Legal

Data Processing Addendum

Last updated: October 7, 2026 · Version 1.0

This Data Processing Addendum (“DPA”) explains how Aventide handles the personal data you put into Aventide about your clients and contacts. It is part of the Aventide Terms of Service.

The short version

  • Your clients’ data is yours. When you put your clients’ details into Aventide, we handle that data for you, on your instructions. In privacy-law terms, you are the “business” or “controller” and we are your “service provider” or “processor”.

  • We use it only to run Aventide for you. We don’t sell it, share it for advertising, or use it to train AI models.

  • We tell you who helps us. Our list of sub-processors is at aventide.ai/legal/subprocessors. We email the account owner at least 15 days before we add one, and you can object.

  • We tell you fast if something goes wrong. If a security incident affects your clients’ data, we tell you without undue delay: we aim for 24 hours, and always within 72 hours of becoming aware of it.

  • You can get your data out, and have it deleted. Email us and we delete it within 30 days.

  • No signature needed. This DPA applies automatically when you use Aventide.

1. When this DPA applies

1.1 It’s part of the Terms. This DPA is incorporated into, and forms part of, the Aventide Terms of Service (the “Terms”) between you and Second Spring Design Inc., a Delaware corporation doing business as Aventide (“Aventide”, “we”, “us”).

1.2 No signature needed. You accept this DPA when you accept the Terms. It takes effect when you first use Aventide and lasts as long as we process Customer Personal Data for you, including during the deletion period in Section 14.

1.3 Who “you” are. “You” means the business that holds the Aventide account. The account owner accepts this DPA for that business.

1.4 If documents conflict. For anything about Customer Personal Data, this DPA wins over the Terms. Everything else in the Terms still applies, including the limits on liability (Section 16).

2. Words we use

  • Customer Data: everything you and your team put into Aventide, connect to it, or create with it.

  • Customer Personal Data: the personal data in Customer Data that we process on your behalf. It does not include Account Data.

  • Account Data: what we need to run your account with us: the names and email addresses of you and your teammates, sign-in, plan and billing details, support conversations, and records of how the product is used (for example, which feature was opened). We handle Account Data as an independent business under our Privacy Policy. If you share your clients’ personal data with us in a support request, we treat it as Customer Personal Data.

  • Privacy Laws: the US state privacy laws that apply to Customer Personal Data, including the California Consumer Privacy Act as amended by the California Privacy Rights Act and its regulations (“CCPA”), and the comprehensive privacy laws of other US states (for example Virginia, Colorado, Connecticut, Utah, Texas and Oregon).

  • Sub-processor: a company we engage that processes Customer Personal Data for us.

  • Security Incident: a breach of security that leads to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to, Customer Personal Data, whether on our systems or a sub-processor’s. It does not include unsuccessful attempts that don’t compromise the data, such as blocked log-in attempts, pings or port scans.

  • Services you connect: outside services you choose to link to Aventide, such as your Google account, your Stripe account, QuickBooks, Zoom, a meeting-note tool or a social media account. They are listed on the sub-processor page under “Services you connect”.

Other terms (like “business”, “service provider”, “controller”, “processor”, “consumer”, “personal data”, “sell” and “share”) mean what the applicable Privacy Law says they mean.

3. Roles

3.1 You are in charge of your clients’ data. For Customer Personal Data, you are the business/controller and Aventide is your service provider/processor (or, under the CCPA, a “service provider”).

3.2 Your account with us is different. For Account Data, Aventide decides how it’s used and is responsible for it under our Privacy Policy.

3.3 Services you connect are your choice. When you connect a service, you decide to send data to it or bring data from it. That service handles the data under its own terms with you. It is not our sub-processor. Sending data to a service you connected, or to a destination you set up (for example, a webhook address on your inquiry form), is one of your instructions under Section 4.

3.4 What you’re responsible for. You are responsible for:

  • having the right to put your clients’ personal data into Aventide and to have us process it as this DPA describes;

  • giving your clients any notices, and getting any consents, the law requires. For example: telling them you use online tools (including AI) to manage your work with them, and getting marketing consent on your inquiry forms where it’s needed. If you record or transcribe calls, or bring in their transcripts, it also means telling the people on them and getting their consent where the law requires;

  • the instructions you give us and the content you and your team send through Aventide;

  • not putting in data Aventide isn’t built for (see “Sensitive data” in Annex 1);

  • keeping your team’s sign-in details safe and removing teammates who should no longer have access.

4. We follow your instructions

4.1 What counts as your instructions. We process Customer Personal Data only on your documented instructions. Your instructions are: the Terms, this DPA, your settings, and the things you and your team do in Aventide (including what you ask Aventide’s assistant to do). Anything else must be agreed by you and us in writing (email is fine).

4.2 This includes Aventide’s AI features. When you use them, you instruct us to send Customer Personal Data to our AI sub-processor to: answer questions, read the email synced to your Inbox, draft emails, replies, messages, proposals and contracts, summarize meeting notes, read dates from documents you upload, and keep “memories” about your business and your clients so the assistant can help you better. Some client memories (preferences, context, relationship notes) are saved automatically; you can see them on the client’s card and delete them. Others (commitments, pricing and Business Hub facts) are only proposed, and are saved only if you approve them.

4.3 Sending and publishing. Aventide’s assistant asks for a person’s approval before it sends email or messages to your clients, sends contracts or invoices, or publishes on your behalf. Messages you set up to go automatically (such as booking confirmations, or a deposit invoice that a contract is set to send when it’s signed) are sent because you set up that feature.

4.4 If an instruction looks unlawful. We will tell you if we believe an instruction breaks a Privacy Law. We may decline to follow it until you change it.

4.5 What we do with Customer Personal Data — and nothing else. We use it only to: (a) provide, maintain and support Aventide for you, including the features you use; (b) keep Aventide and your data secure, and detect and prevent fraud, abuse and illegal activity; (c) find and fix errors; (d) comply with the law; and (e) improve Aventide’s quality and safety, in the ways the CCPA allows a service provider to — never to build a profile of a person for anyone else, never to provide services to another customer, and never to train AI models.

5. US state privacy law terms (including CCPA/CPRA)

5.1 Business purpose. You disclose Customer Personal Data to us only for the limited and specified business purposes in Section 4.5 and Annex 1.

5.2 We will not:

  • sell or share Customer Personal Data (including “sharing” for cross-context behavioral advertising), or use it for targeted advertising;

  • retain, use or disclose it for any purpose other than the business purposes in this DPA, including any commercial purpose of our own, except as the CCPA allows;

  • retain, use or disclose it outside the direct business relationship between you and us;

  • combine it with personal data we receive from someone else or collect on our own, except as the CCPA allows a service provider to (for example, to detect security incidents or prevent fraud).

5.3 Same protection. We will comply with the Privacy Laws that apply to us as your service provider/processor, and give Customer Personal Data the same level of privacy protection those laws require of you.

5.4 Your right to check, stop and fix. You may take reasonable and appropriate steps to make sure we use Customer Personal Data in line with your obligations (Section 15 explains how). If you reasonably believe we are using it without authorization, tell us; we will work with you to stop and remediate the unauthorized use.

5.5 If we can’t comply. If we decide we can no longer meet our obligations under the Privacy Laws or this DPA, we will tell you promptly, and no later than 5 business days after we decide. You may then stop sending us the data and end the affected processing (Section 17.3).

5.6 De-identified data. If we de-identify Customer Personal Data, we will take reasonable measures to keep it de-identified, we publicly commit here not to try to re-identify it, and we will require anyone we give it to to make the same commitments.

5.7 Certification. We certify that we understand the restrictions in this Section 5 and will comply with them.

5.8 Other state laws. Where a state law (such as Virginia, Colorado, Connecticut, Utah, Texas or Oregon) treats us as your “processor”, Sections 4 to 15 are our processor commitments under that law: we follow your instructions, keep the data confidential, use sub-processors only under written contracts with notice and a chance to object, help you with requests and assessments, delete or return data at your direction, and give you the information you need to show compliance.

6. Our people

6.1 Everyone at Aventide who can access Customer Personal Data is bound by a duty of confidentiality (by contract or professional duty) that continues after their work with us ends. Anyone we add later will sign a confidentiality agreement before they get access.

6.2 We limit access to the people who need it to run, support or secure Aventide. Today, that is the two founders. We access Customer Personal Data only to provide support you ask for, fix problems, keep Aventide secure, or comply with the law.

7. Security

7.1 We use the technical and organizational measures in Annex 2 to protect Customer Personal Data.

7.2 We may change these measures as Aventide and the threats change, but we will not reduce the overall level of protection for Customer Personal Data.

7.3 Aventide is not itself SOC 2 certified. Annex 2 says plainly what we have and what we don’t.

8. Sub-processors

8.1 You authorize our sub-processors. You give us general authorization to use the sub-processors listed at aventide.ai/legal/subprocessors, and new ones added under this Section 8.

8.2 Same protection, our responsibility. Each sub-processor is bound by a written contract that protects Customer Personal Data at least as well as this DPA does, to the extent that fits the service it provides. We remain responsible to you for our sub-processors’ work, subject to Section 16.

8.3 Notice of changes. Before a new sub-processor starts processing Customer Personal Data, we will (a) update the sub-processor page and (b) email the account owner at least 15 days in advance. If we need to replace a sub-processor urgently to keep Aventide secure or running, we will tell you as soon as we can, and you keep your right to object.

8.4 Optional features. Some sub-processors only handle data if you or a teammate turn on a feature (for example, Sidekick on WhatsApp). They are marked “optional” on the page. For a new optional feature, we list the sub-processor before the feature launches, and turning the feature on is your authorization. Some messaging apps (today, Telegram) offer only their standard terms, not a data processing agreement, so Section 8.2 can’t fully apply to them. The page says which ones. If that matters to you, don’t turn that channel on.

8.5 Your right to object. You may object to a new sub-processor on reasonable data-protection grounds by emailing support@aventide.ai within 15 days of our notice. We will try in good faith to address it, for example by suggesting a setting or a way to use Aventide without that sub-processor. If we can’t resolve it within 30 days, you may end your subscription (or stop using the affected feature) by telling us in writing. If you end a prepaid annual subscription this way, we will refund the prepaid fees for the unused part of the term.

9. Requests from your clients

9.1 Tools in Aventide. You can view, correct and delete much of your clients’ data yourself. For example: edit a client record, delete a client note or a saved client memory, delete a meeting note, or remove a contact’s access to your client portal. Some deletions take effect immediately (such as a meeting note). Others hide the item first (such as a client record) and keep it in our database.

9.2 We help with the rest. If you can’t fully answer a request from one of your clients (to access, correct, delete, or receive a copy of their data, or to opt out) with the tools in Aventide, email support@aventide.ai. We will help you within the time the law gives you. To have one person’s data permanently erased, email us and we will do it within 30 days. One exception: entries in signed contracts and their audit trails, and in invoice and document histories, are locked as a record of what happened. They can be removed only by deleting the whole business (Section 14.4). Privacy laws generally let you keep records like these (for example, to complete a transaction or defend a legal claim); if you need them gone anyway, tell us and we’ll work it out with you.

9.3 Requests that reach us directly. If one of your clients contacts us directly about Customer Personal Data, we will pass the request to you promptly, and within 5 business days. We won’t answer it ourselves, except to tell them we’ve passed it to you, unless you ask us to or the law requires it.

10. Security incidents

10.1 Notice within 72 hours. If we become aware of a Security Incident, we will tell you without undue delay. We aim to tell you within 24 hours, and will tell you no later than 72 hours after becoming aware of it. “Becoming aware” means we know, or reasonably believe, that a Security Incident has happened.

10.2 How and what. We will email the account owner (and any security contact you send us at support@aventide.ai). We will tell you what we know at the time and update you as we learn more, including: what happened; the kinds of data and roughly how many people are affected; the likely consequences; what we have done and will do about it; and who to contact at Aventide.

10.3 We act fast. We will promptly take reasonable steps to contain and investigate the Security Incident and reduce its harm.

10.4 Notifying people. You decide whether to notify your clients or regulators. We will give you the information we reasonably can to help you do it. We won’t notify your clients or regulators about Customer Personal Data on your behalf unless you ask us to or the law requires it.

10.5 Telling you about a Security Incident is not an admission of fault.

11. Other help we give you

11.1 Assessments. If you need to do a data protection assessment or risk assessment under a Privacy Law, we will give you the information about our processing that is reasonably available to us (this DPA, Annex 2, and the sub-processor page are a good start).

11.2 Regulators. If a regulator asks you about our processing of Customer Personal Data, we will reasonably cooperate.

12. Requests from governments and courts

If a government agency or court demands Customer Personal Data from us, we will try to redirect it to you. We will tell you promptly before we disclose anything, unless the law forbids us to. We will disclose only what we are legally required to.

13. Where data is processed

13.1 We run Aventide in the United States and store Customer Personal Data in our database in the United States. Uploaded files are stored with Cloudflare R2.

13.2 Some sub-processors may process data in other countries. For example, Cloudflare runs a global network that converts and delivers files, and the messaging apps you can turn on for Sidekick (Telegram, WhatsApp and Slack) run their own global services. The sub-processor page says where each one processes data, where we know.

14. Return and deletion — Version A (current)

14.1 While your account is open. We keep Customer Personal Data until you delete it in Aventide or ask us to delete it. Some data is cleared automatically. For example, email synced from Gmail into your Inbox is removed 90 days after it arrives if it’s bulk “FYI” mail, and 180 days after you last touched it if you’ve resolved or dismissed it. Mail that is still open, snoozed or waiting on a draft is not removed automatically.

14.2 Deleting in the app. Some in-app deletions remove data right away. Others archive it so it can be restored: deleting a business archives it, and deleting a client hides the client record. Archived data stays in our database until it is permanently deleted under 14.4.

14.3 Getting a copy. You can download signed contracts and other documents one by one in Aventide. For a full copy of your data (including clients, invoices, bookings and form responses), the account owner can email support@aventide.ai and we will send it in a common format (JSON or CSV) within 30 days.

14.4 Permanent deletion on request. The account owner can ask us to permanently delete a business, one person’s data, or your whole account by emailing support@aventide.ai from the owner’s email address. We will do it within 30 days and confirm in writing. This includes signed contracts and their audit trails, so download any you want to keep first.

14.5 After your subscription ends. If your subscription or trial ends, your data stays in your account so you can come back or take a copy, until you ask us to delete it under 14.4.

14.6 Backups and providers. Deleted data also leaves the backups kept by our database provider when those backups expire, within 7 days. Copies held by sub-processors (for example, our AI provider, email provider or speech-to-text provider) are deleted on their own schedules under their terms with us.

14.7 When we must keep data. If a law requires us to keep some Customer Personal Data, we will keep only what’s required, only for as long as required, protect it under this DPA, and use it for nothing else.

15. Checking our compliance

15.1 Documents first. On request, we will give you the information you reasonably need to confirm we comply with this DPA: this DPA, Annex 2, the sub-processor list, and written answers to a reasonable security questionnaire (once a year, or after a Security Incident). Our main infrastructure providers publish their own independent audit reports; on request we will point you to them.

15.2 Audits. If that information isn’t enough to show compliance, or a regulator requires it, or after a Security Incident affecting your data, you (or an independent auditor you choose who is bound by confidentiality and is not our competitor) may audit our compliance with this DPA. You must give us at least 30 days’ written notice. Audits happen at most once in any 12 months (unless a regulator requires more or there has been a Security Incident), during business hours, in a way that doesn’t disrupt our operations or expose other customers’ data, and at your cost. We may instead arrange an independent assessment at our cost and share the report with you.

15.3 We don’t give access to our sub-processors’ systems. We will pass on what they make available to us.

16. Liability

Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Terms. Liability under the Terms and this DPA together counts toward one combined cap; this DPA does not create a separate or additional cap.

17. Term, changes and ending

17.1 Term. This DPA lasts as long as we process Customer Personal Data for you.

17.2 Changes. We may update this DPA when the law, our services or our sub-processors change. We will give at least 30 days’ notice of material changes by email to the account owner. We will not change this DPA in a way that materially lowers the protection of Customer Personal Data unless the law requires it. Sub-processor changes follow Section 8.

17.3 Ending. If we tell you we can’t comply (Section 5.5), or we don’t fix a material breach of this DPA within 30 days after you tell us about it, you may end your subscription. Section 14 then applies.

17.4 What survives. Sections 5, 6, 10, 12, 14 and 16 continue for as long as we hold any Customer Personal Data.

18. EU, UK and Swiss data protection terms — NOT IN EFFECT

This section is not in effect. Aventide is not yet offered to businesses in the European Economic Area, the United Kingdom or Switzerland. This section takes effect only (a) on the date we publish a notice on this page saying it is in effect, or (b) for your account, if you and we agree in writing that it applies to you. Until then, nothing in this section applies, and Aventide does not promise that it meets the GDPR, UK GDPR or Swiss law.

When in effect, for Customer Personal Data covered by the EU General Data Protection Regulation (“GDPR”), the UK GDPR and Data Protection Act 2018, or the Swiss Federal Act on Data Protection (“FADP”):

18.1 Article 28 terms. Aventide is your processor. Sections 4 to 15 are our commitments under GDPR Article 28(3): we process only on your documented instructions (including about transfers outside the EEA, UK or Switzerland), unless the law requires otherwise and then we tell you first unless the law forbids it; we keep the data confidential; we apply the measures in Annex 2 as required by Article 32; we use sub-processors only under Section 8 with a written contract imposing the same data-protection obligations (Article 28(4)); we help you answer data subject requests and meet your obligations under Articles 32 to 36; we delete or return the data at the end of the services at your choice; and we give you the information needed to show compliance and allow audits under Section 15. We will tell you immediately if we think an instruction infringes data protection law.

18.2 Breach notice. Section 10 applies, and our notice will include the information in GDPR Article 33(3), as far as we have it.

18.3 Transfers out of Europe. Where Customer Personal Data is transferred to Aventide in the United States from the EEA, the UK or Switzerland and no other lawful transfer mechanism applies, the parties agree to the following, which are incorporated by reference:

  • EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914): Module Two (controller to processor) where you are a controller, and Module Three (processor to processor) where you are a processor. Clause 7 (docking) applies. Under Clause 9(a), Option 2 (general written authorization) applies, with the notice period in Section 8.3. The optional wording in Clause 11 does not apply. Under Clause 13, the competent supervisory authority is the one determined by Clause 13(a). Under Clauses 17 and 18, the governing law and courts are those of Ireland. Annexes I and II of the clauses are completed by Annexes 1 and 2 of this DPA; Annex III by the sub-processor page.

  • UK International Data Transfer Addendum to the EU Standard Contractual Clauses (issued by the UK Information Commissioner): Tables 1 to 3 are completed by this DPA and its Annexes, and either party may end the Addendum as allowed by its Section 19.

  • Switzerland: the EU Standard Contractual Clauses apply with the changes the Swiss Federal Data Protection and Information Commissioner (“FDPIC”) requires: the FDPIC is the competent supervisory authority for transfers governed by the FADP, references to the GDPR include the FADP, and data subjects in Switzerland may enforce their rights there.

18.4 Order. If the Standard Contractual Clauses conflict with this DPA, the clauses win. Nothing in this DPA limits the rights of data subjects under the clauses.

Annex 1 — Description of the processing

Parties. Data exporter / controller: the business that holds the Aventide account (contact: the account owner). Data importer / processor: Second Spring Design Inc. d/b/a Aventide, 522 W Riverside Ave, Spokane, WA 99201-0580, United States; contact support@aventide.ai.

