Back to Home

Data Processing Addendum (DPA)

Effective date: October 1, 2026 • Version 1.0

This Data Processing Addendum (“DPA”) supplements the Terms of Service between Rao Industries (“Ava AI,” “Processor,” “we,” or “us”) and the business entity or organization agreeing to these terms (“Customer,” “Controller,” or “you”).

This DPA governs the processing of Personal Data by Ava AI on behalf of Customer in connection with the Ava AI platform, conversational website widget, knowledge base ingestion, and real-time support services. It incorporates the European Union Standard Contractual Clauses (2021/914 Module 2), the UK International Data Transfer Addendum, and US State Privacy Law (CCPA/CPRA) Service Provider certifications.

GDPR & UK Compliant

Article 28 processor terms and Standard Contractual Clauses (SCCs) included.

CCPA Service Provider

Strict certification prohibiting sale, sharing, or cross-context tracking of personal data.

Zero Model Training

Customer conversations and knowledge data are never used to train general AI models.

1. Definitions

“Applicable Data Protection Law” means all global privacy and data protection laws applicable to the processing of Personal Data hereunder, including Regulation (EU) 2016/679 (GDPR), the UK Data Protection Act 2018 and UK GDPR, the California Consumer Privacy Act as amended by CPRA (Cal. Civ. Code § 1798.100 et seq.), the India Digital Personal Data Protection Act, 2023 (DPDP), and similar state and international privacy statutes.
“Controller” means the entity that determines the purposes and means of the processing of Personal Data (Customer).
“Processor” means the entity that processes Personal Data on behalf of the Controller (Rao Industries / Ava AI).
“Customer Personal Data” means any Personal Data provided by or on behalf of Customer or its website visitors to Ava AI for processing via the Service.
“Standard Contractual Clauses (SCCs)” means Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679.

2. Roles and Scope of Processing

2.1 Role Designation: The parties acknowledge and agree that with respect to Customer Personal Data, Customer is the Controller (or a processor acting on behalf of a third-party controller) and Ava AI is a Processor (or subprocessor).

2.2 Customer Instructions:Ava AI shall process Customer Personal Data solely in accordance with Customer's documented instructions, as set forth in the Terms of Service, this DPA, and Customer's administrative configurations in the Ava platform, unless required to do so by applicable law to which Ava AI is subject.

2.3 Details of Processing:

  • Subject Matter: Provision of AI-powered conversational support, website crawling, knowledge base retrieval, and real-time chat routing.
  • Duration: The term of Customer's subscription plus data retention periods defined in our Privacy Policy.
  • Categories of Data Subjects: Customer's authorized users, staff operators, and website visitors who interact with the Ava chat widget.
  • Types of Personal Data: Names, email addresses, phone numbers, interaction logs, IP addresses (for rate-limiting), message transcripts, and queries submitted through chat.

3. Security of Processing (Technical & Organizational Measures)

Ava AI implements and maintains rigorous technical and organizational security measures (TOMs) designed to protect Customer Personal Data against accidental, unauthorized, or unlawful destruction, loss, alteration, disclosure, or access:

Encryption in Transit & at Rest
All web, API, and WebSocket traffic is encrypted using TLS 1.3. Databases and backups are encrypted at rest using AES-256.
Strict Logical Tenant Isolation
Customer data is logically partitioned and scoped by unique organization identifiers (organizationId) across every query.
Confidentiality & Access Controls
Personnel with access to production systems are bound by written non-disclosure obligations and access is governed by least-privilege RBAC.
Disaster Recovery & Redundancy
Automated database snapshot backups and container health-monitoring ensure high availability and rapid disaster recovery.

4. Authorized Subprocessors

4.1 General Authorization: Customer provides general written authorization for Ava AI to engage third-party subprocessors to support the delivery of the Service.

4.2 Subprocessor Obligations: Ava AI imposes data protection obligations on each subprocessor that are no less protective than those set forth in this DPA. Ava AI remains responsible to Customer for the performance of its subprocessors.

