Skip to main content

Aventora Data Processing Addendum — Appendix

FieldValue
Document NameData Processing Addendum Appendix
Version1.2
Effective DateJuly 20, 2026
OwnerAventora Security
Review FrequencyAnnually
ClassificationInternal / Customer Shareable
Approval StatusTemplate approved for customer negotiation — binding only when executed

Important Notice

This document is a template appendix intended to support negotiation and execution of a Data Processing Addendum (“DPA”) between Aventora Inc. (“Aventora,” “Processor”) and a customer (“Customer,” “Controller”). It is structured to align with common GDPR Article 28 processor obligations and similar requirements under PIPEDA, UK GDPR, and other applicable privacy laws.

This appendix is not a binding contract. It must be incorporated into, or executed together with, a master services agreement or standalone DPA signed by authorized representatives of both parties. Customers should consult qualified legal counsel before execution.

For operational policy detail, see the Personal Data Privacy & Protection Policy. For the current subprocessor list, see the Subprocessor Annex.


Appendix A — Data Processing Terms

When incorporated into an executed agreement, the following terms apply to Aventora’s processing of Personal Data on behalf of Customer.


A.1 Definitions

Capitalized terms not defined in this Appendix have the meanings given in the master agreement. For purposes of this Appendix:

TermMeaning
Applicable Data Protection LawPrivacy and data protection laws applicable to the processing of Personal Data under this Appendix, which may include PIPEDA, GDPR, UK GDPR, and U.S. state privacy laws, as applicable to the parties and processing activities
Customer DataPersonal Data processed by Aventora on behalf of Customer pursuant to the Agreement
Data SubjectAn identified or identifiable natural person to whom Personal Data relates
Personal DataInformation about an identified or identifiable natural person processed by Aventora on behalf of Customer
ProcessingAny operation performed on Personal Data, including collection, recording, organization, storage, adaptation, retrieval, consultation, use, disclosure, transmission, alignment, restriction, erasure, or destruction
Security IncidentA breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data processed by Aventora on behalf of Customer
SubprocessorA third party engaged by Aventora to process Personal Data on Aventora’s behalf
AgreementThe master services agreement together with this Appendix and any order forms or statements of work

Terms such as Controller, Processor, Supervisory Authority, and Personal Data Breach have the meanings given in GDPR where GDPR applies to the processing.


A.2 Roles of the Parties

A.2.1 Customer is the Controller (or equivalent under Applicable Data Protection Law) with respect to Customer Data. Customer determines the purposes and means of processing Customer Data except where Aventora determines purposes and means as required by Applicable Data Protection Law.

A.2.2 Aventora is the Processor with respect to Customer Data and will process Customer Data only on documented instructions from Customer, except where Applicable Data Protection Law requires otherwise.

A.2.3 The subject matter, duration, nature, and purpose of processing, types of Personal Data, and categories of Data Subjects are described in Appendix B (Processing Details) and may be further specified in order forms or deployment documentation.


A.3 Customer Instructions

A.3.1 Aventora will process Customer Data only:

(a) to provide the services described in the Agreement;

(b) to implement security, availability, and abuse-prevention controls;

(c) as otherwise documented in written instructions from Customer that are consistent with the Agreement; and

(d) as required by Applicable Data Protection Law, in which case Aventora will inform Customer of that legal requirement before processing unless prohibited by law.

A.3.2 Customer instructs Aventora to process Customer Data using the platform features, configurations, and integrations enabled by Customer. Customer is responsible for ensuring that its instructions comply with Applicable Data Protection Law.

A.3.3 If Aventora reasonably believes an instruction infringes Applicable Data Protection Law, Aventora will promptly notify Customer.


A.4 Aventora Obligations

Aventora will:

A.4.1 Confidentiality — Ensure that personnel authorized to process Customer Data are bound by confidentiality obligations appropriate to the nature of the processing.

A.4.2 Security — Implement appropriate technical and organizational measures to protect Customer Data, taking into account the state of the art, costs of implementation, nature of processing, and risks to Data Subjects. Measures include those described in Appendix C (Security Measures) and the Personal Data Privacy & Protection Policy.

A.4.3 Subprocessors — Comply with Section A.6 (Subprocessors).

A.4.4 Data Subject Rights — Assist Customer, taking into account the nature of processing and information available to Aventora, in responding to Data Subject requests to exercise rights under Applicable Data Protection Law, where technically feasible and as specified in Section A.8.

A.4.5 Security Incidents — Notify Customer of Security Incidents in accordance with Section A.9.

A.4.6 Deletion and Return — Upon termination or expiry of the Agreement, delete or return Customer Data in accordance with Section A.10, subject to Applicable Data Protection Law and backup retention cycles.

