Data Processing Agreement

Effective Date: September 2, 2026

Last Updated: September 2, 2026

This Data Processing Agreement ("DPA") forms part of the Terms and Conditions (averroes.ai/terms) or any other written agreement (the "Agreement") between Averroes.ai, Inc. ("Averroes.ai," "Processor") and the customer accepting the Agreement ("Customer," "Controller"). It governs the processing of Personal Data by Averroes.ai on behalf of Customer in connection with the Services, including VisionRepo and all other Averroes.ai products.

By accepting the Agreement, Customer accepts this DPA. In the event of conflict between this DPA and the Agreement regarding the processing of Personal Data, this DPA prevails.

1. Definitions

  • "Data Protection Law" means all laws applicable to the processing of Personal Data under this DPA, including the GDPR (Regulation (EU) 2016/679), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and the California Consumer Privacy Act as amended by the CPRA.
  • "Personal Data" means any information relating to an identified or identifiable natural person that is contained in Customer Data and processed by Averroes.ai on behalf of Customer.
  • "Customer Data" has the meaning given in the Agreement.
  • "Sub-processor" means any third party engaged by Averroes.ai to process Personal Data on behalf of Customer.
  • "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Decision 2021/914, as amended or replaced.
  • "UK Addendum" means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner.
  • "Controller," "Processor," "Data Subject," "Processing," "Personal Data Breach," and "Supervisory Authority" have the meanings given in the GDPR.

2. Scope and Roles

2.1. Customer is the Controller (or a Processor acting on behalf of a third-party Controller) of Personal Data contained in Customer Data. Averroes.ai is the Processor.

2.2. Averroes.ai is the Controller of Personal Data it processes for its own purposes, such as account, billing, and usage data. That processing is governed by the Averroes.ai Privacy Policy (averroes.ai/privacy), not this DPA.

2.3. Details of the processing are set out in Annex 1.

3. Customer Obligations

3.1. Customer is responsible for the lawfulness of Personal Data it provides to Averroes.ai, including having a valid legal basis, providing any required notices, and obtaining any required consents from Data Subjects.

3.2. Customer's instructions to Averroes.ai for the processing of Personal Data must comply with Data Protection Law.

3.3. Customer shall not upload special categories of Personal Data (including biometric data used for identification, health data, or data relating to criminal convictions) unless agreed in writing with Averroes.ai.

3.4. Where images or video in Customer Data may capture individuals (for example, operators on a production line), Customer is responsible for ensuring that such capture is lawful and that appropriate notices have been given.

4. Processor Obligations

Averroes.ai shall:

4.1. Process Personal Data only on documented instructions from Customer, including with regard to international transfers, unless required to do so by law. Where such a legal requirement applies, Averroes.ai will inform Customer before processing unless the law prohibits it. The Agreement, this DPA, and Customer's use of the Services' features constitute Customer's documented instructions.

4.2. Inform Customer immediately if, in its opinion, an instruction infringes Data Protection Law.

4.3. Ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

4.4. Implement the technical and organizational security measures described in Annex 2, and maintain them at a level appropriate to the risk.

4.5. Not use Personal Data for the purpose of training, improving, or developing machine learning models except (a) in anonymized, aggregated, or de-identified form from which no individual or Customer can be identified, or (b) where Customer has elected in the Services or in writing to permit training on its Customer Data. Customer may withdraw any such election at any time.

4.6. Not sell, share for cross-context behavioral advertising, or otherwise disclose Personal Data to third parties except as permitted by this DPA.

5. Sub-processors

5.1. Customer gives general authorization for Averroes.ai to engage Sub-processors. The current list of Sub-processors is set out in Annex 3 and maintained at averroes.ai/subprocessors.

5.2. Averroes.ai will give Customer at least thirty (30) days' notice of any intended addition or replacement of a Sub-processor by updating the list and, for customers who have subscribed to notifications, by email.

5.3. Customer may object in writing on reasonable data protection grounds within that period. If the parties cannot resolve the objection in good faith, Customer may terminate the affected Services and receive a pro-rata refund of prepaid fees.

5.4. Averroes.ai will impose on each Sub-processor, by written contract, data protection obligations that provide at least the same level of protection as this DPA, and remains liable for the acts and omissions of its Sub-processors.

6. Data Subject Rights

6.1. Averroes.ai will, taking into account the nature of the processing, assist Customer by appropriate technical and organizational measures in responding to requests from Data Subjects to exercise their rights under Data Protection Law.

6.2. If Averroes.ai receives a request directly from a Data Subject relating to Customer's Personal Data, it will not respond except to direct the Data Subject to Customer, unless required by law, and will notify Customer promptly.

7. Personal Data Breach

7.1. Averroes.ai will notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Customer's Personal Data.

7.2. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed. Information may be provided in phases as it becomes available.

7.3. Averroes.ai will cooperate with Customer and take reasonable steps to contain, investigate, and mitigate the breach.

8. Assistance, Audits, and Compliance

8.1. Averroes.ai will provide reasonable assistance to Customer with data protection impact assessments and prior consultations with Supervisory Authorities, to the extent required by Data Protection Law and taking into account the information available to Averroes.ai.

8.2. Averroes.ai will make available to Customer all information reasonably necessary to demonstrate compliance with this DPA.

8.3. Customer may audit Averroes.ai's compliance with this DPA once per twelve (12) month period, or more often following a Personal Data Breach or where required by a Supervisory Authority. Audits will be conducted on at least thirty (30) days' written notice, during normal business hours, in a manner that does not unreasonably disrupt Averroes.ai's operations, and subject to reasonable confidentiality obligations. Where Averroes.ai holds a current third-party audit report or certification (such as SOC 2), it may provide that report in satisfaction of this obligation, and Customer will only conduct an on-site audit if the report does not reasonably address Customer's concerns.

