Avista Care & Avista Chat – Data Processing Agreement (DPA)
Last Updated: 1st of December, 2025
This Data Processing Agreement (“DPA”) forms part of the Terms of Service or any other written or electronic agreement between the Customer (“Controller”) and Avista (“Processor”) for the use of Avista Care and Avista Chat (the “Services”).
This DPA ensures compliance with the EU General Data Protection Regulation (GDPR) and governs how Avista processes personal data on behalf of the Customer.
1. Definitions
“Controller” means the Customer who determines the purposes and means of processing personal data.
“Processor” means Avista, which processes personal data on behalf of the Controller.
“Personal Data” means any information relating to an identified or identifiable natural person.
“Processing” means any operation performed on personal data, such as collection, storage, transmission, or deletion.
“Sub-processor” means any third-party processor engaged by Avista.
“Services” means Avista Care (website maintenance & monitoring) and Avista Chat (AI chatbot services).
2. Scope of Processing
Avista processes personal data solely for the following purposes:
Avista Care
Website monitoring, updates, backups, and performance services
Logging and diagnostics
Security scanning
Customer support
Avista Chat
Training and operating chatbots using customer-provided data
Handling prompts, messages, logs, and uploaded documents
Monitoring usage and performance
Providing support and analytics
Avista processes data only according to the Controller’s documented instructions.
Overview of Avista Chat data flow:
3. Types of Data Processed
Depending on the Services used, Avista may process:
Chat messages, uploaded documents, or AI training inputs (Avista Chat)
Technical information (IP addresses, browser data, error logs)
Billing information (handled by payment processors)
Avista does not use Customer data to train external AI models or for advertising.
4. Duration of Processing
Processing continues for the duration of the Customer’s subscription and is limited to what is needed to deliver the Services. Upon termination, Avista deletes or anonymizes data in accordance with Section 10.
5. Obligations of the Processor (Avista)
Avista agrees to:
Process data only on Controller’s instructions
Maintain confidentiality
Implement appropriate technical and organizational security measures
Assist the Controller in fulfilling GDPR obligations
Notify Controller of data breaches without undue delay
Keep updated records of processing activities
Ensure employees and contractors follow security and privacy policies
6. Sub-Processors
The Controller authorizes Avista to use Sub-processors for hosting, backups, monitoring, AI inference, analytics, and support tools. Avista will: