Privacy notice
This notice describes the current public AVC website and protected access gateway. It does not claim that future customer-account, billing, marketing or Product Cell processing is production-ready.
1. Who operates AVC
AVC is an autonomous operating system owned and operated by Jonas Abde. AVC is not an independent legal person. The legal owner remains the accountable natural-person authority for this public alpha surface. A verified public postal address and general privacy contact channel have not yet been published and remain production-launch blockers.
2. Scope of this notice
This notice covers the public AVC marketing origin and the handoff to the protected login gateway. Separate products, tenants, customer deployments and third-party services may require additional notices before they process personal data.
3. Data processed on the public surface
The current public surface is designed to minimize personal-data collection.
- Hosting and security infrastructure may process ordinary request metadata such as IP address, timestamp, requested path, user-agent information and security signals needed to deliver and protect the service.
- The public AVC origin does not intentionally collect passwords or store identity tokens. Protected sign-in is delegated to the configured access and identity provider.
- The current public website source does not include marketing pixels or analytics trackers. Non-essential tracking must not be introduced before an appropriate consent mechanism is implemented where required.
4. Purposes, legal basis and legitimate interests
Routine request and security data is processed to deliver pages, maintain availability, troubleshoot faults, detect abuse, enforce access boundaries and protect the service. Where the GDPR applies and processing relies on legitimate interests, those interests are the secure, reliable and abuse-resistant operation of AVC and its public infrastructure. Legal obligations may also apply to particular records or incidents. Processing that requires consent remains outside the current public-alpha scope until a valid consent flow exists.
5. Whether providing data is required
Technical request data is generated as part of using the website and is necessary for the hosting and security infrastructure to receive and answer a request. AVC does not currently ask visitors to submit profile, marketing or customer information through the public website. A visitor can avoid this public processing by not using the public service.
6. Cookies and local storage
The public marketing source does not intentionally set non-essential analytics or marketing cookies. Hosting, security or identity providers may use strictly necessary technologies on protected access surfaces. See the cookie notice for the current tracking position and the boundary that applies before non-essential tracking is enabled.
7. Infrastructure and recipients
Cloudflare is used for the current public hosting and protected access boundary. Infrastructure providers may process technical request and security data as part of delivering those services. Following a link to an external service means that service handles subsequent processing under its own terms and privacy information.
8. International transfers
The production data-flow inventory has not yet documented, for every configured provider and processing path, whether personal data is transferred outside the EEA and which adequacy decision, transfer safeguard or other lawful mechanism applies. AVC must complete and publish the relevant transfer information before this notice is used as the privacy notice for a general production customer service. No blanket claim of EU-only processing is made here.
9. Retention
Technical and security data should be retained only for as long as necessary for service operation, troubleshooting, abuse prevention, security and applicable legal requirements. Exact provider retention periods are not yet published on this alpha surface and remain a production-launch compliance item.
10. Automated decision-making on the public site
The current public marketing surface does not make solely automated decisions about visitors that produce legal effects or similarly significant effects. AVC contains AI-native and agentic systems elsewhere, but those uses require their own scope-specific transparency and assessment. See AI Transparency for the current system-level boundary.
11. Your rights
Where the GDPR applies, individuals may have rights to access, rectification, erasure, restriction, objection and data portability, depending on the processing involved. Where a future processing activity relies on consent, that consent must be withdrawable without affecting the lawfulness of processing before withdrawal. A complaint may also be lodged with the competent data-protection authority, including Datatilsynet in Denmark where applicable.
12. Privacy contact
A dedicated public privacy contact address has not yet been published. Until a verified contact channel is added, this public alpha is not approved as a general customer personal-data intake surface. Do not submit personal or sensitive information through the public website.