Aventora Vendor Management Policy
| Field | Value |
|---|---|
| Document Name | Vendor Management Policy |
| Version | 1.0 |
| Effective Date | July 20, 2026 |
| Approval Date | July 20, 2026 |
| Last Reviewed | July 20, 2026 |
| Document Owner | Aventora Security |
| Review Frequency | Annually; upon material changes to vendor risk, privacy law, or subprocessor practices |
| Classification | Internal / Customer Shareable |
| Approval Status | Approved for publication — pending wet-ink signature block completion |
Document Control
This policy establishes Aventora Inc. (“Aventora,” “we,” “us,” or “our”) requirements for evaluating, contracting with, and monitoring vendors and subprocessors that process personal information on Aventora’s behalf or that otherwise access Customer Data in connection with the Aventora platform and related services.
This document is intended for enterprise customers, security assessors, privacy officers, procurement teams, and Aventora personnel. It supports security and privacy reviews and vendor risk questionnaires. Aventora does not claim formal certification or attestation under any specific privacy or security framework based on this document alone. Binding obligations of a specific vendor relationship are those set out in the executed vendor agreement, data processing terms, and applicable law.
Distinction Between Internal Procedures and Vendor Obligations
| Category | Meaning in this policy |
|---|---|
| Internal Aventora procedures | Steps Aventora personnel MUST follow before approving a vendor, during the relationship, and at termination. These are operational controls, not promises made by the vendor. |
| Contractual obligations on vendors | Terms Aventora MUST require in written agreements with vendors and subprocessors that handle personal information, to the extent applicable to the processing activity. These are obligations the vendor owes to Aventora (and, by flow-down, support Aventora’s commitments to customers). |
RFC 2119 Terminology
The key words “MUST,” “MUST NOT,” “REQUIRED,” “SHALL,” “SHALL NOT,” “SHOULD,” “SHOULD NOT,” “RECOMMENDED,” “MAY,” and “OPTIONAL” in this document are to be interpreted as described in RFC 2119.
Approval
| Role | Name | Signature | Date |
|---|---|---|---|
| Chief Executive Officer | [To be completed upon formal approval] | ||
| Document Owner (Aventora Security) | [To be completed upon formal approval] | ||
| Privacy Officer | [To be completed upon formal approval] |
This policy is effective upon the Effective Date stated above. Material revisions require re-approval and an updated version history entry.
Table of Contents
- Purpose
- Scope
- Definitions
- Roles and Responsibilities
- Internal Aventora Vendor Lifecycle Procedures
- Standard Vendor and Subprocessor Contractual Requirements
- Vendor Due Diligence Checklist
- Contract Review Checklist
- Ongoing Monitoring
- Exceptions
- Related Documents
- Version History
1. Purpose
This policy:
- Defines how Aventora evaluates and approves vendors and subprocessors that handle personal information;
- Sets contract-ready standard terms that MUST be imposed on such vendors and subprocessors;
- Provides due-diligence and contract-review checklists that MUST be completed before a vendor handling personal information is approved for production use; and
- Distinguishes Aventora’s internal control activities from obligations that vendors accept by contract.
Customer-facing processor commitments (Customer as Controller; Aventora as Processor) are set out in the Data Processing Addendum Appendix and the applicable executed DPA. This policy governs Aventora’s upstream relationships with its own vendors and subprocessors.
2. Scope
This policy applies to:
- Third-party vendors and subprocessors engaged by Aventora that process personal information on Aventora’s behalf;
- Vendors with access to Customer Data, production systems containing personal information, or encryption keys protecting such data; and
- Material changes to an existing vendor’s processing purpose, locations, subprocessors, or security posture.
This policy does not apply to:
- Customer-directed integrations configured solely by the customer (those remain the customer’s responsibility; see the Subprocessor Annex); or
- Purely internal tools that do not process personal information or Customer Data, except where Engineering Leadership determines a security review is warranted.
