Plain Language Summary
This agreement governs how Avondale.AI handles your data during a commercial engagement. Key points: your data stays on our sovereign, on-premise infrastructure in the United States. No data goes to any third-party cloud. We do not train AI models on your data. Data is purged within 30 days after the engagement ends. We use encryption, access controls, and physical security to protect your data. If something goes wrong, we notify you within 72 hours.
Effective Date: August 9, 2026
1. Parties and Incorporation
This Data Handling Agreement ("DHA" or "Agreement") is entered into between Avondale.AI ("Avondale.AI," "we," "us," "our") and the entity engaging Avondale.AI for commercial services ("Client," "you," "your"). This Agreement is incorporated by reference into and forms part of the Avondale.AI Terms of Service. In the event of a conflict between this Agreement and the Terms of Service, the Terms of Service control. This Agreement applies to commercial engagements only. Consumer products, when available, are governed by separate terms.
2. Definitions
- "Client Data" means any data, information, materials, or content provided by the Client to Avondale.AI for the purpose of performing Services during an Engagement, including but not limited to: configuration files, policy documents, network architecture diagrams, system logs, user directories, compliance documentation, and any data derived from or generated by analysis of such materials.
- "Derived Data" means any output, analysis, finding, or content produced by Avondale.AI through processing Client Data, including AI-generated analysis, expert findings, Deliverables, and discovery knowledge bases.
- "Processing" means any operation performed on Client Data, including collection, analysis, transformation, storage, retrieval, display, transmission, or destruction.
- "Personal Data" means any information relating to an identified or identifiable natural person, to the extent such information is included in Client Data.
- "Engagement" has the meaning defined in the Terms of Service.
3. Data We Collect
Avondale.AI collects and processes only the Client Data necessary to perform the Services defined in the applicable Engagement. This may include:
- Infrastructure Data: System configurations, service configurations, network architecture, user directories, access control lists, device inventories;
- Compliance Data: Existing policies, procedures, control documentation, audit reports, risk assessments, remediation records;
- Operational Data: System logs, performance metrics, network traffic summaries, error logs;
- Identity Data: User account names, role assignments, group memberships (as needed for access control analysis).
Avondale.AI does not collect more data than is necessary for the Engagement. If the Client provides data that Avondale.AI does not need, Avondale.AI will flag it and exclude it from processing. The Client is responsible for ensuring all Client Data provided to Avondale.AI is properly authorized for sharing under applicable law and any obligations to third parties.
4. How Data Is Processed
Client Data is processed for the sole purpose of performing the Services defined in the Engagement. Processing activities include:
- Analysis: AI-assisted and expert analysis of Client Data to produce findings, gap analyses, and recommendations;
- Cross-Referencing: Mapping Client Data against compliance frameworks, security standards, and best practices;
- Knowledge Base Compilation: Organizing Client Data and findings into structured knowledge bases in requested formats;
- Deliverable Production: Generating reports, roadmaps, policies, and other Deliverables for the Client.
Client Data is not processed for any purpose other than performing the Services. Avondale.AI does not use Client Data for marketing, product development, model training, service improvement, or any purpose unrelated to the Engagement. See Section 7 for the prohibition on model training.
5. Where Data Is Processed
Sovereign, On-Premise, United States Only
All processing of Client Data occurs on Avondale.AI's sovereign, on-premise infrastructure located within the United States. No Client Data leaves Avondale.AI's controlled infrastructure.
- Processing Location: Avondale.AI's on-premise infrastructure, physically located in the United States;
- No Third-Party Cloud: Client Data is not transmitted to, stored on, or processed by any third-party cloud service (AWS, Azure, GCP, or others) unless explicitly agreed in writing in the Engagement;
- No Offshore Processing: Client Data is not transmitted to, stored on, or processed by any system located outside the United States;
- Transfer Restrictions: Client Data is not transferred to any third party without the Client's written consent, except as required by law;
- Network Isolation: The infrastructure processing Client Data is network-isolated. Outbound connections are restricted to Avondale.AI-authorized endpoints only. No inbound remote connections are accepted.
