Skip to main content

Aventora Vendor Management Policy

FieldValue
Document NameVendor Management Policy
Version1.0
Effective DateJuly 20, 2026
Approval DateJuly 20, 2026
Last ReviewedJuly 20, 2026
Document OwnerAventora Security
Review FrequencyAnnually; upon material changes to vendor risk, privacy law, or subprocessor practices
ClassificationInternal / Customer Shareable
Approval StatusApproved for publication — pending wet-ink signature block completion

Document Control

This policy establishes Aventora Inc. (“Aventora,” “we,” “us,” or “our”) requirements for evaluating, contracting with, and monitoring vendors and subprocessors that process personal information on Aventora’s behalf or that otherwise access Customer Data in connection with the Aventora platform and related services.

This document is intended for enterprise customers, security assessors, privacy officers, procurement teams, and Aventora personnel. It supports security and privacy reviews and vendor risk questionnaires. Aventora does not claim formal certification or attestation under any specific privacy or security framework based on this document alone. Binding obligations of a specific vendor relationship are those set out in the executed vendor agreement, data processing terms, and applicable law.

Distinction Between Internal Procedures and Vendor Obligations

CategoryMeaning in this policy
Internal Aventora proceduresSteps Aventora personnel MUST follow before approving a vendor, during the relationship, and at termination. These are operational controls, not promises made by the vendor.
Contractual obligations on vendorsTerms Aventora MUST require in written agreements with vendors and subprocessors that handle personal information, to the extent applicable to the processing activity. These are obligations the vendor owes to Aventora (and, by flow-down, support Aventora’s commitments to customers).

RFC 2119 Terminology

The key words “MUST,” “MUST NOT,” “REQUIRED,” “SHALL,” “SHALL NOT,” “SHOULD,” “SHOULD NOT,” “RECOMMENDED,” “MAY,” and “OPTIONAL” in this document are to be interpreted as described in RFC 2119.


Approval

RoleNameSignatureDate
Chief Executive Officer[To be completed upon formal approval]
Document Owner (Aventora Security)[To be completed upon formal approval]
Privacy Officer[To be completed upon formal approval]

This policy is effective upon the Effective Date stated above. Material revisions require re-approval and an updated version history entry.


Table of Contents

  1. Purpose
  2. Scope
  3. Definitions
  4. Roles and Responsibilities
  5. Internal Aventora Vendor Lifecycle Procedures
  6. Standard Vendor and Subprocessor Contractual Requirements
  7. Vendor Due Diligence Checklist
  8. Contract Review Checklist
  9. Ongoing Monitoring
  10. Exceptions
  11. Related Documents
  12. Version History

1. Purpose

This policy:

  • Defines how Aventora evaluates and approves vendors and subprocessors that handle personal information;
  • Sets contract-ready standard terms that MUST be imposed on such vendors and subprocessors;
  • Provides due-diligence and contract-review checklists that MUST be completed before a vendor handling personal information is approved for production use; and
  • Distinguishes Aventora’s internal control activities from obligations that vendors accept by contract.

Customer-facing processor commitments (Customer as Controller; Aventora as Processor) are set out in the Data Processing Addendum Appendix and the applicable executed DPA. This policy governs Aventora’s upstream relationships with its own vendors and subprocessors.


2. Scope

This policy applies to:

  • Third-party vendors and subprocessors engaged by Aventora that process personal information on Aventora’s behalf;
  • Vendors with access to Customer Data, production systems containing personal information, or encryption keys protecting such data; and
  • Material changes to an existing vendor’s processing purpose, locations, subprocessors, or security posture.

This policy does not apply to:

  • Customer-directed integrations configured solely by the customer (those remain the customer’s responsibility; see the Subprocessor Annex); or
  • Purely internal tools that do not process personal information or Customer Data, except where Engineering Leadership determines a security review is warranted.

