Effective date: October 1, 2026 • Version 1.0
This Data Processing Addendum (“DPA”) supplements the Terms of Service between Rao Industries (“Ava AI,” “Processor,” “we,” or “us”) and the business entity or organization agreeing to these terms (“Customer,” “Controller,” or “you”).
This DPA governs the processing of Personal Data by Ava AI on behalf of Customer in connection with the Ava AI platform, conversational website widget, knowledge base ingestion, and real-time support services. It incorporates the European Union Standard Contractual Clauses (2021/914 Module 2), the UK International Data Transfer Addendum, and US State Privacy Law (CCPA/CPRA) Service Provider certifications.
Article 28 processor terms and Standard Contractual Clauses (SCCs) included.
Strict certification prohibiting sale, sharing, or cross-context tracking of personal data.
Customer conversations and knowledge data are never used to train general AI models.
2.1 Role Designation: The parties acknowledge and agree that with respect to Customer Personal Data, Customer is the Controller (or a processor acting on behalf of a third-party controller) and Ava AI is a Processor (or subprocessor).
2.2 Customer Instructions:Ava AI shall process Customer Personal Data solely in accordance with Customer's documented instructions, as set forth in the Terms of Service, this DPA, and Customer's administrative configurations in the Ava platform, unless required to do so by applicable law to which Ava AI is subject.
2.3 Details of Processing:
Ava AI implements and maintains rigorous technical and organizational security measures (TOMs) designed to protect Customer Personal Data against accidental, unauthorized, or unlawful destruction, loss, alteration, disclosure, or access:
organizationId) across every query.4.1 General Authorization: Customer provides general written authorization for Ava AI to engage third-party subprocessors to support the delivery of the Service.
4.2 Subprocessor Obligations: Ava AI imposes data protection obligations on each subprocessor that are no less protective than those set forth in this DPA. Ava AI remains responsible to Customer for the performance of its subprocessors.
4.3 Schedule of Approved Subprocessors:
| Subprocessor | Role / Activity | Country / Location | Transfer Safeguard |
|---|---|---|---|
| Groq, Inc. | AI Inference (Zero Data Retention) | United States | EU SCCs / DPA |
| Render Services, Inc. | Real-time WebSocket Relay & Streaming | United States (Oregon) | EU SCCs / SOC 2 |
| Firecrawl (Mendable, Inc.) | Website Scraping & Content Extraction | United States | EU SCCs / DPA |
| Vercel, Inc. | Edge Hosting & Web Application Delivery | United States / Global CDN | EU SCCs / SOC 2 Type II |
| Supabase, Inc. | Cloud PostgreSQL Database & Storage | United States (AWS) | EU SCCs / SOC 2 Type II |
| Upstash, Inc. | Redis Rate Limiting & Caching | United States (AWS) | EU SCCs / DPA |
| Razorpay Software Pvt Ltd | Subscription & Payment Processing | India | PCI-DSS Level 1 / RBI Regulated |
| Resend, Inc. | Transactional Email Delivery | United States | EU SCCs / DPA |
5.1 EU Transfers: Where the transfer of Customer Personal Data from the European Union, European Economic Area, or Switzerland to Ava AI or its subprocessors involves a cross-border transfer, the parties hereby incorporate by reference the Standard Contractual Clauses (Module 2: Controller-to-Processor) adopted by the European Commission under Implementing Decision (EU) 2021/914:
5.2 UK Transfers:For transfers subject to the UK GDPR, the UK International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (Version B.10.0) is incorporated, with the Information Commissioner's Office (ICO) designated as the supervisory authority.
For the purposes of the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (collectively “CCPA/CPRA”), and similar US state privacy statutes:
In the event of a confirmed Personal Data Breach affecting Customer Personal Data:
8.1 Assistance with DSRs: Ava AI provides administrative tools within the dashboard allowing Customer to retrieve, export, correct, or delete conversation transcripts and contact records. Where Customer requires additional assistance, Ava AI will reasonably assist Customer in responding to data subject requests under Applicable Data Protection Law.
8.2 Deletion upon Termination: Upon termination of the Service, Ava AI shall delete or return Customer Personal Data in accordance with the Terms of Service, unless applicable statutory law requires retention of certain audit or tax records.
To execute an individualized enterprise DPA or address data protection inquiries, please contact our Data Protection and Grievance Officer: