Avut PIM
PrivacyAI privacySubprocessorsTermsDPACookiesSupportOpen app

Legal

Data Processing Addendum

This Data Processing Addendum forms part of the Agreement where Avut processes Customer Personal Data on the Customer's behalf.

Last updated: July 25, 2026

This Data Processing Addendum (“DPA”) forms part of and is incorporated into the agreement, order form, subscription terms, or other written or electronic agreement governing Customer’s use of the Avut PIM services (the “Agreement”) between Norleaf AS, Norwegian organisation number 938 103 984, registered address Kroken 1, 4340 Bryne, Norway (“Processor”), and the customer entity identified in the Agreement (“Customer”).

This DPA applies where Processor processes Customer Personal Data on behalf of Customer in connection with the Services.

For the purposes of this DPA:

  • “Applicable Data Protection Law” means the GDPR and any national law implementing or supplementing the GDPR, in each case as applicable to the Processing of Customer Personal Data under the Agreement.
  • “Customer Personal Data” means personal data processed by Processor on behalf of Customer in connection with the Services.
  • “EEA” means the European Economic Area.
  • “GDPR” means Regulation (EU) 2016/679 as incorporated into and applicable within the EEA.
  • “Personal Data Breach”, “Process”, “Processor”, “Controller”, “Data Subject”, and “Supervisory Authority” have the meanings given to them in Applicable Data Protection Law.

Where Customer acts as a processor on behalf of another controller, Customer appoints Processor as Customer’s subprocessor and warrants that Customer is authorized to do so.

To the extent Processor processes personal data as an independent controller for its own purposes, this DPA does not apply to that Processing. Such Processing may include, where applicable and to the extent determined by Processor rather than Customer, account administration, billing, payment processing, fraud prevention, service security, legal compliance, and other business operations described in Processor’s privacy notice.

In the event of any conflict between this DPA and the Agreement with respect to the Processing of Customer Personal Data, this DPA shall prevail. If the parties separately enter into the European Commission’s Standard Contractual Clauses for international transfers, those clauses shall prevail with respect to the subject matter they govern.

Parties

The service provider and Processor is Norleaf AS, Norwegian organisation number 938 103 984, with registered address Kroken 1, 4340 Bryne, Norway.

The Customer is the Controller of Customer Personal Data, except where Customer acts as a processor for one of its own customers or affiliates, in which case Customer acts as a processor and Processor acts as Customer’s subprocessor.

Purpose

This DPA governs Processor’s Processing of Customer Personal Data on behalf of Customer for the purpose of providing the Services under the Agreement.

The details of the Processing, including the subject matter and duration of the Processing, the nature and purpose of the Processing, the categories of personal data, the categories of Data Subjects, and Customer’s rights and obligations, are set out in Annex I.

Processing instructions

Processor shall process Customer Personal Data only on documented instructions from Customer, including with regard to transfers of Customer Personal Data to a third country or an international organization, unless required to do so by applicable law. In such case, Processor shall inform Customer of that legal requirement before Processing, unless the law prohibits such information on important grounds of public interest.

The Agreement, this DPA, Customer’s use of the Services, Customer’s administrative configuration of the Services, Customer’s API calls, Customer’s support requests, Customer’s activation of integrations or optional features made available under the Agreement, and Customer’s authorization of an external MCP client through Avut’s access and authorization mechanisms together constitute Customer’s documented instructions, provided that such instructions are consistent with the Agreement and Applicable Data Protection Law.

Where Customer selects and connects an external client or integration, that third party may act as a customer-directed recipient or integration rather than as Avut’s subprocessor. Such recipients are described separately from Avut’s subprocessors where relevant. Processor is not required to treat every customer-selected external provider as its subprocessor solely because Processor exposes a standards-based endpoint that such provider can connect to.

Customer may issue additional reasonable documented instructions relating to the Processing of Customer Personal Data, provided that such instructions are consistent with the Agreement, technically feasible, and do not require a material change to the Services unless otherwise agreed by the parties.

Processor shall immediately inform Customer if, in Processor’s opinion, an instruction infringes Applicable Data Protection Law.

Processor shall ensure that persons authorized to process Customer Personal Data:

  • are bound by appropriate confidentiality obligations; and
  • process Customer Personal Data only on documented instructions from Customer, unless otherwise required by applicable law.

Processor shall not:

  • process Customer Personal Data for its own independent purposes;
  • sell Customer Personal Data; or
  • use Customer Personal Data for advertising, profiling, or any purpose unrelated to providing the Services to Customer,

unless expressly required by applicable law or expressly agreed in writing by the parties in a manner consistent with Applicable Data Protection Law.

