AVIOR.CRM - Privacy Policy

 

1. Responsible Entity 

REFINE IT GmbH
Martinistrasse 11
45657 Recklinghausen

Germany

Represented by the managing directors Carsten Bieker, Julian Jansen, Gregor Stefka and Marc Zühlke

 

2. Scope

This privacy policy applies to the AVIOR.CRM application, which is provided and operated exclusively via the Microsoft Azure Cloud.

3. Data Processed

a) User Identification

We use Microsoft Entra ID (formerly Azure Active Directory) for authentication and user identification. Only the following personal data is processed for licensing and access control:

  • User ID

  • Name (as provided by Microsoft Entra ID)

  • Email address (as provided by Microsoft Entra ID)

No additional personal user data is collected, stored, or processed beyond what is required for authentication and licensing.

b) Application Usage Data & Logs

For security, technical operation, and error analysis, the following data may be logged:

  • Access and usage logs (including timestamps, accessed resources, and technical metadata)

  • Diagnostic data and error messages

These logs do not contain any additional user content or sensitive personal information.

 

4. Purpose of Data Processing

Personal data is processed exclusively for the following purposes:

  • Licensing and access management of AVIOR.CRM

  • Ensuring secure, reliable operation of the application

  • Technical troubleshooting and error analysis

  • Compliance with legal obligations

5. Artificial Intelligence

AVIOR.CRM uses Microsoft Azure AI services (e.g., OpenAI, Cognitive Services) exclusively within the Azure Cloud. No personal user data is processed by these services beyond the minimal required authentication information.

6. Data Storage and Processing

All data is processed and stored in the Microsoft Azure Cloud (including Azure Functions and Azure SQL Database). Data is stored exclusively in data centers located in the European Union (EU), unless otherwise required by the customer or applicable law.

7. Data Sharing and Third Parties

Personal data is not shared with third parties, except:

  • With Microsoft as infrastructure provider (data processing agreement in place)

  • If required by law or legal process

No data is shared for advertising or marketing purposes.

8. Retention Period

Personal data and logs are retained only as long as necessary for the purposes stated above or as required by law. Log data is typically deleted after 90 days.

9. Data Subject Rights

As a user, you have the following rights:

  • Right of access (Art. 15 GDPR)

  • Right to rectification (Art. 16 GDPR)

  • Right to erasure (Art. 17 GDPR)

  • Right to restriction of processing (Art. 18 GDPR)

  • Right to data portability (Art. 20 GDPR)

  • Right to object (Art. 21 GDPR)

To exercise your rights, contact us at info@refineit.de.

9. Changes to This Privacy Policy

We reserve the right to update this privacy policy to reflect changes in legal requirements or technical developments. The latest version is always available at https://refineit.de/avior-crm-privacy-policy/