Legal
Privacy Policy
This policy explains how Avut PIM handles merchant, user, workspace, product, and operational data when providing product information management and commerce integration services.
Last updated: July 26, 2026
Who we are
Avut PIM is provided by Norleaf AS, Norwegian organization number 938 103 984, with registered address Kroken 1, 4340 Bryne, Norway.
Avut PIM is a product information management service for merchants and teams that manage catalog data, media, imports, feeds, integrations, AI-assisted workflows, MCP-enabled workflows, and operational history.
For most customer workspace, catalog, product, media, import, export, integration, and AI workflow data stored or generated in Avut PIM, the customer workspace owner acts as the controller and Avut acts as a processor on that customer’s behalf. The customer is responsible for its own privacy notices, legal bases, and instructions for that data.
Avut acts as an independent controller for account registration and login, workspace administration, billing and payment administration, support, service communications, service security, abuse prevention, compliance, and other business operations described in this policy.
If you are an individual whose personal data is included in a customer’s workspace, imports, product content, media, support materials, or integration payloads, the relevant customer is usually the first contact for privacy rights requests relating to that data. Avut may assist the customer in responding in accordance with its processor obligations.
Personal data we process
Depending on how Avut PIM is used, we may process the following categories of personal data:
- account and identity data, such as name, email address, login details, organization membership, role, and user preferences;
- workspace administration data, such as workspace name, workspace owner details, team memberships, permissions, and configuration history;
- billing and commercial data, such as company and billing contact details, subscription plan, invoice metadata, payment status, tax-related details, and limited payment-related metadata returned by our billing provider;
- support and communications data, such as support tickets, emails, feedback, and troubleshooting materials;
- product and catalog content that customers choose to place in Avut PIM, which may include personal data if customers include such data in product text, media, attributes, import files, export files, workflow context, or support messages;
- integration, MCP, and API-related data, such as integration settings, connected account metadata, MCP client and grant metadata, API key metadata, job history, and operational logs; and
- security and audit data, such as access logs, change history, security events, and operator activity needed to protect and administer the service.
We do not intentionally require customers to upload personal data into catalog or product content unless that is necessary for the customer’s own use case. Customers are responsible for determining what personal data they place in their workspaces and for ensuring that they have a lawful basis to do so.
Where data comes from
We receive personal data directly from users, workspace administrators, billing contacts, and other individuals who interact with Avut PIM. We may also receive personal data from connected services and integrations chosen by a customer, from authentication, billing, support, security, and infrastructure providers, and from other persons within the same customer organization, for example where an administrator invites or manages users on behalf of the customer.
Required registration and billing fields are identified in the relevant forms. If required information is not provided, Avut may be unable to create an account, activate a workspace, provide requested features, or complete a purchase.
Why we process data
We process personal data for the following purposes:
- to create and manage accounts, authenticate users, administer workspaces, and enable imports, exports, integrations, MCP connections, and other core service functionality;
- to provide AI-assisted features requested or enabled by the customer;
- to manage subscriptions, invoices, bookkeeping, tax, and compliance obligations;
- to provide support, communicate about the service, and respond to requests;
- to monitor, secure, maintain, and improve the reliability and performance of the service;
- to detect abuse, investigate incidents, enforce our terms, and establish, exercise, or defend legal claims; and
- to comply with applicable laws and lawful requests from competent authorities.
Legal bases for processing
Where Avut acts as controller, we rely on the following legal bases depending on the purpose:
- Contract: where processing is necessary to provide Avut PIM, manage accounts, administer subscriptions, or take steps requested before entering into a contract;
- Legal obligation: where processing is necessary to comply with bookkeeping, tax, accounting, fraud-prevention, sanctions-screening, or other legal requirements that apply to us;
- Legitimate interests: where processing is necessary for our legitimate interests in securing, operating, supporting, maintaining, and improving a business SaaS service, including preventing abuse, keeping audit trails, maintaining system integrity, and defending legal claims, unless those interests are overridden by the rights and freedoms of the individual; and
- Consent: where consent is legally required, such as for certain cookies, similar technologies, or other optional features that require consent.
Avut does not sell personal data.
