Skip to addendum
AvalonTrust center · Data processingDPA request ↗

Trust center

  • Terms of Service
  • Privacy Policy
  • Acceptable Use
  • Data Processing Addendum
  • Sub-processors
  • Cookie & Tracking Notice
  • Security Policy

Effective August 7, 2026

Data Processing Addendum

This DPA governs Juno AI Labs’ processing of Customer Personal Data in Avalon and forms part of the agreement for the Services.

Processor · Juno AI LabsVersion · 2026.08

1. Scope and precedence

This Data Processing Addendum (“DPA”) applies when Juno AI Labs (“Juno”) processes Customer Personal Data on behalf of the customer identified in the Terms of Service, an Order, or another agreement for Avalon (“Customer”). It is incorporated into that agreement (the “Agreement”). If this DPA conflicts with the Agreement about processing Customer Personal Data, this DPA controls. If an executed data-protection addendum conflicts with this online DPA, the executed addendum controls.

This DPA does not apply when Juno acts as an independent controller, including for account administration, direct support, security, and Juno’s legal obligations, which are addressed in the Privacy Policy.

2. Definitions

Applicable Data Protection Law means privacy and data-protection law applicable to the processing, including, where applicable, the EU GDPR, UK GDPR, Swiss Federal Act on Data Protection, and US State Privacy Laws. Customer Personal Data means personal data contained in Customer Content that Juno processes as a processor or service provider for Customer. Data Subject, personal data, process, controller, processor, and supervisory authority have the meanings given by Applicable Data Protection Law. Security Incident means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data in Juno’s control. Sub-processor means a processor Juno engages to process Customer Personal Data.

3. Roles and instructions

Customer is the controller or processor, as applicable, and Juno is Customer’s processor or sub-processor. Customer determines the purposes and means of processing and is responsible for lawful instructions, notices, consents, rights handling, and configuration of members, connections, automations, and retention.

Juno will process Customer Personal Data only to provide, secure, support, and maintain the Services; comply with documented instructions in the Agreement and Customer’s authorized use; and meet legal obligations. If law requires other processing, Juno will inform Customer before processing unless law prohibits notice. Juno will promptly inform Customer if, in its reasonable opinion, an instruction violates Applicable Data Protection Law and may pause the affected processing while the parties resolve it.

4. Compliance and confidentiality

Each party will comply with the obligations applicable to it under Applicable Data Protection Law. Juno will ensure that personnel authorized to process Customer Personal Data are bound by confidentiality obligations and receive access only as needed for their functions.

5. Security

Taking into account the state of the art, implementation costs, and the nature, scope, context, purposes, and risks of processing, Juno will maintain appropriate technical and organizational measures designed to protect Customer Personal Data. The measures are summarized in Annex B and the Security Policy. Juno may update them as technologies and threats evolve, provided the overall level of protection is not materially diminished.

6. Sub-processors

Customer provides general written authorization for Juno to use the Sub-processors on the Sub-processors page. Juno will require each Sub-processor by written agreement to protect Customer Personal Data to a standard consistent with this DPA, to the extent applicable to the services it performs. Juno remains responsible for each Sub-processor’s performance of its data-protection obligations to the extent required by Applicable Data Protection Law.

Juno will post a new Sub-processor at least 15 days before it begins processing Customer Personal Data, except where an urgent replacement is needed to maintain security or availability. Customer may object during that period on reasonable data-protection grounds by emailing privacy@with-avalon.com. The parties will work in good faith on a commercially reasonable solution. If none is available, either party may terminate only the affected feature or Services, and Juno will refund prepaid fees for the terminated period, if any.

7. Data-subject requests

Taking into account the nature of processing, Juno will provide reasonable assistance through product controls or support so Customer can respond to requests to access, correct, delete, restrict, object to, or port Customer Personal Data. If Juno receives a request relating to Customer Personal Data, it will direct the requester to Customer where reasonably identifiable and will not respond substantively unless Customer instructs it or law requires it.

8. Security Incidents

Juno will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data. The notice will include, as information becomes reasonably available, the nature of the incident, affected data and Data Subjects, likely consequences, mitigation taken or proposed, and a contact for follow-up. Juno’s notice is not an admission of fault or liability.

Juno will take reasonable steps to contain, investigate, and remediate the incident and will provide information reasonably needed for Customer’s legally required notifications. Customer is responsible for determining whether and how to notify Data Subjects, regulators, or others, unless law assigns that duty to Juno.

9. Assessments and regulatory assistance

Taking into account the nature of processing and information available to Juno, Juno will reasonably assist Customer with data-protection impact assessments, prior consultations, and responses to supervisory authorities relating to Avalon processing. Customer will reimburse reasonable costs for assistance beyond standard product and documentation support, unless the assistance is required because Juno breached this DPA.

10. Information and audits

Juno will make available information reasonably necessary to demonstrate compliance with this DPA, which may include security documentation, summaries, questionnaires, and independent assessment reports if available. No more than once annually, or after a material Security Incident or regulator request, Customer may audit Juno’s relevant controls.

