Skip to main content
ColleagueOne
Product
OverviewColleagues & teamsWorkspaceAutomationsConnectionsGovernance & security
Use casesSecurityDocsCompany
Sign inRequest access
ProductUse casesSecurityDocsCompanyRequest accessSign in
Draft — pending legal review

Legal · Privacy

Privacy Policy

This policy explains what information Avapti handles when organisations and their authorised users use ColleagueOne, why we handle it, and the choices available to them.

Effective date: [DATE]

On this page

  1. Scope and roles
  2. Data we collect
  3. How we use data
  4. Service providers
  5. Locations and transfers
  6. Retention
  7. Your rights
  8. Contact

1. Scope and our role

This Privacy Policy applies to the ColleagueOne service, the public website atavapti.com, and related support and account interactions. “Avapti”, “we”, “us”, and “our” refer to [AVAPTI LEGAL ENTITY AND ADDRESS].

ColleagueOne is a business service. An organisation that provides access to ColleagueOne generally decides why and how workspace content and its users’ data are processed. For that data, the organisation is the controller and Avapti acts as its processor or service provider under the relevant agreement. We act as a controller for limited business-account, website, security, and relationship data that we use for our own legitimate business purposes.

If you use ColleagueOne through your employer or another organisation, please direct workspace-data requests to that organisation first. Its policies may also apply.

2. Information we collect

Account and sign-in data

When you sign in with Google, we receive your name and email address from Google so that we can create or identify your account and provide access. We do not state that we receive your Google password. If another sign-in method is offered, we receive the identifiers and account details needed to authenticate you through that method.

Workspace content

We process content that authorised users submit to or create with the service, including conversations, goals and instructions, files, documents, spreadsheets, presentations, results, approvals, playbooks, skills, plugin and connection settings, and reviewed memory. Workspace content may include personal or confidential information chosen by the organisation or its users.

Configuration and connection data

We process colleague configurations, selected models and tools, schedules, data-classification labels, approval rules, and information needed to operate connections authorised by an organisation. Connection credentials are held by the gateway and are not handed to an AI colleague. Connected vendors separately process information under their own terms and privacy notices.

Usage, device, and support data

We process operational records such as sign-in events, service requests, run status, approvals, audit-log events, browser and device information, IP address, timestamps, and diagnostic data. We also process the information you include when you contact us for access, support, security, or other enquiries.

We do not use third-party advertising trackers, sell personal data, or display targeted advertising on ColleagueOne or the public website.

3. How and why we use information

We process information to:

  • provide, authenticate, maintain, and support ColleagueOne;
  • execute authorised work and return results for review or approval;
  • apply workspace roles, budgets, schedules, security controls, and organisation policies;
  • operate authorised connections and send data to a selected model provider when needed for a run;
  • protect users, investigate misuse, maintain audit records, and secure the service;
  • communicate about access, service changes, support, and our business relationship;
  • understand reliability and improve the service using operational information; and
  • comply with law and enforce our agreements.

Depending on the context and applicable law, we rely on performance of a contract, legitimate interests, compliance with legal obligations, consent where required, or the documented instructions of the organisation that controls the data. ColleagueOne is not intended for consumer advertising or profiling.

4. AI model processing

ColleagueOne is model-agnostic. To complete authorised work, relevant prompts, instructions, and workspace content may be sent through our model gateway to third-party model providers, including OpenAI, Anthropic, and other providers made available through the gateway. The provider used can depend on the organisation’s or colleague’s configuration.

Model providers process this data to generate requested output and operate their services. Their location, retention, and contractual terms can differ. Organisations should not submit data to a model they are not authorised to use. Contact us for the current provider list and the terms applicable to your deployment.

5. When we share information

We disclose information only as reasonably necessary to operate and protect the service, including to:

  • DigitalOcean, which hosts service infrastructure in Bangalore, India;
  • Google, when a user chooses Google sign-in;
  • OpenRouter and selected model providers, for model routing and inference through the gateway;
  • connected vendors, when an authorised user or administrator enables and uses a connection;
  • professional advisers and authorities, where required by law or to protect rights;
  • a successor organisation, in connection with a corporate transaction, subject to appropriate confidentiality and legal requirements; and
  • other recipients, where the relevant organisation or user directs us to disclose the information or gives valid consent.

See our Subprocessors page for a draft list and the purpose of each service provider.

6. Data locations and international transfers

Our hosting provider’s listed service region is Bangalore, India. Google, OpenRouter, model providers, connected vendors, and support recipients may process information in other countries. This means personal data may be processed outside the UAE or the user’s country.

Where required, we use contractual, organisational, or other lawful transfer measures appropriate to the relevant jurisdiction and service arrangement. UAE Mainland, DIFC, ADGM, and other privacy regimes may impose different requirements. Customers should confirm the applicable transfer arrangements in their agreement or data processing addendum before using the service for regulated data.

7. Security

We use technical and organisational measures designed to protect information. Product controls include an isolated Firecracker microVM sandbox for each colleague, gateway-held credentials, per-run scoped model keys and budgets, approvals for sensitive actions, roles, data-classification and DLP policy controls, and audit logs. No service can guarantee absolute security.

More detail is available on our Security and Responsible Disclosure page.

8. Retention and deletion

We retain account data and workspace content for as long as needed to provide the service to the customer, meet contractual requirements, and maintain security and audit records. After an account or agreement ends, we delete or de-identify information in accordance with the relevant agreement, customer instructions, legal obligations, and our documented retention process. Residual copies may remain in protected backups until they cycle out.

Some records may be kept longer where reasonably necessary for fraud prevention, dispute resolution, financial recordkeeping, security, or legal compliance. The final retention schedule will be documented before this draft is published.

9. Your choices and rights

Depending on your location and the law that applies, you may have rights to access, correct, delete, restrict, object to, or obtain a copy of personal data, and to withdraw consent where processing relies on consent. These rights may be subject to exceptions.

If your account is managed by an organisation, submit workspace requests to its owner or administrator. We will support that organisation in responding as required. For data Avapti controls directly, emailhello@avapti.com. We may need to verify your identity and authority before acting. You may also have the right to complain to the data-protection authority that applies to you.

10. Children

ColleagueOne is a business service and is not directed to children. Organisations must not authorise use by anyone who cannot lawfully agree to the applicable terms or whose data cannot lawfully be processed in the workspace.

11. Changes to this policy

We may update this policy as the service, providers, or legal requirements change. We will post the revised version here, change the effective date, and provide additional notice where required by law or contract.

12. Contact

Questions or privacy requests can be sent tohello@avapti.com.

Controller details: [AVAPTI LEGAL ENTITY, POSTAL ADDRESS, AND PRIVACY CONTACT]

ColleagueOne

AI colleagues that do real work,
under your governance.

Invite-only beta

Product

Colleagues & teamsWorkspaceAutomationsConnectionsGovernance & securityRequest access

Resources

DocumentationAPI referenceChangelogStatus

Company

AboutContactSecurityResponsible disclosure

Legal

PrivacyTermsCookie noticeAcceptable useDPA summarySubprocessors

© 2026 Avapti. All rights reserved.

Built for accountable work.