Legal

Privacy Policy

Last updated 11 August 2026 · Applies to avorasia.com and Avora mobile apps

This policy explains what personal data Avora SIA collects, why, and what you can do about it. We have tried to write it in plain language rather than legal boilerplate — where a term has a specific legal meaning under the General Data Protection Regulation (GDPR), we say so.

1. Who we are

Avora SIA is a mobile app studio registered in Latvia. For the purposes of the GDPR we are the data controller for the personal data described in this policy — meaning we decide why and how it is processed.

CompanyAvora SIA
CountryLatvia (European Union)
Contact[email protected]
Registration no.To be added — see note below
Registered addressTo be added — see note below

We have not appointed a Data Protection Officer, as we are not required to under Article 37 of the GDPR. Privacy questions go to the address above and reach a person, not a queue.

2. What this policy covers

Two different things, which collect very different amounts of data:

  • This website, avorasia.com — covered in section 3. It collects almost nothing.
  • Our mobile apps, published on the App Store and Google Play — covered in section 4. Each app states its own data practices, because they differ.

It does not cover third-party websites we link to. Once you follow a link away from here, that site's own policy applies.

3. This website

What the site does not do

Worth stating plainly, because it is unusual:

  • No cookies. The site sets none — there is no consent banner because there is nothing to consent to.
  • No analytics. No Google Analytics, no Meta pixel, no tracking of any kind.
  • No JavaScript. The page runs no scripts, so nothing can read your device, fingerprint your browser, or store data locally.
  • No forms and no accounts. There is nothing to fill in and nothing to sign up for.

Server logs

Our hosting provider records standard technical information when a page is requested: IP address, the page requested, the time, your browser's user agent, and the page you came from. This is automatic, applies to essentially every website, and is used only to keep the site running and to investigate faults or abuse. We do not use it to build a profile of you and we do not combine it with anything else.

Legal basis: legitimate interests (Article 6(1)(f)) — operating and securing our own website.

No third-party requests

Every file this site needs — stylesheet, images, icons and typefaces — is served from avorasia.com. Loading a page therefore contacts no other company, and no third party receives your IP address or learns that you visited.

This is deliberate. Typefaces in particular are commonly loaded from Google's font service, which transmits each visitor's IP address to Google. We host ours ourselves so that transfer does not happen.

Emailing us

If you email [email protected] we receive your address, your message, and anything you choose to include. We use it to answer you and to keep a record of the conversation. We do not add you to a mailing list.

Legal basis: legitimate interests (Article 6(1)(f)), or steps taken at your request before entering a contract (Article 6(1)(b)) if you are enquiring about a project.

4. Our mobile apps

This section is not finished, and must be completed before the first app is submitted to the App Store or Google Play.

No Avora app has been released yet, so there are no live data practices to describe. Publishing invented ones would be worse than publishing none: Apple's Privacy Nutrition Labels and Google's Data Safety form are both checked against this page, and a mismatch is a common cause of review rejection — as well as a false statement to your users.

For each app, state: what data it collects, whether it leaves the device, which third-party SDKs are embedded (analytics, crash reporting, ad networks), whether data is linked to identity, whether it is used for tracking, and how a user requests deletion. Then have it reviewed by someone qualified in Latvian and EU data protection law.

When apps are released, this section will describe each one individually. Until then, no app-related personal data is processed because no app exists in the stores.

5. Who we share data with

We do not sell personal data, and we do not share it for advertising.

Data is handled on our behalf by a small number of service providers, known as processors under the GDPR, who may access it only to provide their service to us:

ProviderPurposeData involved
Our web hostServing the websiteServer log data
Our email providerReceiving and sending emailMessage contents

We may also disclose data where we are legally required to — for example in response to a valid order from a court or authority.

6. Transfers outside the EEA

We are based in Latvia and prefer providers inside the European Economic Area. Browsing this website transfers nothing outside it, because the site contacts no third parties at all.

Should that change — or where our hosting or email provider processes data outside the EEA — any such transfer relies on the safeguards in Chapter V of the GDPR, such as an adequacy decision or Standard Contractual Clauses.

7. How long we keep it

DataKept for
Server logsAs set by our host, typically a few weeks to a few months
Email correspondenceAs long as needed to handle the matter, then archived or deleted
Business records with a statutory retention periodAs Latvian law requires

8. Your rights

Under the GDPR you can ask us to:

  • Give you a copy of the personal data we hold about you (Article 15)
  • Correct it if it is wrong or incomplete (Article 16)
  • Delete it, where we have no overriding reason to keep it (Article 17)
  • Restrict how we use it while a dispute is resolved (Article 18)
  • Port it to you or another provider in a machine-readable form (Article 20)
  • Object to processing based on legitimate interests (Article 21)

Email [email protected] and we will respond within one month, as the GDPR requires. Exercising these rights is free, and we will not treat you differently for doing so.

If you are unhappy with how we have handled your data you can complain to the Latvian supervisory authority, Datu valsts inspekcija (dvi.gov.lv), or to the authority in your own EU country of residence.

9. Children

This website is aimed at businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with data, contact us and we will delete it.

10. Security

The site is served over HTTPS, so traffic between your browser and our server is encrypted. We keep access to our systems limited to people who need it. No system is perfectly secure, but we take reasonable technical and organisational measures as Article 32 of the GDPR requires.

11. Changes to this policy

When this policy changes we update the date at the top of the page. For changes that meaningfully affect how we handle your data, we will say so more prominently. This page always shows the current version.

12. Contact

Questions about this policy, or a request about your data:

[email protected]

Avora SIA, Latvia