Legal / Data Processing Agreement

Data Processing Agreement (DPA)

Version 1.0 · Last updated: May 23, 2026

This DPA is incorporated into the Terms of Service and governs how Avalori, as Processor, handles institutional data on behalf of the Customer, as Controller. In case of conflict, this DPA controls on data processing matters.

1. Definitions

Controller:
The academic institution or university library that contracts the Service and determines the purposes and means of processing its institutional data.
Processor:
Avalori (Gruppo Suma LLC), which processes institutional data solely on the Controller's documented instructions.
Institutional Data:
COUNTER5 reports, SUSHI 5.0 credentials, EZproxy access logs, repository metadata, circulation records, and physical inventory data uploaded or generated in the Service.
Sub-processor:
A third party engaged by Avalori to process Institutional Data on its behalf.
Security Incident:
Any unauthorized access, disclosure, alteration, loss, or destruction of Institutional Data.

2. Processing instructions

Avalori will process Institutional Data only in accordance with the Controller's documented instructions, as reflected in these Terms of Service and DPA, the platform configuration, and explicit written requests to [email protected].

3. Categories of data and purposes

Data categoryProcessing purpose
COUNTER5 reports (JSON/TSV)Usage analysis, cost-per-use, overlap detection, and renewal recommendations
SUSHI 5.0 credentialsAutomated harvesting of statistics from external vendors
EZproxy access logsAccess monitoring, geographic analysis, and user-level analytics
Repository metadata (OAI-PMH)FAIR evaluation and institutional bibliometric analysis
Circulation records and inventoryLoan analysis and physical collection evaluation

4. Duration of processing

Avalori processes Institutional Data for the duration of the service agreement. Upon termination, data remains available for export for 30 days, after which it will be securely deleted within 60 additional days.

5. Sub-processors

Sub-processorFunctionCountrySafeguard
Supabase, Inc.PostgreSQL database and authenticationUnited StatesDPA / SCCs
Vercel, Inc.Application hosting and CDNUnited StatesDPA / SCCs

Avalori will notify Controller at least 10 days before any sub-processor change. Failure to object within that period constitutes acceptance.

6. Security measures

  • Encryption in transit (TLS 1.2+) and at rest (AES-256).
  • Per-institution data isolation via Row-Level Security (RLS) in PostgreSQL.
  • Role-based access control (RBAC) with least-privilege principles.
  • Audit logs of administrative access to production data.
  • Periodic security reviews and documented incident response plan.

7. Security incident notification

Avalori will notify Controller within 72 hours of becoming aware of a Security Incident, including nature of the incident, data categories affected, and mitigation measures taken.

8. Data subject rights

If Avalori receives a request from an individual related to Controller's Institutional Data, it will promptly redirect it to Controller and provide technically feasible assistance.

9. Privacy impact assessments

Avalori will assist Controller in conducting Privacy Impact Assessments by providing technical information about its processing operations as needed.

10. Audit rights

Controller may audit compliance with this DPA with 30 days' written notice. Avalori may satisfy this right by providing current third-party audit reports (SOC 2 Type II or equivalent).

11. Governing law

This DPA is governed by the laws of the State of Florida, United States. Both parties agree to comply with applicable US federal and state privacy laws, including the CCPA where applicable.

12. Contact

[email protected] · Gruppo Suma LLC · Florida, United States.