8.4. Customer bears its own costs of any audit. If an audit reveals a material non-compliance, Averroes.ai will remediate at its own cost.

9. International Transfers

9.1. Averroes.ai is located in the United States and processes Personal Data in the United States and in other countries where its Sub-processors operate.

9.2. For transfers of Personal Data from the EU, EEA, or Switzerland to a country without an adequacy decision, the parties enter into the SCCs, Module Two (controller to processor) or Module Three (processor to processor) as applicable, which are incorporated by reference with the following elections:

  • Clause 7 (docking clause): included.
  • Clause 9 (sub-processors): Option 2, general written authorization, with the notice period in Section 5.2.
  • Clause 11 (redress): the optional language is not included.
  • Clause 13 and Annex I.C: the competent Supervisory Authority is that of the EU member state in which Customer is established, or, if Customer is not in the EU, that of Ireland.
  • Clause 17 (governing law): the laws of Ireland.
  • Clause 18 (forum): the courts of Ireland.
  • Annexes I and II of the SCCs are populated by Annexes 1, 2, and 3 of this DPA.

9.3. For transfers from the United Kingdom, the UK Addendum applies to the SCCs, with the tables completed by reference to this DPA, and the parties agree that neither may end the UK Addendum under its Section 19.

9.4. For transfers from Switzerland, references in the SCCs to the GDPR are read as references to the Swiss Federal Act on Data Protection, the competent authority is the Swiss Federal Data Protection and Information Commissioner, and Data Subjects in Switzerland may enforce their rights in Switzerland.

9.5. If a transfer mechanism relied on is invalidated, the parties will cooperate in good faith to implement an alternative lawful mechanism.

10. Return and Deletion

10.1. Upon termination or expiration of the Services, Customer may export its Customer Data for thirty (30) days. Averroes.ai will then, at Customer's election, delete or return all Personal Data and delete existing copies, unless retention is required by law.

10.2. Backup copies will be purged in the ordinary course within one hundred eighty (180) days. Personal Data in backups remains subject to this DPA until deleted.

10.3. Deletion will be carried out in accordance with NIST 800-88 or an equivalent standard. Averroes.ai will certify deletion in writing on request.

11. California (CCPA/CPRA)

11.1. To the extent the CCPA applies, Averroes.ai is a "service provider" and Customer is a "business." Averroes.ai will not sell or share Personal Data, retain, use, or disclose it outside the direct business relationship or for any purpose other than the business purposes specified in the Agreement, or combine it with Personal Data from other sources except as permitted by the CCPA.

11.2. Averroes.ai certifies that it understands and will comply with these restrictions and will notify Customer if it can no longer meet its obligations under the CCPA.

12. Liability

12.1. Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, except that these limitations do not apply to (a) a party's liability to Data Subjects under Clause 12 of the SCCs, or (b) liability that cannot be limited under Data Protection Law.

13. General

13.1. This DPA continues in force for as long as Averroes.ai processes Personal Data on behalf of Customer.

13.2. Averroes.ai may update this DPA from time to time to reflect changes in Data Protection Law or the Services. Material changes will be notified with at least thirty (30) days' notice. Changes will not reduce the level of protection for Personal Data.

13.3. This DPA is governed by the governing law of the Agreement, except where the SCCs require otherwise.

Annex 1: Details of Processing

Subject matter: Provision of the Averroes.ai Services, including VisionRepo, for the storage, organization, annotation, and analysis of visual data and the training and deployment of AI models.

Duration: The term of the Agreement plus the retention period in Section 10.

Nature and purpose: Hosting, storage, processing, annotation, analysis, model training and inference, search, collaboration, and export of Customer Data as directed by Customer through the Services.

Categories of Data Subjects: Customer's employees, contractors, and authorized users; individuals who may incidentally appear in images or video uploaded by Customer (such as production line operators); individuals whose Personal Data is contained in metadata or annotations.

Categories of Personal Data: Names, email addresses, job titles, and login credentials of authorized users; usernames and activity logs within the Services; any Personal Data incidentally contained in images, video, metadata, file names, or annotations uploaded by Customer.

Special categories of Personal Data: None intended. Customer shall not upload special categories of data without written agreement (Section 3.3).

Frequency of transfer: Continuous, for the duration of the Services.

Annex 2: Technical and Organizational Measures

Averroes.ai maintains the following measures, which it may update provided the overall level of security is not reduced:

  • Encryption of Personal Data in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent).
  • Role-based access control within the Services, with customer-managed user permissions and support for enterprise SSO.
  • Access to production systems restricted to authorized personnel on a least-privilege basis, with multi-factor authentication.
  • Logical separation of Customer Data between customers.
  • Logging and monitoring of production system access and security events.
  • Vulnerability management, including regular patching and periodic security testing.
  • Secure software development practices, including code review.
  • Regular backups with encryption, and tested restoration procedures.
  • Confidentiality obligations for all personnel with access to Personal Data, and security awareness training.
  • Incident response procedures supporting the breach notification commitments in Section 7.
  • Secure deletion of data in accordance with NIST 800-88.
  • Availability of on-premise deployment, under which Customer Data does not leave Customer's environment.
  • Sub-processor due diligence and contractual flow-down of security obligations.

Annex 3: Sub-processors

Sub-processorPurposeLocation
Amazon Web Services, Inc.Cloud hosting and storageUnited States
PostHog, Inc.Product analytics within the ServicesUnited States
Microsoft CorporationMicrosoft Clarity (website analytics); Microsoft sign-inUnited States
Google LLCGoogle sign-inUnited States
HubSpot, Inc.CRM and support communicationsUnited States
MailerLite LimitedEmail deliveryIreland / EU

The current list is maintained at averroes.ai/subprocessors.