Skip to main content

Aventora Subprocessor Annex

FieldValue
Document NameSubprocessor Annex
Version1.2
Effective DateJuly 20, 2026
Last ReviewedJuly 20, 2026
OwnerAventora Security
Review FrequencyQuarterly (minimum); upon material subprocessor changes
ClassificationInternal / Customer Shareable
Approval StatusApproved for publication — see Version History

Purpose

This Subprocessor Annex lists third parties engaged by Aventora Inc. (“Aventora”) that process personal information on Aventora’s behalf in connection with delivery of the Aventora platform and related services.

This annex supports customer privacy assessments and data processing agreements. It is not a certification or attestation. The subprocessors applicable to a specific customer deployment depend on enabled product features, deployment model, and contractual configuration.

For subprocessor management requirements, see the Vendor Management Policy and Section 24 of the Personal Data Privacy & Protection Policy.


How to Read This Annex

ColumnDescription
SubprocessorLegal entity or service brand name
Processing activityFunction performed on Aventora’s behalf
Data categoriesTypes of personal information that may be processed
Typical location(s)Primary processing or storage regions; may vary by configuration
ApplicabilityWhen the subprocessor is used

Feature-dependent subprocessors are engaged only when the corresponding integration or capability is enabled for the customer deployment.


Infrastructure and Platform Subprocessors

These subprocessors support core hosting and platform operations for Aventora-managed deployments.

SubprocessorProcessing activityData categoriesTypical location(s)Applicability
Amazon Web Services, Inc. (AWS)Cloud infrastructure: compute, storage, networking, database hosting, backup storage, content deliveryAll Customer Data stored or processed in Aventora-managed AWS environments; operational logs; configuration metadataCanada (default: AWS Canadian regions); other regions by agreementAventora-managed cloud deployments
Let’s Encrypt / certificate authoritiesTLS certificate issuance for HTTPS endpointsDomain names; limited technical contact dataGlobal (CA infrastructure)Deployments using automated TLS certificate provisioning

Communication and Engagement Subprocessors

SubprocessorProcessing activityData categoriesTypical location(s)Applicability
Twilio Inc.Outbound and inbound voice, SMS, WhatsApp messaging; telephony webhook deliveryPhone numbers; message and call content; call metadata; engagement statusUnited States and global Twilio network regionsVoice, SMS, or WhatsApp features enabled
Telnyx LLCAlternative telephony and messaging providerPhone numbers; message and call content; call metadataUnited States and provider network regionsDeployments configured to use Telnyx instead of or in addition to Twilio

AI and Language Model Subprocessors

SubprocessorProcessing activityData categoriesTypical location(s)Applicability
OpenAI, L.L.C.Large language model inference for conversational AI, summarization, and related featuresConversation content; prompts derived from customer interactions; contextual metadata necessary for inferenceUnited States (provider infrastructure)AI features configured to use OpenAI
Groq, Inc.Alternative AI inference providerConversation content; prompts; contextual metadataUnited States (provider infrastructure)Deployments configured to use Groq

Personal information transmitted to AI subprocessors is limited to what is necessary for the enabled customer-configured function. Customer Data is not used to train general-purpose models unless explicitly agreed in writing.


Speech and Audio Subprocessors

SubprocessorProcessing activityData categoriesTypical location(s)Applicability
ElevenLabsText-to-speech and speech-related services for voice engagement featuresVoice synthesis input derived from customer interactions; limited audio metadataUnited States and provider infrastructure regionsSpeech features configured to use ElevenLabs
SpeechmaticsSpeech-to-text and text-to-speech services for voice engagement featuresAudio content; transcripts; voice synthesis input where enabledUnited Kingdom / European Union and provider infrastructure regionsSpeech features configured to use Speechmatics

Identity, Calendar, and Productivity Integrations

SubprocessorProcessing activityData categoriesTypical location(s)Applicability
Google LLCOAuth authentication; Google Calendar owned-events read; Gmail read; Google Workspace integrations where enabledNames; email addresses; calendar events; meeting metadata; OAuth tokensGlobal (Google infrastructure)Google OAuth or Calendar integration enabled
Microsoft CorporationOAuth authentication; Microsoft 365 / Outlook Calendar integrations where enabledNames; email addresses; calendar events; meeting metadata; OAuth tokensGlobal (Microsoft Azure / M365 infrastructure)Microsoft OAuth or Calendar integration enabled
FusionAuth (or equivalent identity provider)Multi-factor authentication (MFA) step-up for administrative usersUsername; MFA enrollment metadata; authentication eventsConfigured deployment regionAdministrative MFA enabled where configured

Customer-Directed Integrations

The following third parties may receive personal information when configured and authorized by the customer. Data flows in these cases are directed by customer integration settings. These parties are customer-enabled integrations, not universal Aventora subprocessors for all deployments:

IntegrationProcessing activityData categoriesApplicability
Salesforce, Inc.CRM record sync, engagement updatesContact and account records; engagement metadataCustomer-configured CRM integration
Follow Up BossCRM and lead management syncContact records; engagement metadataCustomer-configured integration
Square, Inc.Payment or commerce hooks where enabledTransaction and customer identifiers as configuredCustomer-configured payment integration
Customer-specified webhooks and APIsOutbound data delivery to customer systemsVaries by customer configurationCustomer-configured outbound integrations

Customers remain responsible for their relationship with customer-directed integration providers and for ensuring appropriate agreements are in place.