3. Definitions

TermMeaning
Customer DataPersonal information and related content submitted to or generated in the Aventora platform on behalf of a customer
Personal Data / personal informationInformation relating to an identified or identifiable natural person, as defined under applicable privacy law
VendorA third party that provides products or services to Aventora and that may process Personal Data or access Customer Data
SubprocessorA Vendor engaged by Aventora to process Personal Data on Aventora’s behalf in connection with the services
Further SubprocessorA third party engaged by a Vendor or Subprocessor to process Personal Data received from Aventora
Agreed Processing LocationsThe countries, regions, or infrastructure locations specified in the applicable Vendor agreement, order form, or security schedule as authorized for processing
Standard Contractual RequirementsThe obligations in Section 6 of this policy

4. Roles and Responsibilities

RoleResponsibility
Aventora SecurityOwns this policy; reviews vendor security and privacy evidence; maintains checklists and approval records
Privacy Officer (or designee)Reviews privacy risk, transfer mechanisms, and data subject rights support
Engineering LeadershipApproves technical integration and production enablement of new vendors
Legal / Contracting (or designee)Ensures Standard Contractual Requirements are reflected in executed agreements
Vendor / SubprocessorPerforms obligations set out in the executed agreement incorporating Section 6

5. Internal Aventora Vendor Lifecycle Procedures

The following are Aventora’s internal procedures. They are not vendor contractual obligations.

5.1 Before Engagement

Before a Vendor that will handle Personal Data is approved for production use, Aventora personnel MUST:

  1. Complete the Vendor Due Diligence Checklist;
  2. Complete the Contract Review Checklist;
  3. Confirm that the executed agreement includes the Standard Contractual Requirements (or legally equivalent terms);
  4. Obtain written approval from Aventora Security and Engineering Leadership; and
  5. Update the Subprocessor Annex where the Vendor is a Subprocessor, and notify customers as required by the applicable customer DPA.

5.2 During the Relationship

Aventora MUST monitor Vendors in accordance with Section 9, including review of material changes to processing locations, Further Subprocessors, security incidents, and certifications or assurance reports where available.

5.3 Customer Notification of Subprocessor Changes

Where Aventora engages a new or replacement Subprocessor that processes Customer Data, Aventora MUST follow the notification and objection process in the applicable customer DPA and the Subprocessor Annex. General written authorization through advance notice and an opportunity to object is the standard model unless a customer agreement requires case-by-case prior consent.

5.4 Termination

Upon termination of a Vendor relationship involving Personal Data, Aventora MUST require return or secure destruction of Personal Data in accordance with Section 6.9, verify completion where feasible, and revoke Vendor access credentials.


6. Standard Vendor and Subprocessor Contractual Requirements

Agreements with Vendors and Subprocessors that process Personal Data MUST include the following obligations, adapted only as necessary to reflect the processing activity, applicable law, and negotiated form, provided that the substance of each requirement is preserved.

Where the text below uses “Vendor,” it includes Subprocessors. Where it uses “Aventora Personal Data,” it means Personal Data made available by or on behalf of Aventora, including Customer Data.

6.1 Compliance with Applicable Privacy Laws

Vendor shall process Aventora Personal Data in compliance with all privacy and data protection laws applicable to Vendor’s processing activities, including, where applicable, PIPEDA, GDPR, UK GDPR, and U.S. state privacy laws.

6.2 Documented Instructions and Purpose Limitation

Vendor shall process Aventora Personal Data only on Aventora’s documented instructions and only for the purpose of providing the contracted products or services. Vendor shall not process Aventora Personal Data for Vendor’s own purposes, including advertising, profiling unrelated to the contracted service, or product improvement that uses identifiable Customer Data, unless expressly authorized in writing by Aventora.

6.3 No Sale or Unauthorized Disclosure

Vendor shall not sell Aventora Personal Data. Vendor shall not disclose Aventora Personal Data to any third party except: (a) to Further Subprocessors authorized under Section 6.6; (b) to personnel bound by confidentiality obligations who need access to perform the contracted services; or (c) as required by law, in which case Vendor shall notify Aventora in advance unless legally prohibited from doing so.

6.4 Security Safeguards

Vendor shall implement and maintain appropriate technical and organizational measures to protect Aventora Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, or damage, taking into account the nature of the processing and the sensitivity of the data. Measures shall include, at minimum, access controls, encryption in transit, encryption at rest where feasible, and security monitoring appropriate to the service.

