Privacy Policy
Last updated: September 7, 2026
This Privacy Policy explains what personal data Avrelion ("Avrelion," "we," "us," or "our") collects through avrelion.com (the "Site") and through our security consulting engagements, how we use and store that data, and the choices available to you. It does not cover data we process as a processor on behalf of clients under a signed engagement agreement or statement of work — that processing is governed by the terms of that agreement.
1. Data We Collect
We collect the minimum data necessary to run the Site, respond to inquiries, and deliver our services.
1.1 Information you provide directly
- Contact and inquiry data — name, email address, company name, and any message content you send us via email or a contact form (e.g. contact@avrelion.com).
- Engagement data — information you provide as part of scoping, authorizing, or conducting a penetration test or forensic investigation, which may include technical infrastructure details, credentials scoped for testing, and incident-related data.
1.2 Information collected automatically
| Category | Examples | Basis |
|---|---|---|
| Strictly necessary | Session/preference cookies (e.g. your cookie consent choice), basic server logs (IP address, timestamp, user agent) needed for security and to operate the Site | Always active — necessary to provide the Site |
| Analytics (optional) | Aggregate, non-identifying usage data such as pages viewed and time on site, collected only via cookies you opt into | Consent — only set after you accept via the cookie banner |
2. How We Use Personal Data
- To respond to inquiries and provide quotes or proposals for services.
- To scope, deliver, and report on penetration testing and digital forensics engagements.
- To operate, secure, and improve the Site (including diagnosing technical issues).
- To understand aggregate Site usage, where you have opted into analytics cookies.
- To comply with legal obligations, and to establish, exercise, or defend legal claims.
We do not sell personal data, and we do not use personal data collected through the Site for third-party advertising.
3. How We Store and Protect Data
- Data is stored using reputable third-party infrastructure providers (e.g. email hosting, cloud storage) that offer industry-standard security controls, including encryption in transit.
- Engagement-related technical data (e.g. scoping documents, findings, evidence from forensic work) is stored on access-controlled systems and retained only as long as needed to deliver the engagement, satisfy contractual or legal obligations, and support any agreed remediation follow-up — after which it is deleted or securely archived per the engagement agreement.
- Contact form and inquiry data is retained for as long as reasonably necessary to respond to you and maintain business records, typically no longer than 24 months from last contact unless a longer period is required by law or an active engagement.
- We limit internal access to personal data to individuals who need it to perform their role.
4. Cookies
The Site uses a small number of strictly necessary cookies required for core functionality, and optional analytics cookies that are only set if you accept them via the cookie banner shown on your first visit. You can review or change your cookie choices at any time using the "Cookie Preferences" control in the footer of the Site. Declining or withdrawing consent does not affect the lawfulness of any processing carried out before your withdrawal.
5. Third-Party Sharing
We do not share personal data with third parties except: (a) with service providers who process data on our behalf under appropriate confidentiality and security obligations (e.g. hosting, email); (b) when required by law, regulation, legal process, or governmental request; or (c) with your consent.
6. Your Rights
Depending on your location, you may have rights to access, correct, delete, or restrict processing of your personal data, to object to certain processing, or to request a copy of your data in a portable format. To exercise any of these rights, contact us at contact@avrelion.com. We will respond within a reasonable timeframe and in accordance with applicable law.
7. Children's Privacy
The Site is intended for business use and is not directed to individuals under the age of 16. We do not knowingly collect personal data from children.
8. International Transfers
Personal data may be processed or stored in countries other than your own. Where required, we rely on appropriate legal safeguards for such transfers.
9. Changes to This Policy
We review and update this Privacy Policy on a regular basis to reflect changes in our practices, services, or applicable law. Material changes will be reflected by updating the "Last updated" date above. We encourage you to review this page periodically.
10. Contact Us
Questions about this Privacy Policy or our data practices can be sent to contact@avrelion.com.