Privacy Policy
Effective January 1, 2026 · A2R Delivery OS™, a product of A2R Ventures LLC
1. Overview
This Privacy Policy describes how A2R Ventures LLC (“A2R,” “we”) collects, uses, stores, and protects information in connection with A2R Delivery OS™ (the “Service”). It applies to the organizations and individual users (“Customer,” “you”) who access the Service. Capitalized terms not defined here have the meaning given in the Terms of Service.
2. Information We Collect
Account & authentication data: name, email address, and a hashed (never plaintext) password for credential-based sign-in, plus organization membership and role assignment.
Customer Data: the engagement, financial, RAID, schedule, audit, and reporting information Customer and its users enter into or import into the Service, as defined in the Terms of Service. This is Customer’s data, held by A2R solely to provide the Service — see Section 4 of the Terms of Service for the full ownership treatment.
Usage & support data: basic application telemetry needed to operate the Service (e.g. which organization and route a support ticket was raised from, so we can route and reproduce issues), and the content of any support ticket submitted through the in-app Support & Ticket Submission feature.
We do not collect payment card data directly — billing, where applicable, is handled by a PCI-compliant third-party payment processor that never shares full card numbers with A2R systems.
3. Multi-Tenant Data Isolation
A2R Delivery OS™ is a multi-tenant application: every organization (“tenant”) that signs up shares the same application infrastructure, but tenant data is logically isolated at the database layer. Every record in the system — every project, deal, RAID entry, financial actual, audit entry, and report — is tagged with the owning organization’s identifier, and every server-side query used to read or write that data is scoped to the identifier of the organization the requesting user is actively a member of, as resolved from that user’s own authenticated session (never from client-supplied input). Role-based access control further scopes what any individual user within a tenant can see to their own portfolio, practice, or engagement assignment, depending on their delivery role. One tenant’s Customer Data is never visible to another tenant through the Service.
4. Encryption
Customer Data is encrypted in transit using TLS 1.3 (or the strongest protocol version supported by the connecting client where TLS 1.3 is unavailable) for every connection to the Service, including API and export/download traffic. Customer Data is encrypted at rest using AES-256 at the database and storage layer. Passwords are never stored in plaintext or in a reversible form — they are hashed using a salted, industry-standard hashing algorithm before storage.
5. We Do Not Sell Your Data
A2R does not sell, rent, or trade Customer Data or personal information to third parties for their own marketing purposes, and never has. We do not share Customer Data with third parties except: (a) with subprocessors who provide infrastructure the Service runs on (e.g. cloud hosting and managed database providers), bound by confidentiality and data-protection obligations at least as protective as this policy; (b) when required by law, subpoena, or valid legal process, after notifying Customer where legally permitted; or (c) with Customer’s explicit direction (for example, an export Customer chooses to download and share themselves).
6. Data Retention & Deletion
Customer Data is retained for as long as the organization maintains an active subscription, plus the 30-day post-termination export window described in the Terms of Service. After that window, Customer Data is deleted from active systems, subject to standard backup-cycle retention (backups are rotated out, not retained indefinitely). Customer may export a full copy of its own workspace at any time via the Service’s Workspace Backup export.
7. Your Rights
Depending on your jurisdiction, you may have rights to access, correct, export, or request deletion of your personal information. Account-level information (name, email) can be corrected by an organization administrator; a full Customer Data export is available at any time via Workspace Backup. To exercise any other privacy right, contact us through the in-app Support & Ticket Submission feature (Help → Contact Support).
9. Children’s Privacy
The Service is a business tool intended for use by professional services organizations and their employees. It is not directed to, and A2R does not knowingly collect personal information from, individuals under the age of 18.
10. Changes to this Policy
A2R may update this Privacy Policy from time to time. Material changes will be notified via the Service or by email to the organization’s registered administrator at least 30 days before taking effect.
11. Contact
Questions about this Privacy Policy can be directed through the in-app Support & Ticket Submission feature (Help → Contact Support), available to any signed-in user of the Service.