An audit must use an independent qualified auditor bound by confidentiality, occur on at least 30 days’ notice during normal business hours, avoid unreasonable disruption, and exclude other customers’ data and Juno’s unrelated confidential information. Customer bears its audit costs unless the audit identifies a material breach by Juno. The parties will use remote review and existing reports before requesting on-site inspection.

11. Return and deletion

During the term, Customer may use available controls to export or delete Customer Personal Data. On termination and Customer’s written request, Juno will delete or return Customer Personal Data within a commercially reasonable period, unless law requires retention. Deleted information may remain in encrypted, isolated backups until normal rotation, during which it remains protected and is not restored except for disaster recovery. Juno may retain security, fraud-prevention, billing, and legal records that it processes as controller.

12. International transfers

Customer authorizes processing in the selected Global or EU workspace architecture and by Sub-processors in the locations listed in the register. For a transfer of Customer Personal Data from the EEA, United Kingdom, or Switzerland to a country without an applicable adequacy decision, the parties will use a legally recognized transfer mechanism, including the applicable 2021 European Commission Standard Contractual Clauses (“SCCs”), UK Addendum, or Swiss adaptations, as required.

Where SCCs apply, the controller-to-processor or processor-to-processor module applies according to the parties’ roles; Customer is the data exporter and Juno is the data importer; the processing details and safeguards in Annexes A and B complete the corresponding annexes; docking applies; and the general Sub-processor authorization and 15-day notice period in this DPA apply. The competent authority, governing member-state law, and courts will be determined under the SCCs based on the exporter’s establishment and applicable law. Contact privacy@with-avalon.com for a signature-ready transfer addendum or deployment-specific annexes.

13. US State Privacy Laws

Where a US State Privacy Law applies, Juno acts as Customer’s processor, service provider, or contractor. Juno will not sell or share Customer Personal Data; retain, use, or disclose it outside the business purposes in the Agreement or as permitted by law; or combine it with personal information received from another person or collected from Juno’s independent interactions with a consumer, except as permitted by law to provide the Services. Customer may take reasonable steps to verify that Juno’s processing is consistent with Customer’s obligations and may require remediation of unauthorized use.

14. Liability and general terms

The liability limitations in the Agreement apply to this DPA to the extent permitted by law. This DPA terminates with the Agreement, except that obligations concerning Customer Personal Data continue while Juno retains it. Amendments required to comply with a change in Applicable Data Protection Law will be made in good faith.

Annex A · Processing details

Subject matterProvision of Avalon’s collaborative workspace, AI-assisted tasks, connected tools, work streams, automations, and support.
DurationThe Agreement term plus the deletion and backup period described above.
Nature and purposeHosting, organizing, retrieving, transmitting, analyzing, generating, summarizing, and acting on Customer Content to perform Customer’s instructions; securing and supporting the Services.
FrequencyContinuous or as initiated by authorized users, configured automations, connected events, webhooks, or inbound email.
Data SubjectsCustomer members and administrators; people who communicate with them; contacts, employees, contractors, customers, prospects, vendors, and other people represented in Customer Content.
Personal dataIdentity and contact data; account and workspace metadata; communications and documents; project, calendar, email, repository, and connected-service content; task and automation content; device, security, and audit data; other data Customer chooses to submit.
Sensitive dataNot required for ordinary use. Customer may submit sensitive data only when authorized, necessary, and covered by appropriate safeguards and an approved use case.
RetentionCustomer Content remains until an authorized user deletes the resource or workspace, unless an Order configures another period. Audit records remain for the workspace life, with limited records retained afterward as legally or operationally necessary.

Annex B · Technical and organizational measures

  • Access control: workspace-scoped authorization, role checks, short-lived sessions, narrow privileged interfaces, and least-privilege provider permissions.
  • Credential protection: authenticated encryption for connector tokens with associated context and versioned regional keys; operating-system protected desktop storage; secrets excluded from source and prompts.
  • Application security: sandboxed desktop renderer, context isolation, disabled Node integration, restrictive content policy, exact deep-link validation, and denied unexpected navigation.
  • Network and ingestion: TLS in transit, exact origin checks, signed webhooks, timestamp and replay protection, deduplication, validation, and request-size limits.
  • AI and tool boundaries: bounded authorized context, validated tool proposals, idempotent external writes, and human input when consequential outcomes are ambiguous.
  • Logging and audit: secret and content redaction; security events for sessions, membership, connectors, writes, and automations; request identifiers for investigation.
  • Resilience and response: regional infrastructure, managed storage and queues, backup and recovery controls, incident investigation, containment, remediation, and notification procedures.
  • People and providers: confidentiality duties, role-based access, provider diligence, contractual data-protection obligations, and periodic control review.

Contact

Privacy and DPA requests: privacy@with-avalon.com. General support: support@with-avalon.com.

Avalon

Work, still in context.

Terms of ServicePrivacy PolicyAcceptable UseData Processing AddendumSub-processorsCookie & Tracking NoticeSecurity PolicySupport

© 2026 Juno AI Labs · Avalon