Bird Labs Ltd ("Bird Labs", "we", "us", "our") operates the Avyn platform and its associated services ("Services"). This Privacy Policy explains how we collect, use, store, share, and protect personal data in connection with the Services.
Bird Labs Ltd is a company registered in England and Wales (Company Number: 16810486), with its registered office at 167-169 Great Portland Street, London, England, W1W 5PF.
We are committed to protecting your privacy and complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, and, where it applies to our processing of personal data of individuals in the European Economic Area, the EU General Data Protection Regulation (EU GDPR).
Bird Labs Ltd is registered with the UK Information Commissioner's Office (ICO) under registration number ZC185728.
1. Who This Policy Applies To
This Privacy Policy applies to:
- Platform users - individuals who create an account on Avyn and use the Services (typically analysts, associates, partners, and other professionals at venture capital, private equity, and investment firms).
- Individuals whose data appears in the platform - professionals whose publicly available or third-party-sourced information is processed by the Services for the purposes of company discovery, enrichment, and classification.
- Website visitors - individuals who visit our website.
2. Our Role Under Data Protection Law
Bird Labs operates in a dual capacity depending on the type of data being processed:
Bird Labs as Controller
We act as an independent data controller for Enriched Data (as defined in our Terms of Service) sourced from third-party professional data providers and publicly available sources, platform user accounts, inferred and derived data (classification scores, tier assignments, ecosystem fit assessments), aggregated and pseudonymised usage analytics, and support communications.
Bird Labs as Processor
We act as a data processor on behalf of our customers (the controllers) for customer-provided contact data, email content and metadata where the customer has connected email integrations, messaging data where the customer has connected messaging integrations (such as LinkedIn), CRM data synchronised from the customer's CRM system, and any other personal data contained within Customer Content that the customer uploads, syncs, ingests, or otherwise makes available to us through the Services (including documents and files ingested through a connected file-storage integration such as Dropbox). The categories above are examples and are not intended to be exhaustive. Where we act as a processor, we process personal data solely in accordance with the customer's instructions and our Data Processing Addendum (DPA), which is available to customers on request.
3. What Personal Data We Collect
3.1 Data You Provide to Us
- Access-request information: Work email address and, if you join the waitlist, your name and firm. We use the email domain to assess whether the request is from a professional firm, show a preview of the relevant firm where available, route existing users to the platform, and respond to the request.
- Account information: Name, email address, job title, company name, and login credentials when you create an account.
- Payment information: Billing details processed by Stripe. Bird Labs does not store credit card numbers.
- Communications: Any information you provide when contacting us for support or feedback.
- Customer Content is processed by us as a processor on the customer's behalf, not as a controller. The categories of Customer Content we process (including data you upload, input, sync, or ingest, such as CRM data, email and messaging integration data, documents and files ingested through a file-storage integration such as Dropbox, outreach communications, and pipeline activity data), and the basis on which we process it, are described in Section 2 (Our Role Under Data Protection Law) and governed by our Data Processing Addendum (DPA).
3.2 Data We Collect Automatically
- Usage data: Information about how you interact with the Services, including features used, pages viewed, actions taken, timestamps, session duration, and the public-site request-access journey. On the public website, optional PostHog analytics and masked session replay are used only for the categories you allow through cookie preferences.
- Device and technical data: IP address, browser type, operating system, and device identifiers.
- Cookies and similar technologies: We use strictly necessary cookies to operate the Services (such as authentication and session management). Subject to your consent, we also use non-essential cookies and similar technologies for product analytics, in-app guidance, and error monitoring, as described in Section 9. If you use the platform from the United States, these are on by default and you can turn them off, as Section 9 explains.
3.3 Data We Source from Third Parties
- Professional profile data: Names, job titles, company affiliations, employment history, education, and professional contact details sourced from third-party professional data providers and publicly available sources.
- Company data: Company names, descriptions, founding dates, funding history, headcount, growth metrics, and industry classifications.
- Derived and inferred data: Classification scores, tier rankings, and ecosystem fit assessments generated by our machine learning models.
Article 14 transparency: Where we obtain personal data about individuals from third-party providers and publicly available sources rather than from the individuals themselves, we provide the information required by Article 14 UK GDPR (and, where applicable, EU GDPR) through this Privacy Policy. This includes the categories of personal data we process (professional profile and company data, as described above), the sources from which it originates (third-party professional data providers and publicly available sources), the purposes and lawful basis for processing (legitimate interests, as set out in Section 4), and the individual's right to object to our processing. Individuals can exercise their rights, including the right to object, by contacting us at privacy@avyn.io.