3. Definitions
| Term | Meaning |
|---|---|
| Customer Data | Personal information and related content submitted to or generated in the Aventora platform on behalf of a customer |
| Personal Data / personal information | Information relating to an identified or identifiable natural person, as defined under applicable privacy law |
| Vendor | A third party that provides products or services to Aventora and that may process Personal Data or access Customer Data |
| Subprocessor | A Vendor engaged by Aventora to process Personal Data on Aventora’s behalf in connection with the services |
| Further Subprocessor | A third party engaged by a Vendor or Subprocessor to process Personal Data received from Aventora |
| Agreed Processing Locations | The countries, regions, or infrastructure locations specified in the applicable Vendor agreement, order form, or security schedule as authorized for processing |
| Standard Contractual Requirements | The obligations in Section 6 of this policy |
4. Roles and Responsibilities
| Role | Responsibility |
|---|---|
| Aventora Security | Owns this policy; reviews vendor security and privacy evidence; maintains checklists and approval records |
| Privacy Officer (or designee) | Reviews privacy risk, transfer mechanisms, and data subject rights support |
| Engineering Leadership | Approves technical integration and production enablement of new vendors |
| Legal / Contracting (or designee) | Ensures Standard Contractual Requirements are reflected in executed agreements |
| Vendor / Subprocessor | Performs obligations set out in the executed agreement incorporating Section 6 |
5. Internal Aventora Vendor Lifecycle Procedures
The following are Aventora’s internal procedures. They are not vendor contractual obligations.
5.1 Before Engagement
Before a Vendor that will handle Personal Data is approved for production use, Aventora personnel MUST:
- Complete the Vendor Due Diligence Checklist;
- Complete the Contract Review Checklist;
- Confirm that the executed agreement includes the Standard Contractual Requirements (or legally equivalent terms);
- Obtain written approval from Aventora Security and Engineering Leadership; and
- Update the Subprocessor Annex where the Vendor is a Subprocessor, and notify customers as required by the applicable customer DPA.
5.2 During the Relationship
Aventora MUST monitor Vendors in accordance with Section 9, including review of material changes to processing locations, Further Subprocessors, security incidents, and certifications or assurance reports where available.
5.3 Customer Notification of Subprocessor Changes
Where Aventora engages a new or replacement Subprocessor that processes Customer Data, Aventora MUST follow the notification and objection process in the applicable customer DPA and the Subprocessor Annex. General written authorization through advance notice and an opportunity to object is the standard model unless a customer agreement requires case-by-case prior consent.
5.4 Termination
Upon termination of a Vendor relationship involving Personal Data, Aventora MUST require return or secure destruction of Personal Data in accordance with Section 6.9, verify completion where feasible, and revoke Vendor access credentials.
6. Standard Vendor and Subprocessor Contractual Requirements
Agreements with Vendors and Subprocessors that process Personal Data MUST include the following obligations, adapted only as necessary to reflect the processing activity, applicable law, and negotiated form, provided that the substance of each requirement is preserved.
Where the text below uses “Vendor,” it includes Subprocessors. Where it uses “Aventora Personal Data,” it means Personal Data made available by or on behalf of Aventora, including Customer Data.
6.1 Compliance with Applicable Privacy Laws
Vendor shall process Aventora Personal Data in compliance with all privacy and data protection laws applicable to Vendor’s processing activities, including, where applicable, PIPEDA, GDPR, UK GDPR, and U.S. state privacy laws.
6.2 Documented Instructions and Purpose Limitation
Vendor shall process Aventora Personal Data only on Aventora’s documented instructions and only for the purpose of providing the contracted products or services. Vendor shall not process Aventora Personal Data for Vendor’s own purposes, including advertising, profiling unrelated to the contracted service, or product improvement that uses identifiable Customer Data, unless expressly authorized in writing by Aventora.
6.3 No Sale or Unauthorized Disclosure
Vendor shall not sell Aventora Personal Data. Vendor shall not disclose Aventora Personal Data to any third party except: (a) to Further Subprocessors authorized under Section 6.6; (b) to personnel bound by confidentiality obligations who need access to perform the contracted services; or (c) as required by law, in which case Vendor shall notify Aventora in advance unless legally prohibited from doing so.
6.4 Security Safeguards
Vendor shall implement and maintain appropriate technical and organizational measures to protect Aventora Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, or damage, taking into account the nature of the processing and the sensitivity of the data. Measures shall include, at minimum, access controls, encryption in transit, encryption at rest where feasible, and security monitoring appropriate to the service.
6.5 Security Incident and Breach Notification
Vendor shall notify Aventora without undue delay, and in any event within the period specified in the agreement (or, if unspecified, within seventy-two (72) hours) after becoming aware of a confirmed personal data breach or security incident affecting Aventora Personal Data. Notification shall include information reasonably available to Vendor regarding the nature of the incident, categories of data affected, likely consequences, and measures taken or proposed to address the incident. Vendor shall cooperate with Aventora’s investigation and remediation.
