01Introduction
Aenvo Natural Interaction Lda. ("AENVO") values privacy and is committed to protecting personal data in compliance with the GDPR (Regulation (EU) 2016/679) and Law no. 58/2019 (GDPR Execution Law). This Policy describes in detail how we collect, use, store, protect, and share personal data within the scope of our website, applications, APIs, services, and Artificial Intelligence models ("Services").
02Who we are and contacts
Data Controller: Aenvo Natural Interaction Lda. ("AENVO").
Contact Email: privacy@aenvo.ai
Data Protection Officer (DPO): Ana Fazendeiro (privacy@aenvo.ai).
Competent Supervisory Authority: Comissão Nacional de Proteção de Dados (CNPD).
03Scope and definitions
This Policy applies to the personal data of customers, end-users, visitors, candidates, partners, and suppliers interacting with our Services.
- 'Personal Data': means any information relating to an identified or identifiable natural person.
- 'Processing': means any operation performed on personal data.
- 'Processor': means an entity that processes personal data on behalf of AENVO.
04Categories of collected data
(a) Account and billing data
Name, email, credentials, address, VAT ID (NIF), payment details.
(b) Technical data
IP address, device identifiers, browser type, timestamps, visited pages, events, cookies, and similar technologies.
(c) Input content and files
Prompts, documents, images, audio, and other materials submitted; and outputs generated by the models.
(d) Support and communications
Tickets, emails, consented recordings, surveys.
(e) Recruitment data
CV, experience, references.
(f) Voice biometric and facial recognition data
When the user makes use of biometric authentication features (by voice or facial recognition), AENVO processes biometric identification data, classified as special category data under Article 9 of Regulation (EU) 2016/679 (GDPR). This processing is carried out exclusively on the basis of the data subject's explicit consent, given freely, specifically, in an informed and unambiguous manner, which may be withdrawn at any time without affecting the ability to use the service through alternative authentication methods.
(g) Demo page statistics
When someone visits a private AENVO demo page (addresses under aenvo.ai/demo/…), we record access statistics to measure interest in our demos: date and time, approximate country, region and city, device type, operating system, browser, browser language, source of the visit (for example, a direct link or a QR code) and whether the demo password was entered correctly. The IP address is used only at the moment of access to determine the approximate location, through the GeoJS service, and is not stored; to count unique visitors we keep only a pseudonymised code from which the IP address cannot be obtained. These pages do not use tracking cookies and the data is not used for advertising. The legal basis is AENVO's legitimate interest in managing its commercial demos (Article 6(1)(f) GDPR). The data is accessible only to authorised AENVO staff and is deleted once it is no longer needed.
05Purposes and legal bases
Provision of Services and contract execution; account management and billing; security and abuse prevention (legitimate interest); improvement and development (legitimate interest balanced with privacy); compliance with legal obligations; marketing and communications with explicit consent; recruitment and application management (pre-contractual measures).
06Model training and data use for AI
By default, AENVO does not use Customers' Personal Data to train general models without an appropriate legal basis or explicit consent. We provide "opt-out" controls and data segregation, and make dedicated environments available when necessary. Publicly available data may be used in accordance with applicable law and minimisation principles; however, we do not associate customers' private content with general models without authorisation.
07Processors and cloud AI processing
To provide its Conversational AI and Authentication Services, AENVO relies on qualified service providers and cloud infrastructure. AENVO contractually ensures that all processors fully comply with the requirements of the GDPR and Regulation (EU) 2024/1689 (AI Act) and are strictly prohibited from retaining, sharing or using users' inputs, prompts or data to train their own models. Any international data transfers take place under appropriate safeguards, namely the European Commission's Standard Contractual Clauses.
08Automated decisions and profiling
Some AENVO services rely on automated decision-making and profiling, namely for fraud detection and content classification. Where required, we provide clear information about the logic involved, the envisaged impact and the user's right to request human intervention, express their point of view and contest the decision, pursuant to Article 22 of the GDPR.
In accordance with Article 14 of Regulation (EU) 2024/1689 (AI Act), AENVO's artificial intelligence systems involved in processes with a significant impact on users have human oversight mechanisms, allowing an operator to intervene whenever necessary.
AENVO does not use its artificial intelligence systems to infer users' emotional state for the purposes of categorisation, decision-making or any other effect, in compliance with the absolute prohibitions established by Article 5 of Regulation (EU) 2024/1689 (AI Act), in force since 2 February 2025.
09Retention and deletion
We retain data only for the necessary period: account data whilst the account is active; typical operational logs up to 30 days; billing data according to legal deadlines; support data for 12 months; we delete or anonymise data when it is no longer needed, unless there is a legal obligation.
