Skip to content
AvumBeta
AboutPricingOur TeamEducationContact
Log inSign up

Data Processing Addendum

Effective and last updated: July 31, 2026

When this Addendum applies.This Data Processing Addendum ("DPA") forms part of the Terms only where the Provider defined below processes personal data on a Business User's behalf as a processor. It does not apply to Consumers, personal use of Avum, or processing for which the Provider is a controller.

1. Parties, execution, and scope

This DPA is between Pentatope Technologies Kft., company registration number 07-09-032526 ("Provider"), and the Business User on whose behalf the Provider processes personal data as a processor ("Customer"). The Provider and Customer are each a "party" and together the "parties."

This DPA is automatically incorporated into the Terms or other written agreement governing Customer's use of Avum (the "Agreement") when and to the extent the Provider processes Customer Personal Data as a processor on Customer's behalf. No separate signature or acceptance is required. Accepting the Terms or viewing this page does not make a Consumer or personal user a Customer under this DPA.

"Customer Personal Data" means personal data that the Provider processes as a processor on Customer's behalf to provide Avum. This DPA does not apply to processing for which the Provider is a controller. "Applicable Data Protection Law" means the GDPR and applicable implementing or supplemental law. Other data-protection terms have their statutory meanings.

2. Roles and responsibilities

For Customer Personal Data, Customer is the controller and the Provider is the processor. If Customer acts as another controller's processor, the Provider is Customer's subprocessor, and Customer confirms it has the necessary authorization.

Customer is responsible for:

  • ensuring its instructions and use comply with law and connected-provider agreements.
  • providing required notices and establishing a lawful basis, including for other people's data.
  • ensuring users may lawfully connect accounts and give instructions.
  • responding to individuals and authorities, with the Provider's assistance below.

The Provider remains a controller for its own customer-relationship, service-administration, security, compliance, and support purposes. That controller processing is governed by Avum's Privacy Policy. The same data may be processed in different roles for distinct purposes.

3. Documented instructions

The Provider will process Customer Personal Data only on Customer's documented instructions, including as necessary to provide, secure, support, and delete Avum as described in the Agreement, this DPA, Annex 1, and Customer's configuration and actions. Transfers are authorized only as described there, in the Subprocessor List, or further written instructions accepted by the Provider.

The Provider may process Customer Personal Data where required by European Union or Member State law. Unless that law prohibits notice on important grounds of public interest, the Provider will inform Customer of the legal requirement before processing.

The Provider will promptly inform Customer if, in the Provider's opinion, an instruction infringes Applicable Data Protection Law and may suspend it while the parties resolve the issue.

4. Personnel and confidentiality

The Provider will ensure that persons authorized to process Customer Personal Data have committed themselves to confidentiality or have an equivalent statutory duty. Access is need-to-know and controlled.

5. Security

Taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing and risks to individuals, the Provider will maintain the Article 32 GDPR measures summarized in Annex 2.

The Provider may update those measures as technology and risks change, provided that an update does not materially reduce the overall protection of Customer Personal Data during the term of the Agreement.

6. Subprocessors

Customer gives the Provider general written authorization to engage the subprocessors listed on the current Subprocessor List for the activities described there. The Provider will:

  • impose in writing the same data-protection obligations that apply to its processing under this DPA.
  • remain responsible to Customer for each subprocessor's performance of those obligations.
  • update the list and give Customer reasonable advance notice at its registered email address of a new subprocessor, or prompt notice afterward if an urgent security, availability, or legal need prevents advance notice.
  • provide information reasonably necessary for Customer to evaluate a proposed subprocessor.

Customer may object to a new subprocessor on reasonable data-protection grounds by contacting contact@avum.io within the reasonable objection period in the notice. The parties will seek a commercially reasonable solution. If none is available, either may terminate the affected Service subject to the Agreement and mandatory law.

7. Assistance to Customer

Taking into account the nature of the processing and the information available to the Provider, the Provider will reasonably assist Customer with:

  • responding to individuals exercising data-protection rights.
  • security, breach notifications, impact assessments, and prior consultation.
  • information about the Provider's processing, subprocessors, safeguards, and security measures.

If the Provider receives a request from an individual relating to Customer Personal Data and can identify the Customer, it will ordinarily refer the request and notify Customer where permitted. The Provider responds on Customer's behalf only on instruction or where law requires.

8. Personal data breaches

The Provider will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. As available, the notice will provide the information required by Article 33(3) GDPR, including the nature, likely consequences, response measures, and a contact point.

The Provider will contain, investigate, mitigate, and remediate the breach and assist with required notifications. Notice is not an admission of liability. Customer determines its own notification duties.

9. Return and deletion

During the term, Customer may retrieve Customer Personal Data using available Service functionality or request reasonable assistance where it is otherwise unavailable. When processing ends, the Provider will, at Customer's choice, delete or return Customer Personal Data and delete copies unless EU or Member State law requires storage.

