Data processing agreement
Last updated: 4 August 2026
This agreement applies between you as customer and Avent Digital AS, and governs how we process personal data on your behalf when operating your website. It is an annex to the terms of service and is accepted when you start using the service.
1. Parties and roles
The customer — the business using Avently — is the data controller. Avent Digital AS (org. no. 915 920 934) is the data processor. This agreement governs our processing of personal data on the customer's behalf under GDPR Article 28 and forms an annex to the terms of service.
2. What we process, and why
We process enquiries from the customer's contact form — name, email, phone, message text and any custom fields — in order to store the enquiry and notify the customer by email. We also process content the customer adds to the website, which may contain personal data (for example staff with photos). Data subjects are visitors to the customer's website and people described in the content.
Enquiries are used solely for this purpose. They are not part of our own customer register, are not used for our marketing, are never sent to AI services, and the notification goes only to the recipient address set by the customer — never in copy to us.
3. The customer's responsibilities
The customer is responsible for ensuring a valid legal basis for collection, that forms do not request more data than necessary, and for responding to data subject requests for access, rectification and erasure. We assist with export and deletion, see section 7. Special categories of personal data (health, ethnicity and similar) must not be collected via the platform.
4. Our obligations
We process personal data only on documented instructions from the customer — this agreement and the settings in the platform. We ensure that persons with access are bound by confidentiality, implement appropriate technical and organisational measures (section 6), and assist the customer with data protection impact assessments where relevant.
In the event of a personal data breach we notify the customer without undue delay, with the information the customer needs to assess notification to the supervisory authority. The 72-hour deadline rests with the customer as controller.
5. Sub-processors
The customer approves these sub-processors on entering the agreement: Supabase (database and sign-in, servers in the EU/Ireland), Vercel (hosting and operations, servers in Stockholm), Resend (delivery of notification emails) and Anthropic (AI processing of website content — never of enquiries). Changes or additions are notified at least 30 days in advance, and the customer may object on reasonable grounds.
Core operations — storage of enquiries and content — take place within the EEA. Where a sub-processor processes data outside the EEA, the transfer relies on the European Commission's Standard Contractual Clauses (SCC) or the EU-US Data Privacy Framework.
6. Security
Encryption in transit (TLS) and at rest. Row-level security in the database and per-site access control, so one customer's data is never accessible to another. Personal logins without shared passwords, automated monitoring with alerting, versioned backups with undo, and spam protection on forms that limits unwanted data collection.
7. Deletion and export
The customer can delete individual enquiries in the customer panel. On termination, enquiries and content are exported in a machine-readable format on request, and all the customer's personal data is deleted no later than 90 days after termination — including from backups, which rotate out within the same period. If we receive an erasure request from a data subject concerning the customer's data, we forward it to the customer rather than deleting on our own initiative.
8. Audit
The customer may request documentation of compliance: this agreement, the sub-processors' agreements and a description of security measures. On-site audits may be arranged where there is a justified need, at the customer's expense.
9. Term
This agreement applies for as long as we process personal data on the customer's behalf. Section 7 on deletion and export continues to apply after termination.
See also privacy policy, terms of service and data processing agreement.