Legal
Data Processing Agreement
Version 2026-07-20 · Adveron Technologies Pte Ltd
1. Parties and scope
This Data Processing Agreement (DPA) is entered into between Adveron Technologies Pte Ltd (Adveron Atlas, the data processor) and the customer organisation that accepts it (Customer, the data controller). It is incorporated by reference into, and forms part of, the Terms of Service.
This DPA applies where, and to the extent that, Adveron Atlas processes personal data on the Customer's behalf in the course of providing the Atlas services, and where that personal data is subject to data-protection law including the EU GDPR, the UK GDPR, and the Singapore Personal Data Protection Act (PDPA).
By accepting the Terms of Service, the person accepting confirms they have authority to bind their organisation to this DPA.
2. Roles of the parties
As between the parties, the Customer is the controller and Adveron Atlas is the processor of the personal data that the Customer and its authorised users submit to the services (Customer Personal Data). Adveron Atlas processes Customer Personal Data only on documented instructions from the Customer, which include the Terms of Service, this DPA, and use of the services' features.
Personal data that Adveron Atlas processes for its own purposes — such as account administration, billing, and security — is governed by the Privacy Policy, under which Adveron Atlas acts as a controller.
3. Subject matter, duration, nature and purpose
Subject matter and duration: processing lasts for the term of the Customer's subscription and any period required to return or delete data as set out below.
Nature and purpose: hosting, storage, and processing of Customer Personal Data to provide the Atlas CRM, ERP, class-scheduling, billing, and AI-assistant functionality selected by the Customer.
- Categories of data subjects: the Customer's own customers, leads, employees, coaches, students, and other end users whose data the Customer chooses to enter.
- Categories of personal data: identifiers and contact details, account and scheduling records, transaction and billing metadata, communications, and any other personal data the Customer submits.
- The Customer must not submit special-category data except where the services are explicitly configured for it and the Customer has a lawful basis to do so.
4. Processor obligations
- Process Customer Personal Data only on the Customer's documented instructions, including for international transfers, unless required by law (in which case Adveron Atlas will inform the Customer where legally permitted).
- Ensure that personnel authorised to process Customer Personal Data are bound by confidentiality obligations.
- Implement appropriate technical and organisational measures as described in Section 5.
- Assist the Customer, taking into account the nature of processing, in fulfilling its obligations to respond to data-subject requests and to maintain security, breach notification, and data-protection impact assessments.
5. Security measures
Adveron Atlas maintains technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, appropriate to the risk. These include:
- Encryption of data in transit (TLS) and at rest.
- Logical tenant isolation, with each Customer's data held in a dedicated database.
- Least-privilege access controls, centralised authentication, and audit logging.
- Network controls including a web application firewall and edge protection.
- Regular backups and a documented recovery process.
6. Sub-processors
The Customer provides a general authorisation for Adveron Atlas to engage the sub-processors listed below to process Customer Personal Data. Each sub-processor is bound by data-protection terms no less protective than those in this DPA.
Adveron Atlas will give the Customer prior notice of any intended addition or replacement of a sub-processor by updating this list, giving the Customer the opportunity to object on reasonable data-protection grounds. The list on this page is the current, authoritative sub-processor list.
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure, database, file storage, and transactional email (SES). | Singapore (ap-southeast-1) |
| Stripe | Payment processing and subscription billing. | United States / global (PCI-DSS certified) |
| Anthropic (Claude, via AWS Bedrock) | AI assistant inference. Processed within the AWS region; not used to train third-party models. | Singapore (ap-southeast-1) |
| Cohere (Embed, via AWS Bedrock) | Text embeddings for search and retrieval. | Singapore (ap-southeast-1) |
| Zhipu AI / Z.ai (GLM models) | Supplementary AI inference for the AI assistant. | Singapore region |
| Authentication and platform services where enabled by the Customer. | United States / global |
7. International transfers
The Atlas services are hosted in Singapore (AWS ap-southeast-1). Where Customer Personal Data originating in the EEA or the UK is transferred to Singapore or to a sub-processor outside the EEA/UK, that transfer is made under an appropriate transfer mechanism, including the European Commission's Standard Contractual Clauses (SCCs) and, for UK data, the UK International Data Transfer Addendum (IDTA), which are incorporated into this DPA by reference and completed in favour of the Customer as data exporter.
For personal data subject to the Singapore PDPA, Adveron Atlas takes reasonable steps to ensure a comparable standard of protection to that under the PDPA for any transfer outside Singapore.
8. Data-subject requests
Taking into account the nature of the processing, Adveron Atlas will assist the Customer by appropriate technical and organisational measures, insofar as possible, in responding to requests from data subjects to exercise their rights of access, rectification, erasure, restriction, portability, and objection.
Where a data subject submits such a request directly to Adveron Atlas, Adveron Atlas will, without undue delay, direct the request to the relevant Customer rather than respond directly, unless legally required to do so.
To honour erasure requests while preserving the integrity of financial and audit records, Adveron Atlas may satisfy a deletion instruction by irreversibly anonymising personal data where outright deletion would break referential or regulatory record-keeping requirements.
9. Personal-data breaches
Adveron Atlas will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data, and will provide the Customer with information reasonably available to assist the Customer in meeting its own breach-notification obligations (including the GDPR 72-hour timeline where applicable).
10. Audit and certifications
Adveron Atlas will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA, and will contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, subject to reasonable notice, confidentiality, and frequency limits, and in a manner that does not compromise the security or confidentiality of other customers.
Where Adveron Atlas holds relevant third-party certifications or attestations, it may satisfy audit requests by providing those reports.
11. Return and deletion of data
On termination or expiry of the Customer's subscription, Adveron Atlas will, at the Customer's choice, return or delete Customer Personal Data within a reasonable period, unless retention is required by law. Backups are deleted in the ordinary course of Adveron Atlas's backup-rotation cycle.
12. General
This DPA is governed by the laws of Singapore. In the event of a conflict between this DPA and the Terms of Service on the subject of personal-data processing, this DPA prevails. All other terms of the Terms of Service remain in full force.
If your organisation requires a counter-signed copy of this DPA on company letterhead for procurement or compliance, contact contact@adverontech.com.