Subject matter and nature. Hosting, storing, organizing, displaying, sending and analyzing Customer Personal Data to provide Aventide: client records and client rooms, the client portal, documents and proposals, e-signature, bookings, inquiry and other forms, invoices and payments, the Inbox (email synced from your connected Gmail), meeting notes imported from tools you connect, file storage, and AI features (drafting, summarizing, reading dates from uploads, and client memories).

Purpose. To provide Aventide to you as described in the Terms and this DPA, on your instructions (Section 4).

Duration. For as long as you use Aventide, plus the deletion period in Section 14.

Frequency. Continuous.

People whose data we process (data subjects). Your clients and prospects (including contacts at client companies); people who use your client portal; people who sign contracts or accept proposals you send; people who book time with you; people who fill in your inquiry and other forms; people you invoice; people who email the Gmail accounts you connect; people who take part in meetings whose notes you import; other people named in your content; and your own team members, as they appear in your content and in record histories.

Kinds of personal data

Data subject

Data

Clients and contacts

Name, company, email, website, photo, notes, next steps, project and pipeline details

Clients (AI memories)

Preferences, context and relationship notes the assistant saves (visible on the client’s card, deletable); commitments and pricing it proposes for your approval

Portal users

Email, sign-in link and session records, which documents they viewed or downloaded

Contract signers

Name, email, typed signature, IP address, browser and device information, timestamps for viewing, consenting, signing or declining, the signed document and its SHA-256 fingerprint, any decline note

Proposal accepters

Typed name, a hashed IP address, browser information

Booking guests

Name, email, notes, time zone, booking details

Inquiry form submitters

Name, email, phone, message, service type, date, budget, any custom answer, marketing-consent wording and version, a hashed IP address, browser information, referring page

Form respondents

Their answers, browser information

Invoice payers

Name, email, amounts, payment status (card and bank details stay with Stripe)

Email correspondents

Sender name and email, subject, a short excerpt, draft replies (full message bodies are fetched from Gmail when you open a thread, and are not stored, except in an assistant conversation where you asked about the message)

Meeting participants

Transcripts, speaker names, AI summaries

Anyone in your files

Whatever your uploaded files, voice notes and documents contain

Your team members

Names and emails recorded in contract and record histories

Imported records

Clients, projects and payment records you import from HoneyBook

Sensitive data. Aventide does not need sensitive personal data, and you should not put it in unless you need to. Aventide is not for health information covered by HIPAA; we don’t sign business associate agreements. Do not use Aventide to collect information directly from children under 13. Identity numbers you keep locked in the Vault (such as tax IDs) are kept out of Aventide’s AI assistant features; see Annex 2.

Sub-processors. See aventide.ai/legal/subprocessors.

Annex 2 — Security measures

This is what Aventide does today. We will update it as we add measures.

Sign-in and access

  • Sign-in runs through Outseta. Aventide never stores passwords.

  • Our servers check the sign-in token on every request (RS256 signatures checked against the provider’s published keys).

  • Every request is tied to one business on the server, and we check that the business belongs to the signed-in person’s account. A request for another business’s data is refused.

  • The database has row-level security turned on. Browsers cannot write to the database directly; all changes go through our server code. Browsers can read only a few tables for live updates, and only rows for their own account.

  • The account owner can limit the Vault and Smart Compliance screens to the owner only.

  • Multi-factor authentication is on for every admin account at Vercel, Supabase, Cloudflare, GitHub, Outseta and Stripe.

Encryption

  • Data travels over encrypted connections (TLS).

  • Our database and file storage providers encrypt stored data at rest.

  • Connection tokens for services you connect are kept in an encrypted secret store (Supabase Vault), not in ordinary tables. Some other connection secrets (for example, meeting-note tool API keys and Slack tokens) are also encrypted with AES-256-GCM, using a key kept outside the database.

Files

  • Uploaded files are kept in private storage and served through short-lived signed links. Two exceptions: your logo, and some images you upload for social posts, are stored at public web addresses so your branded pages and social apps can load them.

Links we send to your clients

  • Signing, portal, booking and payment links use long random tokens. Contract signing links expire; client portal sign-in links expire after 7 days and portal sessions after 90 days, and session tokens are stored hashed.

  • Your clients sign in to the portal by typing their email. The sign-in link goes only to an address on that client’s access list.

  • Contract signers are authenticated by email-link authentication: they reach the document through a unique link sent to their email address.

  • Shared and portal pages can’t be embedded in other websites.

Abuse protection

  • Cloudflare Turnstile protects sign-up and log-in, and booking, inquiry and form submissions.

  • Rate limits protect public forms. IP addresses used for rate limiting are stored only as keyed hashes.

  • Messages from Stripe, Outseta, QuickBooks and our email provider are checked for a valid signature before we act on them.

AI safeguards

  • The assistant works only inside the signed-in business’s data.

  • Text from emails and other outside content is passed to the AI as information to read, not as instructions to follow.

  • Traces of AI runs kept at our hosting provider have their inputs and outputs removed.

  • Items you lock in the Vault are kept out of Aventide’s AI assistant features. Locking is an access setting, not extra encryption: people with infrastructure access could still reach locked items, and we access them only for the reasons in Section 6.2. When you scan a document with Smart Compliance, the file is sent to our AI provider to read dates and identifiers.

  • Our AI provider, Anthropic, does not train its models on data sent through its commercial API, which is how our requests reach it (directly or through Vercel’s AI Gateway). Aventide does not train AI models on Customer Personal Data.

Records you can rely on

  • When a contract is sent, Aventide freezes a copy, and the signer reviews that exact copy. The contract’s history is append-only, and database rules block changes to a sent or signed contract. Signed documents carry a SHA-256 fingerprint.

  • Invoice and document histories are append-only.

How we change the software

  • Every change must pass our automated test suite, lint checks and a clean production build before it can merge.

  • Database changes are kept as migration files and tested against a fresh database on every pull request. New tables are closed to browsers by default.

What we don’t have yet

  • Aventide is not SOC 2 certified, and we haven’t had an independent penetration test or run a bug bounty. Our main infrastructure providers (Vercel, Supabase, Cloudflare and Anthropic) publish their own independent audit reports.

Incidents

  • We investigate and contain security incidents and notify you under Section 10.

Annex 3 — Sub-processors

See aventide.ai/legal/subprocessors.

Contact. Questions about this DPA: support@aventide.ai · Second Spring Design Inc. d/b/a Aventide, 522 W Riverside Ave, Spokane, WA 99201-0580.

Legal

Data Processing Addendum

Last updated: October 7, 2026 · Version 1.0

This Data Processing Addendum (“DPA”) explains how Aventide handles the personal data you put into Aventide about your clients and contacts. It is part of the Aventide Terms of Service.

The short version

  • Your clients’ data is yours. When you put your clients’ details into Aventide, we handle that data for you, on your instructions. In privacy-law terms, you are the “business” or “controller” and we are your “service provider” or “processor”.

  • We use it only to run Aventide for you. We don’t sell it, share it for advertising, or use it to train AI models.

  • We tell you who helps us. Our list of sub-processors is at aventide.ai/legal/subprocessors. We email the account owner at least 15 days before we add one, and you can object.

  • We tell you fast if something goes wrong. If a security incident affects your clients’ data, we tell you without undue delay: we aim for 24 hours, and always within 72 hours of becoming aware of it.

  • You can get your data out, and have it deleted. Email us and we delete it within 30 days.

  • No signature needed. This DPA applies automatically when you use Aventide.

1. When this DPA applies

1.1 It’s part of the Terms. This DPA is incorporated into, and forms part of, the Aventide Terms of Service (the “Terms”) between you and Second Spring Design Inc., a Delaware corporation doing business as Aventide (“Aventide”, “we”, “us”).

1.2 No signature needed. You accept this DPA when you accept the Terms. It takes effect when you first use Aventide and lasts as long as we process Customer Personal Data for you, including during the deletion period in Section 14.

1.3 Who “you” are. “You” means the business that holds the Aventide account. The account owner accepts this DPA for that business.

1.4 If documents conflict. For anything about Customer Personal Data, this DPA wins over the Terms. Everything else in the Terms still applies, including the limits on liability (Section 16).

2. Words we use

  • Customer Data: everything you and your team put into Aventide, connect to it, or create with it.

  • Customer Personal Data: the personal data in Customer Data that we process on your behalf. It does not include Account Data.

  • Account Data: what we need to run your account with us: the names and email addresses of you and your teammates, sign-in, plan and billing details, support conversations, and records of how the product is used (for example, which feature was opened). We handle Account Data as an independent business under our Privacy Policy. If you share your clients’ personal data with us in a support request, we treat it as Customer Personal Data.

  • Privacy Laws: the US state privacy laws that apply to Customer Personal Data, including the California Consumer Privacy Act as amended by the California Privacy Rights Act and its regulations (“CCPA”), and the comprehensive privacy laws of other US states (for example Virginia, Colorado, Connecticut, Utah, Texas and Oregon).

  • Sub-processor: a company we engage that processes Customer Personal Data for us.

  • Security Incident: a breach of security that leads to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to, Customer Personal Data, whether on our systems or a sub-processor’s. It does not include unsuccessful attempts that don’t compromise the data, such as blocked log-in attempts, pings or port scans.

  • Services you connect: outside services you choose to link to Aventide, such as your Google account, your Stripe account, QuickBooks, Zoom, a meeting-note tool or a social media account. They are listed on the sub-processor page under “Services you connect”.

Other terms (like “business”, “service provider”, “controller”, “processor”, “consumer”, “personal data”, “sell” and “share”) mean what the applicable Privacy Law says they mean.

3. Roles

3.1 You are in charge of your clients’ data. For Customer Personal Data, you are the business/controller and Aventide is your service provider/processor (or, under the CCPA, a “service provider”).