The Services are not intended to be used to process special category personal data (such as data revealing health, racial or ethnic origin, religious beliefs, political opinions, or sexual orientation), and we do not require it. We do not intentionally collect special category data as Enriched Data, and our Classification Models do not seek to infer protected characteristics. Customers should not upload, input, or sync special category data as Customer Content. To the extent any special category data nonetheless appears within Customer Content (for example, in free-text email or CRM fields, or in ingested documents), we process it only incidentally, in our capacity as processor, on the customer's documented instructions and lawful basis as controller.
4. Lawful Basis for Processing
We process personal data under the following lawful bases (we have identified what our legitimate interests are where appropriate):
| Data Category | Lawful Basis | Purpose |
|---|---|---|
| Public website access requests | Legitimate interests (responding to requested business enquiries, assessing service fit, and routing existing users) | Access-request qualification, response, waitlist management, and account routing |
| Platform user accounts | Contract | Account creation, authentication, and service delivery |
| Payment processing | Contract | Processing subscription payments |
| Enriched professional profile data | Legitimate interests (operating and providing an effective deal sourcing and investment-intelligence service to customers) | Identifying companies and professionals matching investment criteria |
| Model inference and classification outputs | Legitimate interests (providing decision-support classification to investment professionals and improving model accuracy) | Decision-support classification for investment professionals |
| Optional usage analytics and session replay | Consent | Website and product improvement and performance monitoring |
| Legal compliance data | Legal obligation | Retaining records and responding to lawful requests where required to comply with applicable law (for example, retaining payment records for six years) |
| Device, technical and security data | Legitimate interests (protecting the security and integrity of the Services and preventing fraud and abuse) | Authenticating access, securing the Services, and detecting and preventing unauthorised access, abuse, or security threats |
| Support and customer communications | Legitimate interests (managing the customer relationship and providing support) | Responding to support requests, feedback, and queries, and administering our relationship with you |
| Marketing communications | Consent | Sending marketing communications to platform users who have opted in (you may withdraw consent at any time) |
Legitimate interests assessment: Where we rely on legitimate interests, we have conducted a balancing test and determined that our interests in providing an effective deal sourcing and classification platform do not override the rights and freedoms of the individuals whose data we process. We do not intentionally process special category data or seek to infer protected characteristics (as further explained in Section 3), and we provide mechanisms for individuals to exercise their rights.
5. How We Use Personal Data
- Responding to access requests - checking whether a work email belongs to a professional firm, producing the requested firm preview, routing existing users, managing the waitlist, and contacting requesters about access to Avyn.
- Providing the Services - operating the platform, delivering company discovery, enrichment, classification, CRM integration, and outreach tools.
- Account management - creating and managing user accounts, authenticating access, and providing customer support.
- Payment processing - processing subscription payments via Stripe.
- Improving the Services - analysing usage patterns to improve platform functionality, develop new features, and optimise performance, including using anonymised and aggregated data to train and improve our Classification Models (as described in our Terms of Service, Section 6.4).
- Security and fraud prevention - detecting and preventing unauthorised access, abuse, or security threats.
- Legal compliance - complying with applicable laws and regulations.
- Communications - sending service-related notifications. We do not send marketing emails unless you have opted in.
6. How We Share Personal Data
We do not sell personal data.
We share personal data only in the following circumstances:
- For public-site operation - with Cloudflare for Turnstile bot protection, and, only where the visitor has allowed the relevant optional category, with PostHog for analytics or masked session replay.
- With sub-processors - cloud infrastructure providers, payment processors, authentication providers, professional data providers, and analytics tools. All sub-processors are bound by contractual obligations to protect personal data. A current list of our sub-processors, including their functions and locations, is available on request. Where we act as a processor on behalf of a customer, we provide advance written notice of any change to our sub-processors in accordance with our DPA.
- With third-party integrations configured by the customer (CRM, email, etc.).
- For legal compliance - if required by law, regulation, or legal process.
- In connection with a business transfer - if Bird Labs is involved in a merger, acquisition, or sale of assets.
We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.
7. Your Rights
Under UK GDPR and, where applicable, EU GDPR, individuals have rights to access, rectification, erasure, restriction of processing, data portability, objection to processing based on legitimate interests (including profiling), and rights related to automated decision-making. Where we rely on consent for any processing, individuals may withdraw that consent at any time without affecting the lawfulness of processing before withdrawal. We do not make decisions producing legal or similarly significant effects on individuals based solely on automated processing: our Classification Models provide decision-support outputs only, and final investment decisions are always made by human analysts. Individuals also have the right to lodge a complaint with a supervisory authority (see Section 14).
For platform users: You can exercise most of these rights directly through your account settings, or by contacting us at privacy@avyn.io.
For individuals whose data appears in the platform: Contact us at privacy@avyn.io. We will respond to your request within one month of receiving your request. Where a request is particularly complex or you have made a number of requests, we may extend this period by up to two further months, in which case we will notify you within one month of receipt and explain the reason for the delay, as permitted by UK GDPR (and, where applicable, EU GDPR).
For customers: To have your firm's data deleted, email us at privacy@avyn.io. An email is all we need. We handle the request from there and reply to confirm once the deletion is done. We complete the deletion within 7 days of the request. Where the 30-day export period described in Section 8 is still running, you can ask us to wait until it ends, and we then complete the deletion within 7 days of that date.
Where we act as a processor: Some personal data in the platform belongs to a customer who is its controller, as described in Section 2. Where you ask us to delete personal data of that kind, we pass your request to that customer, tell you that we have done so, and act on their instructions.
Verifying your identity: We may need to request specific information from you to confirm your identity and ensure your right to access the personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask for further information in relation to your request in order to speed up our response.
Fees: You will not normally have to pay a fee to exercise your rights. However, we may charge a reasonable fee, or refuse to act on a request, where the request is manifestly unfounded, repetitive, or excessive.
Objecting to processing based on legitimate interests: Where you object to our processing of personal data (including Enriched Data) that we carry out on the basis of legitimate interests, we will stop that processing unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or the processing is for the establishment, exercise, or defence of legal claims.
8. Data Retention
We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.
To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements. For example:
| Data Category | Retention Period |
|---|---|
| Public website access requests | For as long as needed to assess and respond to the request and manage the prospective business relationship, taking account of the last interaction and any applicable legal-claims period |
| Platform user accounts | Duration of account plus 12 months after account closure |
| Payment records | 6 years (UK legal requirement) |
| Customer Content (processor data) | Duration of subscription plus 30-day export period, then securely deleted within 7 days, or within 7 days of an earlier deletion request from the customer |
| Enriched Data | Refreshed periodically; outdated records removed on a rolling basis |
| Usage analytics | Aggregated and anonymised within 24 months |
| Support communications | 24 months from resolution |
Deleting Customer Content on request: A customer can ask us to delete its Customer Content at any time by emailing privacy@avyn.io. No form and no notice period are required. We complete the deletion within 7 days of the request and reply to confirm when it is done. The deletion removes the customer's Customer Content from our live systems and anonymises the account records of its platform users at the same time. Encrypted backups are kept on a rolling 7-day cycle, so anything held in a backup taken before the deletion is removed when that backup expires. Where the law requires us to keep a limited record, such as the payment records described in the table above, our confirmation says which records those are and why we hold them.
Anonymised and aggregated data: Where we anonymise or aggregate personal data so that it can no longer be associated with an identifiable individual, we may retain and use that data indefinitely for any lawful business purpose, including improving and training our Classification Models, as described in our Terms of Service (Section 6.4).
9. Cookies
We use strictly necessary cookies that are essential for the operation of the Services (such as authentication and session management). These do not require your consent.
We also use non-essential cookies and similar technologies (including local storage), namely:
- Product analytics (PostHog): to understand how users interact with the Services and to improve them; and
- In-app guidance (ProductFruits): to show product walkthroughs, onboarding checklists, and in-app help inside the platform, and to remember which guides you have seen; and
- Masked session replay (PostHog on the public website): to understand how visitors move through the landing page; and
- Error monitoring and session replay (Sentry in the platform): to detect, diagnose, and fix technical faults.
Outside the United States, non-essential cookies and similar technologies are not set until you have consented via our cookie banner. You can accept or reject non-essential cookies, and withdraw or change your choice at any time, through the cookie banner, the Cookie Preferences control in the public website footer, or cookie settings in the platform.
If you use the platform from the United States, which we determine from your IP address, product analytics, in-app guidance, and error monitoring are on by default once you have signed in and accepted our Terms of Service and this Privacy Policy, and we do not show a cookie banner. You can turn any of them off at any time under Settings, Cookie Preferences in the platform, and your choice then replaces the default. If you have already made a choice, it stays in force. The public website always asks for your consent first, wherever you are.
We do not use advertising cookies.
