← Back to Aevora Aevora

Privacy Policy

Snowfairy AI Labs Private Limited — Aevora (White-Label Remote Support Platform)
Last updated: September 14, 2026 · Governing law: India · Designed to support GDPR, UK GDPR, CCPA/CPRA & DPDP Act 2023 rights
Snowfairy AI Labs Private Limited ("Snowfairy", "we", "us") is committed to transparency about what the Aevora platform collects, why, how long it is kept, who can see it, and the rights you have. Because Aevora is remote-access software, this policy also explains, plainly, exactly what a support Session can and cannot see or transmit — and what it is built to never touch.

Contents

  1. Who This Policy Covers
  2. Account & Organization Data
  3. Session Data
  4. AI Diagnostic Data
  5. Visual Diagnosis (Screen Recording)
  6. Emergency Account Recovery Data
  7. Solo/Freelancer Verification Data
  8. What We Never Collect
  9. Cookies & Website Data
  10. How We Use Data
  11. Dispute & Chargeback Evidence
  12. Data Storage & Security
  13. Data Retention Schedule
  14. Third-Party Services
  15. Your Rights by Jurisdiction
  16. Children's Privacy
  17. International Data Transfers
  18. Changes to This Policy
  19. Contact & Grievance Redressal

1. Who This Policy Covers

This Policy covers data Snowfairy collects directly, as the platform provider: your organization's Licensee account, your Technicians' accounts, and the Platform's own operational and diagnostic data. It does not cover how your organization itself uses or stores data about your own End Users outside the Platform — that is governed by your organization's own privacy practices, for which you are responsible as the Licensee.

2. Account & Organization Data

When your organization creates a Licensee account: organization name, billing contact email, branding assets you upload (logo, colors), and seat/plan configuration. When a Technician account is created: their name and email address, managed via Firebase Authentication — we never see or store raw passwords.

3. Session Data

For every support Session: a device identifier, Session start/end timestamps, which Technician (or AI, in self-service mode) handled it, and a record of any diagnostic action proposed, approved, and applied. Screen and input data during a live Session travels directly between the Technician's console and the End User's device, encrypted for the duration of the Session — Snowfairy's own servers do not receive or store the video/input stream itself.

4. AI Diagnostic Data

Where AI-assisted diagnostics are used, a redacted snapshot of the device's diagnostic state (recent system fault entries, disk space, flagged device or service problems, antivirus status) is generated locally on the End User's device and sent to our AI providers to produce a proposed fix. Before this data leaves the device, it passes through an automated redaction step that strips emails, phone numbers, MAC/IP addresses, and credential-shaped text.

Chat messages exchanged with the AI during a Session are processed by our AI providers (see Section 14) solely to generate that Session's replies, and are retained only for the active conversation window described in Section 13.

5. Visual Diagnosis (Screen Recording)

The Platform includes an optional, last-resort visual diagnosis feature: a bounded set of local screenshots captured only while an End User explicitly starts a recording, used to help diagnose an issue that could not be explained from other evidence.

6. Emergency Account Recovery Data

Where enabled and used, the emergency local-account-recovery feature processes: the device owner's on-file recovery email, a one-time verification code (hashed, not stored in plain text), and an audit trail of the approval and execution steps. This feature requires both the device owner's own verification and, separately, an authorizing Technician's approval before anything executes; see our Terms of Service Section 7.

7. Solo/Freelancer Verification Data

An individual applying for a Solo/Freelancer license submits: full name, phone number, billing address, and a government-issued ID photo, used solely to verify eligibility for that license tier. ID photos are stored in a private, access-restricted cloud storage bucket, visible only to platform administrators reviewing the application, and are not used for any other purpose.

8. What We Never Collect

  • Live Session video/input streams on our own servers — these travel directly, encrypted, between Technician and End User.
  • Payment card numbers, CVV, or bank account details — handled entirely by our Payment Processor.
  • Passwords, card numbers, or other sensitive personal data through the AI chat — the Platform is built to refuse these if offered; see our Terms of Service.
  • Keystrokes, clipboard contents, microphone, or camera data outside an actively consented support Session.
  • Visual-diagnosis screenshots the End User chose not to send.

9. Cookies & Website Data

Our website and web consoles use a Secure, HttpOnly authentication session cookie for sign-in, standard short-lived Firebase Authentication tokens, and non-personal local-storage UI preferences (such as your light/dark theme choice) that are never transmitted to our servers. We do not use advertising cookies, cross-site tracking, or retargeting pixels.

