This data processing agreement ("DPA") forms part of the agreement between to be confirmed ("Avertari", the processor) and the customer ("Customer", the controller) for the Avertari service. It meets the requirements of Article 28 of the UK GDPR. Need a countersigned copy for your records? Email [email protected].
Scope of processing
| Subject matter | Providing the Avertari service: detecting joiner, mover and leaver events and suggesting access changes. |
|---|---|
| Duration | The term of the agreement, plus the deletion period in section 8. |
| Nature & purpose | Reading records from systems the Customer connects; correlating identities, accounts and access; generating, storing and displaying suggestions and audit records. |
| Data subjects | The Customer's current, future and former employees, contractors and other workforce members; the Customer's authorised users of Avertari. |
| Personal data | Name and identifiers; work email; job title, department, team, location and manager; employment status and start, change and end dates; accounts, group memberships, roles and entitlements in connected systems; sign-in and activity metadata; audit logs. |
| Special category data | None intended. Connectors request only the fields listed above. The Customer shouldn't configure Avertari to process special category data. |
Processing on instructions
Avertari processes Customer personal data only on the Customer's documented instructions. Those instructions are this DPA, the agreement and the Customer's configuration of the service, unless the law requires otherwise. In that case Avertari will tell the Customer first, unless the law forbids it. Avertari will tell the Customer if it believes an instruction breaches data protection law.
Confidentiality
Avertari ensures that everyone authorised to process Customer personal data is bound by confidentiality, and that access is limited to those who need it to provide the service.
Security
Avertari applies appropriate technical and organisational measures to protect Customer personal data, including those in the Annex. We may update these measures as long as the overall level of protection doesn't go down.
Subprocessors
The Customer authorises Avertari to use the subprocessors listed on our subprocessors page. Avertari will:
- give at least 30 days' notice before adding or replacing a subprocessor. The Customer may object on reasonable data protection grounds, and if we can't resolve the objection the Customer may terminate the affected service and receive a pro-rata refund;
- impose data protection terms on each subprocessor that are at least as protective as this DPA;
- remain responsible for its subprocessors' performance.
Assistance
Taking into account the nature of the processing, Avertari will help the Customer:
- respond to data subject requests. If Avertari receives a request directly, it will pass it on to the Customer without responding itself;
- carry out data protection impact assessments and consult regulators where required;
- meet its security and breach-notification obligations.
Personal data breaches
Avertari will notify the Customer without undue delay, and in any case within 48 hours, of becoming aware of a personal data breach affecting Customer personal data. The notice will include what's known at the time (the nature of the breach, likely consequences and measures taken or proposed), with updates as more becomes known.
Return and deletion
When the agreement ends, the Customer may export its data for 30 days. After that, Avertari deletes Customer personal data within 30 days by destroying the Customer's dedicated encryption key and deleting the underlying records. Backups become unreadable once the key is destroyed. On request, Avertari will confirm deletion in writing. This doesn't apply where the law requires Avertari to keep specific data.
Audits
Avertari will make available the information needed to demonstrate compliance with this DPA. Once available, this includes third-party audit reports such as SOC 2. Where that isn't enough, the Customer may carry out an audit, or have one carried out, once a year, with at least 30 days' notice, during business hours and under confidentiality obligations. The Customer bears its own costs.
International transfers
Customer personal data in the Avertari platform is stored and processed in the United Kingdom (Google Cloud, europe-west2 London). Avertari won't transfer it outside the UK unless an appropriate safeguard is in place under UK data protection law, such as an adequacy regulation or the UK International Data Transfer Agreement or Addendum.
Liability and precedence
Each party's liability under this DPA is subject to the limitations in the agreement. If this DPA conflicts with the agreement on the processing of personal data, this DPA takes priority.
Annex: security measures
- Access to Customer systems: read-only scopes. Administrator consent or signed-key authentication where the vendor supports it. No storage of user passwords.
- Encryption: TLS 1.2 or higher in transit. Encryption at rest for all data, plus envelope encryption of connector credentials with a Cloud KMS key dedicated to each Customer.
- Isolation: tenant isolation enforced in the database layer. A separate encryption key for each Customer.
- Access control: single sign-on with phishing-resistant MFA for staff. No standing human access to production data or credentials. Emergency access is time-limited and logged.
- Logging: audit logs of administrative actions and of every access to keys and secrets, kept in append-only storage.
- Network: production services on private networks with no public database endpoints, inside a cloud service perimeter.
- Change management: infrastructure as code, peer review, automated testing, secret scanning, and short-lived federated credentials for deployment.
- Resilience: managed database backups with point-in-time recovery, in the same region as the primary data.
- Vulnerability management: dependency and container scanning, and a public vulnerability disclosure policy.