it. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
- Right to Grievance Redressal-Lodge a complaint regarding our handling of your personal data and receive a response within a reasonable timeframe.
9.2 Additional Rights for Individuals in India (DPDPA)
- Right to nominate-Nominate another individual to exercise your rights in the event of your death or incapacity.
- Right to grievance redressal-Raise complaints regarding our processing of your personal data with our Grievance Officer (see Section 14).
9.3 Additional Rights for Individuals in the EU/EEA, including Austria (GDPR)
- Right to restriction of processing-Request that we limit how we use your data in certain circumstances.
- Right to data portability-Receive your personal data in a structured, commonly used, machine-readable format, and have it transmitted to another controller.
- Right to object-Object to processing based on legitimate interests or for direct marketing purposes.
- Rights related to automated decision-making-Not be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects, and to request human intervention.
- Right to lodge a complaint-with your local EU/EEA data protection supervisory authority, such as the Austrian Datenschutzbehörde (DSB), or the supervisory authority of your habitual residence or place of alleged infringement.
9.4 Additional Rights for Individuals in the United Kingdom (UK GDPR / DPA 2018)
Individuals in the UK have substantially the same rights as those described in Section 9.3 for the EU/EEA, under the UK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025. This includes the rights to access, rectification, erasure, restriction, portability, objection, and safeguards relating to automated decision-making (subject to the UK's updated automated decision-making framework). UK individuals may lodge a complaint with the Information Commissioner's Office (ICO).
9.5 Additional Rights for Individuals in the United Arab Emirates (UAE PDPL)
- Right to access-Confirm whether we are processing your personal data and obtain a copy of it.
- Right to rectification and erasure-Request correction of inaccurate data or deletion of your data (including a right to be forgotten), subject to legal exceptions.
- Right to data portability-Receive your personal data in a structured, machine-readable format to transfer it to another service provider.
- Right to object-Object to processing for direct marketing or automated profiling purposes, and have such processing stop.
- Right to lodge a complaint-with the UAE Data Office, or, where applicable, the DIFC Commissioner of Data Protection or the ADGM Office of Data Protection.
9.6 Additional Rights for California Residents (CCPA/CPRA and CIPA)
- Right to know and access-the categories and specific pieces of personal information collected, sources, purposes, and third parties with whom it is shared.
- Right to delete-your personal information, subject to statutory exceptions.
- Right to correct-inaccurate personal information.
- Right to opt out of sale or sharing-of personal information, including cross-context behavioral advertising. We do not currently sell personal information for monetary consideration.
- Right to limit use of sensitive personal information-to purposes necessary to provide the requested goods or services.
- Right to non-discrimination-We will not deny goods/services, charge different prices, or provide a different level of service because you exercised a privacy right.
- Right to opt out of tracking technologies-covered by CIPA, including analytics and advertising cookies, as described in Section 5.
- Authorized agent-You may designate an authorized agent to submit requests on your behalf, subject to identity verification.
9.7 How to Exercise Your Rights
You may submit a request through our Data Privacy Request Page, or by emailing privacy@avoautomation.com. We may need to verify your identity before processing your request. We will respond within the timeframe required by applicable law (for example, statutory timelines under DPDPA, GDPR, and CCPA/CPRA, which may vary by jurisdiction). Requests are tracked and monitored through our Data Request Manager.
10. Children's Privacy
Our Website and services are not directed to children, and we do not knowingly collect personal data from individuals under the age of 18 without verifiable parental or guardian consent, consistent with DPDPA's protections for children. Where local law sets a different age threshold for consent-for example, under EU/UK GDPR (typically 13–16, depending on member state), or under the UAE PDPL-we apply the threshold required by that law for the relevant individual. If we become aware that we have collected personal data from a child without appropriate consent, we will take steps to delete that information promptly.
11. International Data Transfers
As we operate from India and conduct business in Austria, the United Kingdom, the United Arab Emirates, and the United States, your personal data may be stored, processed, or transferred across these and other jurisdictions in which we or our service providers operate. Where we transfer personal data across borders, we apply appropriate safeguards, including, as applicable:
- Under DPDPA (India)-transferring data only to jurisdictions that are not restricted by the Central Government of India.
- Under EU GDPR (Austria/EU)-relying on adequacy decisions, Standard Contractual Clauses (SCCs), or other legally recognized transfer mechanisms.
- Under UK GDPR-relying on UK adequacy regulations, the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU SCCs.
- Under UAE PDPL-transferring data only where the destination jurisdiction offers an adequate level of protection (as determined by the UAE Data Office), or by relying on contractual safeguards (SCCs/BCRs) or explicit, informed consent where neither adequacy nor contractual safeguards apply.
- Under CCPA/CPRA (US-California)-imposing contractual obligations on service providers and third parties restricting their use and onward transfer of personal information.
Where we act as a controller/data fiduciary established in India transferring data to our operations or service providers in Austria, the UK, the UAE, or the US (or vice versa), we ensure that an appropriate transfer mechanism recognized under the originating jurisdiction's law is in place before the transfer occurs.
12. Automated Decision-Making and Profiling
We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing without human involvement. Where we use automated tools (for example, lead scoring or marketing personalization), you may request human review of any decision that significantly affects you, as described in Section 9.
13. External Links
Our Website may contain links to third-party websites, plug-ins, and applications. Clicking those links may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy practices. We encourage you to review the privacy policy of every website you visit.
14. Grievance Officer and Data Protection Contacts
In accordance with the Digital Personal Data Protection Act, 2023, we have appointed a Grievance Officer to address your concerns regarding the processing of your personal data:
Grievance and Data Protection Officer: Shouvik Banerjee-Head of Legal.
