Last updated: September 2026
Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the Terms of Service and governs Aventra Wellness's processing of personal data on behalf of tenants. The tenant is the Controller; Aventra is the Processor. This DPA applies to all verticals and, for medical tenants, is read together with the BAA.
1. Roles & scope
The tenant (Controller) determines the purposes and means of processing client and staff personal data. Aventra (Processor) processes that data only on documented instructions from the tenant, as set out in the Terms and the tenant's workspace configuration. This DPA covers all processing performed to deliver the service.
2. Categories of data & subjects
- Data subjects: tenant clients, members, staff, and authorized users.
- Categories of data: contact details, identifiers, appointment and transaction records, and, for medical tenants, health information governed by the BAA.
- Purposes: booking, point of sale, marketing, staffing, clinical charting, and reporting.
3. Processor obligations
Aventra will process personal data only on the tenant's documented instructions, including with regard to transfers, unless required by law. Aventra will not engage sub-processors without appropriate data-protection terms, will ensure personnel are bound by confidentiality, and will support the tenant's obligations to data subjects.
4. Security measures
- Encryption in transit (TLS) and at rest.
- Role-based, least-privilege access with audit logging.
- Logical tenant isolation and regular backup testing.
- Incident response and breach notification procedures.
- Periodic security review and sub-processor due diligence.
5. Sub-processors
Aventra uses sub-processors for cloud hosting, payment processing (Base44 Payments / Wix; Stripe where configured), and transactional email. A current list is available on request. Aventra remains liable for sub-processor performance and ensures flow-down of equivalent obligations. Tenants will be notified of material changes to sub-processors.
6. Data subject rights & assistance
Taking into account the nature of processing, Aventra will assist the tenant with data subject requests (access, rectification, erasure, portability, objection) and with impact assessments where required, by providing the functionality and data exports available in the platform.
7. Breach notification
Aventra will notify the tenant of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware, providing sufficient information for the tenant to meet its own notification obligations.
8. International transfers
Where personal data is transferred outside its jurisdiction of origin, Aventra relies on appropriate safeguards, including Standard Contractual Clauses or an equivalent transfer mechanism, and requires the same of its sub-processors.
9. Return & deletion on termination
Upon termination, Aventra will, at the tenant's choice, return or delete personal data, and delete existing copies unless retention is required by law. Data retained under legal obligation remains protected under this DPA.
10. Audit
The tenant may verify Aventra's compliance through third-party audit reports (e.g., SOC 2 Type II) made available upon reasonable request, supplemented by written information where necessary.
Questions about this document? Email legal@aventrawellness.com.