6.5 Security Incident and Breach Notification

Vendor shall notify Aventora without undue delay, and in any event within the period specified in the agreement (or, if unspecified, within seventy-two (72) hours) after becoming aware of a confirmed personal data breach or security incident affecting Aventora Personal Data. Notification shall include information reasonably available to Vendor regarding the nature of the incident, categories of data affected, likely consequences, and measures taken or proposed to address the incident. Vendor shall cooperate with Aventora’s investigation and remediation.

6.6 Further Subprocessors — Authorization and Flow-Down

(a) Prior written authorization. Vendor shall obtain Aventora’s prior written authorization before engaging a new Further Subprocessor to process Aventora Personal Data, where required by the Vendor agreement or applicable law. Such authorization may be given as a general written authorization under which Vendor provides Aventora with advance written notice of a proposed new Further Subprocessor and a reasonable opportunity to object, rather than requiring case-by-case consent for every engagement, provided that the notice-and-objection process is set out in the agreement.

(b) Flow-down. Vendor shall impose on each Further Subprocessor written data protection obligations that are no less protective of Aventora Personal Data than the obligations in this Section 6. Vendor remains responsible to Aventora for the performance of Further Subprocessors to the extent required by applicable law and the Vendor agreement.

6.7 Prohibition on Re-Identification

Vendor shall not attempt to re-identify any de-identified, anonymized, aggregated, or pseudonymized data derived from Aventora Personal Data, unless: (a) Aventora has expressly authorized such re-identification in writing; and (b) the re-identification is permitted by applicable law. Vendor shall implement technical and organizational measures reasonably designed to prevent unauthorized re-identification by Vendor personnel and Further Subprocessors.

6.8 Assistance with Data Subject Rights

Vendor shall promptly assist Aventora, taking into account the nature of the processing and the information available to Vendor, in responding to data subject rights requests relating to Aventora Personal Data, including requests for access, correction, deletion, restriction of processing, portability, objection, and related requests, to the extent required by applicable privacy law. Assistance shall be provided within timeframes that enable Aventora to meet its own legal and contractual deadlines.

6.9 International Transfers and Processing Locations

Vendor shall not transfer Aventora Personal Data outside the Agreed Processing Locations or jurisdictions specified in the Vendor agreement (or, if none are specified, the locations disclosed to Aventora during diligence) without Aventora’s prior written approval. Where an international transfer is approved, Vendor shall implement all legally required safeguards before the transfer occurs, including, as applicable: Standard Contractual Clauses; transfer impact assessments; supplementary measures; or equivalent lawful transfer mechanisms recognized under applicable data protection law.

6.10 Return or Secure Destruction

Upon termination or expiry of the Vendor agreement, or upon Aventora’s written request, Vendor shall return or securely destroy Aventora Personal Data (including copies) within the period specified in the agreement, except to the extent retention is required by applicable law, in which case Vendor shall continue to protect the retained data and process it only as necessary to comply with that legal obligation. Upon request, Vendor shall provide written certification of destruction where reasonably practicable.

6.11 Audit, Evidence, and Cooperation

Where required by the Vendor agreement or applicable law, Vendor shall make available to Aventora information reasonably necessary to demonstrate compliance with its data protection obligations, including relevant security documentation, audit summaries, or certifications. Vendor shall cooperate in good faith with reasonable audit or assessment requests by Aventora or Aventora’s customers (or their appointed auditors), subject to confidentiality, scheduling, and scope limitations set out in the agreement.


7. Vendor Due Diligence Checklist

Internal Aventora procedure. Aventora Security (or designee) MUST complete this checklist, and retain evidence of completion, before approving a Vendor that will handle Personal Data for production use.

