Aventora Subprocessor Annex
| Field | Value |
|---|---|
| Document Name | Subprocessor Annex |
| Version | 1.2 |
| Effective Date | July 20, 2026 |
| Last Reviewed | July 20, 2026 |
| Owner | Aventora Security |
| Review Frequency | Quarterly (minimum); upon material subprocessor changes |
| Classification | Internal / Customer Shareable |
| Approval Status | Approved for publication — see Version History |
Purpose
This Subprocessor Annex lists third parties engaged by Aventora Inc. (“Aventora”) that process personal information on Aventora’s behalf in connection with delivery of the Aventora platform and related services.
This annex supports customer privacy assessments and data processing agreements. It is not a certification or attestation. The subprocessors applicable to a specific customer deployment depend on enabled product features, deployment model, and contractual configuration.
For subprocessor management requirements, see the Vendor Management Policy and Section 24 of the Personal Data Privacy & Protection Policy.
How to Read This Annex
| Column | Description |
|---|---|
| Subprocessor | Legal entity or service brand name |
| Processing activity | Function performed on Aventora’s behalf |
| Data categories | Types of personal information that may be processed |
| Typical location(s) | Primary processing or storage regions; may vary by configuration |
| Applicability | When the subprocessor is used |
Feature-dependent subprocessors are engaged only when the corresponding integration or capability is enabled for the customer deployment.
Infrastructure and Platform Subprocessors
These subprocessors support core hosting and platform operations for Aventora-managed deployments.
| Subprocessor | Processing activity | Data categories | Typical location(s) | Applicability |
|---|---|---|---|---|
| Amazon Web Services, Inc. (AWS) | Cloud infrastructure: compute, storage, networking, database hosting, backup storage, content delivery | All Customer Data stored or processed in Aventora-managed AWS environments; operational logs; configuration metadata | Canada (default: AWS Canadian regions); other regions by agreement | Aventora-managed cloud deployments |
| Let’s Encrypt / certificate authorities | TLS certificate issuance for HTTPS endpoints | Domain names; limited technical contact data | Global (CA infrastructure) | Deployments using automated TLS certificate provisioning |
Communication and Engagement Subprocessors
| Subprocessor | Processing activity | Data categories | Typical location(s) | Applicability |
|---|---|---|---|---|
| Twilio Inc. | Outbound and inbound voice, SMS, WhatsApp messaging; telephony webhook delivery | Phone numbers; message and call content; call metadata; engagement status | United States and global Twilio network regions | Voice, SMS, or WhatsApp features enabled |
| Telnyx LLC | Alternative telephony and messaging provider | Phone numbers; message and call content; call metadata | United States and provider network regions | Deployments configured to use Telnyx instead of or in addition to Twilio |
AI and Language Model Subprocessors
| Subprocessor | Processing activity | Data categories | Typical location(s) | Applicability |
|---|---|---|---|---|
| OpenAI, L.L.C. | Large language model inference for conversational AI, summarization, and related features | Conversation content; prompts derived from customer interactions; contextual metadata necessary for inference | United States (provider infrastructure) | AI features configured to use OpenAI |
| Groq, Inc. | Alternative AI inference provider | Conversation content; prompts; contextual metadata | United States (provider infrastructure) | Deployments configured to use Groq |
Personal information transmitted to AI subprocessors is limited to what is necessary for the enabled customer-configured function. Customer Data is not used to train general-purpose models unless explicitly agreed in writing.
Speech and Audio Subprocessors
| Subprocessor | Processing activity | Data categories | Typical location(s) | Applicability |
|---|---|---|---|---|
| ElevenLabs | Text-to-speech and speech-related services for voice engagement features | Voice synthesis input derived from customer interactions; limited audio metadata | United States and provider infrastructure regions | Speech features configured to use ElevenLabs |
| Speechmatics | Speech-to-text and text-to-speech services for voice engagement features | Audio content; transcripts; voice synthesis input where enabled | United Kingdom / European Union and provider infrastructure regions | Speech features configured to use Speechmatics |
Identity, Calendar, and Productivity Integrations
| Subprocessor | Processing activity | Data categories | Typical location(s) | Applicability |
|---|---|---|---|---|
| Google LLC | OAuth authentication; Google Calendar owned-events read; Gmail read; Google Workspace integrations where enabled | Names; email addresses; calendar events; meeting metadata; OAuth tokens | Global (Google infrastructure) | Google OAuth or Calendar integration enabled |
| Microsoft Corporation | OAuth authentication; Microsoft 365 / Outlook Calendar integrations where enabled | Names; email addresses; calendar events; meeting metadata; OAuth tokens | Global (Microsoft Azure / M365 infrastructure) | Microsoft OAuth or Calendar integration enabled |
| FusionAuth (or equivalent identity provider) | Multi-factor authentication (MFA) step-up for administrative users | Username; MFA enrollment metadata; authentication events | Configured deployment region | Administrative MFA enabled where configured |
Customer-Directed Integrations
The following third parties may receive personal information when configured and authorized by the customer. Data flows in these cases are directed by customer integration settings. These parties are customer-enabled integrations, not universal Aventora subprocessors for all deployments:
| Integration | Processing activity | Data categories | Applicability |
|---|---|---|---|
| Salesforce, Inc. | CRM record sync, engagement updates | Contact and account records; engagement metadata | Customer-configured CRM integration |
| Follow Up Boss | CRM and lead management sync | Contact records; engagement metadata | Customer-configured integration |
| Square, Inc. | Payment or commerce hooks where enabled | Transaction and customer identifiers as configured | Customer-configured payment integration |
| Customer-specified webhooks and APIs | Outbound data delivery to customer systems | Varies by customer configuration | Customer-configured outbound integrations |
Customers remain responsible for their relationship with customer-directed integration providers and for ensuring appropriate agreements are in place.