3.2 Your account with us is different. For Account Data, Aventide decides how it’s used and is responsible for it under our Privacy Policy.

3.3 Services you connect are your choice. When you connect a service, you decide to send data to it or bring data from it. That service handles the data under its own terms with you. It is not our sub-processor. Sending data to a service you connected, or to a destination you set up (for example, a webhook address on your inquiry form), is one of your instructions under Section 4.

3.4 What you’re responsible for. You are responsible for:

  • having the right to put your clients’ personal data into Aventide and to have us process it as this DPA describes;

  • giving your clients any notices, and getting any consents, the law requires. For example: telling them you use online tools (including AI) to manage your work with them, and getting marketing consent on your inquiry forms where it’s needed. If you record or transcribe calls, or bring in their transcripts, it also means telling the people on them and getting their consent where the law requires;

  • the instructions you give us and the content you and your team send through Aventide;

  • not putting in data Aventide isn’t built for (see “Sensitive data” in Annex 1);

  • keeping your team’s sign-in details safe and removing teammates who should no longer have access.

4. We follow your instructions

4.1 What counts as your instructions. We process Customer Personal Data only on your documented instructions. Your instructions are: the Terms, this DPA, your settings, and the things you and your team do in Aventide (including what you ask Aventide’s assistant to do). Anything else must be agreed by you and us in writing (email is fine).

4.2 This includes Aventide’s AI features. When you use them, you instruct us to send Customer Personal Data to our AI sub-processor to: answer questions, read the email synced to your Inbox, draft emails, replies, messages, proposals and contracts, summarize meeting notes, read dates from documents you upload, and keep “memories” about your business and your clients so the assistant can help you better. Some client memories (preferences, context, relationship notes) are saved automatically; you can see them on the client’s card and delete them. Others (commitments, pricing and Business Hub facts) are only proposed, and are saved only if you approve them.

4.3 Sending and publishing. Aventide’s assistant asks for a person’s approval before it sends email or messages to your clients, sends contracts or invoices, or publishes on your behalf. Messages you set up to go automatically (such as booking confirmations, or a deposit invoice that a contract is set to send when it’s signed) are sent because you set up that feature.

4.4 If an instruction looks unlawful. We will tell you if we believe an instruction breaks a Privacy Law. We may decline to follow it until you change it.

4.5 What we do with Customer Personal Data — and nothing else. We use it only to: (a) provide, maintain and support Aventide for you, including the features you use; (b) keep Aventide and your data secure, and detect and prevent fraud, abuse and illegal activity; (c) find and fix errors; (d) comply with the law; and (e) improve Aventide’s quality and safety, in the ways the CCPA allows a service provider to — never to build a profile of a person for anyone else, never to provide services to another customer, and never to train AI models.

5. US state privacy law terms (including CCPA/CPRA)

5.1 Business purpose. You disclose Customer Personal Data to us only for the limited and specified business purposes in Section 4.5 and Annex 1.

5.2 We will not:

  • sell or share Customer Personal Data (including “sharing” for cross-context behavioral advertising), or use it for targeted advertising;

  • retain, use or disclose it for any purpose other than the business purposes in this DPA, including any commercial purpose of our own, except as the CCPA allows;

  • retain, use or disclose it outside the direct business relationship between you and us;

  • combine it with personal data we receive from someone else or collect on our own, except as the CCPA allows a service provider to (for example, to detect security incidents or prevent fraud).

5.3 Same protection. We will comply with the Privacy Laws that apply to us as your service provider/processor, and give Customer Personal Data the same level of privacy protection those laws require of you.

5.4 Your right to check, stop and fix. You may take reasonable and appropriate steps to make sure we use Customer Personal Data in line with your obligations (Section 15 explains how). If you reasonably believe we are using it without authorization, tell us; we will work with you to stop and remediate the unauthorized use.

5.5 If we can’t comply. If we decide we can no longer meet our obligations under the Privacy Laws or this DPA, we will tell you promptly, and no later than 5 business days after we decide. You may then stop sending us the data and end the affected processing (Section 17.3).

5.6 De-identified data. If we de-identify Customer Personal Data, we will take reasonable measures to keep it de-identified, we publicly commit here not to try to re-identify it, and we will require anyone we give it to to make the same commitments.

5.7 Certification. We certify that we understand the restrictions in this Section 5 and will comply with them.

5.8 Other state laws. Where a state law (such as Virginia, Colorado, Connecticut, Utah, Texas or Oregon) treats us as your “processor”, Sections 4 to 15 are our processor commitments under that law: we follow your instructions, keep the data confidential, use sub-processors only under written contracts with notice and a chance to object, help you with requests and assessments, delete or return data at your direction, and give you the information you need to show compliance.

6. Our people

6.1 Everyone at Aventide who can access Customer Personal Data is bound by a duty of confidentiality (by contract or professional duty) that continues after their work with us ends. Anyone we add later will sign a confidentiality agreement before they get access.

6.2 We limit access to the people who need it to run, support or secure Aventide. Today, that is the two founders. We access Customer Personal Data only to provide support you ask for, fix problems, keep Aventide secure, or comply with the law.

7. Security

7.1 We use the technical and organizational measures in Annex 2 to protect Customer Personal Data.

7.2 We may change these measures as Aventide and the threats change, but we will not reduce the overall level of protection for Customer Personal Data.

7.3 Aventide is not itself SOC 2 certified. Annex 2 says plainly what we have and what we don’t.

8. Sub-processors

8.1 You authorize our sub-processors. You give us general authorization to use the sub-processors listed at aventide.ai/legal/subprocessors, and new ones added under this Section 8.

8.2 Same protection, our responsibility. Each sub-processor is bound by a written contract that protects Customer Personal Data at least as well as this DPA does, to the extent that fits the service it provides. We remain responsible to you for our sub-processors’ work, subject to Section 16.

8.3 Notice of changes. Before a new sub-processor starts processing Customer Personal Data, we will (a) update the sub-processor page and (b) email the account owner at least 15 days in advance. If we need to replace a sub-processor urgently to keep Aventide secure or running, we will tell you as soon as we can, and you keep your right to object.

8.4 Optional features. Some sub-processors only handle data if you or a teammate turn on a feature (for example, Sidekick on WhatsApp). They are marked “optional” on the page. For a new optional feature, we list the sub-processor before the feature launches, and turning the feature on is your authorization. Some messaging apps (today, Telegram) offer only their standard terms, not a data processing agreement, so Section 8.2 can’t fully apply to them. The page says which ones. If that matters to you, don’t turn that channel on.

8.5 Your right to object. You may object to a new sub-processor on reasonable data-protection grounds by emailing support@aventide.ai within 15 days of our notice. We will try in good faith to address it, for example by suggesting a setting or a way to use Aventide without that sub-processor. If we can’t resolve it within 30 days, you may end your subscription (or stop using the affected feature) by telling us in writing. If you end a prepaid annual subscription this way, we will refund the prepaid fees for the unused part of the term.

9. Requests from your clients

9.1 Tools in Aventide. You can view, correct and delete much of your clients’ data yourself. For example: edit a client record, delete a client note or a saved client memory, delete a meeting note, or remove a contact’s access to your client portal. Some deletions take effect immediately (such as a meeting note). Others hide the item first (such as a client record) and keep it in our database.

9.2 We help with the rest. If you can’t fully answer a request from one of your clients (to access, correct, delete, or receive a copy of their data, or to opt out) with the tools in Aventide, email support@aventide.ai. We will help you within the time the law gives you. To have one person’s data permanently erased, email us and we will do it within 30 days. One exception: entries in signed contracts and their audit trails, and in invoice and document histories, are locked as a record of what happened. They can be removed only by deleting the whole business (Section 14.4). Privacy laws generally let you keep records like these (for example, to complete a transaction or defend a legal claim); if you need them gone anyway, tell us and we’ll work it out with you.

9.3 Requests that reach us directly. If one of your clients contacts us directly about Customer Personal Data, we will pass the request to you promptly, and within 5 business days. We won’t answer it ourselves, except to tell them we’ve passed it to you, unless you ask us to or the law requires it.

10. Security incidents

10.1 Notice within 72 hours. If we become aware of a Security Incident, we will tell you without undue delay. We aim to tell you within 24 hours, and will tell you no later than 72 hours after becoming aware of it. “Becoming aware” means we know, or reasonably believe, that a Security Incident has happened.

10.2 How and what. We will email the account owner (and any security contact you send us at support@aventide.ai). We will tell you what we know at the time and update you as we learn more, including: what happened; the kinds of data and roughly how many people are affected; the likely consequences; what we have done and will do about it; and who to contact at Aventide.

10.3 We act fast. We will promptly take reasonable steps to contain and investigate the Security Incident and reduce its harm.

10.4 Notifying people. You decide whether to notify your clients or regulators. We will give you the information we reasonably can to help you do it. We won’t notify your clients or regulators about Customer Personal Data on your behalf unless you ask us to or the law requires it.

10.5 Telling you about a Security Incident is not an admission of fault.

11. Other help we give you

11.1 Assessments. If you need to do a data protection assessment or risk assessment under a Privacy Law, we will give you the information about our processing that is reasonably available to us (this DPA, Annex 2, and the sub-processor page are a good start).

11.2 Regulators. If a regulator asks you about our processing of Customer Personal Data, we will reasonably cooperate.

12. Requests from governments and courts

If a government agency or court demands Customer Personal Data from us, we will try to redirect it to you. We will tell you promptly before we disclose anything, unless the law forbids us to. We will disclose only what we are legally required to.

13. Where data is processed

13.1 We run Aventide in the United States and store Customer Personal Data in our database in the United States. Uploaded files are stored with Cloudflare R2.