#Verification itemRequired for Personal Data VendorsStatus (Pass / Fail / N/A)Evidence / notes
D-01Vendor legal entity, service description, and data processing purpose documentedYes
D-02Categories of Personal Data and data subjects identifiedYes
D-03Processing locations / jurisdictions identified and acceptable for the intended useYes
D-04Security practices reviewed (access control, encryption, incident response, certifications if available)Yes
D-05Privacy practices reviewed (use limitations, retention, Further Subprocessors)Yes
D-06Re-identification: Vendor contract or terms prohibit unauthorized re-identification of de-identified, anonymized, aggregated, or pseudonymized data (Section 6.7)Yes
D-07Further Subprocessors: Prior written authorization / notice-and-objection process confirmed (Section 6.6)Yes
D-08Data subject rights: Vendor will promptly assist with access, correction, deletion, restriction, portability, objection, and related requests (Section 6.8)Yes
D-09International transfers: Transfers outside Agreed Processing Locations require Aventora’s prior written approval; lawful transfer safeguards required when approved (Section 6.9)Yes
D-10Breach / security incident notification commitments adequateYes
D-11Return or secure destruction commitments adequateYes
D-12No sale / unauthorized disclosure restrictions adequateYes
D-13Business continuity / availability assessed for critical servicesAs applicable
D-14Subprocessor Annex update and customer notification plan identified (if Subprocessor)As applicable

Approval gate: A Vendor that will handle Personal Data MUST NOT be approved for production use if any of D-06, D-07, D-08, or D-09 is Fail, unless an exception is granted under Section 10 with compensating controls.


8. Contract Review Checklist

Internal Aventora procedure. Legal / Contracting (or designee), with Aventora Security, MUST verify the following clauses (or legally equivalent wording) appear in the Vendor agreement or data processing addendum before execution.

#Contractual requirementSection referencePresent (Y/N)Notes / redline needed
C-01Compliance with applicable privacy laws6.1
C-02Processing only on documented instructions and for the contracted purpose6.2
C-03No sale or unauthorized disclosure of Personal Data6.3
C-04Security safeguards6.4
C-05Security incident and breach notification6.5
C-06Further Subprocessor prior written authorization (general authorization via notice and opportunity to object permitted)6.6
C-07Subprocessor flow-down of data protection obligations6.6(b)
C-08No unauthorized re-identification of de-identified, anonymized, aggregated, or pseudonymized data6.7
C-09Prompt assistance with data subject rights (access, correction, deletion, restriction, portability, objection, related requests)6.8
C-10No transfer outside Agreed Processing Locations without prior written approval; approved transfers require SCCs, transfer impact assessments, supplementary measures, or equivalent6.9
C-11Return or secure destruction of Personal Data6.10
C-12Audit, evidence, and cooperation (where applicable)6.11

Approval gate: Execution MUST NOT proceed if C-08, C-09, or C-10 is “N,” or if C-06 is “N” where Further Subprocessing is permitted or reasonably foreseeable, unless an exception is granted under Section 10.


9. Ongoing Monitoring

Aventora SHOULD periodically review Vendors that process Personal Data for continued suitability, including:

  • Material changes to processing activities, locations, or Further Subprocessors;
  • Security or privacy incident notifications;
  • Updated assurance reports or security questionnaires, where available; and
  • Renewal or renegotiation opportunities to close gaps against Section 6.

Material adverse findings MUST be escalated to Aventora Security and may result in remediation requirements, restricted use, or termination.


10. Exceptions

Exceptions to this policy MAY be granted only where:

  • A legitimate business or technical requirement exists;
  • Compensating controls are documented in writing;
  • The exception is approved by Aventora Security and, for contractual gaps, Legal / Contracting;
  • The exception is time-bound and reviewed at least annually; and
  • Material customer-facing impacts are disclosed or agreed with affected customers where required by contract.

Exception records MUST include the requirement waived, justification, approver, effective dates, and remediation plan if applicable.



12. Version History

VersionDateAuthor / OwnerSummary of Changes
1.0.1July 27, 2026Aventora SecurityLinked Information Security Risk Management Policy and Risk Assessment and Treatment Procedure
1.0July 20, 2026Aventora SecurityInitial Vendor Management Policy: standard contractual requirements (including re-identification prohibition, Further Subprocessor authorization, data subject rights assistance, and international transfer controls), due-diligence checklist, and contract review checklist

Contact

PurposeContact
Document OwnerAventora Security — security@aventora.ai
Privacy inquiriesprivacy@aventora.ai
Vendor / subprocessor assessmentssecurity@aventora.ai or your designated account representative

This document is provided for informational and contractual support purposes. It does not constitute legal advice. Binding vendor obligations are those in the executed Vendor agreement. Customers should consult qualified legal counsel regarding their own vendor risk and privacy obligations.