How we share data
We share personal data only where necessary for the purposes described in this policy, including with:
- service providers that help us operate Avut PIM, such as hosting, storage, authentication, security, communications, billing, and AI providers;
- Microsoft Graph, when Avut sends service, support, operational, product, or legal communications;
- payment and billing providers, including Stripe and, for eligible Shopify-originated workspaces, Shopify Billing, to manage subscriptions, invoices, payment status, fraud prevention, and related financial operations;
- integration providers and platforms that a customer chooses to connect to Avut PIM;
- professional advisers, auditors, insurers, and parties involved in a financing, investment, merger, acquisition, or corporate reorganization, subject to appropriate confidentiality safeguards; and
- public authorities or other recipients where disclosure is required by law or necessary to establish, exercise, or defend legal claims.
Avut currently uses Stripe-hosted Checkout Sessions for new subscriptions and add-on purchases, and Stripe Customer Portal for subscription self-service. Payment card details are therefore normally entered on Stripe-hosted pages rather than into Avut’s own forms. Avut normally receives billing contact details, subscription status, invoice information, and limited payment metadata needed to administer the subscription, but does not store full payment card numbers or CVC codes.
Eligible workspaces created through the Shopify app may instead use Shopify Billing. In that case, plan selection creates a Shopify app-subscription approval flow, and Shopify returns subscription and billing status needed to administer the workspace. A workspace is assigned one billing provider and must not be actively billed through both Stripe and Shopify Billing.
Our current public register of subprocessors and third-party providers is available at: https://avut.io/privacy/subprocessors
Optional MCP connections
Avut may provide a standards-based remote MCP server that allows an authorized external AI or MCP client to use a limited set of Avut tools when the user connects the client and authorizes access through OAuth. Such clients are selected by the customer or user, and the provider of the external client is not necessarily selected, controlled, or contracted by Avut.
The user initiates the connection, signs into Avut, selects exactly one workspace, reviews the requested access, and authorizes it through OAuth. A connection is bound to the Avut user, external client, OAuth grant, and selected workspace. Avut may recheck the grant, workspace access, current membership, role, permissions, and applicable tenant tool policy when tools are used.
The selected external client receives only data returned by tools invoked through the authorized connection. Results are designed to be tenant-scoped, permission-checked, bounded, and minimized. Public tool responses are designed to exclude credentials, API keys, raw OAuth material, connector secrets, raw exceptions, storage keys, checksums, and similar sensitive implementation details. Product and catalog data may nevertheless contain personal data if the customer placed personal data into product names, descriptions, attributes, media, import data, or other catalog fields.
Where a customer connects an external MCP client, the external client provider may process prompts, conversation context, tool requests, and returned Avut data under the customer’s own account, contract, retention, residency, and model-training settings with that provider. Customers should connect such a client only if their organization permits that provider to process the selected workspace data.
Avut treats OAuth authorization for MCP as an access authorization and customer instruction, not as GDPR consent.
Workspace administrators can disable MCP access and revoke individual client grants. Removing a connector only in the external client may not revoke the corresponding server-side Avut grant.
Avut stores MCP client and grant metadata, audit records, operation records, and opaque token or authorization-code hashes. Avut does not store raw OAuth access tokens or refresh tokens for MCP connections. Authorization-code hashes are removed after one day. Expired or revoked token hashes are removed after 31 days. Security audit records follow Avut’s 365-day audit-retention target. Short-lived write previews expire after 10 minutes.
AI-assisted features
When AI features are enabled by a customer or by an authorized user, Avut may send the data necessary for the requested task to the AI provider configured by Avut for that feature or workspace. Avut’s built-in AI features currently use OpenAI through the API for supported translation, inline product content generation, assistant workflows, alt text, image generation, tariff suggestions, and import mapping suggestions.
We aim to minimize the data sent for each task and to avoid sending unrelated data. For more detailed information about AI feature categories, data handling, human review, retention, and customer-directed MCP clients, please see Avut’s AI Privacy page.
OpenAI states that API inputs and outputs are not used to train or improve its models by default unless the API customer explicitly opts into data sharing. Under OpenAI’s default API controls, abuse-monitoring logs for the Chat Completions and image endpoints used by Avut may be retained for up to 30 days, subject to provider configuration, legal exceptions, and any approved modified-abuse-monitoring or zero-data-retention controls.
