Version 1.3.0 — Last updated: September 9, 2026
Pontos Platforms LLC ("Company," "we," "us") operates the Aqvori platform ("Service"). We are committed to protecting the privacy of our users. This Privacy Policy explains how we collect, use, store, and share information when you use the Service.
When you register, we collect your full name, work email address, company or organization name, and job title (if provided). We also collect a hashed version of your password — we never store passwords in plain text.
As you use the Service, you may create or upload data including client records, project details, meeting notes, documents, email content, time entries, credentials (encrypted in the Vault), and other operational data ("Service Data"). You control what Service Data you provide.
We automatically collect technical information to operate and secure the Service:
When you use AI-powered features (Vori), we log metadata about AI interactions including the type of request, token usage, timestamps, and associated user and tenant identifiers. Where — and only where — your organization has configured its own API key for a third-party AI provider, portions of your Service Data (such as meeting transcripts, document content, and contextual project data) are sent to that provider to fulfill the request. If your organization has not configured a provider key, no Service Data is sent to any AI provider. We do not authorize any AI provider to use Your Data for model training.
Documents you upload to the Service (PDFs, Word documents, spreadsheets, and other files) are stored securely and may be processed by AI features when you explicitly invoke them. Documents are associated with your organization and subject to tenant isolation.
| Purpose | Data Used |
|---|---|
| Providing the Service | Account info, Service Data |
| AI features (Vori — summaries, analysis, recommendations, document generation) | Service Data sent to the third-party AI provider your organization has configured, if any |
| Security and fraud prevention | IP address, device fingerprint, audit logs |
| Service improvement and analytics | Aggregated, anonymized usage data |
| Transactional communications | Email address, and — where you have opted in — mobile phone number (service notifications, alerts, workflow triggers only) |
| Legal compliance | As required by applicable law |
We share your information only in the following limited circumstances:
We do not sell your information to third parties. We do not share your information with advertisers. We do not use Your Data for marketing purposes. We do not share, sell, rent, or trade your mobile information — including your mobile phone number and SMS opt-in or consent data — with any third parties or affiliates for marketing or promotional purposes. Mobile opt-in data and consent are never shared with third parties or lead generators. Where SMS is used, we share the minimum necessary information only with the subcontractor that delivers the messages on our behalf (our SMS delivery provider), solely to operate the messaging service.
Aqvori operates a multi-tenant architecture with strict data isolation. Each organization's data is logically separated and cannot be accessed by other organizations. Tenant isolation is enforced at the database query level, API middleware level, and session management level. Tenant isolation is enforced at the application query layer and by PostgreSQL row-level security; all database queries are scoped to the authenticated tenant. No security control is absolute.
We retain your Service Data for as long as your account is active. Upon account termination or deletion request, we will delete your Service Data within 30 days, except for the following:
We implement commercially reasonable security measures including:
The Service uses the following essential cookies:
| Cookie | Purpose | Type |
|---|---|---|
vori_token | Authentication — maintains your logged-in session | Essential |
vori_csrf | CSRF protection — prevents cross-site request forgery attacks | Essential |
vori_portal_token | Authentication — maintains your logged-in session in the client portal | Essential |
These cookies are strictly essential for the operation of the Service. We do not use tracking cookies, third-party analytics cookies, or advertising cookies. No consent banner is required as all cookies are essential.
Depending on your jurisdiction, you may have the right to:
For most personal data in the Service, the organization that invited you is the controller and Aqvori is its processor — that organization decides what is collected, corrected, or deleted. Direct requests about that data to your organization; if you contact us instead, we will acknowledge your request within 5 business days and forward it to your organization, and we will assist that organization in responding. Where Aqvori is itself the controller (for example, account and billing records we hold about our direct customers), we will acknowledge within 5 business days and respond within 30 days.
The Service is designed for business professionals and is not intended for use by individuals under 18 years of age. We do not knowingly collect information from anyone under 18. If we become aware that we have collected personal information from a minor, we will take steps to delete that information promptly.
Your data is processed and stored in the United States (Oregon region). If you access the Service from outside the United States, your data will be transferred to and processed in the United States. By using the Service, you consent to this transfer. We implement appropriate safeguards to protect your data during any international transfer.
The Service is not offered as a HIPAA-compliant service, and Pontos Platforms LLC does not currently offer a Business Associate Agreement. We make no representation that the Service has been audited against the HIPAA Security Rule or is suitable for Protected Health Information ("PHI") as defined under the Health Insurance Portability and Accountability Act of 1996.
For questions about regulated data, contact support@aqvori.com.
Some organizations using the Service choose to send you transactional text messages (SMS). SMS is off by default and is sent only after you opt in.
When your organization connects a Google account or Google Workspace to the Service, Aqvori accesses certain Google user data on your behalf, using the OAuth scopes below, solely to provide the features you connect:
Storage: file content remains in your organization's own Google Drive; Aqvori stores only references to it together with the application data you create. Access and sharing: Google user data is accessed per user, on your behalf, and is visible only to you and authorized members of your organization. It is never sold, used for advertising, or used to train generalized artificial-intelligence models, and is not shared with third parties except as necessary to provide the features you connect or as required by law. Retention: access continues until you disconnect Google in Settings or close your account, after which Aqvori stops accessing your Google data.
Limited Use. Aqvori's use and transfer of information received from Google APIs to any other application will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Aqvori uses Google user data only to provide and improve the features you connect, does not transfer or sell it to third parties except to provide those features or as required by law, does not use it for advertising, and does not allow humans to read it except with your consent, for security or to comply with applicable law, or where the data has been aggregated and anonymized.
We may update this Privacy Policy from time to time. Material changes will be communicated via the Service or email at least 15 days before they take effect. The "Last updated" date at the top indicates when the policy was most recently revised.
For privacy inquiries or to exercise your data rights, contact us at:
Pontos Platforms LLC
Email: support@aqvori.com