A.4.7 Demonstrable Compliance — Make available information reasonably necessary to demonstrate compliance with this Appendix and allow for audits as described in Section A.11.

A.4.8 No Sale — Not sell Customer Data or use Customer Data for advertising or unrelated commercial purposes.

A.4.9 No Model Training — Not use Customer Data to train general-purpose artificial intelligence models unless explicitly agreed in writing.


A.5 Customer Obligations

Customer will:

A.5.1 Ensure it has established an appropriate lawful basis for processing and has provided required notices to Data Subjects;

A.5.2 Configure the platform, roles, permissions, and integrations in accordance with its privacy commitments;

A.5.3 Not submit Personal Data to the platform in violation of Applicable Data Protection Law or the Agreement;

A.5.4 Provide documented instructions where required for processing activities initiated by Customer;

A.5.5 Respond to Data Subject requests where Customer is Controller, requesting Aventora assistance where needed; and

A.5.6 Notify Aventora promptly of any complaint, investigation, or inquiry from a Supervisory Authority relating to Aventora’s processing of Customer Data, to the extent permitted by law.


A.6 Subprocessors

A.6.1 General authorization. Customer provides general authorization for Aventora to engage Subprocessors to support delivery of the services, subject to the requirements of this Section.

A.6.2 Current Subprocessors. The Subprocessors engaged as of the effective date are listed in the Subprocessor Annex and/or Appendix D (Subprocessors) to the executed DPA.

A.6.3 New Subprocessors. Aventora will notify Customer of intended additions or replacements of Subprocessors that process Customer Data [INSERT NOTICE PERIOD, e.g., 30 days] in advance. Notification may be provided by email, account notice, or publication of an updated subprocessor list.

A.6.4 Objection. Customer may object to a new Subprocessor on reasonable grounds relating to data protection within [INSERT OBJECTION PERIOD, e.g., 14 days] of notification. If the parties cannot resolve the objection within a reasonable period, either party may exercise remedies specified in the Agreement.

A.6.5 Subprocessor terms. Aventora will impose data protection obligations on Subprocessors by contract that are substantially similar to those in this Appendix with respect to the protection of Customer Data. Without limiting the foregoing, Aventora’s standard Subprocessor terms require each Subprocessor to:

(a) process Personal Data only on documented instructions and for the contracted purpose, in compliance with Applicable Data Protection Law;

(b) not sell Customer Data or make unauthorized disclosures of Customer Data;

(c) implement appropriate technical and organizational security measures;

(d) notify Aventora without undue delay of a confirmed personal data breach or security incident affecting Customer Data;

(e) obtain Aventora’s prior written authorization before engaging a new further subprocessor where required by contract or Applicable Data Protection Law (which authorization may be given as general written authorization through advance notice and an opportunity for Aventora to object, rather than case-by-case consent in every instance);

(f) flow down data protection obligations to further subprocessors that are no less protective than those owed to Aventora;

(g) not attempt to re-identify any de-identified, anonymized, aggregated, or pseudonymized data derived from Customer Data unless Aventora has expressly authorized such re-identification in writing and such re-identification is permitted by Applicable Data Protection Law;

(h) promptly assist Aventora with data subject rights requests relating to Customer Data, including access, correction, deletion, restriction, portability, objection, and related requests, to the extent required by Applicable Data Protection Law;

(i) not transfer Customer Data outside the agreed processing locations or jurisdictions without Aventora’s prior written approval, and where an international transfer is approved, implement all legally required safeguards, including Standard Contractual Clauses, transfer impact assessments, supplementary measures, or equivalent lawful transfer mechanisms;

(j) return or securely destroy Customer Data upon termination or Aventora’s request, subject to legal retention requirements; and

(k) provide information reasonably necessary to demonstrate compliance and cooperate with audits where required by the Subprocessor agreement or Applicable Data Protection Law.

The operational standard terms and pre-approval checklists Aventora uses for Vendors and Subprocessors are set out in the Vendor Management Policy.

A.6.6 Responsibility. Aventora remains responsible to Customer for the performance of Subprocessors’ obligations to the extent required by Applicable Data Protection Law.


A.7 International Transfers

A.7.1 Customer acknowledges that Personal Data may be transferred to and processed in countries other than the country of origin, including countries that may not provide the same level of data protection, where necessary to provide the services.

A.7.2 Where GDPR or UK GDPR applies and a transfer requires a transfer mechanism, the parties will execute appropriate safeguards such as:

(a) the EU Standard Contractual Clauses (Module Two: Controller to Processor) or UK International Data Transfer Addendum, as applicable; or

(b) another lawful transfer tool recognized under Applicable Data Protection Law, which may include transfer impact assessments and supplementary measures as required.

