Legal

Privacy Policy

This policy explains what information AvidiaVDI collects, how we use and share it, and the choices and rights you have. It applies to our website, customer portals, and the virtual desktop infrastructure service we operate for small and medium businesses.

Last Updated: January 15, 2026

Shared responsibility. AvidiaVDI operates the underlying platform, security controls, and data centers. When you deploy virtual desktops for your small or medium business, you (as the customer or administrator) act as the data controller for the data those desktops process. This policy describes what AvidiaVDI does with data; your organization's own privacy notice governs data you place inside desktops.

1. Information We Collect

We collect the following categories of information:

  • Account information. Name, work email, company, role, and authentication identifiers when an administrator or end user registers or is provisioned by your organization.
  • Billing information. Company billing contact, VAT/tax IDs, and payment metadata (processed by our payment provider — we do not store full card numbers).
  • Session metadata. Connection times, assigned pool, gateway region, client IP, session duration, and error codes needed to operate and troubleshoot the service.
  • Device & technical information. Client type (browser, native), operating system, screen resolution, and network performance metrics reported by the client.
  • Support communications. Messages, tickets, and attachments you send us.

2. Session & Desktop Data

AvidiaVDI streams pixels from a remote virtual desktop to your endpoint over an encrypted transport. We operate a non-custodial model for what happens inside those desktops:

  • We do not inspect, record, index, or scan the contents of desktop sessions, keystrokes, clipboard, or files inside your virtual machines.
  • Non-persistent desktops are ephemeral. Session state is destroyed on logout or pool recycle unless your administrator has configured persistent profiles or attached storage volumes.
  • Persistent volumes and profile data configured by your administrator remain within the region and storage class your organization selects.

3. How We Use Information

We use the information described above to:

  • Provision, operate, secure, and maintain the AvidiaVDI service.
  • Authenticate users, enforce access policies, and prevent abuse or fraud.
  • Investigate incidents, diagnose issues, and provide customer support.
  • Bill customers and comply with tax, accounting, and legal obligations.
  • Send service and security notifications, and (where permitted) product updates.
  • Improve reliability, performance, and capacity planning using aggregated metrics.

5. Data Sharing & Subprocessors

We do not sell personal information. We share data only with vetted subprocessors acting under written data-processing agreements, in these categories:

  • Cloud infrastructure and colocation providers hosting our compute and storage.
  • Identity, MFA, and directory federation providers used to authenticate users.
  • Payment processing and tax-calculation providers for billing.
  • Email, in-product messaging, and customer-support tooling.
  • Privacy-respecting analytics and error-reporting used to operate the service.

We may also disclose information when required by law, to protect rights and safety, or in connection with a corporate transaction (with continued protection of the data).

6. International Transfers

AvidiaVDI operates data centers in multiple regions. Customers choose the region for their tenant, and desktop workloads run in that region. Where personal data is transferred internationally (for example, to provide global support), we rely on European Commission Standard Contractual Clauses, the UK IDTA, and additional safeguards as appropriate.

7. Data Retention

  • Non-persistent session state: destroyed at session end.
  • Account records: retained while your organization is a customer.
  • Deleted-account records: purged within 30 days of contract termination, except where a longer period is required by law.
  • Security and audit logs: retained for up to 90 days by default, longer if a customer's plan or a legal obligation requires it.
  • Billing and tax records: retained as required by applicable law (typically up to 7 years).

8. Security

Our security program is designed to align with recognized industry frameworks. Core controls include:

  • Encryption in transit using modern TLS and AES-256-GCM session encryption.
  • Encryption at rest for persistent volumes and backups.
  • Tenant isolation at the hypervisor, network, and identity layers.
  • Enforced MFA for administrator accounts and least-privilege internal access.
  • Continuous monitoring, vulnerability management, and periodic third-party testing.

No system is perfectly secure. You are responsible for configuring desktops, access policies, and endpoint controls appropriate to the data your workforce processes.

9. Your Rights

Depending on where you live, you may have the right to:

  • Access the personal information we hold about you.
  • Correct information that is inaccurate or incomplete.
  • Request deletion of your information.
  • Object to or restrict certain processing.
  • Receive your information in a portable format.
  • Withdraw consent where processing is based on consent.
  • Lodge a complaint with a supervisory authority.

If your organization provisioned your account, please contact your administrator first — they act as the controller for your workspace data. To reach us directly, use the contact details below.

10. Regional Notices

EEA / UK (GDPR). You have the rights described above and may lodge a complaint with your local supervisory authority.

California (CCPA/CPRA). California residents have the right to know, delete, correct, and limit certain uses of personal information. We do not sell personal information or share it for cross-context behavioral advertising.

Canada (PIPEDA). You may request access to and correction of your personal information.

Brazil (LGPD). You have rights of confirmation, access, correction, anonymization, portability, and deletion.

11. Children's Privacy

AvidiaVDI is a business service and is not directed to individuals under 16. We do not knowingly collect information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.

12. Cookies & Tracking

Our website uses strictly necessary cookies to keep you signed in and to remember your preferences. Where required, we ask for consent before setting optional analytics cookies. We do not use third-party advertising cookies.

13. Changes to This Policy

We may update this policy from time to time. When we make material changes, we will update the "Last Updated" date and, where appropriate, notify customers by email or in-product notice.

14. Contact Us

Questions about this policy or our privacy practices can be sent to our Data Protection Officer:

AvidiaVDI — Data Protection Officer

Email: privacy@avidiavdi.com

Mailing address available on request.