The cookies and similar technologies we use are set out below:
| Name / technology | Provider | Type | Purpose | Consent required? |
|---|---|---|---|---|
| Session / authentication cookies | Bird Labs (Avyn) | Strictly necessary | Maintain your logged-in session, authenticate access, and keep the Services secure | No |
| Load balancing / security cookies | Bird Labs (Avyn) | Strictly necessary | Route requests correctly and protect against fraud and abuse | No |
| Cloudflare Turnstile security and form-protection technologies | Cloudflare | Strictly necessary | Protect public access-request forms from automated abuse | No |
| Cookie consent preference | Bird Labs (Avyn) | Strictly necessary | Remember your cookie choices for up to six months | No |
| Product analytics (PostHog): ph_[project_api_key]_posthog cookie plus related local-storage entries (cookie duration up to 12 months / 365 days; local-storage entries persist until cleared) | PostHog | Analytics (non-essential) | Understand how users interact with the Services to improve and optimise them | Yes, except in the platform in the United States, where it is on by default and you can turn it off |
| Masked session replay (PostHog on the public website): related cookie and local-storage identifiers plus encrypted replay events; form inputs are masked | PostHog | Session replay (non-essential) | Understand page journeys and improve the public website | Yes - separate replay choice |
| In-app guidance (ProductFruits): local-storage entries and related identifiers that remember which walkthroughs and onboarding guides you have seen (persist until cleared) | ProductFruits (Product Fruits s.r.o.) | In-app guidance (non-essential) | Show product walkthroughs, onboarding checklists, and in-app help, and measure whether they are completed | Yes, except in the platform in the United States, where it is on by default and you can turn it off |
| Session replay and error monitoring (Sentry): sentryReplaySession session-storage entry (duration: browser session; Sentry does not set persistent cookies) | Sentry (Functional Software, Inc.) | Error monitoring and session replay (non-essential) | Detect, diagnose, and fix technical faults and improve reliability | Yes, except in the platform in the United States, where it is on by default and you can turn it off |
Strictly necessary cookies are essential to provide the Services and are set without consent. Outside the United States, non-essential cookies are set only where you have consented via our cookie banner. In the platform in the United States they are on by default, as described above. Either way, you can withdraw or change your choice at any time through Cookie Preferences on the public website or the cookie settings in the platform.
10. International Transfers
Bird Labs primarily processes data within the United Kingdom and European Economic Area. Where data is transferred outside the UK/EEA (for example, to sub-processors based in the United States), we ensure appropriate safeguards are in place, including, for transfers to the United States, the UK Extension to the EU-US Data Privacy Framework (the UK-US "data bridge") where the recipient is self-certified to it; the International Data Transfer Agreement (IDTA) or UK Addendum issued by the UK Information Commissioner's Office, together with a transfer risk assessment, for transfers subject to UK GDPR; the European Commission's Standard Contractual Clauses (or the EU-US Data Privacy Framework) for transfers subject to EU GDPR; or transfer to countries benefiting from an adequacy decision. Details of the specific mechanism used for a particular transfer are available on request.
11. Data Security
We implement appropriate technical and organisational measures to protect personal data and prevent it from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. These include encryption in transit and at rest, access controls and authentication, regular security assessments, and incident response procedures.
No system is completely secure. If we become aware of a security breach that affects your personal data, we will notify you and the relevant supervisory authority in accordance with applicable law.
12. Children's Data and Third-Party Links
The Services are not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children.
The Services and our website may include links to, or integrations with, third-party websites, applications, and services. We do not control those third parties and are not responsible for their privacy practices. We encourage you to review the privacy information of any third-party website or service before providing personal data to it.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated to platform users via email or in-platform notification at least 30 days before they take effect.
It is important that the personal data we hold about platform users is accurate and current. Please keep us informed, through your account settings or by contacting us at privacy@avyn.io, if your personal data changes during your relationship with us.
14. Contact Us and Complaints
Bird Labs Ltd167-169 Great Portland Street
London, England, W1W 5PF
Email: privacy@avyn.io
You can contact Cameron Helsby, our Data Protection Officer, in relation to this Privacy Policy or any data protection matter at cameron@avyn.io. As required under Article 27 EU GDPR, we have appointed Prighter EU Rep GmbH (part of the Prighter Group) as our representative in the European Union. Individuals in the EEA may contact our EU representative to exercise their data protection rights via our EU representative's contact page.
If you are not satisfied with our response, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk. If you are located in the European Economic Area, you also have the right to lodge a complaint with the supervisory authority in your country of residence, place of work, or the place of the alleged infringement.