Email: shouvik.banerjee@avoautomation.com
Address: AVO AUTOMATION PRIVATE LIMITED- 40/A SLK1, KHB Industrial Area, Yelahanka, Bangalore, Bangalore North, Karnataka, India, 560064.
If you are not satisfied with our response, you have the right to escalate your complaint to the relevant supervisory authority for your jurisdiction, including:
- India: The Data Protection Board of India
- Austria/EU: the Austrian Datenschutzbehörde (DSB), or your local EU/EEA supervisory authority
- United Kingdom: The Information Commissioner's Office (ICO)
- United Arab Emirates: the UAE Data Office (or the DIFC/ADGM data protection authority, where applicable)
- United States (California): the California Privacy Protection Agency (CPPA)
15. Data Privacy Request Page
We maintain a Data Privacy Request page where you may submit:
- Access requests
- Correction requests
- Deletion requests
- Opt-out requests (including opt-out of sale/sharing and tracking technologies)
- Consent withdrawal requests
- Grievances and complaints
All requests are logged, tracked, and monitored through our Data Request Manager to ensure timely resolution in accordance with applicable statutory timeframes.
16. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. The "Last Updated" date at the top of this Policy indicates when it was last revised. We review this Policy at least annually, and on a more frequent basis where there is a material change in our data processing activities or in applicable law. Where required by law, we will notify you of material changes through the Website or by other appropriate means.
17. Contact Us
For privacy-related questions, requests, or concerns, please contact us at:
Email: privacy@avoautomation.com
|
Registered Adress (Austria/EU, if appliable) |
Avo Automation GmbH, Saturn Tower, Leonard-Bernstein-Strasse 10/8th Floor 1220 Vienna. |
|
Registered Adress (United States, if applicable) |
Avo Automation Inc, 525 Vine St. Suite 2300, Cincinnati, OH 45202 USA. |
|
Registered Address (United Kingdom, if applicable) |
Avo Automation UK Pvt, Ltd. 10 John Street, London, WC IN 2 EB United Kingdom. |
|
Registered Address (United Arab Emirates, if applicable) |
Automation Solutions Private Limited- Cloud Suite 208 Desks D03-D04,15, Al Sarab Tower, Abu Dhabi Global Market Square, Abu Dhabi, Al Maryah Island, United Arab Emirates. |
|
Registered Address (India-Head Office) |
AVO AUTOMATION PRIVATE LIMITED- 40/A SLK1, KHB Industrial Area, Yelahanka, Bangalore, Bangalore North, Karnataka, India, 560064. |
Annex A - Cross-Jurisdictional Compliance Summary
The table below summarizes how this Policy addresses the principal requirements of DPDPA 2023 (India), the EU GDPR (including Austria), the UK GDPR/DPA 2018, the UAE PDPL, and CCPA/CPRA (California, US), to assist internal compliance review across all jurisdictions in which we operate.
|
Requirement |
DPDPA 2023 (India) |
GDPR / Austria (EU) |
UK GDPR / DPA 2018 (UK) |
UAE PDPL (UAE) |
CCPA/CPRA & CIPA (US-California) |
|
Governing concept |
Data Fiduciary / Data Principal |
Controller / Processor / Data Subject |
Controller / Processor / Data Subject |
Controller / Processor / Data Subject |
Business / Service Provider / Consumer |
|
Legal basis |
Consent or "legitimate uses" |
Consent, contract, legal obligation, legitimate interest |
Consent, contract, legal obligation, legitimate interest (plus recognized legitimate interests) |
Consent (default); contract/legal obligation as exceptions |
Disclosed business/commercial purpose |
|
Consent standard |
Free, specific, informed, unconditional, itemized; withdrawable as easily as given |
Freely given, specific, informed, unambiguous |
Same as EU GDPR, with relaxed cookie-consent exemptions for low-risk uses |
Explicit, free, specific, informed, revocable |
Opt-out model (opt-in for minors and sale/sharing) |
|
Key individual rights |
Access, correction, erasure, grievance redressal, nominate a representative |
Access, rectification, erasure, restriction, portability, objection, automated-decision safeguards |
Same as EU GDPR; modified automated decision-making rules |
Access, rectification, erasure, portability, object to direct marketing/profiling |
Know, delete, correct, opt out of sale/sharing, limit sensitive PI use, non-discrimination, portability |
|
Designated contact |
Grievance Officer (mandatory) |
Data Protection Officer (where applicable) |
Data Protection Officer / Senior Responsible Individual (where applicable) |
DPO mandatory for large-scale sensitive data/high-risk processing |
Designated request methods (toll-free number/webform) |
|
Breach notification |
Notify Data Protection Board of India and affected Data Principals |
Notify supervisory authority within 72 hours; notify individuals if high risk |
Notify ICO within 72 hours; notify individuals if high risk |
Notify UAE Data Office and affected individuals without undue delay |
No fixed statutory deadline; reasonable security required; private right of action for certain breaches |
|
Cross-border transfers |
Permitted except to countries restricted by the Central Government |
Adequacy decisions, SCCs, or other approved safeguards |
Adequacy regulations, UK SCCs/IDTA, or approved safeguards |
Adequacy, contractual safeguards (SCCs/BCRs), or explicit consent |
Contractual safeguards; service-provider agreements restricting use/sale |
|
Children/minors |
Verifiable parental consent under 18 |
Parental consent typically required under 16 (varies 13–16 by member state) |
Same as EU, with enhanced protections under DUAA 2025 |
Parental/guardian consent for minors as defined under UAE law |
Opt-in consent required to sell/share data of consumers under 16 |
|
Regulator |
Data Protection Board of India |
National supervisory authority (e.g., Austrian Datenschutzbehörde) |
Information Commissioner's Office (ICO) |
UAE Data Office |
California Privacy Protection Agency (CPPA) |