Privacy Policy for Avola Flow
Last updated: 20 September 2026.
Avola Flow is a project collaboration tool operated by Avola Media (Avola ApS, "Avola", "we"). This page explains what information we collect through Avola Flow, why, and how long we keep it. This applies whether you have an Avola Flow account or you're simply following a link someone shared with you. By using Avola Flow, you consent to this.
Information we collect
We collect the following categories of information about you:
- Account information: your name, email address, company, and role, provided when your account is created.
- Usage activity: actions you take in Avola Flow (for example, logging in, and project, deliverable, or invoice-related updates) are recorded in a security log, together with your IP address and browser (user agent). This includes opening a shared deliverable link, even if you don't have an Avola Flow account.
- Technical data: a single session cookie keeps you logged in to Avola Flow. We don't use advertising or analytics cookies. A light/dark theme preference may be saved in your own browser only — it's never sent to us.
How we use it
To operate Avola Flow: to authenticate you, show you the projects and data relevant to your role, notify you about relevant activity, and to detect and prevent abuse.
Avola staff may access account and project data, including logging in as your account, to provide support or troubleshoot an issue — every such action is recorded in our security log.
Connecting other applications
Avola Flow provides an API and an MCP connector so you or your company can connect another application — for example an AI assistant — to your own Avola Flow account. Following the data minimization principle, a connected application only ever sees what your account can already see in Avola Flow: your own name and company, and the projects, deliverables, and schedule you have access to. It never receives another person's name or email address — where a schedule item involves other people, a connected application is only told whether it's assigned to you, not who else is on it.
A personal access token can be revoked at any time by generating a new one, which invalidates the old one immediately. An application connected via OAuth (such as an AI assistant) instead receives a short-lived credential that expires automatically after a few hours.
Who we share it with
We use a small number of external services to make Avola Flow work:
| Service | What it's for |
|---|---|
| Mandrill | Sends the emails Avola Flow generates, using your name, email, and relevant project or invoice details. |
| Dinero | Avola's accounting system, where invoice records are kept. |
| Hetzner | Stores the project documents. |
| ipwho.is | Used internally by Avola staff to look up the general location of an IP address already in our security log, only when investigating suspicious activity. No account data is sent, and nothing from this lookup is stored. |
| Google Fonts | Fonts are loaded directly from Google when you view a page. |
| Simply.com | Our hosting provider, which stores Avola Flow's data. |
We don't sell your data, and we don't share it for advertising purposes.
We aim to keep your data within the European Union. Our hosting, file storage, and accounting systems are all EU-based; a small number of services we rely on (for example, our email provider) may process data outside the EU, subject to their own data-protection safeguards.
How long we keep it
Retention periods depend on the type of data:
| What | How long |
|---|---|
| Security log entries | 30 days |
| Account records | For as long as your account or project relationship with Avola is active, and afterwards for as long as required by our legal and accounting obligations |
| Project records | For as long as your account or project relationship with Avola is active, and afterwards for as long as required by our legal and accounting obligations |
| Invoice records | For as long as your account or project relationship with Avola is active, and afterwards for as long as required by our legal and accounting obligations |
| Document records | For as long as your account or project relationship with Avola is active, and afterwards for as long as required by our legal and accounting obligations |
Your rights
You can ask us what data we hold about you, request a correction, or ask us to delete it, subject to what we're legally required to keep (for example, accounting records). Contact us at dataprotection.ww@avolamedia.com.
You can also lodge a complaint with the Danish Data Protection Agency (Datatilsynet, www.datatilsynet.dk) if you believe your data has been handled unlawfully.
© 2026 Avola ApS · Privacy Policy