Customer must communicate a return request before the applicable deletion deadline. If Customer does not do so, it instructs the Provider to follow Avum's deletion process. Backup data is put beyond ordinary use and overwritten on the applicable cycle. Irreversibly anonymized information need not be deleted.

10. Information and audits

The Provider will make available information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA. Customer should first use available documentation and independent reports.

If that information is not reasonably sufficient, Customer or an independent auditor mandated by Customer may audit relevant processing, including inspection where legally required. With reasonable notice, the parties will agree scope, timing, safeguards, and costs so the audit avoids disruption and protects other customers, security information, and third-party confidentiality. Authorities' lawful powers are unaffected.

11. International transfers

The Provider will transfer Customer Personal Data outside the European Economic Area only in compliance with Chapter V GDPR. Where a recipient is not covered by an adequacy decision or another lawful transfer mechanism, the Provider will use the applicable module of the European Commission's 2021 Standard Contractual Clauses and, where appropriate, supplementary measures. The Provider will provide information about the relevant safeguard on reasonable request, subject to necessary confidentiality and security restrictions.

12. Customer-selected providers and independent controllers

Google and Microsoft calendar services connected by Customer are customer-selected third-party services, not the Provider's subprocessors. Customer instructs the Provider to exchange data with authorized accounts, and the provider's role is governed by Customer's relationship with it.

The applicable Paddle entity acts as Merchant of Record and processes billing and transaction data under its own terms and privacy notice. Paddle and other independent controllers are outside this DPA for Customer-directed calendar processing.

13. Term, precedence, and contact

This DPA begins automatically when incorporated as described in Section 1 and the Provider begins processing Customer Personal Data as a processor, and continues until that processing ends. It prevails over conflicting Agreement terms concerning Customer Personal Data. The Agreement otherwise remains unchanged to the extent legally permitted.

Questions, execution requests, data-protection requests, and subprocessor objections may be sent to contact@avum.io.

Annex 1: Details of processing

Subject matter and duration

Provision of Avum's customer-directed calendar synchronization and unified-calendar functions, including related support, security, and deletion. Processing continues for the Service term and stated deletion and backup periods.

Nature and purposes

Retrieving and displaying calendar information, performing Customer-configured synchronization and requested operations, maintaining and securing the Service, preventing conflicting operations, and returning or deleting data.

Categories of personal data

  • authorized-user and business contact information.
  • connected-account, authorization, and OAuth credential data.
  • calendar metadata and access permissions.
  • event details and provider metadata processed transiently.
  • Customer configuration and requested actions.
  • limited operational, security, and support data.

Avum does not persist event details as a separate calendar store. Event details are processed transiently to perform requested operations. Content-free technical state may be retained under the applicable retention policy.

Categories of data subjects

  • Customer's authorized users and account administrators.
  • owners and users of connected calendar accounts.
  • other individuals represented in calendar data processed at Customer's direction.

Special categories and sensitive data

Avum permits incidental special-category content in ordinary calendar entries. It is not designed for systematic processing in which the sensitive nature of the data is material to the Customer's workflow or for processing criminal-offence data. Customer must comply with Articles 9 and 10 GDPR, minimize the data it instructs the Provider to process, and refrain from instructing any prohibited processing. This DPA's safeguards still apply.

Frequency

Processing is recurring or continuous while Customer maintains authorized connections or active Sync Rules, and on demand when an authorized user uses other Service functions.

Annex 2: Technical and organizational measures

  • Data minimization. Event details are processed transiently rather than retained as a separate calendar store. Operational records are designed to use limited technical identifiers and status information.
  • Transport and infrastructure protection. Data is encrypted in transit using current transport-security protocols. The Provider uses the at-rest protections supplied by its managed cloud infrastructure for stored service data.
  • Access control. Production and support access is limited by role and operational need, using least-privilege practices. Access to event details for support is exceptional and subject to scoped authorization and confidentiality controls.
  • Credential and secret handling. Credentials and other secrets are restricted to systems and personnel that need them and are kept out of ordinary application logs.
  • Environment separation. Production systems and credentials are separated from development and test environments using technical and organizational controls.
  • Logging and monitoring. The Provider uses security, availability, and error monitoring. Logging is designed to avoid event details and OAuth secrets and to minimize directly identifying data.
  • Availability and recovery. Managed cloud resilience, backups where appropriate, retry and recovery controls, and operational monitoring support continued availability and restoration.
  • Secure maintenance. The Provider maintains risk-based security maintenance, testing, and remediation processes.
  • Incident response. The Provider maintains procedures for responding to and communicating personal data breaches.
  • Supplier governance. Processors are selected and managed through contractual data-protection and security obligations, with transfer safeguards where required.
AboutEducationImprove AvumTerms & ConditionsPrivacy PolicyContactSupport