Operational and Support Subprocessors

SubprocessorProcessing activityData categoriesTypical location(s)Applicability
Google Workspace (Google LLC)Aventora corporate email, calendar, and collaboration for personnelBusiness contact information; support correspondence; limited Customer Data in support ticketsGlobal (Google infrastructure)Aventora internal operations; support interactions
GitHub, Inc. (Microsoft)Source code hosting and CI/CD for Aventora developmentSource code; limited configuration metadata; no production Customer Data by defaultUnited StatesAventora development operations

Aventora personnel access to Customer Data for support is limited to what is necessary, subject to confidentiality obligations, and governed by the Personal Data Privacy & Protection Policy.


Subprocessor Change Notification

Aventora evaluates subprocessors before engagement and monitors them throughout the relationship. When Aventora adds or replaces a subprocessor that processes Customer Data on Aventora’s behalf, Aventora will:

  1. Conduct appropriate vendor due diligence before engagement;
  2. Execute data protection terms with the subprocessor appropriate to the processing activity;
  3. Notify customers of material subprocessor changes in accordance with the applicable services agreement or data processing addendum; and
  4. Update this annex and its version history.

Customers with contractual objection rights regarding new subprocessors should refer to their executed data processing addendum for the notification period and objection process.


Objection and Alternative Arrangements

Where required by agreement, customers may object to a new subprocessor on reasonable grounds relating to data protection. Aventora will work in good faith to address objections through:

  • Alternative technical configurations where feasible;
  • Reasonable compensating controls; or
  • Other remedies as specified in the applicable agreement.

If no satisfactory resolution is reached, remedies (if any) are as defined in the customer’s executed contract.


Due Diligence Summary

Aventora’s subprocessor evaluation considers, as appropriate to the processing activity. The authoritative checklists (including approval gates) are in the Vendor Management Policy.

Evaluation areaDescription
Security practicesAccess controls, encryption, incident response, and security documentation
Privacy practicesData use limitations, Further Subprocessors, and data subject rights support
Processing locationsGeographic regions where data may be stored or processed; transfers outside agreed locations require prior written approval and lawful transfer safeguards
Contractual termsConfidentiality, security, deletion, breach notification, no unauthorized re-identification, Further Subprocessor authorization, data subject rights assistance, and international transfer controls
Business continuityAvailability and recovery capabilities for critical services
Ongoing monitoringPeriodic review of material changes and incident notifications

Before a subprocessor that handles personal information is approved, Aventora verifies at minimum that the agreement includes:

  1. Prohibition on unauthorized re-identification of de-identified, anonymized, aggregated, or pseudonymized data;
  2. Prior written authorization (or general authorization via notice and opportunity to object) before engagement of new Further Subprocessors;
  3. Prompt assistance with data subject rights requests (access, correction, deletion, restriction, portability, objection, and related requests); and
  4. No transfer of personal data outside agreed processing locations without Aventora’s prior written approval, with legally required safeguards for approved international transfers.

Provider infrastructure certifications (for example, AWS SOC reports) apply to the provider, not to Aventora.


Deployment-Specific Subprocessor List

Customers may request a deployment-specific subprocessor list identifying the subprocessors applicable to their enabled features, hosting region, and configuration. Contact security@aventora.ai or your account representative.

For self-hosted or private cloud deployments, the customer may act as infrastructure provider. Subprocessor applicability for AI, telephony, and integration features still applies based on enabled capabilities.



Version History

VersionDateSummary of changes
1.2July 20, 2026Linked Vendor Management Policy; expanded Due Diligence Summary with four mandatory contractual verification items (re-identification, Further Subprocessor authorization, data subject rights assistance, international transfers)
1.1July 6, 2026Added ElevenLabs and Speechmatics as feature-dependent speech subprocessors; added Last Reviewed date
1.0July 6, 2026Initial subprocessor annex

Changelog

DateChange
2026-07-31Google OAuth processing activity clarified as owned-calendar and Gmail read (aligned with consent-screen scopes; no calendar write or Gmail send in the verified scope set).
2026-07-20v1.2: Vendor Management Policy link; due-diligence verification items for re-identification, Further Subprocessors, DSRs, and international transfers.
2026-07-06v1.1: Added ElevenLabs and Speechmatics (feature-dependent speech services).
2026-07-06Initial release of Subprocessor Annex v1.0.

This annex is provided for customer assessment purposes. Contractual subprocessor terms are governed by the executed services agreement and data processing addendum.