13.2 Some sub-processors may process data in other countries. For example, Cloudflare runs a global network that converts and delivers files, and the messaging apps you can turn on for Sidekick (Telegram, WhatsApp and Slack) run their own global services. The sub-processor page says where each one processes data, where we know.

14. Return and deletion — Version A (current)

14.1 While your account is open. We keep Customer Personal Data until you delete it in Aventide or ask us to delete it. Some data is cleared automatically. For example, email synced from Gmail into your Inbox is removed 90 days after it arrives if it’s bulk “FYI” mail, and 180 days after you last touched it if you’ve resolved or dismissed it. Mail that is still open, snoozed or waiting on a draft is not removed automatically.

14.2 Deleting in the app. Some in-app deletions remove data right away. Others archive it so it can be restored: deleting a business archives it, and deleting a client hides the client record. Archived data stays in our database until it is permanently deleted under 14.4.

14.3 Getting a copy. You can download signed contracts and other documents one by one in Aventide. For a full copy of your data (including clients, invoices, bookings and form responses), the account owner can email support@aventide.ai and we will send it in a common format (JSON or CSV) within 30 days.

14.4 Permanent deletion on request. The account owner can ask us to permanently delete a business, one person’s data, or your whole account by emailing support@aventide.ai from the owner’s email address. We will do it within 30 days and confirm in writing. This includes signed contracts and their audit trails, so download any you want to keep first.

14.5 After your subscription ends. If your subscription or trial ends, your data stays in your account so you can come back or take a copy, until you ask us to delete it under 14.4.

14.6 Backups and providers. Deleted data also leaves the backups kept by our database provider when those backups expire, within 7 days. Copies held by sub-processors (for example, our AI provider, email provider or speech-to-text provider) are deleted on their own schedules under their terms with us.

14.7 When we must keep data. If a law requires us to keep some Customer Personal Data, we will keep only what’s required, only for as long as required, protect it under this DPA, and use it for nothing else.

15. Checking our compliance

15.1 Documents first. On request, we will give you the information you reasonably need to confirm we comply with this DPA: this DPA, Annex 2, the sub-processor list, and written answers to a reasonable security questionnaire (once a year, or after a Security Incident). Our main infrastructure providers publish their own independent audit reports; on request we will point you to them.

15.2 Audits. If that information isn’t enough to show compliance, or a regulator requires it, or after a Security Incident affecting your data, you (or an independent auditor you choose who is bound by confidentiality and is not our competitor) may audit our compliance with this DPA. You must give us at least 30 days’ written notice. Audits happen at most once in any 12 months (unless a regulator requires more or there has been a Security Incident), during business hours, in a way that doesn’t disrupt our operations or expose other customers’ data, and at your cost. We may instead arrange an independent assessment at our cost and share the report with you.

15.3 We don’t give access to our sub-processors’ systems. We will pass on what they make available to us.

16. Liability

Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Terms. Liability under the Terms and this DPA together counts toward one combined cap; this DPA does not create a separate or additional cap.

17. Term, changes and ending

17.1 Term. This DPA lasts as long as we process Customer Personal Data for you.

17.2 Changes. We may update this DPA when the law, our services or our sub-processors change. We will give at least 30 days’ notice of material changes by email to the account owner. We will not change this DPA in a way that materially lowers the protection of Customer Personal Data unless the law requires it. Sub-processor changes follow Section 8.

17.3 Ending. If we tell you we can’t comply (Section 5.5), or we don’t fix a material breach of this DPA within 30 days after you tell us about it, you may end your subscription. Section 14 then applies.

17.4 What survives. Sections 5, 6, 10, 12, 14 and 16 continue for as long as we hold any Customer Personal Data.

18. EU, UK and Swiss data protection terms — NOT IN EFFECT

This section is not in effect. Aventide is not yet offered to businesses in the European Economic Area, the United Kingdom or Switzerland. This section takes effect only (a) on the date we publish a notice on this page saying it is in effect, or (b) for your account, if you and we agree in writing that it applies to you. Until then, nothing in this section applies, and Aventide does not promise that it meets the GDPR, UK GDPR or Swiss law.

When in effect, for Customer Personal Data covered by the EU General Data Protection Regulation (“GDPR”), the UK GDPR and Data Protection Act 2018, or the Swiss Federal Act on Data Protection (“FADP”):

18.1 Article 28 terms. Aventide is your processor. Sections 4 to 15 are our commitments under GDPR Article 28(3): we process only on your documented instructions (including about transfers outside the EEA, UK or Switzerland), unless the law requires otherwise and then we tell you first unless the law forbids it; we keep the data confidential; we apply the measures in Annex 2 as required by Article 32; we use sub-processors only under Section 8 with a written contract imposing the same data-protection obligations (Article 28(4)); we help you answer data subject requests and meet your obligations under Articles 32 to 36; we delete or return the data at the end of the services at your choice; and we give you the information needed to show compliance and allow audits under Section 15. We will tell you immediately if we think an instruction infringes data protection law.

18.2 Breach notice. Section 10 applies, and our notice will include the information in GDPR Article 33(3), as far as we have it.

18.3 Transfers out of Europe. Where Customer Personal Data is transferred to Aventide in the United States from the EEA, the UK or Switzerland and no other lawful transfer mechanism applies, the parties agree to the following, which are incorporated by reference:

  • EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914): Module Two (controller to processor) where you are a controller, and Module Three (processor to processor) where you are a processor. Clause 7 (docking) applies. Under Clause 9(a), Option 2 (general written authorization) applies, with the notice period in Section 8.3. The optional wording in Clause 11 does not apply. Under Clause 13, the competent supervisory authority is the one determined by Clause 13(a). Under Clauses 17 and 18, the governing law and courts are those of Ireland. Annexes I and II of the clauses are completed by Annexes 1 and 2 of this DPA; Annex III by the sub-processor page.

  • UK International Data Transfer Addendum to the EU Standard Contractual Clauses (issued by the UK Information Commissioner): Tables 1 to 3 are completed by this DPA and its Annexes, and either party may end the Addendum as allowed by its Section 19.

  • Switzerland: the EU Standard Contractual Clauses apply with the changes the Swiss Federal Data Protection and Information Commissioner (“FDPIC”) requires: the FDPIC is the competent supervisory authority for transfers governed by the FADP, references to the GDPR include the FADP, and data subjects in Switzerland may enforce their rights there.

18.4 Order. If the Standard Contractual Clauses conflict with this DPA, the clauses win. Nothing in this DPA limits the rights of data subjects under the clauses.

Annex 1 — Description of the processing

Parties. Data exporter / controller: the business that holds the Aventide account (contact: the account owner). Data importer / processor: Second Spring Design Inc. d/b/a Aventide, 522 W Riverside Ave, Spokane, WA 99201-0580, United States; contact support@aventide.ai.

Subject matter and nature. Hosting, storing, organizing, displaying, sending and analyzing Customer Personal Data to provide Aventide: client records and client rooms, the client portal, documents and proposals, e-signature, bookings, inquiry and other forms, invoices and payments, the Inbox (email synced from your connected Gmail), meeting notes imported from tools you connect, file storage, and AI features (drafting, summarizing, reading dates from uploads, and client memories).

Purpose. To provide Aventide to you as described in the Terms and this DPA, on your instructions (Section 4).

Duration. For as long as you use Aventide, plus the deletion period in Section 14.

Frequency. Continuous.

People whose data we process (data subjects). Your clients and prospects (including contacts at client companies); people who use your client portal; people who sign contracts or accept proposals you send; people who book time with you; people who fill in your inquiry and other forms; people you invoice; people who email the Gmail accounts you connect; people who take part in meetings whose notes you import; other people named in your content; and your own team members, as they appear in your content and in record histories.

Kinds of personal data

Data subject

Data

Clients and contacts

Name, company, email, website, photo, notes, next steps, project and pipeline details

Clients (AI memories)

Preferences, context and relationship notes the assistant saves (visible on the client’s card, deletable); commitments and pricing it proposes for your approval

Portal users

Email, sign-in link and session records, which documents they viewed or downloaded

Contract signers

Name, email, typed signature, IP address, browser and device information, timestamps for viewing, consenting, signing or declining, the signed document and its SHA-256 fingerprint, any decline note

Proposal accepters

Typed name, a hashed IP address, browser information

Booking guests

Name, email, notes, time zone, booking details

Inquiry form submitters

Name, email, phone, message, service type, date, budget, any custom answer, marketing-consent wording and version, a hashed IP address, browser information, referring page

Form respondents

Their answers, browser information

Invoice payers

Name, email, amounts, payment status (card and bank details stay with Stripe)

Email correspondents

Sender name and email, subject, a short excerpt, draft replies (full message bodies are fetched from Gmail when you open a thread, and are not stored, except in an assistant conversation where you asked about the message)

Meeting participants

Transcripts, speaker names, AI summaries

Anyone in your files

Whatever your uploaded files, voice notes and documents contain

Your team members

Names and emails recorded in contract and record histories

Imported records

Clients, projects and payment records you import from HoneyBook

Sensitive data. Aventide does not need sensitive personal data, and you should not put it in unless you need to. Aventide is not for health information covered by HIPAA; we don’t sign business associate agreements. Do not use Aventide to collect information directly from children under 13. Identity numbers you keep locked in the Vault (such as tax IDs) are kept out of Aventide’s AI assistant features; see Annex 2.

Sub-processors. See aventide.ai/legal/subprocessors.

Annex 2 — Security measures

This is what Aventide does today. We will update it as we add measures.

Sign-in and access

  • Sign-in runs through Outseta. Aventide never stores passwords.

  • Our servers check the sign-in token on every request (RS256 signatures checked against the provider’s published keys).

  • Every request is tied to one business on the server, and we check that the business belongs to the signed-in person’s account. A request for another business’s data is refused.

  • The database has row-level security turned on. Browsers cannot write to the database directly; all changes go through our server code. Browsers can read only a few tables for live updates, and only rows for their own account.

