Legal

Privacy Policy

Last updated October 7, 2026

This policy explains what we collect, why, who helps us process it and how long we keep it. We work mostly from cloud billing and resource metadata, read through scoped roles you control and can revoke.

1. Overview and our role

This Privacy Policy explains how Averium, Inc. (“Averium”, “we”) handles information through the Averium website, client portal and browser extension.

Averium is the controller of account, contact, billing and website data. For personal data that sits in your cloud environment and that we process to provide the Service, such as user names in CloudTrail events or email addresses in resource tags, we act as your processor and process it only on your behalf and for that purpose.

2. Information we collect

  • Access requests. If you ask for access or a free estimate, we collect your company name and website, your name and work email, your approximate monthly AWS spend, an optional LinkedIn profile URL and the IP address you submitted from. We use them to review and answer your request and to prevent abuse.
  • Information from others. A colleague, or Averium when setting up your organization, may give us your name and work email to invite you.
  • Account information. Name, work email, company, role in your organization and authentication data (a hashed password and your two-factor settings). If a third-party sign-in option is offered and you use it, we receive basic profile information from that provider.
  • Cloud metadata. Through the roles you deploy we read billing, cost, usage and commitment data; resource inventory, including resource IDs, names and tags; and utilization metrics from CloudWatch and Container Insights. If you deploy the DevOps Hub, we also read CloudTrail management events around a cost spike, including the IAM user or role names that made changes. If you use pull-request cost feedback, we process the Terraform plans your CI sends and do not store them. Resource names, tags and CloudTrail identities can contain personal data of your staff.
  • Billing data from your AWS billing relationship. If your AWS billing is transferred to Averium, or your accounts join Averium’s AWS Organization, Averium and our distributor Pax8 receive your AWS billing and usage data through that relationship, independently of the IAM roles. This continues until the billing transfer ends or the accounts leave the organization.
  • Payments. For bank transfers we record the payer name and reference shown on our bank statement. If card payment is offered and you use it, a third-party payment processor collects your card details under its own terms, and we never receive the full card number. For other payment methods we record the transaction reference needed to reconcile your invoice.
  • Support and AI assistant. Messages you send us through the in-app chat or email, and questions, answers and files in the AI assistant (see below).
  • Funding requests. Project details, expected AWS spend and documents you submit when you ask us to apply for AWS funding.
  • Technical data. Log data such as IP address, browser type and time of request, used for security and reliability. IP geolocation by DB-IP.

3. AI assistant

The AI assistant in the portal chat is optional. When you use it, we send your question, the recent conversation, any files you attach (for example Cost Explorer screenshots or CSV exports) and a summary of your organization’s cloud cost data to Anthropic, PBC (USA) to generate the answer. The summary includes account names and IDs, spend, savings, cost by tag and the results of Cost Explorer queries the assistant runs in your account. Anthropic processes this data under its commercial terms and does not use it to train its models. We store questions and answers so a recent answer can be reused for members of your organization, and short notes the assistant saves about your environment. You can ask us to show or delete them at info@averium.io. Choosing “Talk to the FinOps team” sends your message to Averium staff, not to the AI.

4. How we access your cloud

We access your AWS accounts only through the IAM roles created by the Averium stacks you deploy, and your Azure subscriptions only through an Azure Lighthouse delegation you approve (Reader and Cost Management Reader). Changes happen only under an engagement model you authorize, through AWS-native mechanisms in your accounts.

Authorized Averium staff, using two-factor authentication and an internal audit log, may access your portal workspace to provide support and open time-limited AWS Console sessions with exactly the permissions of those roles.

To revoke access, delete the Averium stacks and any IAM roles under the /averium/ path, remove the Azure delegation under Service providers, and end any billing transfer or Averium AWS Organization membership.

5. Browser extension

  • Sign-in. You sign in with your portal email and password and your two-factor code. The extension stores a per-device session token in the browser’s extension storage, never your password. At sign-in it sends a short device description (browser and OS) so you can recognize and revoke the device in the portal. Tokens expire after 90 days, and signing out or revoking the device invalidates them.
  • What it does. It talks only to Averium over HTTPS to show your organization’s spend, savings and cost alerts, to send and receive support-chat messages, and to download your invoices and reports when you ask. It shows desktop notifications for your cost alerts.
  • What it does not do. It does not read your browsing history, the content of web pages or your activity on other sites.

