Legal
Privacy Policy
Last updated: 27 July 2026
This Privacy Policy explains how Avaixi OÜ handles personal data for the Avaixi website, payment and checkout flows, hosted services, license services, and Avaixi products and related applications.
Who We Are
The data controller is Avaixi OÜ.
- Registration number
- 17535840
- Registered address
- Sepapaja tn 6, 15551 Tallinn, Harju Maakond, Estonia
- VAT status
- Not VAT registered
Privacy contact: privacy@avaixi.com
What Personal Data We Process
- Website request data, such as IP address, request path, browser user agent, timestamps, and security logs.
- Checkout and purchase data, such as email address, selected plan, checkout status, Stripe references, purchase status, and refund status.
- Where licensing applies, license data such as product id, plan, license status, license key hash or prefix, activation count, machine fingerprint/hash, validation result, and validation timestamps.
- Admin account data for authorized Avaixi administrators, such as GitHub user id, GitHub login, email address, and admin audit events.
- Support data you choose to send us, such as messages, screenshots, diagnostics, logs, support bundles, and issue history.
Product Data and Processing
Avaixi products may process data locally, through hosted services, or through a combination of both. The applicable product documentation describes how and where product data is processed. Data that a product is designed to keep local is not sent to Avaixi unless a feature you enable requires it or you deliberately provide it for support. Where a product uses license validation, the hosted license service may receive license and activation metadata.
Support Bundles
Some Avaixi products may let you create a diagnostic export or support bundle. Depending on the product, it may include version and package information, runtime or integration status, job history, recent logs, license status, local paths, and other diagnostic metadata. These exports are designed to avoid secrets and private content, but you should still review what you send and avoid emailing passwords, full license keys, credentials, API keys, confidential documents, or raw data exports.
Purposes and Legal Bases
- Website, downloads, and service operation
- Legitimate interests in operating and securing the website and services.
- Checkout, purchases, subscriptions, product delivery, and license operations
- Performance of a contract or steps before entering into a contract.
- Accounting, tax, fraud prevention, refunds, and consumer-rights obligations
- Legal obligations and legitimate interests in preventing misuse.
- Support and troubleshooting
- Performance of a contract, legitimate interests in resolving issues, and any information you choose to provide.
- Admin access and security audit logs
- Legitimate interests in protecting hosted administration tools and product operations.
Cookies and Browser Storage
We currently do not use analytics or advertising cookies on the public website. The site and admin area may use essential cookies for login, security, and checkout flow operation. The website may use browser session storage for interface behavior, such as product page transitions. Avaixi products may use local browser or application storage for interface preferences and session state.
Processors and Third Parties
We use service providers where needed to operate the business and product. These may include:
- Stripe for checkout, payment processing, refunds, tax-related payment records, and payment fraud prevention.
- GitHub for administrator OAuth login to Avaixi admin pages. This is for authorized administrators, not customer login.
- Hosting and infrastructure providers for the website, hosted products, license services, downloads, logs, and backups.
- Email providers for support, privacy, security, billing, and legal communications.
We do not sell personal data.
Retention
We keep personal data only as long as needed for the purposes above. Where licensing applies, license and activation records are kept while needed to provide validation, prevent abuse, support activation transfers, and maintain customer records. Purchase, invoice, refund, chargeback, and tax records may be retained for applicable legal and accounting periods. Security and technical logs are kept for a limited period unless needed to investigate abuse, fraud, outages, or security incidents. Support messages are kept as long as needed to resolve the issue and maintain service records.
Your Rights
Under the GDPR, you may have rights to access, correct, delete, restrict, object to processing, or receive a copy of your personal data. You may also have the right to withdraw consent where processing is based on consent, without affecting processing already carried out before withdrawal.
To make a privacy request, contact privacy@avaixi.com. We may need to verify your identity before acting on a request.
Complaints
You may contact us first at privacy@avaixi.com. You may also lodge a complaint with the Estonian Data Protection Inspectorate or another competent data protection authority.
International Transfers
Some providers may process data outside Estonia or the European Economic Area. Where required, we rely on appropriate safeguards such as EU standard contractual clauses, adequacy decisions, or equivalent transfer mechanisms.
Children
The website, checkout flows, hosted services, and Avaixi products are intended for business and adult users. They are not directed to children.
Changes
We may update this policy as the product, website, payment flow, or legal requirements change. The latest version will be published on this page.