Skip to main content
ColleagueOne
Product
OverviewColleagues & teamsWorkspaceAutomationsConnectionsGovernance & security
Use casesSecurityDocsCompany
Sign inRequest access
ProductUse casesSecurityDocsCompanyRequest accessSign in
Draft — pending legal review

Legal · Data processing

Data Processing Addendum summary

This non-binding summary outlines the data-processing terms Avapti intends to make available to ColleagueOne business customers. A signed DPA, not this page, will govern processing.

Effective date: [DATE]

On this page

  1. Status and parties
  2. Processing details
  3. Processor commitments
  4. Security and incidents
  5. Subprocessors and transfers
  6. Rights and assistance
  7. End of service
  8. Contact

1. Status and parties

This page is a plain-language product summary, not an executed data processing addendum or legal advice. The customer agreement and a DPA signed by [AVAPTI LEGAL ENTITY] and the customer will control. The final DPA must identify the governing legal framework, parties, notices and any required transfer mechanism.

For customer workspace content, the customer generally acts as controller and Avapti as processor or service provider. Each party remains responsible for its independent processing and legal obligations.

2. Processing details

The subject matter is providing, securing, supporting and improving the contracted ColleagueOne service for the customer. Processing continues for the subscription or private-beta access period plus the limited retention and deletion period stated in the executed agreement.

Data may include account names and email addresses; goals, conversations and instructions; files and generated documents, presentations, PDFs and spreadsheets; results, approvals, reviewed memory; colleague, plugin and connection configuration; and service, security and audit records. Data subjects may include customer users, personnel, contacts and people described in content the customer chooses to submit.

3. Processor commitments

The intended DPA will require Avapti to process personal data only on the customer’s documented instructions, including instructions expressed through authorised use of the service, unless applicable law requires otherwise. Personnel authorised to process customer data will be subject to appropriate confidentiality obligations.

Avapti will not sell customer personal data or use it for targeted advertising. Model providers may process workspace content as needed to provide the selected model service through the gateway, subject to the applicable agreement and provider configuration.

4. Security and incident response

Relevant product measures include a separate Firecracker microVM sandbox for each colleague, gateway-held credentials, per-run scoped model access, budgets, sensitive-action approvals, data-classification labels, DLP policy, roles, enterprise identity options and audit logging. Measures remain subject to the service configuration and do not constitute a certification claim.

The intended DPA will require notice to the customer without undue delay after Avapti confirms a personal-data breach affecting customer data, together with information reasonably available to support the customer’s response. Exact notification contacts and any contractual period belong in the executed DPA.

5. Subprocessors and international transfers

Avapti uses subprocessors to provide the service. The current draft list identifies DigitalOcean for hosting in Bangalore, Google for sign-in, and OpenRouter or model providers selected through the gateway. See the draft Subprocessors page.

The executed DPA should define customer notice and objection rights for material subprocessor changes and require substantially equivalent data-protection obligations. It must also identify the lawful transfer mechanism required for relevant cross-border processing. ColleagueOne does not claim UAE data residency.

6. Data-subject rights and compliance assistance

Taking account of the nature of processing and information available, the intended DPA will require reasonable assistance with data-subject requests, security obligations, impact assessments and regulator consultations where applicable. Customers should first use available service controls and provide enough information to identify the relevant organisation and data.

Avapti will make information reasonably necessary to demonstrate compliance with the executed DPA available under agreed confidentiality, scope and frequency terms. Audit language, costs and any independent-report process remain [TO BE CONFIRMED IN THE EXECUTED DPA].

7. Return and deletion at the end of service

At the customer’s choice and subject to the executed agreement, Avapti will delete or return customer personal data after service ends unless law requires retention. The final DPA must state export methods, backup handling, deletion timing and any limited legal or security retention.

8. Contact and next steps

Private-beta customers should request the current DPA through their Avapti contact. General questions may be sent to hello@avapti.com. Privacy requests are also described in the Privacy Policy.

ColleagueOne

AI colleagues that do real work,
under your governance.

Invite-only beta

Product

Colleagues & teamsWorkspaceAutomationsConnectionsGovernance & securityRequest access

Resources

DocumentationAPI referenceChangelogStatus

Company

AboutContactSecurityResponsible disclosure

Legal

PrivacyTermsCookie noticeAcceptable useDPA summarySubprocessors

© 2026 Avapti. All rights reserved.

Built for accountable work.