6. How we use information

  • To provide, operate and improve the Service.
  • To prepare savings estimates, reports, invoices and recommendations.
  • To carry out optimizations you have authorized.
  • To review access requests and set up your organization.
  • To communicate with you: service notices, cost alerts and support.
  • To secure the Service and prevent abuse.
  • To meet legal, accounting and tax obligations.

Our legal bases are performance of our contract with you, our legitimate interest in running, securing and improving the Service, compliance with legal obligations and, where we ask for it, your consent.

7. Who we share information with

We do not sell personal information, do not share it for advertising, and never use it to assess creditworthiness. We share it only with the following, and only as needed to run the Service:

  • Amazon Web Services, Inc. hosts the Averium portal and database (US East, N. Virginia). Data inside your own AWS accounts is processed by AWS under your agreement with AWS.
  • Google LLC (Google Workspace) delivers our email, including invites, alerts, invoices and reports.
  • Anthropic, PBC powers the AI assistant, as described above.
  • Pax8, Inc., our AWS distributor, processes your company record, AWS account IDs and charges where we manage your AWS billing.
  • AWS as our partner. When you ask us to apply for AWS funding, we submit your project details, contact and expected spend to AWS. We may tag your resources with the AWS Partner attribution tag so AWS can attribute the usage we help optimize to Averium.
  • Microsoft Corporation, only if you connect Azure.
  • Slack or Microsoft Teams, only if you add an incoming-webhook URL. We then post cost and budget alerts, scheduling and remediation updates and cost-spike investigations, which can include the IAM user or role names involved, to the channel you choose.
  • PandaDoc, when we send an agreement for electronic signature.
  • Banks and payment processors that handle your payment.
  • Legal and corporate. Where required by law, to protect rights and safety, or as part of a merger, acquisition or sale of assets.

We will tell account owners before we add a new provider that processes personal data from your cloud environment.

8. International transfers

Averium is based in the United States and stores data in AWS’s US East (N. Virginia) region. If you are in the EEA, the UK or Switzerland, your personal data is transferred to the United States. We rely on the European Commission’s Standard Contractual Clauses and the UK Addendum, or another lawful transfer mechanism, for these transfers and for onward transfers to our providers.

9. Security

We use least-privilege IAM roles with external IDs, encryption in transit and at rest, hashed passwords and access tokens, two-factor authentication (required for portal accounts and for all Averium staff), and an audit log of Averium staff actions. No system is perfectly secure, but we work to protect your information and to limit what we can access in the first place.

10. How long we keep information

  • Account, workspace and cloud data: while your organization is a client, and then until you ask us to delete it or we no longer need it for the purposes above.
  • Invoices and payment records: as long as accounting and tax law requires, typically seven years.
  • Access requests that do not lead to an account: up to 24 months.
  • Support chat and AI assistant history: while your organization is a client, unless you ask us to delete it sooner.

11. Your rights and choices

You can update your profile in the portal, revoke cloud access at any time as described above, and ask us for access to, correction, export or deletion of your personal information at info@averium.io. We respond within the time required by applicable law. If we process the data as your organization’s processor, we will pass your request to your organization.

  • EEA and UK (GDPR). You have the rights of access, rectification, erasure, restriction, portability and objection, and you can complain to your local supervisory authority.
  • California (CCPA/CPRA). You have the rights to know, delete and correct your personal information and to opt out of its sale or sharing. We do not sell it or share it for cross-context behavioral advertising, and we will not discriminate against you for using these rights.

12. Cookies

We use only strictly necessary cookies: a session cookie that keeps you signed in and a preference cookie that remembers which organization you selected. We do not use analytics, advertising or tracking cookies on the website or in the portal.

13. Changes to this policy

We will post updates here and change the date above. For material changes we will notify account owners by email or in the portal at least 30 days before they take effect.

14. Contact

Averium, Inc., 111b South Governors Avenue, Dover, DE 19904, USA. Privacy requests: info@averium.io. See also our Terms of Service.