6.6 Further Subprocessors — Authorization and Flow-Down
(a) Prior written authorization. Vendor shall obtain Aventora’s prior written authorization before engaging a new Further Subprocessor to process Aventora Personal Data, where required by the Vendor agreement or applicable law. Such authorization may be given as a general written authorization under which Vendor provides Aventora with advance written notice of a proposed new Further Subprocessor and a reasonable opportunity to object, rather than requiring case-by-case consent for every engagement, provided that the notice-and-objection process is set out in the agreement.
(b) Flow-down. Vendor shall impose on each Further Subprocessor written data protection obligations that are no less protective of Aventora Personal Data than the obligations in this Section 6. Vendor remains responsible to Aventora for the performance of Further Subprocessors to the extent required by applicable law and the Vendor agreement.
6.7 Prohibition on Re-Identification
Vendor shall not attempt to re-identify any de-identified, anonymized, aggregated, or pseudonymized data derived from Aventora Personal Data, unless: (a) Aventora has expressly authorized such re-identification in writing; and (b) the re-identification is permitted by applicable law. Vendor shall implement technical and organizational measures reasonably designed to prevent unauthorized re-identification by Vendor personnel and Further Subprocessors.
6.8 Assistance with Data Subject Rights
Vendor shall promptly assist Aventora, taking into account the nature of the processing and the information available to Vendor, in responding to data subject rights requests relating to Aventora Personal Data, including requests for access, correction, deletion, restriction of processing, portability, objection, and related requests, to the extent required by applicable privacy law. Assistance shall be provided within timeframes that enable Aventora to meet its own legal and contractual deadlines.
6.9 International Transfers and Processing Locations
Vendor shall not transfer Aventora Personal Data outside the Agreed Processing Locations or jurisdictions specified in the Vendor agreement (or, if none are specified, the locations disclosed to Aventora during diligence) without Aventora’s prior written approval. Where an international transfer is approved, Vendor shall implement all legally required safeguards before the transfer occurs, including, as applicable: Standard Contractual Clauses; transfer impact assessments; supplementary measures; or equivalent lawful transfer mechanisms recognized under applicable data protection law.
6.10 Return or Secure Destruction
Upon termination or expiry of the Vendor agreement, or upon Aventora’s written request, Vendor shall return or securely destroy Aventora Personal Data (including copies) within the period specified in the agreement, except to the extent retention is required by applicable law, in which case Vendor shall continue to protect the retained data and process it only as necessary to comply with that legal obligation. Upon request, Vendor shall provide written certification of destruction where reasonably practicable.
6.11 Audit, Evidence, and Cooperation
Where required by the Vendor agreement or applicable law, Vendor shall make available to Aventora information reasonably necessary to demonstrate compliance with its data protection obligations, including relevant security documentation, audit summaries, or certifications. Vendor shall cooperate in good faith with reasonable audit or assessment requests by Aventora or Aventora’s customers (or their appointed auditors), subject to confidentiality, scheduling, and scope limitations set out in the agreement.
7. Vendor Due Diligence Checklist
Internal Aventora procedure. Aventora Security (or designee) MUST complete this checklist, and retain evidence of completion, before approving a Vendor that will handle Personal Data for production use.
| # | Verification item | Required for Personal Data Vendors | Status (Pass / Fail / N/A) | Evidence / notes |
|---|---|---|---|---|
| D-01 | Vendor legal entity, service description, and data processing purpose documented | Yes | ||
| D-02 | Categories of Personal Data and data subjects identified | Yes | ||
| D-03 | Processing locations / jurisdictions identified and acceptable for the intended use | Yes | ||
| D-04 | Security practices reviewed (access control, encryption, incident response, certifications if available) | Yes | ||
| D-05 | Privacy practices reviewed (use limitations, retention, Further Subprocessors) | Yes | ||
| D-06 | Re-identification: Vendor contract or terms prohibit unauthorized re-identification of de-identified, anonymized, aggregated, or pseudonymized data (Section 6.7) | Yes | ||
| D-07 | Further Subprocessors: Prior written authorization / notice-and-objection process confirmed (Section 6.6) | Yes | ||
| D-08 | Data subject rights: Vendor will promptly assist with access, correction, deletion, restriction, portability, objection, and related requests (Section 6.8) | Yes | ||
| D-09 | International transfers: Transfers outside Agreed Processing Locations require Aventora’s prior written approval; lawful transfer safeguards required when approved (Section 6.9) | Yes | ||
| D-10 | Breach / security incident notification commitments adequate | Yes | ||
| D-11 | Return or secure destruction commitments adequate | Yes | ||
| D-12 | No sale / unauthorized disclosure restrictions adequate | Yes | ||
| D-13 | Business continuity / availability assessed for critical services | As applicable | ||
| D-14 | Subprocessor Annex update and customer notification plan identified (if Subprocessor) | As applicable |
Approval gate: A Vendor that will handle Personal Data MUST NOT be approved for production use if any of D-06, D-07, D-08, or D-09 is Fail, unless an exception is granted under Section 10 with compensating controls.