  • The account owner can limit the Vault and Smart Compliance screens to the owner only.

  • Multi-factor authentication is on for every admin account at Vercel, Supabase, Cloudflare, GitHub, Outseta and Stripe.

Encryption

  • Data travels over encrypted connections (TLS).

  • Our database and file storage providers encrypt stored data at rest.

  • Connection tokens for services you connect are kept in an encrypted secret store (Supabase Vault), not in ordinary tables. Some other connection secrets (for example, meeting-note tool API keys and Slack tokens) are also encrypted with AES-256-GCM, using a key kept outside the database.

Files

  • Uploaded files are kept in private storage and served through short-lived signed links. Two exceptions: your logo, and some images you upload for social posts, are stored at public web addresses so your branded pages and social apps can load them.

Links we send to your clients

  • Signing, portal, booking and payment links use long random tokens. Contract signing links expire; client portal sign-in links expire after 7 days and portal sessions after 90 days, and session tokens are stored hashed.

  • Your clients sign in to the portal by typing their email. The sign-in link goes only to an address on that client’s access list.

  • Contract signers are authenticated by email-link authentication: they reach the document through a unique link sent to their email address.

  • Shared and portal pages can’t be embedded in other websites.

Abuse protection

  • Cloudflare Turnstile protects sign-up and log-in, and booking, inquiry and form submissions.

  • Rate limits protect public forms. IP addresses used for rate limiting are stored only as keyed hashes.

  • Messages from Stripe, Outseta, QuickBooks and our email provider are checked for a valid signature before we act on them.

AI safeguards

  • The assistant works only inside the signed-in business’s data.

  • Text from emails and other outside content is passed to the AI as information to read, not as instructions to follow.

  • Traces of AI runs kept at our hosting provider have their inputs and outputs removed.

  • Items you lock in the Vault are kept out of Aventide’s AI assistant features. Locking is an access setting, not extra encryption: people with infrastructure access could still reach locked items, and we access them only for the reasons in Section 6.2. When you scan a document with Smart Compliance, the file is sent to our AI provider to read dates and identifiers.

  • Our AI provider, Anthropic, does not train its models on data sent through its commercial API, which is how our requests reach it (directly or through Vercel’s AI Gateway). Aventide does not train AI models on Customer Personal Data.

Records you can rely on

  • When a contract is sent, Aventide freezes a copy, and the signer reviews that exact copy. The contract’s history is append-only, and database rules block changes to a sent or signed contract. Signed documents carry a SHA-256 fingerprint.

  • Invoice and document histories are append-only.

How we change the software

  • Every change must pass our automated test suite, lint checks and a clean production build before it can merge.

  • Database changes are kept as migration files and tested against a fresh database on every pull request. New tables are closed to browsers by default.

What we don’t have yet

  • Aventide is not SOC 2 certified, and we haven’t had an independent penetration test or run a bug bounty. Our main infrastructure providers (Vercel, Supabase, Cloudflare and Anthropic) publish their own independent audit reports.

Incidents

  • We investigate and contain security incidents and notify you under Section 10.

Annex 3 — Sub-processors

See aventide.ai/legal/subprocessors.

Contact. Questions about this DPA: support@aventide.ai · Second Spring Design Inc. d/b/a Aventide, 522 W Riverside Ave, Spokane, WA 99201-0580.

Legal

Data Processing Addendum

Last updated: October 7, 2026 · Version 1.0

This Data Processing Addendum (“DPA”) explains how Aventide handles the personal data you put into Aventide about your clients and contacts. It is part of the Aventide Terms of Service.

The short version

  • Your clients’ data is yours. When you put your clients’ details into Aventide, we handle that data for you, on your instructions. In privacy-law terms, you are the “business” or “controller” and we are your “service provider” or “processor”.

  • We use it only to run Aventide for you. We don’t sell it, share it for advertising, or use it to train AI models.

  • We tell you who helps us. Our list of sub-processors is at aventide.ai/legal/subprocessors. We email the account owner at least 15 days before we add one, and you can object.

  • We tell you fast if something goes wrong. If a security incident affects your clients’ data, we tell you without undue delay: we aim for 24 hours, and always within 72 hours of becoming aware of it.

  • You can get your data out, and have it deleted. Email us and we delete it within 30 days.

  • No signature needed. This DPA applies automatically when you use Aventide.

1. When this DPA applies

1.1 It’s part of the Terms. This DPA is incorporated into, and forms part of, the Aventide Terms of Service (the “Terms”) between you and Second Spring Design Inc., a Delaware corporation doing business as Aventide (“Aventide”, “we”, “us”).

1.2 No signature needed. You accept this DPA when you accept the Terms. It takes effect when you first use Aventide and lasts as long as we process Customer Personal Data for you, including during the deletion period in Section 14.

1.3 Who “you” are. “You” means the business that holds the Aventide account. The account owner accepts this DPA for that business.

1.4 If documents conflict. For anything about Customer Personal Data, this DPA wins over the Terms. Everything else in the Terms still applies, including the limits on liability (Section 16).

2. Words we use

  • Customer Data: everything you and your team put into Aventide, connect to it, or create with it.

  • Customer Personal Data: the personal data in Customer Data that we process on your behalf. It does not include Account Data.

  • Account Data: what we need to run your account with us: the names and email addresses of you and your teammates, sign-in, plan and billing details, support conversations, and records of how the product is used (for example, which feature was opened). We handle Account Data as an independent business under our Privacy Policy. If you share your clients’ personal data with us in a support request, we treat it as Customer Personal Data.

  • Privacy Laws: the US state privacy laws that apply to Customer Personal Data, including the California Consumer Privacy Act as amended by the California Privacy Rights Act and its regulations (“CCPA”), and the comprehensive privacy laws of other US states (for example Virginia, Colorado, Connecticut, Utah, Texas and Oregon).

  • Sub-processor: a company we engage that processes Customer Personal Data for us.

  • Security Incident: a breach of security that leads to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to, Customer Personal Data, whether on our systems or a sub-processor’s. It does not include unsuccessful attempts that don’t compromise the data, such as blocked log-in attempts, pings or port scans.

  • Services you connect: outside services you choose to link to Aventide, such as your Google account, your Stripe account, QuickBooks, Zoom, a meeting-note tool or a social media account. They are listed on the sub-processor page under “Services you connect”.

Other terms (like “business”, “service provider”, “controller”, “processor”, “consumer”, “personal data”, “sell” and “share”) mean what the applicable Privacy Law says they mean.

3. Roles

3.1 You are in charge of your clients’ data. For Customer Personal Data, you are the business/controller and Aventide is your service provider/processor (or, under the CCPA, a “service provider”).

3.2 Your account with us is different. For Account Data, Aventide decides how it’s used and is responsible for it under our Privacy Policy.

3.3 Services you connect are your choice. When you connect a service, you decide to send data to it or bring data from it. That service handles the data under its own terms with you. It is not our sub-processor. Sending data to a service you connected, or to a destination you set up (for example, a webhook address on your inquiry form), is one of your instructions under Section 4.

3.4 What you’re responsible for. You are responsible for:

  • having the right to put your clients’ personal data into Aventide and to have us process it as this DPA describes;

  • giving your clients any notices, and getting any consents, the law requires. For example: telling them you use online tools (including AI) to manage your work with them, and getting marketing consent on your inquiry forms where it’s needed. If you record or transcribe calls, or bring in their transcripts, it also means telling the people on them and getting their consent where the law requires;

  • the instructions you give us and the content you and your team send through Aventide;

  • not putting in data Aventide isn’t built for (see “Sensitive data” in Annex 1);

  • keeping your team’s sign-in details safe and removing teammates who should no longer have access.

4. We follow your instructions

4.1 What counts as your instructions. We process Customer Personal Data only on your documented instructions. Your instructions are: the Terms, this DPA, your settings, and the things you and your team do in Aventide (including what you ask Aventide’s assistant to do). Anything else must be agreed by you and us in writing (email is fine).

4.2 This includes Aventide’s AI features. When you use them, you instruct us to send Customer Personal Data to our AI sub-processor to: answer questions, read the email synced to your Inbox, draft emails, replies, messages, proposals and contracts, summarize meeting notes, read dates from documents you upload, and keep “memories” about your business and your clients so the assistant can help you better. Some client memories (preferences, context, relationship notes) are saved automatically; you can see them on the client’s card and delete them. Others (commitments, pricing and Business Hub facts) are only proposed, and are saved only if you approve them.

4.3 Sending and publishing. Aventide’s assistant asks for a person’s approval before it sends email or messages to your clients, sends contracts or invoices, or publishes on your behalf. Messages you set up to go automatically (such as booking confirmations, or a deposit invoice that a contract is set to send when it’s signed) are sent because you set up that feature.

4.4 If an instruction looks unlawful. We will tell you if we believe an instruction breaks a Privacy Law. We may decline to follow it until you change it.

4.5 What we do with Customer Personal Data — and nothing else. We use it only to: (a) provide, maintain and support Aventide for you, including the features you use; (b) keep Aventide and your data secure, and detect and prevent fraud, abuse and illegal activity; (c) find and fix errors; (d) comply with the law; and (e) improve Aventide’s quality and safety, in the ways the CCPA allows a service provider to — never to build a profile of a person for anyone else, never to provide services to another customer, and never to train AI models.

5. US state privacy law terms (including CCPA/CPRA)

5.1 Business purpose. You disclose Customer Personal Data to us only for the limited and specified business purposes in Section 4.5 and Annex 1.

5.2 We will not:

  • sell or share Customer Personal Data (including “sharing” for cross-context behavioral advertising), or use it for targeted advertising;

  • retain, use or disclose it for any purpose other than the business purposes in this DPA, including any commercial purpose of our own, except as the CCPA allows;

  • retain, use or disclose it outside the direct business relationship between you and us;

  • combine it with personal data we receive from someone else or collect on our own, except as the CCPA allows a service provider to (for example, to detect security incidents or prevent fraud).

