Aventra legal & privacy
Privacy Policy
Last updated: 10 September 2026
Who operates Aventra
Aventra is a software product operated by Security Consultants and Mitigators Ltd. This policy explains how personal information is handled when people use Aventra, connect authorised third-party services, communicate with us, or interact with growth activity managed through the platform.
Information we may process
Depending on the features used, Aventra may process account and contact information, business profile information, customer and prospect records provided or lawfully obtained by the customer, campaign and communication records, provider connection identifiers and permission metadata, technical security and audit records, and information returned by authorised third-party services.
For Meta and Instagram integrations, Aventra only requests and uses information and permissions required for enabled capabilities. This can include an authorised professional account identifier and profile information, media or publishing information, permission status and publishing results. Messaging or comment information is processed only where the relevant Aventra capability is supported, enabled, authorised and permitted by Meta.
How we use information
We use information to provide and secure Aventra, connect authorised services, prepare and execute customer-approved growth activity, maintain customer and conversation records, provide support, detect misuse, keep auditable operational evidence, improve reliability and comply with legal obligations.
Legal bases
Where UK data-protection law applies, processing may be based on performance of a contract, legitimate interests in operating and securing the service, compliance with legal obligations, or consent where consent is required. Customers remain responsible for ensuring that information they place into Aventra and activities they authorise have an appropriate lawful basis.
Third-party providers
Aventra can connect to external providers at a customer's direction. Those providers process data under their own terms and privacy notices. Aventra does not treat a provider connection as authority to perform unrelated actions, and provider permissions are used only for supported and authorised capabilities.
Retention and deletion
Information is retained only for as long as reasonably required for the service, security, audit, contractual and legal purposes for which it was collected. Customers can disconnect supported provider connections and may request deletion of eligible personal data. Some records may need to be retained where required for legal, security, fraud-prevention or immutable audit purposes.
Security
Aventra uses access controls, tenant separation, encrypted credential storage, governed provider permissions, operational logging and other technical and organisational safeguards designed to protect information and prevent unauthorised use.
Your rights
Subject to applicable law, individuals may have rights to request access, correction, deletion, restriction, objection or portability of their personal information, and to complain to the relevant data-protection authority.
Contact
Privacy and data requests relating to Aventra can be sent to developers@aventrauk.com. Please provide enough information for us to verify and respond to the request without sending passwords or provider secrets.