Where the Services include optional AI, translation, enrichment, MCP, or integration features, Customer’s activation and use of such features in accordance with the Agreement shall constitute documented instructions for the corresponding Processing, subject always to this DPA and the Subprocessor arrangements set out below.

Subprocessors

Customer grants Processor a general written authorization to engage subprocessors to provide parts of the Services.

Processor shall maintain a list of subprocessors in Annex III and in its publicly available Subprocessors and Third-Party Providers register incorporated by reference into Annex III. The public register is currently located at: https://avut.io/privacy/subprocessors

Processor shall notify Customer in writing, including by email, in-product notice, or other documented electronic means, at least 30 days before any intended addition or replacement of a subprocessor that will process Customer Personal Data, thereby giving Customer the opportunity to object on reasonable data protection grounds.

If Customer objects in good faith on reasonable data protection grounds, the parties shall work together in good faith to resolve the objection. If the parties cannot resolve the objection within a reasonable period, Customer may cease using the affected feature or, if necessary, terminate the affected part of the Services or the Agreement in accordance with the Agreement.

Processor shall enter into a written agreement with each subprocessor imposing data protection obligations no less protective than those set out in this DPA, in particular with respect to documented instructions, confidentiality, security, assistance, deletion or return, and audit rights as relevant to the subprocessor’s role.

Processor shall remain fully liable to Customer for the performance of each subprocessor’s obligations where that subprocessor fails to fulfill its data protection obligations.

Security measures

Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the Processing, as well as the risks of varying likelihood and severity to the rights and freedoms of natural persons, Processor shall implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk in accordance with Article 32 GDPR.

The technical and organizational measures applicable to the Services are described in Annex II.

Processor may update or modify the security measures from time to time, provided that the overall level of protection is not materially reduced.

Confidentiality and incidents

Processor shall ensure that all personnel and contractors authorized to process Customer Personal Data are subject to appropriate contractual or statutory duties of confidentiality.

Processor shall notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.

Such notice shall include, to the extent known at the time:

  • a description of the nature of the Personal Data Breach;
  • the categories of affected Customer Personal Data and, where possible, the categories and approximate number of affected Data Subjects and records;
  • the likely consequences of the Personal Data Breach; and
  • the measures taken or proposed to address the Personal Data Breach and mitigate its possible adverse effects.

Processor shall provide additional information without undue further delay as it becomes available and shall take reasonable steps to identify, contain, investigate, remediate, and mitigate the Personal Data Breach.

Processor shall assist Customer, taking into account the nature of the Processing and the information available to Processor, in meeting Customer’s obligations relating to Personal Data Breaches under Applicable Data Protection Law.

International transfers and audits

Processor shall not transfer Customer Personal Data outside the EEA unless such transfer is made in accordance with Chapter V of the GDPR and this DPA.

Where Customer Personal Data is transferred outside the EEA, Processor shall use a valid transfer mechanism under Applicable Data Protection Law, which may include:

  • an adequacy decision;
  • the European Commission’s Standard Contractual Clauses; or
  • another lawful transfer mechanism recognized under Applicable Data Protection Law.

Where required by Applicable Data Protection Law, Processor shall provide Customer with information reasonably necessary to understand the applicable transfer mechanism and, where relevant, any supplementary measures applied in connection with the transfer.

Processor shall make available to Customer all information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR.

As a first step, Processor may satisfy audit and inspection requests by providing recent and relevant third-party audit reports, security certifications, summaries of penetration testing, security whitepapers, or similar independent assurance materials, to the extent available and reasonably sufficient to demonstrate compliance.

Where such materials are not reasonably sufficient, Customer may, by itself or through an independent auditor bound by confidentiality obligations, conduct an audit of Processor’s relevant controls no more than once in any twelve-month period, unless:

  • required by a Supervisory Authority;
  • reasonably required following a Personal Data Breach affecting Customer Personal Data; or
  • Customer reasonably suspects material non-compliance with this DPA.

Any audit shall be subject to reasonable prior notice, shall take place during normal business hours, and shall be conducted in a manner that minimizes disruption to Processor’s business and does not compromise the security, confidentiality, or availability of Processor’s systems or other customers’ data. Customer shall bear its own audit costs, unless the audit reveals material non-compliance by Processor with this DPA, in which case Processor shall reimburse Customer’s reasonable and documented audit costs.

Assistance and deletion

Taking into account the nature of the Processing, Processor shall assist Customer by appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of Customer’s obligation to respond to requests for exercising Data Subjects’ rights under Chapter III GDPR.

If Processor receives a request directly from a Data Subject relating to Customer Personal Data, Processor shall, unless prohibited by law, promptly notify Customer and shall not respond to the request except on Customer’s documented instructions or as required by applicable law.