5.3 Same protection. We will comply with the Privacy Laws that apply to us as your service provider/processor, and give Customer Personal Data the same level of privacy protection those laws require of you.

5.4 Your right to check, stop and fix. You may take reasonable and appropriate steps to make sure we use Customer Personal Data in line with your obligations (Section 15 explains how). If you reasonably believe we are using it without authorization, tell us; we will work with you to stop and remediate the unauthorized use.

5.5 If we can’t comply. If we decide we can no longer meet our obligations under the Privacy Laws or this DPA, we will tell you promptly, and no later than 5 business days after we decide. You may then stop sending us the data and end the affected processing (Section 17.3).

5.6 De-identified data. If we de-identify Customer Personal Data, we will take reasonable measures to keep it de-identified, we publicly commit here not to try to re-identify it, and we will require anyone we give it to to make the same commitments.

5.7 Certification. We certify that we understand the restrictions in this Section 5 and will comply with them.

5.8 Other state laws. Where a state law (such as Virginia, Colorado, Connecticut, Utah, Texas or Oregon) treats us as your “processor”, Sections 4 to 15 are our processor commitments under that law: we follow your instructions, keep the data confidential, use sub-processors only under written contracts with notice and a chance to object, help you with requests and assessments, delete or return data at your direction, and give you the information you need to show compliance.

6. Our people

6.1 Everyone at Aventide who can access Customer Personal Data is bound by a duty of confidentiality (by contract or professional duty) that continues after their work with us ends. Anyone we add later will sign a confidentiality agreement before they get access.

6.2 We limit access to the people who need it to run, support or secure Aventide. Today, that is the two founders. We access Customer Personal Data only to provide support you ask for, fix problems, keep Aventide secure, or comply with the law.

7. Security

7.1 We use the technical and organizational measures in Annex 2 to protect Customer Personal Data.

7.2 We may change these measures as Aventide and the threats change, but we will not reduce the overall level of protection for Customer Personal Data.

7.3 Aventide is not itself SOC 2 certified. Annex 2 says plainly what we have and what we don’t.

8. Sub-processors

8.1 You authorize our sub-processors. You give us general authorization to use the sub-processors listed at aventide.ai/legal/subprocessors, and new ones added under this Section 8.

8.2 Same protection, our responsibility. Each sub-processor is bound by a written contract that protects Customer Personal Data at least as well as this DPA does, to the extent that fits the service it provides. We remain responsible to you for our sub-processors’ work, subject to Section 16.

8.3 Notice of changes. Before a new sub-processor starts processing Customer Personal Data, we will (a) update the sub-processor page and (b) email the account owner at least 15 days in advance. If we need to replace a sub-processor urgently to keep Aventide secure or running, we will tell you as soon as we can, and you keep your right to object.

8.4 Optional features. Some sub-processors only handle data if you or a teammate turn on a feature (for example, Sidekick on WhatsApp). They are marked “optional” on the page. For a new optional feature, we list the sub-processor before the feature launches, and turning the feature on is your authorization. Some messaging apps (today, Telegram) offer only their standard terms, not a data processing agreement, so Section 8.2 can’t fully apply to them. The page says which ones. If that matters to you, don’t turn that channel on.

8.5 Your right to object. You may object to a new sub-processor on reasonable data-protection grounds by emailing support@aventide.ai within 15 days of our notice. We will try in good faith to address it, for example by suggesting a setting or a way to use Aventide without that sub-processor. If we can’t resolve it within 30 days, you may end your subscription (or stop using the affected feature) by telling us in writing. If you end a prepaid annual subscription this way, we will refund the prepaid fees for the unused part of the term.

9. Requests from your clients

9.1 Tools in Aventide. You can view, correct and delete much of your clients’ data yourself. For example: edit a client record, delete a client note or a saved client memory, delete a meeting note, or remove a contact’s access to your client portal. Some deletions take effect immediately (such as a meeting note). Others hide the item first (such as a client record) and keep it in our database.

9.2 We help with the rest. If you can’t fully answer a request from one of your clients (to access, correct, delete, or receive a copy of their data, or to opt out) with the tools in Aventide, email support@aventide.ai. We will help you within the time the law gives you. To have one person’s data permanently erased, email us and we will do it within 30 days. One exception: entries in signed contracts and their audit trails, and in invoice and document histories, are locked as a record of what happened. They can be removed only by deleting the whole business (Section 14.4). Privacy laws generally let you keep records like these (for example, to complete a transaction or defend a legal claim); if you need them gone anyway, tell us and we’ll work it out with you.

9.3 Requests that reach us directly. If one of your clients contacts us directly about Customer Personal Data, we will pass the request to you promptly, and within 5 business days. We won’t answer it ourselves, except to tell them we’ve passed it to you, unless you ask us to or the law requires it.

10. Security incidents

10.1 Notice within 72 hours. If we become aware of a Security Incident, we will tell you without undue delay. We aim to tell you within 24 hours, and will tell you no later than 72 hours after becoming aware of it. “Becoming aware” means we know, or reasonably believe, that a Security Incident has happened.

10.2 How and what. We will email the account owner (and any security contact you send us at support@aventide.ai). We will tell you what we know at the time and update you as we learn more, including: what happened; the kinds of data and roughly how many people are affected; the likely consequences; what we have done and will do about it; and who to contact at Aventide.

10.3 We act fast. We will promptly take reasonable steps to contain and investigate the Security Incident and reduce its harm.

10.4 Notifying people. You decide whether to notify your clients or regulators. We will give you the information we reasonably can to help you do it. We won’t notify your clients or regulators about Customer Personal Data on your behalf unless you ask us to or the law requires it.

10.5 Telling you about a Security Incident is not an admission of fault.

11. Other help we give you

11.1 Assessments. If you need to do a data protection assessment or risk assessment under a Privacy Law, we will give you the information about our processing that is reasonably available to us (this DPA, Annex 2, and the sub-processor page are a good start).

11.2 Regulators. If a regulator asks you about our processing of Customer Personal Data, we will reasonably cooperate.

12. Requests from governments and courts

If a government agency or court demands Customer Personal Data from us, we will try to redirect it to you. We will tell you promptly before we disclose anything, unless the law forbids us to. We will disclose only what we are legally required to.

13. Where data is processed

13.1 We run Aventide in the United States and store Customer Personal Data in our database in the United States. Uploaded files are stored with Cloudflare R2.

13.2 Some sub-processors may process data in other countries. For example, Cloudflare runs a global network that converts and delivers files, and the messaging apps you can turn on for Sidekick (Telegram, WhatsApp and Slack) run their own global services. The sub-processor page says where each one processes data, where we know.

14. Return and deletion — Version A (current)

14.1 While your account is open. We keep Customer Personal Data until you delete it in Aventide or ask us to delete it. Some data is cleared automatically. For example, email synced from Gmail into your Inbox is removed 90 days after it arrives if it’s bulk “FYI” mail, and 180 days after you last touched it if you’ve resolved or dismissed it. Mail that is still open, snoozed or waiting on a draft is not removed automatically.

14.2 Deleting in the app. Some in-app deletions remove data right away. Others archive it so it can be restored: deleting a business archives it, and deleting a client hides the client record. Archived data stays in our database until it is permanently deleted under 14.4.

14.3 Getting a copy. You can download signed contracts and other documents one by one in Aventide. For a full copy of your data (including clients, invoices, bookings and form responses), the account owner can email support@aventide.ai and we will send it in a common format (JSON or CSV) within 30 days.

14.4 Permanent deletion on request. The account owner can ask us to permanently delete a business, one person’s data, or your whole account by emailing support@aventide.ai from the owner’s email address. We will do it within 30 days and confirm in writing. This includes signed contracts and their audit trails, so download any you want to keep first.

14.5 After your subscription ends. If your subscription or trial ends, your data stays in your account so you can come back or take a copy, until you ask us to delete it under 14.4.

14.6 Backups and providers. Deleted data also leaves the backups kept by our database provider when those backups expire, within 7 days. Copies held by sub-processors (for example, our AI provider, email provider or speech-to-text provider) are deleted on their own schedules under their terms with us.

14.7 When we must keep data. If a law requires us to keep some Customer Personal Data, we will keep only what’s required, only for as long as required, protect it under this DPA, and use it for nothing else.

15. Checking our compliance

15.1 Documents first. On request, we will give you the information you reasonably need to confirm we comply with this DPA: this DPA, Annex 2, the sub-processor list, and written answers to a reasonable security questionnaire (once a year, or after a Security Incident). Our main infrastructure providers publish their own independent audit reports; on request we will point you to them.

15.2 Audits. If that information isn’t enough to show compliance, or a regulator requires it, or after a Security Incident affecting your data, you (or an independent auditor you choose who is bound by confidentiality and is not our competitor) may audit our compliance with this DPA. You must give us at least 30 days’ written notice. Audits happen at most once in any 12 months (unless a regulator requires more or there has been a Security Incident), during business hours, in a way that doesn’t disrupt our operations or expose other customers’ data, and at your cost. We may instead arrange an independent assessment at our cost and share the report with you.

15.3 We don’t give access to our sub-processors’ systems. We will pass on what they make available to us.

16. Liability

Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Terms. Liability under the Terms and this DPA together counts toward one combined cap; this DPA does not create a separate or additional cap.

17. Term, changes and ending

17.1 Term. This DPA lasts as long as we process Customer Personal Data for you.

17.2 Changes. We may update this DPA when the law, our services or our sub-processors change. We will give at least 30 days’ notice of material changes by email to the account owner. We will not change this DPA in a way that materially lowers the protection of Customer Personal Data unless the law requires it. Sub-processor changes follow Section 8.

