Effective August 25, 2026 · Version 1.0
Aveiro Technologies Inc. (“Aveiro,” “we,” “us,” or “our”) provides fraud, AML, compliance, screening, monitoring, risk-intelligence, investigation, API and related services (the “Services”). This Privacy Policy explains how we collect, use, disclose, retain and protect personal information through our website, waitlist, business communications and Services.
For website visitors, waitlist members, business contacts and Aveiro account administrators, Aveiro generally determines the purposes of processing. When a business customer submits personal information to Aveiro for risk assessment, screening, monitoring, transaction analysis or investigations, Aveiro generally processes that information on the customer’s instructions as a service provider or processor. The customer remains responsible for its lawful basis, notices, permissions and decisions.
Depending on the Services used, Aveiro may process business contact and account information; names, aliases, dates of birth, countries and customer identifiers; transaction and activity data; email and phone intelligence; device fingerprints and identifiers; IP, network, proxy, VPN, TOR and approximate geolocation signals; authentication and behavioral events; sanctions, PEP, watchlist and adverse-media information; corporate/entity and registry information; blockchain addresses, transaction hashes, exposure and attribution data; relationship/link information; risk scores, rules, alerts, monitoring status, analyst actions and audit records.
We collect information you submit through the waitlist, demos, account creation, billing, support, configuration, feedback and communications. Business customers may also submit information about their users, customers, applicants, counterparties, beneficiaries, owners or representatives. Customers should submit only information reasonably necessary for their configured use case.
We may process IP addresses, device/browser/OS data, device fingerprints, session information, network characteristics, API metadata, authentication events and security telemetry. Depending on configuration, Aveiro may also process logins, registrations, profile changes, beneficiary additions, transactions, deposits, withdrawals, payment attempts, amounts, currencies, timing, velocity, status, channel and behavioral patterns.
Aveiro may receive or access information from government and corporate registries, sanctions and watchlists, PEP sources, adverse-media and open-source sources, commercial risk databases, network/telecommunications intelligence, fraud intelligence, blockchain analytics and other providers. Source coverage, accuracy and availability vary.
Where enabled, Aveiro may process public blockchain addresses, transaction identifiers, on-chain activity, counterparties, exposure information, attribution labels and risk indicators. Public or pseudonymous blockchain data may constitute personal information when reasonably associated with an identifiable individual.
Aveiro may derive relationships among accounts, devices, IPs, phone numbers, emails, beneficiaries, entities, transactions and blockchain addresses. We may generate event and customer risk scores, severity/occurrence assessments, rule outcomes, alerts, clusters, monitoring status, AI summaries and other decision-support information.
We use personal information to provide and secure the Services; authenticate users; perform configured fraud, AML, watchlist, transaction and blockchain screening or monitoring; generate risk and relationship intelligence; detect abuse and account takeover; investigate incidents; support customers; administer billing; improve reliability and performance; communicate about the Services; enforce agreements; and comply with law. Broader product/model improvement using customer data is subject to applicable law, customer agreements and communicated commitments.
Aveiro may use rules, risk matrices, statistical methods, behavioral and relationship analysis, machine learning and artificial intelligence. Risk outputs can change as new events arrive and are decision-support indicators, not proof that a person or activity is fraudulent, criminal, sanctioned or non-compliant. Business customers determine how Aveiro outputs are used and are responsible for appropriate human review. AI-generated summaries or suggestions should be independently reviewed before consequential use.
Depending on context and jurisdiction, processing may be based on consent, contract, legitimate or reasonable business purposes, fraud/security prevention, legal obligations or other grounds permitted by law. Where consent is required, Aveiro seeks a form appropriate to the sensitivity and reasonable expectations involved. Consent may be withdrawn subject to legal or contractual restrictions. Customers are responsible for the legal basis applicable to data they submit for processing.
We may disclose information to service providers and subprocessors supporting hosting, security, communications, billing, analytics, screening and intelligence; the business customer that controls the relevant information and its authorized users; professional advisers, auditors and insurers; authorities where required or permitted by law; parties to a merger, financing, acquisition or similar transaction; and other parties where authorized by the individual, customer or law. We do not sell personal information as a data broker.