8. Contract Review Checklist
Internal Aventora procedure. Legal / Contracting (or designee), with Aventora Security, MUST verify the following clauses (or legally equivalent wording) appear in the Vendor agreement or data processing addendum before execution.
| # | Contractual requirement | Section reference | Present (Y/N) | Notes / redline needed |
|---|---|---|---|---|
| C-01 | Compliance with applicable privacy laws | 6.1 | ||
| C-02 | Processing only on documented instructions and for the contracted purpose | 6.2 | ||
| C-03 | No sale or unauthorized disclosure of Personal Data | 6.3 | ||
| C-04 | Security safeguards | 6.4 | ||
| C-05 | Security incident and breach notification | 6.5 | ||
| C-06 | Further Subprocessor prior written authorization (general authorization via notice and opportunity to object permitted) | 6.6 | ||
| C-07 | Subprocessor flow-down of data protection obligations | 6.6(b) | ||
| C-08 | No unauthorized re-identification of de-identified, anonymized, aggregated, or pseudonymized data | 6.7 | ||
| C-09 | Prompt assistance with data subject rights (access, correction, deletion, restriction, portability, objection, related requests) | 6.8 | ||
| C-10 | No transfer outside Agreed Processing Locations without prior written approval; approved transfers require SCCs, transfer impact assessments, supplementary measures, or equivalent | 6.9 | ||
| C-11 | Return or secure destruction of Personal Data | 6.10 | ||
| C-12 | Audit, evidence, and cooperation (where applicable) | 6.11 |
Approval gate: Execution MUST NOT proceed if C-08, C-09, or C-10 is “N,” or if C-06 is “N” where Further Subprocessing is permitted or reasonably foreseeable, unless an exception is granted under Section 10.
9. Ongoing Monitoring
Aventora SHOULD periodically review Vendors that process Personal Data for continued suitability, including:
- Material changes to processing activities, locations, or Further Subprocessors;
- Security or privacy incident notifications;
- Updated assurance reports or security questionnaires, where available; and
- Renewal or renegotiation opportunities to close gaps against Section 6.
Material adverse findings MUST be escalated to Aventora Security and may result in remediation requirements, restricted use, or termination.
10. Exceptions
Exceptions to this policy MAY be granted only where:
- A legitimate business or technical requirement exists;
- Compensating controls are documented in writing;
- The exception is approved by Aventora Security and, for contractual gaps, Legal / Contracting;
- The exception is time-bound and reviewed at least annually; and
- Material customer-facing impacts are disclosed or agreed with affected customers where required by contract.
Exception records MUST include the requirement waived, justification, approver, effective dates, and remediation plan if applicable.
11. Related Documents
- Personal Data Privacy & Protection Policy (Section 24)
- Subprocessor Annex
- Data Processing Addendum Appendix
- AI Governance Policy (Section 11)
- Information Security Risk Management Policy
- Risk Assessment and Treatment Procedure
- Integration Security
- Customer Security Package
- Data Classification and Handling Policy
12. Version History
| Version | Date | Author / Owner | Summary of Changes |
|---|---|---|---|
| 1.0.1 | July 27, 2026 | Aventora Security | Linked Information Security Risk Management Policy and Risk Assessment and Treatment Procedure |
| 1.0 | July 20, 2026 | Aventora Security | Initial Vendor Management Policy: standard contractual requirements (including re-identification prohibition, Further Subprocessor authorization, data subject rights assistance, and international transfer controls), due-diligence checklist, and contract review checklist |
Contact
| Purpose | Contact |
|---|---|
| Document Owner | Aventora Security — security@aventora.ai |
| Privacy inquiries | privacy@aventora.ai |
| Vendor / subprocessor assessments | security@aventora.ai or your designated account representative |
This document is provided for informational and contractual support purposes. It does not constitute legal advice. Binding vendor obligations are those in the executed Vendor agreement. Customers should consult qualified legal counsel regarding their own vendor risk and privacy obligations.