4.3 Schedule of Approved Subprocessors:

SubprocessorRole / ActivityCountry / LocationTransfer Safeguard
Groq, Inc.AI Inference (Zero Data Retention)United StatesEU SCCs / DPA
Render Services, Inc.Real-time WebSocket Relay & StreamingUnited States (Oregon)EU SCCs / SOC 2
Firecrawl (Mendable, Inc.)Website Scraping & Content ExtractionUnited StatesEU SCCs / DPA
Vercel, Inc.Edge Hosting & Web Application DeliveryUnited States / Global CDNEU SCCs / SOC 2 Type II
Supabase, Inc.Cloud PostgreSQL Database & StorageUnited States (AWS)EU SCCs / SOC 2 Type II
Upstash, Inc.Redis Rate Limiting & CachingUnited States (AWS)EU SCCs / DPA
Razorpay Software Pvt LtdSubscription & Payment ProcessingIndiaPCI-DSS Level 1 / RBI Regulated
Resend, Inc.Transactional Email DeliveryUnited StatesEU SCCs / DPA

5. International Data Transfers (EU SCCs & UK Addendum)

5.1 EU Transfers: Where the transfer of Customer Personal Data from the European Union, European Economic Area, or Switzerland to Ava AI or its subprocessors involves a cross-border transfer, the parties hereby incorporate by reference the Standard Contractual Clauses (Module 2: Controller-to-Processor) adopted by the European Commission under Implementing Decision (EU) 2021/914:

  • Clause 7 (Docking clause) applies.
  • Clause 9 (Use of sub-processors): Option 2 (General written authorization) applies with a 10-day notice period.
  • Clause 11 (Redress): The optional requirement that data subjects may lodge a complaint with an independent dispute resolution body does not apply.
  • Clause 17 (Governing law): The law of the Republic of Ireland shall govern.
  • Clause 18 (Choice of forum): Courts of Ireland shall have jurisdiction.

5.2 UK Transfers:For transfers subject to the UK GDPR, the UK International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (Version B.10.0) is incorporated, with the Information Commissioner's Office (ICO) designated as the supervisory authority.

6. US State Privacy Law (California CCPA/CPRA) Service Provider Certification

For the purposes of the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (collectively “CCPA/CPRA”), and similar US state privacy statutes:

  • Ava AI acts strictly as a Service Provider or Processor with respect to Customer Personal Data.
  • No Sale or Sharing:Ava AI shall not “sell” or “share” Customer Personal Data as those terms are defined under the CCPA/CPRA.
  • Retention & Use Limitations: Ava AI shall not retain, use, disclose, or otherwise process Customer Personal Data for any purpose other than for the business purposes specified in the Terms of Service and this DPA, or outside the direct business relationship between Ava AI and Customer.
  • No Cross-Context Behavioral Advertising: Ava AI shall not combine Customer Personal Data with personal data received from or on behalf of another person or entity, except as expressly permitted under Cal. Civ. Code § 1798.140(ag).
  • Statutory Certification: Ava AI certifies that it understands the contractual restrictions set forth in this Section and will comply with them.

7. Incident Notification & Data Breach Response

In the event of a confirmed Personal Data Breach affecting Customer Personal Data:

  • Ava AI shall notify Customer without undue delay (and in any event within 48 hours of becoming aware of the breach).
  • In accordance with Indian statutory requirements under the Information Technology (CERT-In) Directions 2022, cybersecurity incidents will also be reported to the Indian Computer Emergency Response Team within the mandated 6-hour reporting window.
  • The notification will describe the nature of the breach, affected data categories, estimated number of affected data subjects, and remedial steps taken.

8. Data Subject Rights & Data Deletion

8.1 Assistance with DSRs: Ava AI provides administrative tools within the dashboard allowing Customer to retrieve, export, correct, or delete conversation transcripts and contact records. Where Customer requires additional assistance, Ava AI will reasonably assist Customer in responding to data subject requests under Applicable Data Protection Law.

8.2 Deletion upon Termination: Upon termination of the Service, Ava AI shall delete or return Customer Personal Data in accordance with the Terms of Service, unless applicable statutory law requires retention of certain audit or tax records.

9. Privacy & Data Protection Inquiries

To execute an individualized enterprise DPA or address data protection inquiries, please contact our Data Protection and Grievance Officer:

Rao Industries (Ava AI)
Contact Grievance Officer: grievance@getava.in