Legal / Data Processing Agreement
Version 1.0 · Last updated: May 23, 2026
This DPA is incorporated into the Terms of Service and governs how Avalori, as Processor, handles institutional data on behalf of the Customer, as Controller. In case of conflict, this DPA controls on data processing matters.
Avalori will process Institutional Data only in accordance with the Controller's documented instructions, as reflected in these Terms of Service and DPA, the platform configuration, and explicit written requests to [email protected].
| Data category | Processing purpose |
|---|---|
| COUNTER5 reports (JSON/TSV) | Usage analysis, cost-per-use, overlap detection, and renewal recommendations |
| SUSHI 5.0 credentials | Automated harvesting of statistics from external vendors |
| EZproxy access logs | Access monitoring, geographic analysis, and user-level analytics |
| Repository metadata (OAI-PMH) | FAIR evaluation and institutional bibliometric analysis |
| Circulation records and inventory | Loan analysis and physical collection evaluation |
Avalori processes Institutional Data for the duration of the service agreement. Upon termination, data remains available for export for 30 days, after which it will be securely deleted within 60 additional days.
| Sub-processor | Function | Country | Safeguard |
|---|---|---|---|
| Supabase, Inc. | PostgreSQL database and authentication | United States | DPA / SCCs |
| Vercel, Inc. | Application hosting and CDN | United States | DPA / SCCs |
Avalori will notify Controller at least 10 days before any sub-processor change. Failure to object within that period constitutes acceptance.
Avalori will notify Controller within 72 hours of becoming aware of a Security Incident, including nature of the incident, data categories affected, and mitigation measures taken.
If Avalori receives a request from an individual related to Controller's Institutional Data, it will promptly redirect it to Controller and provide technically feasible assistance.
Avalori will assist Controller in conducting Privacy Impact Assessments by providing technical information about its processing operations as needed.
Controller may audit compliance with this DPA with 30 days' written notice. Avalori may satisfy this right by providing current third-party audit reports (SOC 2 Type II or equivalent).
This DPA is governed by the laws of the State of Florida, United States. Both parties agree to comply with applicable US federal and state privacy laws, including the CCPA where applicable.
[email protected] · Gruppo Suma LLC · Florida, United States.