Processor shall assist Customer, taking into account the nature of the Processing and the information available to Processor, in ensuring compliance with Customer’s obligations pursuant to Articles 32 to 36 GDPR, including with respect to:

  • security of Processing;
  • notification of Personal Data Breaches;
  • communication of Personal Data Breaches to Data Subjects;
  • data protection impact assessments; and
  • prior consultation with a Supervisory Authority where required.

Upon termination or expiry of the Services, and at Customer’s choice, Processor shall return or delete all Customer Personal Data and shall delete existing copies unless applicable law requires storage of the Customer Personal Data.

Unless otherwise agreed in writing or technically impossible, Customer shall communicate its choice of return or deletion no later than the effective date of termination or expiry. If Customer does not communicate a choice, Processor may delete the Customer Personal Data after the expiration of any export period made available under the Agreement.

To the extent Customer Personal Data remains in backup media after deletion from active systems, Processor may retain such data until deletion or overwriting in accordance with Processor’s standard backup retention cycle, provided that such retained data remains protected under this DPA and is not otherwise actively processed except as required by applicable law.

Upon Customer’s written request, Processor shall confirm in writing that return or deletion has been completed in accordance with this section.

Customer responsibilities

Customer remains responsible for:

  • the lawfulness of the Processing of Customer Personal Data, including establishing an appropriate legal basis;
  • providing any notices and transparency information required under Applicable Data Protection Law;
  • the accuracy, quality, and legality of Customer Personal Data submitted to the Services;
  • ensuring that its instructions to Processor are lawful and sufficiently documented; and
  • determining whether the Services, security measures, subprocessors, transfer mechanisms, and any customer-directed recipients are appropriate for Customer’s intended use of the Services.

Nothing in this DPA relieves Processor of its own direct obligations under Applicable Data Protection Law.

Liability

Except as otherwise expressly required by Applicable Data Protection Law, each party’s liability arising out of or in connection with this DPA shall be subject to the exclusions and limitations of liability set out in the Agreement.

Nothing in the Agreement or this DPA excludes or limits any liability to the extent such exclusion or limitation is prohibited by Applicable Data Protection Law.

General

This DPA may be executed electronically and may be accepted by electronic means.

This DPA remains in effect for as long as Processor processes Customer Personal Data on behalf of Customer under the Agreement.

The parties may update the Annexes to this DPA in writing or by other documented electronic means, provided that no such update reduces the level of protection required by Applicable Data Protection Law.

Annex I – Details of the Processing

Subject matter of the Processing

Provision of the Avut PIM services and related support, maintenance, hosting, storage, security, export, import, workflow, integration, MCP, and other processing activities necessary to provide the Services under the Agreement.

Duration of the Processing

The Processing shall continue for the term of the Agreement and for any limited period thereafter during which Processor processes Customer Personal Data for return, deletion, legal retention, backup retention, or transition purposes in accordance with the Agreement and this DPA.

Nature and purpose of the Processing

Processor processes Customer Personal Data to provide, secure, support, maintain, and improve the operational delivery of the Services for Customer in accordance with Customer’s documented instructions, including where applicable to:

  • host and store Customer data within the Services;
  • enable workspace administration and user access;
  • import, organize, transform, enrich, export, and synchronize Customer data;
  • operate integrations, APIs, and MCP tool access enabled by Customer;
  • provide support and troubleshooting requested by Customer;
  • maintain service security, resilience, logging, and monitoring;
  • provide optional workflow, AI, translation, or MCP-related processing activated by Customer; and
  • make relevant Customer Personal Data available to customer-directed recipients only to the extent returned by authorized integrations or MCP tools invoked under Customer’s documented instructions.

Categories of Data Subjects

Depending on Customer’s use of the Services, Data Subjects may include:

  • Customer’s employees, contractors, and authorized users;
  • Customer’s business contacts, suppliers, partners, resellers, or other business counterparties;
  • individuals whose personal data is included by Customer in product information, catalog records, media assets, imports, exports, integrations, MCP prompts, workflows, or support materials; and
  • any other Data Subjects identified by Customer in its documented instructions.

Categories of Personal Data

Depending on Customer’s use of the Services, Customer Personal Data may include:

  • identification and contact data, such as name, business email address, phone number, postal address, username, or similar identifiers;
  • professional or organizational information, such as role, title, department, employer, or business relationship information;
  • account and authentication-related data, such as login identifiers, role assignments, session metadata, and access-related metadata;
  • content data uploaded, created, stored, generated, or exported within the Services, including free-text fields, media metadata, labels, comments, notes, workflow content, product records, and catalog records;
  • technical and usage data relating to Customer’s use of the Services to the extent such data constitutes personal data;
  • MCP-related metadata, such as client and grant metadata, operation records, audit records, and token or authorization-code hashes; and
  • any other personal data that Customer chooses to upload to or process within the Services.

Special categories and Article 10 data

Unless otherwise expressly agreed in writing, the Services are not intended to require the routine Processing of special categories of personal data under Article 9 GDPR or personal data relating to criminal convictions and offences under Article 10 GDPR. If Customer nevertheless uploads such data, Customer is responsible for ensuring that such Processing is lawful and covered by its documented instructions, and Processor shall process such data only in accordance with this DPA and Applicable Data Protection Law.

Customer’s rights and obligations

Customer determines the purposes of the Processing and the means made available through the Services, issues documented instructions to Processor, and remains responsible for compliance with its obligations as Controller under Applicable Data Protection Law.

Annex II – Technical and Organisational Measures

Processor shall implement and maintain measures appropriate to the risks presented by the Processing and the nature of the Services, including as applicable:

Organizational measures

  • documented information security and data protection policies;
  • assignment of responsibility for security and privacy governance;
  • confidentiality obligations for personnel and contractors with access to Customer Personal Data;
  • onboarding, role change, and offboarding processes for personnel access;
  • personnel training appropriate to security and privacy responsibilities;
  • incident response and escalation procedures;
  • vendor and subprocessor due diligence and contract controls;
  • change management processes for systems affecting Customer Personal Data; and
  • periodic review of access rights and privileges.

Access control

  • role-based access controls;
  • least-privilege access principles;
  • authentication controls appropriate to user role and risk;
  • additional controls for administrative or privileged access, including multi-factor authentication where appropriate; and
  • logging of relevant administrative and security events.

System and data protection

  • encryption of Customer Personal Data in transit using current industry-standard transport encryption;
  • encryption or other equivalent protection of Customer Personal Data at rest where appropriate to the risk and service architecture;
  • logical separation of customer environments or equivalent segregation controls appropriate to a multi-tenant service, where applicable;
  • secure management of credentials, secrets, and encryption keys; and
  • malware protection, endpoint hardening, and similar baseline security controls where relevant.

Availability and resilience

  • backup, restore, and recovery measures appropriate to the Services;
  • resilience measures intended to support ongoing confidentiality, integrity, availability, and resilience of processing systems and services; and
  • procedures for testing, assessing, and evaluating the effectiveness of security measures where appropriate.

Monitoring and vulnerability management

  • monitoring and alerting for security-relevant events;
  • vulnerability identification, remediation, and patch management processes; and
  • periodic security testing proportionate to the risks and the service architecture.

Data lifecycle and MCP controls

  • controls for export, deletion, retention, and restricted access to Customer Personal Data;
  • deletion workflows for active systems and retention handling for backups and archival copies;
  • procedures to limit unnecessary Processing and to support data minimization where feasible within the Services;
  • OAuth-based authorization with PKCE for MCP connections;
  • tokens and grants bound to the intended audience, resource, user, client, and workspace where applicable;
  • checks of current membership, role, permissions, and tenant tool policy when MCP tools are used;
  • bounded result sets, strict schemas, output minimization, and redaction of sensitive implementation details;
  • revocation and workspace-level disablement controls for MCP access;
  • rate limiting and abuse protections where appropriate; and
  • optimistic concurrency, preview expiry, and idempotency controls for separately authorized MCP write operations.

Annex III – Authorized Subprocessors

The then-current list of Avut’s subprocessors and other relevant third-party providers is available at: https://avut.io/privacy/subprocessors

Unless otherwise agreed, the publicly posted register is the maintained source for ongoing updates, and this Annex III is the authorized snapshot as of the effective date of this DPA for Avut-engaged subprocessors.

SubprocessorService FunctionRegion / Processing LocationTransfer mechanism if outside the EEA
ClerkAuthentication and user managementProvider-managed and account-dependentChapter V transfer mechanism as applicable under the provider contract and public register
NeonManaged PostgreSQL database hostingFrankfurt, GermanyNot expected for in-region database hosting; Chapter V mechanism where applicable for support, backups, or remote access
CloudflareR2 object storage and related media delivery functionsAutomatic location setting; exact country not guaranteedChapter V transfer mechanism as applicable under the provider contract and public register
UpstashRedis, cache, and coordination servicesProvider-managed and deployment-dependentChapter V transfer mechanism as applicable under the provider contract and public register
OpenAIAvut-operated AI featuresProvider-managed and service-dependentChapter V transfer mechanism as applicable under the provider contract and public register
Fly.ioApplication and worker hostingFrankfurt, GermanyChapter V transfer mechanism as applicable under the provider contract and public register

For clarity, customer-directed integrations and external MCP clients are described in the public register but are not, solely by reason of customer-directed connection, automatically treated as Processor’s subprocessors under this Annex III.