6. Security Measures
Avondale.AI implements and maintains reasonable and appropriate technical, physical, and organizational security measures to protect Client Data. These measures include:
Technical Security
- Encryption at Rest: Client Data stored on Avondale.AI infrastructure is encrypted using LUKS2 with AES-256 or equivalent;
- Encryption in Transit: All data transmissions to and from Avondale.AI infrastructure use TLS 1.3 or equivalent. No unencrypted transmission of Client Data is permitted;
- Access Controls: Access to Client Data is restricted to a single authorized Avondale.AI operator. No shared accounts. No generic credentials. All access is logged;
- Authentication: Multi-factor authentication is required for all access to infrastructure hosting Client Data;
- Network Security: Infrastructure hosting Client Data is protected by firewall rules restricting inbound connections. No inbound remote connections are accepted. All management access is through encrypted, authenticated channels;
- Key Management: Encryption keys are managed on Avondale.AI-controlled infrastructure. No master keys, no backdoors, no key escrow with third parties. Keys are rotated periodically;
- Operating System Hardening: Infrastructure hosting Client Data runs hardened Linux with current security patches, minimal attack surface, and disabled unnecessary services.
Physical Security
- Physical Access Control: Physical access to infrastructure hosting Client Data is restricted and logged. Only authorized Avondale.AI personnel have physical access;
- Location: Infrastructure is located in a controlled-access facility within the United States.
Organizational Security
- Personnel: Only authorized Avondale.AI personnel with a need to know may access Client Data. All personnel are bound by confidentiality obligations;
- Training: Avondale.AI personnel are trained on data handling, security practices, and this Agreement;
- Incident Response: Avondale.AI maintains an incident response plan for suspected or actual data security incidents.
7. No Model Training
We Do Not Train AI Models on Your Data
Avondale.AI does not use Client Data or Derived Data to train, fine-tune, improve, evaluate, or benchmark any AI model. This prohibition is absolute and applies during and after the Engagement.
Specifically:
- Client Data is not used as training data for any AI model;
- Client Data is not used to fine-tune or adapt existing AI models;
- Client Data is not used to evaluate, test, or benchmark AI model performance;
- Client Data is not used to develop or improve Avondale.AI's commercial products or services;
- Derived Data (findings, analyses, knowledge bases) is not used for model training, fine-tuning, or service improvement;
- No AI model used in the processing of Client Data retains, memorizes, or can reproduce Client Data after the Engagement concludes.
8. No Sub-Processors
Avondale.AI does not use sub-processors for Client Data processing. All processing is performed by Avondale.AI personnel on Avondale.AI-controlled infrastructure. No third party processes, accesses, or stores Client Data.
If Avondale.AI ever needs to engage a sub-processor for a specific Engagement, Avondale.AI will:
- Notify the Client in writing before engaging the sub-processor;
- Obtain the Client's written consent;
- Ensure the sub-processor is bound by data protection obligations no less protective than this Agreement;
- Remain fully liable for the sub-processor's handling of Client Data.
Until and unless such written notice and consent occurs, no sub-processor processes any Client Data. The current list of sub-processors is: none.
9. Data Retention and Purge
Client Data is retained only for the duration necessary to perform the Services in the Engagement. After the Engagement concludes:
- Default Timeline: All Client Data and Derived Data is purged no later than thirty (30) days after termination or completion of the Engagement, unless a different timeline is specified in the Engagement;
- Purge Method: Data is securely deleted using cryptographic erasure or multi-pass overwrite in accordance with NIST SP 800-88 guidelines. Simple file deletion is not sufficient;
- Verification: Upon request, Avondale.AI will provide written confirmation that Client Data has been purged;
- Legal Hold: If Avondale.AI is legally required to retain Client Data beyond the purge timeline (e.g., litigation hold, regulatory requirement), Avondale.AI will notify the Client and retain only the data required for the minimum period necessary;
- No Backup Retention: Avondale.AI does not maintain backup copies of Client Data beyond the purge timeline. Backups, if any exist during the Engagement, are purged on the same schedule as primary data.
10. Data Return and Destruction
Upon termination or completion of the Engagement, the Client may request return of its Client Data. Avondale.AI will:
- Return all Client Data to the Client in a mutually agreed format (e.g., encrypted archive, secure transfer);
- Provide Deliverables and Derived Data as specified in the Engagement;
- Purge all Client Data, Derived Data, and any copies from Avondale.AI infrastructure within thirty (30) days of the return or termination date;
- Provide written certification of destruction upon request;
- Not retain any copy of Client Data except as required by law and with notice to the Client.
The Client is responsible for maintaining its own backups of Client Data. Avondale.AI is not responsible for data loss after the purge timeline has elapsed.
11. Breach Notification
In the event of a suspected or confirmed data security incident involving Client Data, Avondale.AI will:
- Notify the Client: Within seventy-two (72) hours of confirming that a security breach has occurred that is reasonably likely to have compromised Client Data. Notification will be made by phone and confirmed in writing;
- Provide Details: To the extent known at the time of notification, Avondale.AI will provide: the nature of the breach, the categories of Client Data affected, the likely consequences, and the measures taken or proposed to address the breach;
- Investigate: Avondale.AI will conduct a prompt investigation to determine the scope and impact of the breach;
- Remediate: Avondale.AI will take reasonable steps to contain the breach, secure affected systems, and prevent recurrence;
- Document: Avondale.AI will maintain a record of the breach, the investigation, and the remediation measures;
- Cooperate: Avondale.AI will cooperate with the Client and any regulatory authorities as required by law.