A.7.3 Default hosting for Aventora-managed deployments is in AWS Canadian regions unless otherwise agreed. Certain enabled features (for example, AI inference or global telephony) may involve processing in additional jurisdictions as described in the Subprocessor Annex.

A.7.4 Aventora will require its Subprocessors not to transfer Customer Data outside the processing locations agreed with Aventora without Aventora’s prior written approval and, where an international transfer is approved, to implement the legally required safeguards described in Section A.6.5(i) and this Section A.7.


A.8 Data Subject Requests

A.8.1 Aventora will provide reasonable assistance to Customer in responding to Data Subject requests to exercise rights under Applicable Data Protection Law, including rights of access, rectification, erasure, restriction, portability, and objection, where technically feasible through platform functionality or operational procedures.

A.8.2 Customer will submit requests to Aventora through [INSERT CONTACT METHOD, e.g., security@aventora.ai or the customer support portal] with sufficient detail to identify the Data Subject and the requested action.

A.8.3 Aventora may charge reasonable fees or refuse manifestly unfounded or excessive requests where permitted by Applicable Data Protection Law, after informing Customer of the reasons.

A.8.4 If Aventora receives a Data Subject request directly, Aventora will promptly redirect the Data Subject to Customer unless required by Applicable Data Protection Law to respond directly.


A.9 Security Incidents

A.9.1 Notification. Aventora will notify Customer without undue delay, and in any event within [INSERT PERIOD, e.g., 72 hours] of becoming aware of a confirmed Security Incident affecting Customer Data, where notification is required by Applicable Data Protection Law or the Agreement.

A.9.2 Content. Notification will include, to the extent known at the time:

(a) a description of the nature of the Security Incident;

(b) categories and approximate number of Data Subjects and records affected, where feasible;

(c) likely consequences; and

(d) measures taken or proposed to address the incident.

Aventora may provide information in phases as an investigation progresses.

A.9.3 Cooperation. Aventora will cooperate with Customer and provide reasonable assistance in investigating and mitigating the Security Incident, including information reasonably required for Customer to meet regulatory notification obligations where Aventora acts as Processor.

A.9.4 Law enforcement. Aventora may delay notification or limit disclosure where required by law enforcement or regulatory inquiry, and will inform Customer where permitted.


A.10 Deletion and Return of Customer Data

A.10.1 Upon termination or expiry of the Agreement, Aventora will, at Customer’s election specified in writing within [INSERT PERIOD, e.g., 30 days]:

(a) return Customer Data in a commonly used, machine-readable format where technically feasible; and/or

(b) securely delete Customer Data from active systems,

subject to:

(i) Applicable Data Protection Law requiring continued storage;

(ii) backup retention cycles, with deleted data purged from backups within [INSERT BACKUP RETENTION PERIOD, e.g., 90 days]; and

(iii) anonymized or aggregated data that does not identify Data Subjects.

A.10.2 Aventora will certify deletion upon Customer’s written request where commercially reasonable.


A.11 Audits and Information

A.11.1 Aventora will make available to Customer information reasonably necessary to demonstrate compliance with this Appendix, which may include:

(a) this policy documentation and security summaries;

(b) responses to reasonable security and privacy questionnaires; and

(c) summaries of third-party assessments or certifications actually held by Aventora, if and when available.

A.11.2 Customer may conduct an audit no more than once per twelve (12) month period (or more frequently if required by Applicable Data Protection Law or following a confirmed Security Incident), subject to:

(a) [INSERT NOTICE PERIOD, e.g., 30 days] prior written notice;

(b) execution of a mutually acceptable confidentiality agreement;

(c) scope limited to Aventora’s processing of Customer Data under the Agreement;

(d) conduct during normal business hours in a manner that does not unreasonably disrupt Aventora operations; and

(e) Customer bearing its own costs and reasonable costs incurred by Aventora.

A.11.3 Where available, a third-party audit report or certification may satisfy audit obligations in lieu of an on-site audit, at Customer’s election.

Aventora does not currently claim formal SOC 2, ISO 27001, or similar certification unless explicitly stated in a valid attestation provided to Customer.


A.12 Liability

Liability arising from or related to this Appendix is governed by the liability provisions of the Agreement. Nothing in this Appendix limits either party’s liability where limitation is prohibited by Applicable Data Protection Law.


A.13 Term and Precedence

A.13.1 This Appendix remains in effect for the duration of Aventora’s processing of Customer Data under the Agreement.

A.13.2 In the event of conflict between this Appendix and the Agreement regarding the processing of Personal Data, this Appendix prevails with respect to data protection matters, unless the Agreement explicitly states otherwise.


