1. Who operates AVC

AVC is an autonomous operating system owned and operated by Jonas Abde. AVC is not an independent legal person. The legal owner remains the accountable natural-person authority for this public alpha surface. A verified public postal address and general privacy contact channel have not yet been published and remain production-launch blockers.

2. Scope of this notice

This notice covers the public AVC marketing origin and the handoff to the protected login gateway. Separate products, tenants, customer deployments and third-party services may require additional notices before they process personal data.

3. Data processed on the public surface

The current public surface is designed to minimize personal-data collection.

4. Purposes, legal basis and legitimate interests

Routine request and security data is processed to deliver pages, maintain availability, troubleshoot faults, detect abuse, enforce access boundaries and protect the service. Where the GDPR applies and processing relies on legitimate interests, those interests are the secure, reliable and abuse-resistant operation of AVC and its public infrastructure. Legal obligations may also apply to particular records or incidents. Processing that requires consent remains outside the current public-alpha scope until a valid consent flow exists.

5. Whether providing data is required

Technical request data is generated as part of using the website and is necessary for the hosting and security infrastructure to receive and answer a request. AVC does not currently ask visitors to submit profile, marketing or customer information through the public website. A visitor can avoid this public processing by not using the public service.

6. Cookies and local storage

The public marketing source does not intentionally set non-essential analytics or marketing cookies. Hosting, security or identity providers may use strictly necessary technologies on protected access surfaces. See the cookie notice for the current tracking position and the boundary that applies before non-essential tracking is enabled.

7. Infrastructure and recipients

Cloudflare is used for the current public hosting and protected access boundary. Infrastructure providers may process technical request and security data as part of delivering those services. Following a link to an external service means that service handles subsequent processing under its own terms and privacy information.

Known launch blocker

8. International transfers

The production data-flow inventory has not yet documented, for every configured provider and processing path, whether personal data is transferred outside the EEA and which adequacy decision, transfer safeguard or other lawful mechanism applies. AVC must complete and publish the relevant transfer information before this notice is used as the privacy notice for a general production customer service. No blanket claim of EU-only processing is made here.

9. Retention

Technical and security data should be retained only for as long as necessary for service operation, troubleshooting, abuse prevention, security and applicable legal requirements. Exact provider retention periods are not yet published on this alpha surface and remain a production-launch compliance item.

10. Automated decision-making on the public site

The current public marketing surface does not make solely automated decisions about visitors that produce legal effects or similarly significant effects. AVC contains AI-native and agentic systems elsewhere, but those uses require their own scope-specific transparency and assessment. See AI Transparency for the current system-level boundary.

11. Your rights

Where the GDPR applies, individuals may have rights to access, rectification, erasure, restriction, objection and data portability, depending on the processing involved. Where a future processing activity relies on consent, that consent must be withdrawable without affecting the lawfulness of processing before withdrawal. A complaint may also be lodged with the competent data-protection authority, including Datatilsynet in Denmark where applicable.

Known launch blocker

12. Privacy contact

A dedicated public privacy contact address has not yet been published. Until a verified contact channel is added, this public alpha is not approved as a general customer personal-data intake surface. Do not submit personal or sensitive information through the public website.