Operational and Support Subprocessors
| Subprocessor | Processing activity | Data categories | Typical location(s) | Applicability |
|---|---|---|---|---|
| Google Workspace (Google LLC) | Aventora corporate email, calendar, and collaboration for personnel | Business contact information; support correspondence; limited Customer Data in support tickets | Global (Google infrastructure) | Aventora internal operations; support interactions |
| GitHub, Inc. (Microsoft) | Source code hosting and CI/CD for Aventora development | Source code; limited configuration metadata; no production Customer Data by default | United States | Aventora development operations |
Aventora personnel access to Customer Data for support is limited to what is necessary, subject to confidentiality obligations, and governed by the Personal Data Privacy & Protection Policy.
Subprocessor Change Notification
Aventora evaluates subprocessors before engagement and monitors them throughout the relationship. When Aventora adds or replaces a subprocessor that processes Customer Data on Aventora’s behalf, Aventora will:
- Conduct appropriate vendor due diligence before engagement;
- Execute data protection terms with the subprocessor appropriate to the processing activity;
- Notify customers of material subprocessor changes in accordance with the applicable services agreement or data processing addendum; and
- Update this annex and its version history.
Customers with contractual objection rights regarding new subprocessors should refer to their executed data processing addendum for the notification period and objection process.
Objection and Alternative Arrangements
Where required by agreement, customers may object to a new subprocessor on reasonable grounds relating to data protection. Aventora will work in good faith to address objections through:
- Alternative technical configurations where feasible;
- Reasonable compensating controls; or
- Other remedies as specified in the applicable agreement.
If no satisfactory resolution is reached, remedies (if any) are as defined in the customer’s executed contract.
Due Diligence Summary
Aventora’s subprocessor evaluation considers, as appropriate to the processing activity. The authoritative checklists (including approval gates) are in the Vendor Management Policy.
| Evaluation area | Description |
|---|---|
| Security practices | Access controls, encryption, incident response, and security documentation |
| Privacy practices | Data use limitations, Further Subprocessors, and data subject rights support |
| Processing locations | Geographic regions where data may be stored or processed; transfers outside agreed locations require prior written approval and lawful transfer safeguards |
| Contractual terms | Confidentiality, security, deletion, breach notification, no unauthorized re-identification, Further Subprocessor authorization, data subject rights assistance, and international transfer controls |
| Business continuity | Availability and recovery capabilities for critical services |
| Ongoing monitoring | Periodic review of material changes and incident notifications |
Before a subprocessor that handles personal information is approved, Aventora verifies at minimum that the agreement includes:
- Prohibition on unauthorized re-identification of de-identified, anonymized, aggregated, or pseudonymized data;
- Prior written authorization (or general authorization via notice and opportunity to object) before engagement of new Further Subprocessors;
- Prompt assistance with data subject rights requests (access, correction, deletion, restriction, portability, objection, and related requests); and
- No transfer of personal data outside agreed processing locations without Aventora’s prior written approval, with legally required safeguards for approved international transfers.
Provider infrastructure certifications (for example, AWS SOC reports) apply to the provider, not to Aventora.
Deployment-Specific Subprocessor List
Customers may request a deployment-specific subprocessor list identifying the subprocessors applicable to their enabled features, hosting region, and configuration. Contact security@aventora.ai or your account representative.
For self-hosted or private cloud deployments, the customer may act as infrastructure provider. Subprocessor applicability for AI, telephony, and integration features still applies based on enabled capabilities.
Related Documents
- Vendor Management Policy
- Personal Data Privacy & Protection Policy
- Privacy & Data Protection Executive Summary
- Data Processing Addendum Appendix
- Integration Security
Version History
| Version | Date | Summary of changes |
|---|---|---|
| 1.2 | July 20, 2026 | Linked Vendor Management Policy; expanded Due Diligence Summary with four mandatory contractual verification items (re-identification, Further Subprocessor authorization, data subject rights assistance, international transfers) |
| 1.1 | July 6, 2026 | Added ElevenLabs and Speechmatics as feature-dependent speech subprocessors; added Last Reviewed date |
| 1.0 | July 6, 2026 | Initial subprocessor annex |
Changelog
| Date | Change |
|---|---|
| 2026-07-31 | Google OAuth processing activity clarified as owned-calendar and Gmail read (aligned with consent-screen scopes; no calendar write or Gmail send in the verified scope set). |
| 2026-07-20 | v1.2: Vendor Management Policy link; due-diligence verification items for re-identification, Further Subprocessors, DSRs, and international transfers. |
| 2026-07-06 | v1.1: Added ElevenLabs and Speechmatics (feature-dependent speech services). |
| 2026-07-06 | Initial release of Subprocessor Annex v1.0. |
This annex is provided for customer assessment purposes. Contractual subprocessor terms are governed by the executed services agreement and data processing addendum.