Legal
Privacy Policy
Last updated 29 July 2026
This policy explains how Averanta Studio (“we”, “us”) handles personal data when you visit averanta.studio, submit an enquiry, use a project thread (including as an invited teammate), sign an in-thread agreement, or pay for services. We process data in line with UK GDPR and the Data Protection Act 2018.
Who we are
Averanta Studio provides AI consultancy and related software services. For privacy questions, contact hello@averanta.studio.
What we collect
Depending on how you use the site, we may process:
- Enquiry details — name, email, company, package interest, and what you tell us about your product or workflow when you book a call or submit an intake form.
- Project thread content — messages exchanged in a ticket thread (including by invited teammates), call proposals, scheduling details, and related status updates.
- Team access details — names and emails of people invited to a project thread, who invited them, and invite-related transactional email.
- Access and security data — one-time email verification codes and an essential session cookie used after successful verification so you can reopen the thread without re-entering a code every visit (the cookie expires automatically after a limited period).
- Agreement records — Statement of Work or NDA content we send you, plus acceptance details such as signer name, email, time, drawn signature image where provided, and limited technical metadata (for example IP address and browser user agent) used to evidence acceptance. Accepted agreements may be available as downloadable PDFs.
- Payment-related data — billing email, name, and payment status via Stripe. We do not store full card numbers on our servers. Invoice PDFs may be available from the thread where applicable.
- Staff account data — name, email, and login session data for people with admin access.
- Technical data — standard server logs such as IP address, browser type, and request timing, used for security and reliability.
How we use your data
- Respond to enquiries and run discovery or paid engagements.
- Create and operate your project thread, including messaging, teammate invites, call proposals, invoices, agreements, and related PDF downloads.
- Send transactional email (thread links, invite notices, verification codes, and service updates related to your request).
- Process payments and keep accounting records.
- Record and evidence agreement acceptance where you sign in-thread.
- Secure the service, prevent abuse, and debug issues.
- Comply with legal obligations.
We do not sell your personal data. We do not use your enquiry or thread content to train public AI models.
Legal bases
- Contract / steps prior to contract — handling enquiries, delivering booked sessions, and providing the client portal.
- Legitimate interests — securing the service, improving reliability, and basic business administration, balanced against your rights.
- Legal obligation — tax and accounting records for payments.
- Consent — where we rely on it for a specific optional use (we will say so at the point of collection).
Cookies and similar tech
We use essential cookies only — for example a project-thread session cookie after you verify with an email code (so you stay signed into that thread for a limited period), and staff authentication cookies for the admin area. We do not use advertising cookies or third-party analytics trackers on the marketing site.
Processors we use
We use trusted providers to run the service. They process data on our instructions:
- Stripe — payments and invoices (Stripe Privacy Policy).
- Resend — transactional email delivery.
- Hosting / database providers — application hosting and storage for tickets, messages, and related records.
Some providers may process data outside the UK. Where that happens, we rely on appropriate safeguards such as the UK International Data Transfer Agreement or equivalent mechanisms required by law.
How long we keep data
- Enquiries and project threads (including messages, teammate invites, and related records) are kept while the engagement is active and for a reasonable period afterwards for continuity and dispute handling, unless you ask us to delete them sooner and we have no legal need to retain them.
- Accepted agreements and payment or invoice records are retained as needed for contract evidence, tax, and accounting (payment records typically up to six years in the UK).
- Verification codes expire automatically after a short period. Session cookies expire automatically after a limited period.
Your rights
Under UK GDPR you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion (in certain circumstances)
- Restrict or object to certain processing
- Data portability (where applicable)
- Withdraw consent where processing is based on consent
Email hello@averanta.studio to exercise these rights. You can also complain to the Information Commissioner’s Office (ICO).
Children
Our services are aimed at businesses and professionals. We do not knowingly collect personal data from children.
Changes
We may update this policy from time to time. The “Last updated” date at the top will change when we do. Continued use of the site after an update means you acknowledge the revised policy.
Contact
Privacy requests: hello@averanta.studio
See also our Terms of Service.