Avondale.AI is not required to notify the Client of a breach that does not involve Client Data or that has no reasonable likelihood of affecting Client Data.
12. Data Subject Rights
If Client Data contains Personal Data, the Client is responsible for handling data subject requests. Avondale.AI will assist the Client in fulfilling data subject requests where feasible, including:
- Access: Providing the Client with a copy of the Personal Data processed during the Engagement;
- Correction: Correcting inaccurate Personal Data at the Client's request during the Engagement;
- Deletion: Purging Personal Data per the retention timeline in Section 9;
- Restriction: Restricting processing of specific Personal Data at the Client's request, where feasible;
- Portability: Returning Personal Data to the Client in a structured, commonly used format.
Avondale.AI does not interact directly with the Client's data subjects. The Client remains the data controller and is responsible for all data subject communications. Avondale.AI acts as a data processor on behalf of the Client.
13. Cross-Border Data Transfer Prohibition
No Client Data Leaves the United States
Avondale.AI does not transfer, transmit, or make accessible Client Data to any system, person, or entity located outside the United States. This prohibition is absolute and applies to all forms of transfer, including remote access, cloud processing, and data replication.
- No Client Data is stored on systems located outside the United States;
- No Client Data is processed by systems located outside the United States;
- No personnel located outside the United States have access to Client Data;
- No remote access to Client Data is granted from outside the United States;
- No third party outside the United States is engaged to process, store, or transmit Client Data.
This provision does not apply to data that has been anonymized or de-identified such that it can no longer be associated with the Client or any individual, and that is used solely for aggregate, non-identifiable statistical purposes. However, Avondale.AI does not currently engage in such anonymization during or after Engagements.
14. Audit Rights
The Client may audit Avondale.AI's compliance with this Data Handling Agreement upon thirty (30) days written notice. Audits may include:
- Review of data handling practices and procedures;
- Review of security measures and configurations (summary level, not including credentials or keys);
- Verification of data purge completion;
- Review of incident response records;
- Verification that no sub-processors are in use.
Audits will be conducted during business hours, at the Client's expense, and will not unreasonably interfere with Avondale.AI operations. The Client may audit no more than once per twelve (12) month period unless a documented security incident has occurred. Audit results are confidential and subject to the confidentiality provisions of the Terms of Service.
15. Liability for Data Incidents
Avondale.AI's liability for any data security incident involving Client Data is governed by the limitation of liability provisions in the Terms of Service, Section 11. The Client acknowledges that:
- Avondale.AI is not an insurer of Client Data. The liability cap in the Terms of Service applies to data incidents;
- The Client bears responsibility for data it provides to Avondale.AI, including ensuring it has the right to share such data;
- Avondale.AI is not liable for data incidents caused by the Client's failure to maintain security on its own infrastructure;
- Avondale.AI is not liable for data incidents caused by the Client's MSP or third-party technology provider, including unauthorized access to Avondale.AI infrastructure by such parties (see Acceptable Use Policy, Section 4, MSP Restrictions);
- Avondale.AI is not liable for data incidents caused by events outside its reasonable control, including force majeure events as defined in the Terms of Service.
16. Changes to This Agreement
Avondale.AI may update this Data Handling Agreement from time to time. The effective date at the top of this page indicates when the current version was posted. Changes apply to new Engagements entered into after the effective date. Engagements already in progress are governed by the Agreement in effect at the time the Engagement was initiated, unless the Engagement expressly provides otherwise.
17. Execution
This Data Handling Agreement may be executed electronically or in writing. Execution may be by: (a) signing an Engagement that references this Agreement, (b) written acknowledgment of this Agreement, or (c) making payment for Services, which constitutes acceptance of this Agreement as part of the Terms of Service.
Avondale.AI
By: _________________________________
Name: Stephen Sargent
Title: Founder & CTO
Date: _______________________________
Client
By: _________________________________
Name: _______________________________
Title: ______________________________
Date: _______________________________
Relationship to Terms of Service: This Data Handling Agreement is incorporated by reference into the Avondale.AI Terms of Service. In the event of a conflict between this Agreement and the Terms of Service, the Terms of Service control. This Agreement does not create any warranty or right not expressly stated in the Terms of Service or the applicable Engagement.