1. Information We Collect
We collect the following categories of information:
- Account information. Name, work email, company, role, and authentication identifiers when an administrator or end user registers or is provisioned by your organization.
- Billing information. Company billing contact, VAT/tax IDs, and payment metadata (processed by our payment provider — we do not store full card numbers).
- Session metadata. Connection times, assigned pool, gateway region, client IP, session duration, and error codes needed to operate and troubleshoot the service.
- Device & technical information. Client type (browser, native), operating system, screen resolution, and network performance metrics reported by the client.
- Support communications. Messages, tickets, and attachments you send us.
2. Session & Desktop Data
AvidiaVDI streams pixels from a remote virtual desktop to your endpoint over an encrypted transport. We operate a non-custodial model for what happens inside those desktops:
- We do not inspect, record, index, or scan the contents of desktop sessions, keystrokes, clipboard, or files inside your virtual machines.
- Non-persistent desktops are ephemeral. Session state is destroyed on logout or pool recycle unless your administrator has configured persistent profiles or attached storage volumes.
- Persistent volumes and profile data configured by your administrator remain within the region and storage class your organization selects.
3. How We Use Information
We use the information described above to:
- Provision, operate, secure, and maintain the AvidiaVDI service.
- Authenticate users, enforce access policies, and prevent abuse or fraud.
- Investigate incidents, diagnose issues, and provide customer support.
- Bill customers and comply with tax, accounting, and legal obligations.
- Send service and security notifications, and (where permitted) product updates.
- Improve reliability, performance, and capacity planning using aggregated metrics.
4. Legal Bases for Processing
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
- Contract. To deliver the service to customers and their authorized users.
- Legitimate interests. To secure and improve the service, prevent fraud, and communicate about material changes.
- Legal obligation. To meet tax, accounting, and lawful-request obligations.
- Consent. Where required, for optional cookies, marketing communications, or specific product features.
6. International Transfers
AvidiaVDI operates data centers in multiple regions. Customers choose the region for their tenant, and desktop workloads run in that region. Where personal data is transferred internationally (for example, to provide global support), we rely on European Commission Standard Contractual Clauses, the UK IDTA, and additional safeguards as appropriate.
7. Data Retention
- Non-persistent session state: destroyed at session end.
- Account records: retained while your organization is a customer.
- Deleted-account records: purged within 30 days of contract termination, except where a longer period is required by law.
- Security and audit logs: retained for up to 90 days by default, longer if a customer's plan or a legal obligation requires it.
- Billing and tax records: retained as required by applicable law (typically up to 7 years).
8. Security
Our security program is designed to align with recognized industry frameworks. Core controls include:
- Encryption in transit using modern TLS and AES-256-GCM session encryption.
- Encryption at rest for persistent volumes and backups.
- Tenant isolation at the hypervisor, network, and identity layers.
- Enforced MFA for administrator accounts and least-privilege internal access.
- Continuous monitoring, vulnerability management, and periodic third-party testing.
No system is perfectly secure. You are responsible for configuring desktops, access policies, and endpoint controls appropriate to the data your workforce processes.
9. Your Rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you.
- Correct information that is inaccurate or incomplete.
- Request deletion of your information.
- Object to or restrict certain processing.
- Receive your information in a portable format.
- Withdraw consent where processing is based on consent.
- Lodge a complaint with a supervisory authority.
If your organization provisioned your account, please contact your administrator first — they act as the controller for your workspace data. To reach us directly, use the contact details below.
10. Regional Notices
EEA / UK (GDPR). You have the rights described above and may lodge a complaint with your local supervisory authority.
California (CCPA/CPRA). California residents have the right to know, delete, correct, and limit certain uses of personal information. We do not sell personal information or share it for cross-context behavioral advertising.
Canada (PIPEDA). You may request access to and correction of your personal information.
Brazil (LGPD). You have rights of confirmation, access, correction, anonymization, portability, and deletion.
11. Children's Privacy
AvidiaVDI is a business service and is not directed to individuals under 16. We do not knowingly collect information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.
13. Changes to This Policy
We may update this policy from time to time. When we make material changes, we will update the "Last Updated" date and, where appropriate, notify customers by email or in-product notice.
14. Contact Us
Questions about this policy or our privacy practices can be sent to our Data Protection Officer:
AvidiaVDI — Data Protection Officer
Email: privacy@avidiavdi.com
Mailing address available on request.