Skip to main content

Data Processing Agreement (DPA)

Template Version: 1.0 Effective Date: [DATE]


This Data Processing Agreement ("DPA") is entered into between:

Data Controller: [CUSTOMER_LEGAL_NAME], a company registered at [CUSTOMER_ADDRESS] ("Customer")

Data Processor: Pavri, Inc., a company incorporated in [STATE], USA ("Pavri")

Together referred to as the "Parties."

This DPA supplements and forms part of the Master Service Agreement or Terms of Service between the Parties ("Agreement").


1. Definitions

  • Personal Data: Any information relating to an identified or identifiable natural person processed under this DPA
  • Processing: Any operation performed on Personal Data
  • Sub-processor: Any third party engaged by Pavri to process Personal Data on behalf of Customer
  • Data Breach: A confirmed breach of security leading to accidental or unlawful access to Personal Data

2. Scope of Processing

2.1 Subject Matter

Pavri processes Personal Data as necessary to provide the AI agent security monitoring services described in the Agreement.

2.2 Nature and Purpose

Processing ActivityPurpose
Agent telemetry ingestionMonitoring AI agent behavior for security threats
Policy enforcement decisionsApplying governance rules to agent actions
Audit log storageCompliance evidence and incident investigation
Session analysisThreat detection and operator visibility

2.3 Categories of Data Subjects

Customer's employees, contractors, and end users whose interactions generate agent telemetry.

2.4 Categories of Personal Data

  • Operational data: IP addresses in audit logs, user identifiers in session metadata
  • Agent-generated data: Tool call metadata, model invocation summaries
  • Account data: Names, email addresses of dashboard users

Note: Pavri does not receive or store raw AI model prompts or outputs by default. Log forwarding of prompt content is opt-in and subject to additional controls.


3. Pavri's Obligations

3.1 Processing on Instructions Only

Pavri processes Personal Data only on Customer's documented instructions, except where required by applicable law.

3.2 Confidentiality

Pavri ensures persons authorized to process Personal Data are bound by appropriate confidentiality obligations.

3.3 Security

Pavri implements appropriate technical and organizational measures including:

  • TLS 1.2+ for data in transit
  • AES-256 for data at rest
  • Role-based access controls
  • Annual security training for personnel with data access
  • Incident response procedures (see Incident Response Plan)

3.4 Sub-processors

Customer authorizes Pavri to use Sub-processors. Pavri maintains a current list of Sub-processors at [SUBPROCESSOR_LIST_URL]. Pavri will:

  • Give 30 days' prior notice of new Sub-processors
  • Impose equivalent data protection obligations on Sub-processors
  • Remain liable for Sub-processor performance

3.5 Data Subject Rights

Pavri will assist Customer in responding to Data Subject rights requests within the agreed timeframes. Requests may be submitted to privacy@pavri.ai.

3.6 Data Breach Notification

Pavri will notify Customer of a confirmed Data Breach within 72 hours of becoming aware, providing:

  • Nature of the breach
  • Categories and approximate number of data subjects affected
  • Likely consequences
  • Measures taken or proposed to address the breach

3.7 Data Deletion

Upon termination of the Agreement or written request, Pavri will delete all Customer Personal Data within 30 days, except where retention is required by law. Encrypted backup copies will be purged after the 30-day backup retention period.

3.8 Audits

Customer may audit Pavri's compliance with this DPA once per year with 30 days' notice, or following a Security Incident. Audits may be conducted through questionnaire, documentation review, or on-site inspection (at Customer's cost).


4. Customer's Obligations

Customer warrants that:

  • It has a valid legal basis for the Personal Data it submits for processing
  • It has provided appropriate notices to Data Subjects
  • It will not submit Special Category Data (health, financial, etc.) without explicit written agreement

5. International Data Transfers

Where Personal Data is transferred from the EU/EEA to Pavri in the US, the Parties agree that the EU Standard Contractual Clauses (Controller to Processor, 2021/914/EU) are hereby incorporated by reference and form part of this DPA.


6. Liability

Each Party's liability under this DPA is subject to the limitations set out in the Agreement.


7. Term

This DPA is effective upon execution and remains in force for the duration of the Agreement.


8. Signatures

Data Controller:

Signature: ___________________________ Name: [CUSTOMER_SIGNATORY_NAME] Title: [CUSTOMER_SIGNATORY_TITLE] Date: [DATE]

Data Processor (Pavri, Inc.):

Signature: ___________________________ Name: [PAVRI_SIGNATORY_NAME] Title: [PAVRI_SIGNATORY_TITLE] Date: [DATE]


Appendix A — Sub-processor List: [SUBPROCESSOR_LIST_URL] Appendix B — Standard Contractual Clauses: Incorporated by reference (2021/914/EU)