Skip to content
avertari
How it works Trust Contact Become a design partner

Legal

Data processing agreement

Effective 24 September 2026

On this page

  1. Scope of processing
  2. Processing on instructions
  3. Confidentiality
  4. Security
  5. Subprocessors
  6. Assistance
  7. Personal data breaches
  8. Return and deletion
  9. Audits
  10. International transfers
  11. Liability and precedence
  12. Annex: security measures
Draft. This document is being reviewed by our legal advisers and may change before general availability. Questions: [email protected].

This data processing agreement ("DPA") forms part of the agreement between to be confirmed ("Avertari", the processor) and the customer ("Customer", the controller) for the Avertari service. It meets the requirements of Article 28 of the UK GDPR. Need a countersigned copy for your records? Email [email protected].

Scope of processing

Subject matterProviding the Avertari service: detecting joiner, mover and leaver events and suggesting access changes.
DurationThe term of the agreement, plus the deletion period in section 8.
Nature & purposeReading records from systems the Customer connects; correlating identities, accounts and access; generating, storing and displaying suggestions and audit records.
Data subjectsThe Customer's current, future and former employees, contractors and other workforce members; the Customer's authorised users of Avertari.
Personal dataName and identifiers; work email; job title, department, team, location and manager; employment status and start, change and end dates; accounts, group memberships, roles and entitlements in connected systems; sign-in and activity metadata; audit logs.
Special category dataNone intended. Connectors request only the fields listed above. The Customer shouldn't configure Avertari to process special category data.

Processing on instructions

Avertari processes Customer personal data only on the Customer's documented instructions. Those instructions are this DPA, the agreement and the Customer's configuration of the service, unless the law requires otherwise. In that case Avertari will tell the Customer first, unless the law forbids it. Avertari will tell the Customer if it believes an instruction breaches data protection law.

Confidentiality

Avertari ensures that everyone authorised to process Customer personal data is bound by confidentiality, and that access is limited to those who need it to provide the service.

Security

Avertari applies appropriate technical and organisational measures to protect Customer personal data, including those in the Annex. We may update these measures as long as the overall level of protection doesn't go down.

Subprocessors

The Customer authorises Avertari to use the subprocessors listed on our subprocessors page. Avertari will:

  • give at least 30 days' notice before adding or replacing a subprocessor. The Customer may object on reasonable data protection grounds, and if we can't resolve the objection the Customer may terminate the affected service and receive a pro-rata refund;
  • impose data protection terms on each subprocessor that are at least as protective as this DPA;
  • remain responsible for its subprocessors' performance.

Assistance

Taking into account the nature of the processing, Avertari will help the Customer:

  • respond to data subject requests. If Avertari receives a request directly, it will pass it on to the Customer without responding itself;
  • carry out data protection impact assessments and consult regulators where required;
  • meet its security and breach-notification obligations.

Personal data breaches

Avertari will notify the Customer without undue delay, and in any case within 48 hours, of becoming aware of a personal data breach affecting Customer personal data. The notice will include what's known at the time (the nature of the breach, likely consequences and measures taken or proposed), with updates as more becomes known.

Return and deletion

When the agreement ends, the Customer may export its data for 30 days. After that, Avertari deletes Customer personal data within 30 days by destroying the Customer's dedicated encryption key and deleting the underlying records. Backups become unreadable once the key is destroyed. On request, Avertari will confirm deletion in writing. This doesn't apply where the law requires Avertari to keep specific data.

Audits

Avertari will make available the information needed to demonstrate compliance with this DPA. Once available, this includes third-party audit reports such as SOC 2. Where that isn't enough, the Customer may carry out an audit, or have one carried out, once a year, with at least 30 days' notice, during business hours and under confidentiality obligations. The Customer bears its own costs.

International transfers

Customer personal data in the Avertari platform is stored and processed in the United Kingdom (Google Cloud, europe-west2 London). Avertari won't transfer it outside the UK unless an appropriate safeguard is in place under UK data protection law, such as an adequacy regulation or the UK International Data Transfer Agreement or Addendum.

Liability and precedence

Each party's liability under this DPA is subject to the limitations in the agreement. If this DPA conflicts with the agreement on the processing of personal data, this DPA takes priority.

Annex: security measures

  • Access to Customer systems: read-only scopes. Administrator consent or signed-key authentication where the vendor supports it. No storage of user passwords.
  • Encryption: TLS 1.2 or higher in transit. Encryption at rest for all data, plus envelope encryption of connector credentials with a Cloud KMS key dedicated to each Customer.
  • Isolation: tenant isolation enforced in the database layer. A separate encryption key for each Customer.
  • Access control: single sign-on with phishing-resistant MFA for staff. No standing human access to production data or credentials. Emergency access is time-limited and logged.
  • Logging: audit logs of administrative actions and of every access to keys and secrets, kept in append-only storage.
  • Network: production services on private networks with no public database endpoints, inside a cloud service perimeter.
  • Change management: infrastructure as code, peer review, automated testing, secret scanning, and short-lived federated credentials for deployment.
  • Resilience: managed database backups with point-in-time recovery, in the same region as the primary data.
  • Vulnerability management: dependency and container scanning, and a public vulnerability disclosure policy.
avertari

Joiner, mover and leaver intelligence for the tools you already run.

Product

How it works Joiners, movers, leavers Trust centre

Company

Contact Design partners [email protected]

Legal

Privacy policy Terms of service Data processing Subprocessors security.txt

© 2026 Avertari. Company details

This site sets no cookies and loads nothing from third parties.