Appendix B — Processing Details

The following describes typical processing under the Aventora platform. Customer-specific details may be specified in order forms or deployment documentation.

B.1 Subject matter and duration

ElementDescription
Subject matterProvision of Aventora’s AI-powered customer engagement platform and related support services
DurationTerm of the Agreement plus deletion period described in Section A.10

B.2 Nature and purpose of processing

PurposeDescription
Service deliveryOperating engagement workflows across voice, SMS, email, chat, and related channels
Platform administrationAuthentication, authorization, configuration, and account management
AI-assisted featuresNatural language understanding, summarization, and automated responses where enabled
Security and operationsMonitoring, incident detection, logging, backup, and disaster recovery
SupportResolving customer support requests relating to the platform

B.3 Categories of Data Subjects

  • Customer employees and authorized users
  • Customer end users, leads, contacts, and other individuals interacting through customer-configured channels
  • Individuals whose data is synchronized from customer-connected systems (for example, CRM or calendar contacts)

B.4 Categories of Personal Data

CategoryExamples
Identity and contact dataName, email, phone number, job title, organization
Account dataUsernames, roles, authentication metadata
Communication dataMessage content, call/SMS records, transcripts where enabled, timestamps
Engagement dataInteraction history, routing decisions, AI-generated outputs where enabled
Technical dataIP addresses, device/browser metadata, API logs
Calendar dataEvents and scheduling metadata where integrations are enabled

B.5 Special categories

Special categories of Personal Data (as defined under GDPR Article 9) and sensitive Personal Information are not intended to be processed unless required for a contracted feature and permitted by Customer’s lawful basis and the Agreement. Customer is responsible for classification and lawful processing of such data.

B.6 Frequency of processing

Continuous during the Agreement term, as triggered by Customer configuration and end-user interactions.


Appendix C — Security Measures

Aventora implements technical and organizational measures appropriate to the risk, including:

MeasureDescription
Encryption in transitTLS 1.2 or higher for production traffic
Encryption at restProvider-supported encryption for production data stores where configured
Access controlRole-based access control and least privilege
AuthenticationStrong authentication; MFA required for privileged administrative access
Logging and monitoringSecurity and operational logging for production environments
Secure developmentPrivacy-by-design and security-by-design practices
Vendor managementSubprocessor evaluation and contractual data protection terms per the Vendor Management Policy, including re-identification, Further Subprocessor, data subject rights, and transfer controls
Incident responseProcedures for detection, containment, investigation, notification, and recovery
Backups and DRBackup and disaster recovery procedures for production data
Personnel securityConfidentiality obligations and security awareness training
Data minimizationProcessing limited to data necessary for contracted services

Detailed measures are described in the Personal Data Privacy & Protection Policy. Customer-specific security requirements may be incorporated during deployment where agreed in writing.


Appendix D — Subprocessors

The current list of Subprocessors is maintained in the Subprocessor Annex. At execution, parties may attach a deployment-specific subprocessor list identifying subprocessors applicable to Customer’s enabled features and configuration.


Appendix E — Standard Contractual Clauses (Placeholder)

Where required for international transfers under GDPR or UK GDPR, the parties will execute:

  • EU SCCs: Commission Implementing Decision (EU) 2021/914, Module Two (Controller to Processor), as supplemented by this Appendix; and/or
  • UK Addendum: UK Information Commissioner’s International Data Transfer Addendum to the EU SCCs,

with completed Annex I (Parties), Annex II (Description of Transfer — referencing Appendix B), and Annex III (Subprocessors — referencing Appendix D).

[Parties to complete SCC annexes at execution with legal counsel.]


Execution Block (Template)

DATA PROCESSING ADDENDUM

This Data Processing Addendum is entered into as of [DATE] (“Effective Date”) by and between:

Customer: [CUSTOMER LEGAL NAME], with address at [ADDRESS]

Aventora: Aventora Inc., with address at Toronto, Ontario, Canada

This DPA incorporates Appendix A through Appendix E (as applicable) and is governed by the [MASTER AGREEMENT NAME AND DATE]. Capitalized terms have the meanings set forth in Appendix A.

CustomerAventora Inc.
Signature__________________________________________________
Name
Title
Date


Version History

VersionDateSummary
1.2July 20, 2026Expanded A.6.5 with explicit Subprocessor contractual requirements (re-identification prohibition, Further Subprocessor authorization, data subject rights assistance, international transfer controls); added A.7.4 Subprocessor transfer flow-down; linked Vendor Management Policy
1.1July 6, 2026Set Aventora legal address to Toronto, Ontario, Canada
1.0July 6, 2026Initial DPA appendix template

This template is provided for contractual negotiation support and does not constitute legal advice. Parties should consult qualified legal counsel before execution.