17.3 Ending. If we tell you we can’t comply (Section 5.5), or we don’t fix a material breach of this DPA within 30 days after you tell us about it, you may end your subscription. Section 14 then applies.

17.4 What survives. Sections 5, 6, 10, 12, 14 and 16 continue for as long as we hold any Customer Personal Data.

18. EU, UK and Swiss data protection terms — NOT IN EFFECT

This section is not in effect. Aventide is not yet offered to businesses in the European Economic Area, the United Kingdom or Switzerland. This section takes effect only (a) on the date we publish a notice on this page saying it is in effect, or (b) for your account, if you and we agree in writing that it applies to you. Until then, nothing in this section applies, and Aventide does not promise that it meets the GDPR, UK GDPR or Swiss law.

When in effect, for Customer Personal Data covered by the EU General Data Protection Regulation (“GDPR”), the UK GDPR and Data Protection Act 2018, or the Swiss Federal Act on Data Protection (“FADP”):

18.1 Article 28 terms. Aventide is your processor. Sections 4 to 15 are our commitments under GDPR Article 28(3): we process only on your documented instructions (including about transfers outside the EEA, UK or Switzerland), unless the law requires otherwise and then we tell you first unless the law forbids it; we keep the data confidential; we apply the measures in Annex 2 as required by Article 32; we use sub-processors only under Section 8 with a written contract imposing the same data-protection obligations (Article 28(4)); we help you answer data subject requests and meet your obligations under Articles 32 to 36; we delete or return the data at the end of the services at your choice; and we give you the information needed to show compliance and allow audits under Section 15. We will tell you immediately if we think an instruction infringes data protection law.

18.2 Breach notice. Section 10 applies, and our notice will include the information in GDPR Article 33(3), as far as we have it.

18.3 Transfers out of Europe. Where Customer Personal Data is transferred to Aventide in the United States from the EEA, the UK or Switzerland and no other lawful transfer mechanism applies, the parties agree to the following, which are incorporated by reference:

  • EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914): Module Two (controller to processor) where you are a controller, and Module Three (processor to processor) where you are a processor. Clause 7 (docking) applies. Under Clause 9(a), Option 2 (general written authorization) applies, with the notice period in Section 8.3. The optional wording in Clause 11 does not apply. Under Clause 13, the competent supervisory authority is the one determined by Clause 13(a). Under Clauses 17 and 18, the governing law and courts are those of Ireland. Annexes I and II of the clauses are completed by Annexes 1 and 2 of this DPA; Annex III by the sub-processor page.

  • UK International Data Transfer Addendum to the EU Standard Contractual Clauses (issued by the UK Information Commissioner): Tables 1 to 3 are completed by this DPA and its Annexes, and either party may end the Addendum as allowed by its Section 19.

  • Switzerland: the EU Standard Contractual Clauses apply with the changes the Swiss Federal Data Protection and Information Commissioner (“FDPIC”) requires: the FDPIC is the competent supervisory authority for transfers governed by the FADP, references to the GDPR include the FADP, and data subjects in Switzerland may enforce their rights there.

18.4 Order. If the Standard Contractual Clauses conflict with this DPA, the clauses win. Nothing in this DPA limits the rights of data subjects under the clauses.

Annex 1 — Description of the processing

Parties. Data exporter / controller: the business that holds the Aventide account (contact: the account owner). Data importer / processor: Second Spring Design Inc. d/b/a Aventide, 522 W Riverside Ave, Spokane, WA 99201-0580, United States; contact support@aventide.ai.

Subject matter and nature. Hosting, storing, organizing, displaying, sending and analyzing Customer Personal Data to provide Aventide: client records and client rooms, the client portal, documents and proposals, e-signature, bookings, inquiry and other forms, invoices and payments, the Inbox (email synced from your connected Gmail), meeting notes imported from tools you connect, file storage, and AI features (drafting, summarizing, reading dates from uploads, and client memories).

Purpose. To provide Aventide to you as described in the Terms and this DPA, on your instructions (Section 4).

Duration. For as long as you use Aventide, plus the deletion period in Section 14.

Frequency. Continuous.

People whose data we process (data subjects). Your clients and prospects (including contacts at client companies); people who use your client portal; people who sign contracts or accept proposals you send; people who book time with you; people who fill in your inquiry and other forms; people you invoice; people who email the Gmail accounts you connect; people who take part in meetings whose notes you import; other people named in your content; and your own team members, as they appear in your content and in record histories.

Kinds of personal data

Data subject

Data

Clients and contacts

Name, company, email, website, photo, notes, next steps, project and pipeline details

Clients (AI memories)

Preferences, context and relationship notes the assistant saves (visible on the client’s card, deletable); commitments and pricing it proposes for your approval

Portal users

Email, sign-in link and session records, which documents they viewed or downloaded

Contract signers

Name, email, typed signature, IP address, browser and device information, timestamps for viewing, consenting, signing or declining, the signed document and its SHA-256 fingerprint, any decline note

Proposal accepters

Typed name, a hashed IP address, browser information

Booking guests

Name, email, notes, time zone, booking details

Inquiry form submitters

Name, email, phone, message, service type, date, budget, any custom answer, marketing-consent wording and version, a hashed IP address, browser information, referring page

Form respondents

Their answers, browser information

Invoice payers

Name, email, amounts, payment status (card and bank details stay with Stripe)

Email correspondents

Sender name and email, subject, a short excerpt, draft replies (full message bodies are fetched from Gmail when you open a thread, and are not stored, except in an assistant conversation where you asked about the message)

Meeting participants

Transcripts, speaker names, AI summaries

Anyone in your files

Whatever your uploaded files, voice notes and documents contain

Your team members

Names and emails recorded in contract and record histories

Imported records

Clients, projects and payment records you import from HoneyBook

Sensitive data. Aventide does not need sensitive personal data, and you should not put it in unless you need to. Aventide is not for health information covered by HIPAA; we don’t sign business associate agreements. Do not use Aventide to collect information directly from children under 13. Identity numbers you keep locked in the Vault (such as tax IDs) are kept out of Aventide’s AI assistant features; see Annex 2.

Sub-processors. See aventide.ai/legal/subprocessors.

Annex 2 — Security measures

This is what Aventide does today. We will update it as we add measures.

Sign-in and access

  • Sign-in runs through Outseta. Aventide never stores passwords.

  • Our servers check the sign-in token on every request (RS256 signatures checked against the provider’s published keys).

  • Every request is tied to one business on the server, and we check that the business belongs to the signed-in person’s account. A request for another business’s data is refused.

  • The database has row-level security turned on. Browsers cannot write to the database directly; all changes go through our server code. Browsers can read only a few tables for live updates, and only rows for their own account.

  • The account owner can limit the Vault and Smart Compliance screens to the owner only.

  • Multi-factor authentication is on for every admin account at Vercel, Supabase, Cloudflare, GitHub, Outseta and Stripe.

Encryption

  • Data travels over encrypted connections (TLS).

  • Our database and file storage providers encrypt stored data at rest.

  • Connection tokens for services you connect are kept in an encrypted secret store (Supabase Vault), not in ordinary tables. Some other connection secrets (for example, meeting-note tool API keys and Slack tokens) are also encrypted with AES-256-GCM, using a key kept outside the database.

Files

  • Uploaded files are kept in private storage and served through short-lived signed links. Two exceptions: your logo, and some images you upload for social posts, are stored at public web addresses so your branded pages and social apps can load them.

Links we send to your clients

  • Signing, portal, booking and payment links use long random tokens. Contract signing links expire; client portal sign-in links expire after 7 days and portal sessions after 90 days, and session tokens are stored hashed.

  • Your clients sign in to the portal by typing their email. The sign-in link goes only to an address on that client’s access list.

  • Contract signers are authenticated by email-link authentication: they reach the document through a unique link sent to their email address.

  • Shared and portal pages can’t be embedded in other websites.

Abuse protection

  • Cloudflare Turnstile protects sign-up and log-in, and booking, inquiry and form submissions.

  • Rate limits protect public forms. IP addresses used for rate limiting are stored only as keyed hashes.

  • Messages from Stripe, Outseta, QuickBooks and our email provider are checked for a valid signature before we act on them.

AI safeguards

  • The assistant works only inside the signed-in business’s data.

  • Text from emails and other outside content is passed to the AI as information to read, not as instructions to follow.

  • Traces of AI runs kept at our hosting provider have their inputs and outputs removed.

  • Items you lock in the Vault are kept out of Aventide’s AI assistant features. Locking is an access setting, not extra encryption: people with infrastructure access could still reach locked items, and we access them only for the reasons in Section 6.2. When you scan a document with Smart Compliance, the file is sent to our AI provider to read dates and identifiers.

  • Our AI provider, Anthropic, does not train its models on data sent through its commercial API, which is how our requests reach it (directly or through Vercel’s AI Gateway). Aventide does not train AI models on Customer Personal Data.

Records you can rely on

  • When a contract is sent, Aventide freezes a copy, and the signer reviews that exact copy. The contract’s history is append-only, and database rules block changes to a sent or signed contract. Signed documents carry a SHA-256 fingerprint.

  • Invoice and document histories are append-only.

How we change the software

  • Every change must pass our automated test suite, lint checks and a clean production build before it can merge.

  • Database changes are kept as migration files and tested against a fresh database on every pull request. New tables are closed to browsers by default.

What we don’t have yet

  • Aventide is not SOC 2 certified, and we haven’t had an independent penetration test or run a bug bounty. Our main infrastructure providers (Vercel, Supabase, Cloudflare and Anthropic) publish their own independent audit reports.

Incidents

  • We investigate and contain security incidents and notify you under Section 10.

Annex 3 — Sub-processors

See aventide.ai/legal/subprocessors.

Contact. Questions about this DPA: support@aventide.ai · Second Spring Design Inc. d/b/a Aventide, 522 W Riverside Ave, Spokane, WA 99201-0580.