This Data Processing Agreement ("DPA") forms part of the Terms and Conditions (the "Agreement") between Aventro Ltd. ("Aventro Ltd.", "Processor") and the customer entity that has accepted the Agreement ("Customer", "Controller"). It governs Aventro Ltd.'s processing of Personal Data on Customer's behalf in connection with the Aventro platform (the "Service"). Where there is a conflict on data-protection matters, this DPA prevails.
1. Definitions
Terms such as "Personal Data", "Processing", "Controller", "Processor", "Data Subject", "Sub-processor", and "Supervisory Authority" have the meanings in Data Protection Law. "Data Protection Law" means all laws applicable to the Processing under this DPA, including the EU GDPR, the UK GDPR, Israel's Protection of Privacy Law (including Amendment 13), and the CCPA/CPRA. "Customer Personal Data" means Personal Data that Aventro Ltd. Processes on Customer's behalf under the Agreement.
2. Roles and Scope
2.1 As between the parties, Customer is the Controller (or a processor acting for its own controller) and Aventro Ltd. is the Processor of Customer Personal Data.
2.2 Aventro Ltd. Processes Customer Personal Data only to provide the Service and only on Customer's documented instructions, including as set out in the Agreement, this DPA, and Customer's use of the Service. Annex I describes the Processing.
2.3 Aventro Ltd. will inform Customer if, in its opinion, an instruction infringes Data Protection Law (without obligation to give legal advice).
2.4 CCPA. Aventro Ltd. acts as a service provider. Aventro Ltd. will not sell or share Customer Personal Data, will not retain, use, or disclose it for any purpose other than performing the Service (or as permitted by the CCPA), and will not combine it with data from other sources except as permitted by the CCPA.
3. Confidentiality
Aventro Ltd. ensures that persons authorized to Process Customer Personal Data are bound by confidentiality obligations and Process it only as instructed.
4. Security
Aventro Ltd. implements appropriate technical and organizational measures to protect Customer Personal Data, as described in Annex II, taking into account the state of the art, the costs of implementation, and the nature, scope, and risk of the Processing.
5. Sub-processors
5.1 Customer provides general authorization for Aventro Ltd. to engage Sub-processors to provide the Service. Aventro Ltd. maintains a current list of Sub-processors at the Subprocessors page.
5.2 Aventro Ltd. imposes data-protection obligations on Sub-processors that are no less protective than this DPA and remains responsible for their performance.
5.3 Aventro Ltd. will give Customer notice of intended additions or replacements of Sub-processors (for example by updating the list and, where Customer subscribes, by email) with a reasonable opportunity to object on reasonable data-protection grounds. If the parties cannot resolve a reasonable objection, Customer may terminate the affected Service as its remedy.
6. Data Subject Requests
Taking into account the nature of the Processing, Aventro Ltd. will assist Customer by appropriate technical and organizational measures, insofar as possible, to respond to Data Subject requests to exercise their rights. Where a Data Subject contacts Aventro Ltd. directly regarding Customer Personal Data, Aventro Ltd. will refer them to Customer unless otherwise legally required.
7. Personal Data Breach
Aventro Ltd. will notify Customer without undue delay, and where feasible within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to help Customer meet its notification obligations, and information about remediation.
8. Deletion and Return
On termination or expiry of the Agreement, Aventro Ltd. will, at Customer's choice, delete or return Customer Personal Data, and delete existing copies, except to the extent retention is required by law. Customer may export Customer Personal Data using Service features before deletion.
9. Audits
Aventro Ltd. will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, by Customer or its mandated auditor, subject to reasonable confidentiality and security conditions and reasonable notice. Aventro Ltd. may satisfy audit requests by providing third-party certifications or reports where available.
10. International Transfers
10.1 Aventro Ltd. is established in Israel, which the European Commission recognizes as providing an adequate level of data protection (reaffirmed in 2024). Transfers of Customer Personal Data from the EEA/UK to Aventro Ltd. may rely on that adequacy recognition.
10.2 For onward transfers to Sub-processors located outside Israel/the EEA/UK (for example the United States), Aventro Ltd. puts in place an appropriate transfer mechanism, such as the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, together with supplementary measures where required.
11. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement.
12. Term
This DPA takes effect when the Agreement does and continues while Aventro Ltd. Processes Customer Personal Data.
Annex I — Description of Processing
- Subject matter: provision of the Aventro due-diligence platform.
- Duration: the term of the Agreement plus any legally required retention.
- Nature and purpose: hosting, storage, AI-assisted analysis and scoring, cross-source verification, report generation, collaboration, and sharing, as configured by Customer.
- Types of Personal Data: account and contact details; professional profile data; company intake and evidence data (which may include personal data about founders, team members, and third parties, and may include financial data); collaboration content; usage data; and, where Customer enables it, verification results from third-party sources.
- Special/"especially sensitive" categories: the Service is not designed for special-category data, but evidence may include financial details (treated as especially sensitive under Israeli law). Customer controls what it uploads.
- Categories of Data Subjects: Customer's users; founders, executives, and team members of companies analyzed; and other individuals named in Customer's Content.
- Frequency: continuous, for the duration of the Agreement.
Annex II — Technical and Organizational Measures
- Encryption of data in transit (TLS) and at rest for sensitive evidence categories using per-Deal derived keys.
- Access control: role-based access, row-level security, and organization-level data segregation; administrative access restricted to named personnel on the principle of least privilege, with privileged actions that modify customer data logged.
- Auditability: logging of security-relevant events (visibility changes, shares, exports).
- Resilience: managed cloud infrastructure with provider-level redundancy; encrypted backups of the production database and of stored evidence, retained off-platform under separate access control, with a documented restoration procedure.
- Vendor management: data-protection terms and security due diligence for Sub-processors.
- Development practices: access to production data restricted to named personnel.
Annex III — Sub-processors
The current list of Sub-processors is maintained at the Subprocessors page and incorporated by reference.
Questions about this document? Contact us at legal@aventro.ai