Data Processing Agreement (transmission contract)
Published by: AvanceAI LLC
Version: 2026-07-26.1
Last updated: July 26, 2026
This document sets the personal-data processing terms between the AVA by Avance customer (“Customer”) and AvanceAI LLC, a Utah limited liability company, United States (“Avance,” “we”). It is both a data processing agreement and the transmission contract referred to in Article 25 of Colombian Decree 1377 of 2013.
- Customer: acts as responsable (controller).
- Avance: acts as encargado (processor) for personal data the Customer entrusts to us when using AVA,
avance.ai, andapp.avance.ai.
Registered business address: <PLACEHOLDER: Utah registered business address>.
Privacy contact: privacy@avance.ai.
1. Subject matter
To govern Avance’s processing, on the Customer’s behalf, of personal data of data subjects located primarily in Colombia, in connection with AVA (CRM, messaging, automation, websites, advertising conversions, and related features).
2. Duration
This agreement applies while the Customer maintains an active account or Avance retains the Customer’s personal data to provide the service, meet legal obligations, or complete deletion or return at the end of the relationship, as described in section 11.
3. Nature and purpose of processing
Avance processes personal data only to:
- provide, operate, secure, and improve AVA according to the Customer’s documented instructions and product documentation;
- authenticate users, maintain sessions, and enforce access controls;
- send and receive messages (including WhatsApp, Facebook, and Instagram when the Customer connects them);
- run automations, AI-assisted analysis, and retrieval-augmented context (RAG) when the Customer uses those features;
- process advertising conversions and measurement the Customer configures (for example Meta Conversions API, Google Ads);
- bill and collect for the service; and
- meet applicable legal duties and notify security incidents.
Avance does not process the Customer’s personal data for Avance’s own marketing directed at the Customer’s data subjects.
4. Categories of data
Depending on what the Customer uploads, captures, or connects, categories may include:
- identity and contact data (name, email, phone, and similar);
- conversation and messaging data;
- product-usage and authentication metadata;
- advertising and click identifiers (for example
fbc/fbp,gclidwhen present); - IP addresses and derived geolocation data (including enrichment via ip-api.com on the Conversions API path; see /subprocessors);
- Customer payment and billing data (not the Customer’s end-customers’ card data, except where a payment subprocessor processes it directly);
- content and files uploaded by the Customer or its users.
5. Categories of data subjects
- the Customer’s prospects, customers, and contacts;
- the Customer’s authorized users (employees, contractors, independent professionals);
- visitors of Customer sites or forms connected to AVA;
- other individuals whose data the Customer enters into AVA.
6. Avance’s obligations as encargado
Avance will:
- process data only under the Customer’s lawful instructions and this agreement;
- not use the data for purposes other than those stated here;
- keep personal data confidential and require confidentiality from authorized personnel;
- implement security measures appropriate to the risk (section 7);
- not transmit or transfer data to third parties except as authorized in section 8 or required by law;
- assist the Customer with consultas and reclamos (section 9) and security incidents (section 10);
- delete or return data when the service ends (section 11);
- make available reasonable information needed to demonstrate compliance with this agreement (section 12);
- inform the Customer if, in Avance’s opinion, an instruction infringes Law 1581 of 2012, Decree 1377 of 2013, or other applicable data-protection rules.
7. Security measures
Without limiting /security, Avance applies, among other controls: encryption in transit (TLS); encryption at rest for the managed database on AWS; automated backups; role-based access control; logical tenant isolation; infrastructure audit logging; and MFA for administrative access. Measures are reviewed as risk and the service evolve.
8. Subprocessors
The Customer authorizes Avance to use the subprocessors listed at /subprocessors for the purposes stated there. Avance will impose data-protection obligations on those subprocessors that are no less protective than this agreement, to the extent the service allows. Avance will notify material changes to that list as described on the subprocessors page.
9. Assistance with consultas and reclamos (Law 1581, Arts. 14–15)
As encargado, Avance will assist the Customer (responsable) in handling:
- Consultas: within ten (10) business days after the request, where the response depends on information or actions in Avance systems;
- Reclamos: within fifteen (15) business days after the request, on the same terms.
The Customer remains the point of contact for the data subject and before Colombia’s Superintendence of Industry and Commerce (SIC), unless law or an authority requires otherwise. Requests to the processor may be sent to privacy@avance.ai.
10. Security incidents and notification to the SIC
If Avance becomes aware of a security breach affecting personal data processed on the Customer’s behalf, Avance will notify the Customer without undue delay, with available information that enables the Customer to meet its duties as responsable, including any required notice to the SIC and to data subjects.
The chain is: Avance (encargado) → Customer (responsable) → SIC / data subjects, under Colombian rules and the Customer’s assessment. Avance does not assume SIC notification on the Customer’s behalf unless a separate written agreement says so.
11. Deletion and return on termination
When the contractual relationship ends or the Customer reasonably requests in writing:
- account or location deletion follows the
active→pending_deletion→purgedcycle with a ~30-day grace period described at /en/data-deletion (duringpending_deletion, login and API access remain available; restore is support-operated); - Avance will delete or return the Customer’s personal data in production systems under its control after that window ends (and the daily purge runs), except where retention is legally required, needed to resolve disputes or enforce rights, or covered by the de-identified audit exception;
- backups are removed on the ordinary retention cycle (currently automated RDS backups with a 30-day retention), not instantly.
There is no self-serve export feature. If the Customer needs a copy of its data before deletion, it must request one at support@avance.ai or privacy@avance.ai. Avance will handle reasonable return requests through support channels and does not promise self-serve product formats or timelines.
12. Audit rights
The Customer may request, with reasonable notice and no more than once every twelve (12) months (unless there is an incident or authority demand), reasonable information or evidence about security measures and compliance with this agreement. Avance may satisfy the request through documentation, questionnaires, or—when strictly necessary and after agreeing scope, confidentiality, and costs—a limited audit that does not endanger other customers’ security.
13. International transfer to the United States
AVA’s infrastructure runs in AWS us-east-1 (United States). Personal data of Colombian data subjects is transferred internationally to the USA to provide the service.
The Customer, as responsable, elects that transfer by contracting AVA. Avance acts as encargado/recipient in the USA. The Customer must consider Colombia’s international-transfer rules and SIC information on adequacy listings or other applicable mechanisms. This agreement does not replace the Customer’s own analysis or required authorizations.
Avance does not operate AVA production infrastructure in Colombia and does not claim Colombian IPs or data centers for this product.
14. National Registry of Databases (RNBD)
Registration or updating in the RNBD, when required (including the 100,000 UVT asset threshold or other applicable criteria), is the Customer’s obligation as responsable, not Avance’s as encargado. Avance does not register the Customer’s databases in the RNBD.
15. Governing law and disputes
This agreement is governed by the laws of the State of Utah, United States, without prejudice to Colombian data-protection rules that are mandatory for processing relating to data subjects in Colombia. The courts of the State of Utah have exclusive jurisdiction over contractual disputes between the parties, except where mandatory law provides otherwise.
16. Contact
- Privacy: privacy@avance.ai
- Security: security@avance.ai
- Support: support@avance.ai