Providers that process personal information for Aveiro are expected to act only for authorized purposes and be subject to contractual, confidentiality and security obligations appropriate to their role. Aveiro intends to maintain a current subprocessor list as the production service matures.
Aveiro and its providers may process information outside the individual’s or customer’s country. Information may therefore be subject to the laws and lawful-access requirements of those jurisdictions. Where required, Aveiro will use appropriate contractual or other transfer safeguards. Customers with data-residency requirements should confirm available options in their order form or Data Processing Addendum.
We retain personal information only as long as reasonably necessary for the identified purposes, security, contractual commitments, disputes and legal obligations. Customer-processed data may be returned or deleted according to customer instructions, service configuration and the applicable DPA. When information is no longer required, we take reasonable steps to delete, destroy or de-identify it, subject to backup, legal-hold, security and technical limitations.
Aveiro uses administrative, technical and organizational safeguards designed to protect personal information against loss, theft and unauthorized access, disclosure, copying, use, alteration or destruction. Measures may include access controls, authentication, encryption where appropriate, logging, environment separation, secure development, monitoring, vendor controls and incident response. No system can guarantee absolute security.
Aveiro maintains processes to assess and respond to suspected privacy or security incidents. Where required by law or contract, we will notify affected customers, individuals or authorities in accordance with applicable requirements. Customers should promptly report suspected compromise of Aveiro accounts, API credentials or customer data.
We take reasonable steps appropriate to our role to maintain information sufficiently accurate, complete and current for its intended use. Because many screening and intelligence sources are supplied by customers or third parties, Aveiro cannot guarantee that all underlying information is accurate or current.
Depending on applicable law and Aveiro’s role, individuals may request access to personal information, request correction, challenge accuracy, withdraw consent where applicable, ask questions or make a complaint. We may verify identity and may limit requests where permitted or required by law. If Aveiro processes information solely for a business customer, we may direct the request to that customer or assist it in responding.
If a customer uses Aveiro outputs to support a consequential decision about an individual, questions about that decision should generally be directed to the customer controlling the decision. Aveiro may provide customers with explainability information such as triggered rules, signals, event history, score changes or analyst records, subject to legal, security, intellectual-property and third-party-data restrictions.
Our website and Services may use cookies or similar technologies necessary for authentication, security, preferences and service operation, and may use analytics or performance technologies where enabled. Before public launch, Aveiro will identify the technologies actually deployed and provide a cookie notice or consent mechanism where required.
If you join our waitlist, request information or opt in to product communications, we may use your business contact information for launch notices, product updates, invitations and related communications. You may unsubscribe from marketing communications at any time. We may still send necessary account, security or contractual communications.
The Services are designed for businesses and professional users and are not directed to children. Business customers are responsible for determining whether their use involves information about minors and for obtaining required permissions and safeguards.
Aveiro may create and use aggregated or de-identified information that does not reasonably identify an individual or customer for analytics, security, benchmarking, service improvement and performance evaluation, subject to law and contractual commitments. We will not intentionally re-identify such information except where permitted for security, testing or validation.
We may preserve, use or disclose information where required or permitted by law, court order or lawful process, to establish or defend legal claims, protect rights or security, or facilitate a permitted corporate transaction. We may challenge requests we reasonably believe are invalid or overbroad where appropriate.
We may update this Policy as Aveiro, our Services, technologies or legal obligations change. We will update the effective date and provide additional notice of material changes where required. If a change requires new consent or another legal basis, we will take appropriate steps before applying it.
Aveiro Technologies Inc. is responsible for personal information under its control and will designate a Privacy Officer or other accountable role. Privacy questions may be directed to the Privacy Officer, Aveiro Technologies Inc., at contact@aveiro.io.
We encourage individuals to contact Aveiro first so we can review and address privacy questions or complaints. If a concern is not resolved, individuals may have the right to contact the privacy regulator with jurisdiction over the matter.