10. How We Use Data

DataPurposeLegal Basis
Account & organization dataLicense delivery, billing, branding configurationContract performance
Session metadata & audit trailService delivery, security, dispute evidence, complianceContract / Legitimate interest
AI diagnostic snapshotsGenerate proposed fixes during a SessionContract performance
Visual-diagnosis screenshots (if sent)One-time AI analysis, then deletedExplicit consent
Recovery verification dataEmergency account-recovery featureContract / Legitimate interest
Solo/Freelancer ID photoLicense-tier eligibility verificationContract performance

We do not sell your personal data, use it for advertising profiling, or share it with data brokers.

11. Dispute & Chargeback Evidence

Account, license, and Session-usage records may be disclosed to our Payment Processor, the acquiring bank, or a card network's dispute resolution body in the event of a chargeback or fraud allegation, consistent with our Terms of Service Section 15. GDPR Art. 6(1)(f) DPDP Act 2023 §4(1)(b)

12. Data Storage & Security

Account, license, and Session-metadata are stored in Google Firebase (Firestore + Authentication), on Google Cloud infrastructure. Security measures include TLS 1.2+ encryption in transit, Firebase Security Rules restricting each Licensee's data to its own organization, and multi-factor authentication for platform-administrator access. In the event of a personal data breach posing risk to your rights, we will notify you as required by applicable law. GDPR Art. 33–34 DPDP Act 2023 §8(6)

13. Data Retention Schedule

DataRetention
Account & organization dataUntil account deletion is requested
Billing/license records7 years (tax & audit compliance)
Session audit trail90 days from Session date, then automatically deleted
AI diagnostic snapshots & chatActive conversation window only (a few hours), then deleted
Visual-diagnosis local screenshotsDeleted immediately after sending/discarding; 24-hour automatic purge for anything left behind
Solo/Freelancer ID photoDuration of application review, then deleted unless license is granted

14. Third-Party Services

ServicePurposePolicy
Google FirebaseAuthentication, database, hosting, cloud functionsfirebase.google.com/support/privacy
Payment processor / MoR (Paddle, outside India)Payment processing, dispute handlingpaddle.com/legal/privacy
Payment processor (Razorpay, India)Payment processingrazorpay.com/privacy
Groq / Anthropic (Claude)AI-assisted diagnostics, including visual diagnosisgroq.com/privacy-policy · anthropic.com/legal/privacy
ResendTransactional email (recovery codes, renewal reminders)resend.com/legal/privacy-policy
CloudflareWebsite & signaling infrastructurecloudflare.com/privacypolicy

We do not share your data with any other third party, except as required by law or as part of the dispute-resolution process described in Section 11.

15. Your Rights by Jurisdiction

JurisdictionYour Rights
IndiaAccess, correction, erasure, grievance redressal within 30 days, right to withdraw consent, right to complain to the Data Protection Board of India
EU / EEAAccess, rectification, erasure, restriction, portability, objection, and the right to lodge a complaint with your national supervisory authority (GDPR)
United KingdomSame as EU GDPR; right to complain to the ICO
United States (California)Right to know, delete, correct, and opt out of sale/sharing (we do not sell or share personal data); we honour Global Privacy Control signals
All other locationsWe honour reasonable data requests under principles of transparency and fairness

To exercise any right, email support@snowfairy.ai. We respond within 30 days (45 days for California requests, extendable once with notice). We may verify your identity before acting on a request.

16. Children's Privacy

The Platform is a business tool and is not directed at children. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, contact support@snowfairy.ai and we will delete it without undue delay. DPDP Act 2023 §9 GDPR Art. 8

17. International Data Transfers

Our data is stored on Google Firebase infrastructure. Transfers from the EU/EEA rely on Google's Standard Contractual Clauses under GDPR Art. 46(2)(c); transfers from the UK rely on the UK International Data Transfer Agreement. Cross-border transfers for Indian users follow DPDP Act 2023 §16. We do not transfer data to jurisdictions lacking adequate protection without appropriate safeguards.

18. Changes to This Policy

We may update this Privacy Policy from time to time, posting a new "Last updated" date and notifying you of material changes by email or in-app notice at least 14 days before they take effect.

19. Contact & Grievance Redressal

Privacy & Grievance Officer
Snowfairy AI Labs Private Limited
CIN: U62099UP2025PTC226386
Registered Address: 01, Mohansarai–Mataladai Road, Gangapur (Varanasi), Varanasi, Uttar Pradesh – 221302, India
Email: support@snowfairy.ai · contact@snowfairy.ai — subject line "Privacy Request"
Response: acknowledged within 3 business days; resolved within 30 days (or applicable statutory deadline)

Appointed as Grievance Officer under the Digital Personal Data Protection Act 2023 §13. If your grievance is not resolved within 30 days, you may escalate to the Data Protection Board of India once operational. EU/UK residents may lodge a complaint with their national supervisory authority if unsatisfied with our response. GDPR Art. 77