Avut does not use AI features to make solely automated decisions that produce legal or similarly significant effects about individuals.
International transfers
Avut uses approved subprocessors and service providers to operate the service. Where personal data is transferred outside the EEA, we rely on a valid transfer mechanism under Chapter V of the GDPR, such as an adequacy decision or the European Commission’s Standard Contractual Clauses, together with any supplementary measures required by applicable law.
A customer’s use of a third-party integration or external MCP client may direct us to send data to that recipient, but such customer direction does not replace the need for a lawful transfer mechanism where one is required. The applicable provider relationship and transfer arrangements may differ depending on whether the provider is engaged by Avut as part of the Avut service or independently selected and connected by the customer.
Where data is stored
Avut’s primary application and database infrastructure is currently located in Frankfurt, Germany. Certain data may nevertheless be processed or stored in other regions by relevant providers, including for object storage, security, support functions, backups, customer-authorized integrations, external MCP clients, billing, and AI functionality.
Cloudflare R2 object storage currently uses an automatic location setting. Avut therefore does not state that all customer data is stored or processed exclusively within one country or exclusively within the EEA.
Current provider roles and regional notes are described in our public register at https://avut.io/privacy/subprocessors
Retention
We retain personal data only for as long as necessary for the purposes described in this policy and in line with the storage limitation principle.
- Account, workspace administration, and profile data are retained for as long as the account or workspace is active, and may be retained for up to 30 days after closure to manage export, reactivation, disputes, security, and service winding-down.
- Billing, payment, tax, and accounting records are retained for as long as required by applicable bookkeeping, tax, and financial reporting laws.
- Security and audit logs are normally retained for 365 days.
- Notifications are normally retained for 90 days.
- Finalized import, export, feed, catalog, translation, AI, media-ingest, and integration jobs or events are normally retained for 60 days.
- Temporary operator or privacy export packages are normally deleted within 14 days after delivery.
- Privacy request evidence may be retained for up to three years after closure where needed for compliance and recordkeeping.
- MCP authorization-code hashes are removed after one day, and expired or revoked MCP token hashes are removed after 31 days.
- Backup and disaster-recovery copies may persist for limited periods in provider-managed backup cycles and are deleted or overwritten in the ordinary course.
When Avut acts as a processor for customer workspace data, we retain that data until the customer deletes it, closes the workspace, or instructs us to delete it, subject to applicable backup cycles, legal obligations, and security needs. Customer agreements separately describe deletion and return obligations under Article 28.
Your rights
Subject to applicable law, you may have the right to request access, rectification, erasure, restriction, objection, and data portability. You may also withdraw consent at any time where we rely on consent.
To exercise your rights, contact us using the details in the Contact section below. We may ask for additional information to verify your identity before completing a request. We normally respond without undue delay and within one month, although the period may be extended where permitted by law due to the complexity or number of requests.
If your request concerns personal data that Avut processes on behalf of a customer workspace, we may direct you to that customer as the relevant controller, or we may assist that customer in responding in accordance with our processor obligations.
You also have the right to lodge a complaint with your local supervisory authority. In Norway, the relevant authority is Datatilsynet.
Automated decisions and children
Avut PIM is a business service and is not directed to children.
Avut does not use solely automated decision-making that produces legal effects or similarly significant effects about individuals in the manner described in Article 22 GDPR.
Cookies and similar technologies
Avut currently uses cookies and similar technologies only where they are strictly necessary to provide authentication, security, requested preferences, and core application functionality. Avut’s separate Cookie Policy describes the current cookie and browser storage use in more detail.
If Avut later introduces analytics, advertising, or other non-essential technologies, they will not be enabled until any required consent has been obtained.
Security
Avut uses technical and organizational measures designed for a business SaaS service, which may include access controls, role-based permissions, secret management, logging, monitoring, encryption in transit, and other measures appropriate to the risk.
No service can guarantee absolute security. However, we work to protect personal data against unauthorized or unlawful processing and against accidental loss, destruction, or damage.
Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our services, providers, legal obligations, or privacy practices. If we make material changes, we will update the “Last updated” date and, where appropriate, provide additional notice through the service or by other reasonable means.
Contact
For privacy questions, data requests, or deletion requests, contact admin@avut.io.