For high-risk data processing, namely the processing of voice and image biometric data, AENVO carries out Data Protection Impact Assessments (DPIA) pursuant to Article 35 of the GDPR before processing begins, ensuring that risks to the rights and freedoms of data subjects are identified and mitigated. Data provided in interactions with AI agents is not used to train language models without the user's prior consent.
10Recipients and international transfers
We share data with strictly necessary Processors (cloud, email, monitoring, analytics) under Data Processing Agreements (DPA). For transfers outside the EEA, we adopt appropriate safeguards such as Standard Contractual Clauses (SCCs) and transfer impact assessments.
11Sub-processors
We publish a list of Sub-processors (Google Cloud — hosting, Titan — email, Google Analytics — analytics) with purpose, legal basis, and retention periods; we update it periodically and notify of relevant changes when required by contract.
12Data subject rights
Right of access, rectification, erasure, restriction, portability, and objection; right to withdraw consent; right to complain to the CNPD.
To exercise your rights, contact privacy@aenvo.ai. We will respond within 15 days (under the LGPD) or one month (under Article 12 of the GDPR). In cases of high complexity or a large number of requests, this period may be extended by a further two months, with a duly reasoned notification to the data subject within the initial one-month period.
Users with accessibility needs can contact AENVO at the same email address to exercise their rights through accessible alternative channels, in accordance with Directive (EU) 2019/882 (EAA) and Portuguese Decree-Law no. 82/2022.
13Information security
We apply encryption in transit (TLS 1.2+) and at rest (AES-256), RBAC, MFA, environment segregation, logging and auditing, penetration testing, vulnerability management, backups and DR, incident response, and responsible vulnerability disclosure.
The security measures implemented by AENVO are aligned with the cybersecurity best practices established by Portuguese Decree-Law no. 125/2025, which transposes Directive (EU) 2022/2555 (NIS2) into Portuguese law and has been in force since 3 April 2026, adopted voluntarily as a cybersecurity maturity benchmark.
AENVO's Information Security and Privacy Management System formally adopts the international standards ISO/IEC 27001 (Information Security) and ISO/IEC 27701 (Privacy Information Management, PIMS), ensuring the implementation and continuous auditing of technical and organisational controls to safeguard personal data and AI models. In addition, in accordance with Article 15 of the AI Act, AENVO implements protections against prompt injection and data poisoning attacks.
14Artificial intelligence systems and transparency
AENVO develops and operates conversational artificial intelligence systems, including voice and text customer service agents. In accordance with Regulation (EU) 2024/1689 (AI Act) and, in particular, its Article 50, in force since 2 February 2025, all AENVO artificial intelligence agents identify themselves as automated systems at the start of each interaction, ensuring that users are fully aware that they are communicating with an artificial intelligence system and not with a human being.
AENVO's artificial intelligence systems are not used to infer users' emotions, feelings or psychological states for categorisation or decision-making purposes, pursuant to the absolute prohibition established by Article 5(1)(f) of the AI Act.
AI-generated responses are intended for informational and workflow automation purposes. AENVO ensures that its AI systems are developed and operated according to the principles of transparency, security, accuracy and accountability, in line with the European Commission's ethics guidelines (AI HLEG).
15Cookies and similar technologies
We use essential, functional, analytical and advertising cookies. Analytical and advertising cookies, including those used by Google Analytics, are loaded only after the user gives explicit consent through the consent banner, in accordance with Article 7 of the GDPR and Portuguese Law no. 41/2004, as amended by Law no. 46/2012. The user can manage or withdraw their preferences at any time via the "Manage Cookies" link available on the website. For more information, please see our Cookie Policy.
16Children
The Services are not intended for minors under 18 years of age. We do not knowingly collect data from children; if you identify improper collection, please contact us for removal.
17Digital accessibility
AENVO is committed to the digital accessibility of its services, in compliance with Directive (EU) 2019/882 (European Accessibility Act) and Portuguese Decree-Law no. 82/2022, in force since 28 June 2025. We strive to ensure that our digital services are accessible to people with visual, hearing, motor and cognitive disabilities. The Digital Accessibility Statement is available online.
Users who need assistance or alternative channels to exercise their rights can contact us at privacy@aenvo.ai.
18Changes to this Policy
We may update this Policy to reflect practices or legal requirements. We will publish the update date and, when material, notify customers.
19Contacts and complaints
Contact privacy@aenvo.ai; supervisory authority: CNPD (www.cnpd.pt).