Legal
Privacy Policy
This policy explains what personal data Avora SIA collects, why, and what you can do about it. We have tried to write it in plain language rather than legal boilerplate — where a term has a specific legal meaning under the General Data Protection Regulation (GDPR), we say so.
1. Who we are
Avora SIA is a mobile app studio registered in Latvia. For the purposes of the GDPR we are the data controller for the personal data described in this policy — meaning we decide why and how it is processed.
| Company | Avora SIA |
|---|---|
| Country | Latvia (European Union) |
| Contact | [email protected] |
| Registration no. | To be added — see note below |
| Registered address | To be added — see note below |
We have not appointed a Data Protection Officer, as we are not required to under Article 37 of the GDPR. Privacy questions go to the address above and reach a person, not a queue.
2. What this policy covers
Two different things, which collect very different amounts of data:
- This website, avorasia.com — covered in section 3. It collects almost nothing.
- Our mobile apps, published on the App Store and Google Play — covered in section 4. Each app states its own data practices, because they differ.
It does not cover third-party websites we link to. Once you follow a link away from here, that site's own policy applies.
3. This website
What the site does not do
Worth stating plainly, because it is unusual:
- No cookies. The site sets none — there is no consent banner because there is nothing to consent to.
- No analytics. No Google Analytics, no Meta pixel, no tracking of any kind.
- No JavaScript. The page runs no scripts, so nothing can read your device, fingerprint your browser, or store data locally.
- No forms and no accounts. There is nothing to fill in and nothing to sign up for.
Server logs
Our hosting provider records standard technical information when a page is requested: IP address, the page requested, the time, your browser's user agent, and the page you came from. This is automatic, applies to essentially every website, and is used only to keep the site running and to investigate faults or abuse. We do not use it to build a profile of you and we do not combine it with anything else.
Legal basis: legitimate interests (Article 6(1)(f)) — operating and securing our own website.
No third-party requests
Every file this site needs — stylesheet, images, icons and typefaces — is served from avorasia.com. Loading a page therefore contacts no other company, and no third party receives your IP address or learns that you visited.
This is deliberate. Typefaces in particular are commonly loaded from Google's font service, which transmits each visitor's IP address to Google. We host ours ourselves so that transfer does not happen.
Emailing us
If you email [email protected] we receive your address, your message, and anything you choose to include. We use it to answer you and to keep a record of the conversation. We do not add you to a mailing list.
Legal basis: legitimate interests (Article 6(1)(f)), or steps taken at your request before entering a contract (Article 6(1)(b)) if you are enquiring about a project.
4. Our mobile apps
This section is not finished, and must be completed before the first app is submitted to the App Store or Google Play.
No Avora app has been released yet, so there are no live data practices to describe. Publishing invented ones would be worse than publishing none: Apple's Privacy Nutrition Labels and Google's Data Safety form are both checked against this page, and a mismatch is a common cause of review rejection — as well as a false statement to your users.
For each app, state: what data it collects, whether it leaves the device, which third-party SDKs are embedded (analytics, crash reporting, ad networks), whether data is linked to identity, whether it is used for tracking, and how a user requests deletion. Then have it reviewed by someone qualified in Latvian and EU data protection law.
When apps are released, this section will describe each one individually. Until then, no app-related personal data is processed because no app exists in the stores.
5. Who we share data with
We do not sell personal data, and we do not share it for advertising.
Data is handled on our behalf by a small number of service providers, known as processors under the GDPR, who may access it only to provide their service to us:
| Provider | Purpose | Data involved |
|---|---|---|
| Our web host | Serving the website | Server log data |
| Our email provider | Receiving and sending email | Message contents |
We may also disclose data where we are legally required to — for example in response to a valid order from a court or authority.
6. Transfers outside the EEA
We are based in Latvia and prefer providers inside the European Economic Area. Browsing this website transfers nothing outside it, because the site contacts no third parties at all.
Should that change — or where our hosting or email provider processes data outside the EEA — any such transfer relies on the safeguards in Chapter V of the GDPR, such as an adequacy decision or Standard Contractual Clauses.
7. How long we keep it
| Data | Kept for |
|---|---|
| Server logs | As set by our host, typically a few weeks to a few months |
| Email correspondence | As long as needed to handle the matter, then archived or deleted |
| Business records with a statutory retention period | As Latvian law requires |
8. Your rights
Under the GDPR you can ask us to:
- Give you a copy of the personal data we hold about you (Article 15)
- Correct it if it is wrong or incomplete (Article 16)
- Delete it, where we have no overriding reason to keep it (Article 17)
- Restrict how we use it while a dispute is resolved (Article 18)
- Port it to you or another provider in a machine-readable form (Article 20)
- Object to processing based on legitimate interests (Article 21)
Email [email protected] and we will respond within one month, as the GDPR requires. Exercising these rights is free, and we will not treat you differently for doing so.
If you are unhappy with how we have handled your data you can complain to the Latvian supervisory authority, Datu valsts inspekcija (dvi.gov.lv), or to the authority in your own EU country of residence.
9. Children
This website is aimed at businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with data, contact us and we will delete it.
10. Security
The site is served over HTTPS, so traffic between your browser and our server is encrypted. We keep access to our systems limited to people who need it. No system is perfectly secure, but we take reasonable technical and organisational measures as Article 32 of the GDPR requires.
11. Changes to this policy
When this policy changes we update the date at the top of the page. For changes that meaningfully affect how we handle your data, we will say so more prominently. This page always shows the current version.