Legal
Privacy Policy
Effective Date: August 28, 2026
Avermont Group is committed to protecting your personal information and your right to privacy. This Privacy Policy explains what information we collect, how we use it, and what rights you have in relation to it. This policy applies to all clients, website visitors, and individuals who interact with Avermont Group. Because we serve clients internationally, this policy is designed to align with applicable privacy laws including the California Consumer Privacy Act (CCPA), the General Data Protection Regulation (GDPR), Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), and other applicable data protection frameworks.
1. Overview
Avermont Group (we, us, or our) is committed to protecting your personal information and your right to privacy. This Privacy Policy explains what information we collect, how we use it, and what rights you have in relation to it. This policy applies to all clients, website visitors, and individuals who interact with Avermont Group.
2. Information We Collect
2.1 Information You Provide Directly
Full name and business name; email address and phone number; business address and location information; payment information (processed and stored by our payment processor; we do not store full card details); login credentials and platform access information shared during onboarding; communications and correspondence with our team.
2.2 Information Collected Automatically
Website usage data (pages visited, time on site, referral source); IP address and browser/device information; cookies and similar tracking technologies (see Section 8).
2.3 Information from Third Parties
Business profile data (e.g., Google Business Profile information relevant to service delivery); publicly available information related to your business for the purpose of delivering agreed services.
2.4 SMS and Messaging Data
In delivering SMS-based services, including review request automation, missed call text-back, and AI SMS conversation services, the Company processes phone numbers, message content, and response data on behalf of the Client. This data is used solely to deliver the contracted services. Clients are responsible for ensuring their own end-customers provided valid consent to receive SMS messages from the Client's business before instructing Avermont Group to send messages to those numbers.
3. How We Use Your Information
We use your information for the following purposes: to deliver, operate, and improve our services; to communicate with you about your account, services, and support; to process payments and manage billing; to meet our legal and contractual obligations; to detect, prevent, and address fraud or security issues; to comply with applicable law and regulatory requirements; to send service-related communications (not marketing without your consent); and for aggregate, anonymized analytics to improve our operations.
4. Legal Basis for Processing (GDPR Clients)
For clients located in the European Economic Area (EEA) or United Kingdom, our legal bases for processing your personal data are: Contractual Necessity (processing required to fulfill our service agreement with you); Legitimate Interests (processing for fraud prevention, security, and business operations); Legal Obligation (processing required by applicable law); and Consent (where we have obtained your explicit consent, e.g., marketing communications). Avermont Group does not maintain an establishment in the European Union and does not appoint a Data Protection Officer. Our alignment with GDPR is based on applicable safeguards such as Standard Contractual Clauses and the processor obligations described in this policy. Clients acting as data controllers remain responsible for their own GDPR compliance with respect to their end-customers' data.
5. Data Sharing & Disclosure
We do not sell your personal information. We may share your information only in the following circumstances: Service Delivery (with third-party tools and platforms necessary to deliver our services, subject to appropriate data processing agreements); Payment Processing (with our payment processor, Stripe, Inc., to facilitate billing, governed by their own Privacy Policy); Legal Compliance (when required by law, court order, or governmental authority); Business Transfer (in connection with a merger, acquisition, or sale of Company assets, with appropriate notice); and Protection of Rights (to protect the rights, property, or safety of Avermont Group, our clients, or the public). All third-party service providers used by Avermont Group are contractually required to protect your data and use it only for the purposes we specify.
5.1 Data Controller and Processor Roles
Where Avermont Group processes end-customer data provided by a Client (for example, phone numbers and message content for SMS services), Avermont Group acts as a data processor on behalf of the Client, who acts as the data controller. Clients serving end-users in the European Economic Area or United Kingdom are responsible for their own GDPR compliance obligations as data controllers, including obtaining valid consent and providing required notices to their end-customers.
5.2 Data Processing Agreements
EU/UK clients may request a Data Processing Agreement (DPA) by emailing askavermontgroup@gmail.com. The Company will provide a DPA within 10 business days of the request.
6. Data Retention
We retain your personal information only as long as necessary to fulfill the purposes outlined in this policy, comply with our legal obligations, resolve disputes, and enforce our agreements. Specific retention periods apply as follows: billing records are retained for 7 years (IRS compliance); client communications are retained for 3 years; platform access credentials are deleted within 30 days of service termination; and SMS message logs are retained for 2 years. When your information is no longer needed, we will securely delete or anonymize it.
7. Data Security
Avermont Group implements industry-standard technical and organizational security measures to protect your personal information against unauthorized access, disclosure, alteration, or destruction. These include but are not limited to encrypted data transmission, secure access controls, and regular security assessments. No method of transmission over the internet is completely secure, and we cannot guarantee absolute security.
7.1 Breach Notification
In the event of a data breach, the Company will notify affected clients within 72 hours of becoming aware of the breach. The Company will also notify relevant supervisory authorities as required by applicable law, including under GDPR Article 33 and the California Consumer Privacy Act.
8. Cookies
Our website uses cookies and similar tracking technologies to enhance your experience. These include: Essential Cookies (required for the website to function); Analytics Cookies (help us understand how visitors use our site); and Marketing Cookies (used to deliver relevant content, with consent where required). You may disable cookies through your browser settings. Disabling certain cookies may affect the functionality of our website.
9. Your Privacy Rights
Depending on your location, you may have the following rights regarding your personal data. All Users: right to access the personal information we hold about you; right to correct inaccurate information; right to request deletion of your data (subject to legal retention obligations). California Residents (CCPA/CPRA): right to know what personal information is collected and how it is used; right to opt out of the sale of personal information (we do not sell data); right to non-discrimination for exercising privacy rights; right to limit use of sensitive personal information. EEA/UK Residents (GDPR): right to data portability; right to restrict or object to processing; right to withdraw consent at any time; right to lodge a complaint with a supervisory authority. Canadian Residents (PIPEDA): right to access and correct personal information; right to withdraw consent, subject to legal or contractual limitations. The Company designates its Privacy Lead as the accountable person for PIPEDA purposes. To exercise any of these rights, contact our Privacy Lead at askavermontgroup@gmail.com. We will respond to all verified requests within 30 days.
10. International Data Transfers
As we serve clients internationally, your data may be processed in countries outside your own, including the United States. Where required by law, we implement appropriate safeguards (such as Standard Contractual Clauses for EU data) to help ensure your information is protected regardless of where it is processed.
11. Children's Privacy
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. If we become aware that we have collected such information, we will delete it promptly.
12. Updates to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or a prominent notice on our website. Continued use of our services after the effective date of an updated policy constitutes your acceptance of the changes.
13. Contact
For all privacy-related requests, contact our Privacy Lead at askavermontgroup@gmail.com. We will respond to all verified requests within 30 days. For general inquiries: askavermontgroup@gmail.com. Avermont Group, Pennsylvania, USA.
Related Policies