Data Handling Agreement

Plain Language Summary

This agreement governs how Avondale.AI handles your data during a commercial engagement. Key points: your data stays on our sovereign, on-premise infrastructure in the United States. No data goes to any third-party cloud. We do not train AI models on your data. Data is purged within 30 days after the engagement ends. We use encryption, access controls, and physical security to protect your data. If something goes wrong, we notify you within 72 hours.

Effective Date: August 9, 2026

1. Parties and Incorporation

This Data Handling Agreement ("DHA" or "Agreement") is entered into between Avondale.AI ("Avondale.AI," "we," "us," "our") and the entity engaging Avondale.AI for commercial services ("Client," "you," "your"). This Agreement is incorporated by reference into and forms part of the Avondale.AI Terms of Service. In the event of a conflict between this Agreement and the Terms of Service, the Terms of Service control. This Agreement applies to commercial engagements only. Consumer products, when available, are governed by separate terms.

2. Definitions

3. Data We Collect

Avondale.AI collects and processes only the Client Data necessary to perform the Services defined in the applicable Engagement. This may include:

Avondale.AI does not collect more data than is necessary for the Engagement. If the Client provides data that Avondale.AI does not need, Avondale.AI will flag it and exclude it from processing. The Client is responsible for ensuring all Client Data provided to Avondale.AI is properly authorized for sharing under applicable law and any obligations to third parties.

4. How Data Is Processed

Client Data is processed for the sole purpose of performing the Services defined in the Engagement. Processing activities include:

  1. Analysis: AI-assisted and expert analysis of Client Data to produce findings, gap analyses, and recommendations;
  2. Cross-Referencing: Mapping Client Data against compliance frameworks, security standards, and best practices;
  3. Knowledge Base Compilation: Organizing Client Data and findings into structured knowledge bases in requested formats;
  4. Deliverable Production: Generating reports, roadmaps, policies, and other Deliverables for the Client.

Client Data is not processed for any purpose other than performing the Services. Avondale.AI does not use Client Data for marketing, product development, model training, service improvement, or any purpose unrelated to the Engagement. See Section 7 for the prohibition on model training.

5. Where Data Is Processed

Sovereign, On-Premise, United States Only

All processing of Client Data occurs on Avondale.AI's sovereign, on-premise infrastructure located within the United States. No Client Data leaves Avondale.AI's controlled infrastructure.

6. Security Measures

Avondale.AI implements and maintains reasonable and appropriate technical, physical, and organizational security measures to protect Client Data. These measures include:

Technical Security

Physical Security

Organizational Security

7. No Model Training

We Do Not Train AI Models on Your Data

Avondale.AI does not use Client Data or Derived Data to train, fine-tune, improve, evaluate, or benchmark any AI model. This prohibition is absolute and applies during and after the Engagement.

Specifically:

8. No Sub-Processors

Avondale.AI does not use sub-processors for Client Data processing. All processing is performed by Avondale.AI personnel on Avondale.AI-controlled infrastructure. No third party processes, accesses, or stores Client Data.

If Avondale.AI ever needs to engage a sub-processor for a specific Engagement, Avondale.AI will:

  1. Notify the Client in writing before engaging the sub-processor;
  2. Obtain the Client's written consent;
  3. Ensure the sub-processor is bound by data protection obligations no less protective than this Agreement;
  4. Remain fully liable for the sub-processor's handling of Client Data.

Until and unless such written notice and consent occurs, no sub-processor processes any Client Data. The current list of sub-processors is: none.

9. Data Retention and Purge

Client Data is retained only for the duration necessary to perform the Services in the Engagement. After the Engagement concludes:

  1. Default Timeline: All Client Data and Derived Data is purged no later than thirty (30) days after termination or completion of the Engagement, unless a different timeline is specified in the Engagement;
  2. Purge Method: Data is securely deleted using cryptographic erasure or multi-pass overwrite in accordance with NIST SP 800-88 guidelines. Simple file deletion is not sufficient;
  3. Verification: Upon request, Avondale.AI will provide written confirmation that Client Data has been purged;
  4. Legal Hold: If Avondale.AI is legally required to retain Client Data beyond the purge timeline (e.g., litigation hold, regulatory requirement), Avondale.AI will notify the Client and retain only the data required for the minimum period necessary;
  5. No Backup Retention: Avondale.AI does not maintain backup copies of Client Data beyond the purge timeline. Backups, if any exist during the Engagement, are purged on the same schedule as primary data.

10. Data Return and Destruction

Upon termination or completion of the Engagement, the Client may request return of its Client Data. Avondale.AI will:

  1. Return all Client Data to the Client in a mutually agreed format (e.g., encrypted archive, secure transfer);
  2. Provide Deliverables and Derived Data as specified in the Engagement;
  3. Purge all Client Data, Derived Data, and any copies from Avondale.AI infrastructure within thirty (30) days of the return or termination date;
  4. Provide written certification of destruction upon request;
  5. Not retain any copy of Client Data except as required by law and with notice to the Client.

The Client is responsible for maintaining its own backups of Client Data. Avondale.AI is not responsible for data loss after the purge timeline has elapsed.

11. Breach Notification

In the event of a suspected or confirmed data security incident involving Client Data, Avondale.AI will:

  1. Notify the Client: Within seventy-two (72) hours of confirming that a security breach has occurred that is reasonably likely to have compromised Client Data. Notification will be made by phone and confirmed in writing;
  2. Provide Details: To the extent known at the time of notification, Avondale.AI will provide: the nature of the breach, the categories of Client Data affected, the likely consequences, and the measures taken or proposed to address the breach;
  3. Investigate: Avondale.AI will conduct a prompt investigation to determine the scope and impact of the breach;
  4. Remediate: Avondale.AI will take reasonable steps to contain the breach, secure affected systems, and prevent recurrence;
  5. Document: Avondale.AI will maintain a record of the breach, the investigation, and the remediation measures;
  6. Cooperate: Avondale.AI will cooperate with the Client and any regulatory authorities as required by law.

Avondale.AI is not required to notify the Client of a breach that does not involve Client Data or that has no reasonable likelihood of affecting Client Data.

12. Data Subject Rights

If Client Data contains Personal Data, the Client is responsible for handling data subject requests. Avondale.AI will assist the Client in fulfilling data subject requests where feasible, including:

Avondale.AI does not interact directly with the Client's data subjects. The Client remains the data controller and is responsible for all data subject communications. Avondale.AI acts as a data processor on behalf of the Client.

13. Cross-Border Data Transfer Prohibition

No Client Data Leaves the United States

Avondale.AI does not transfer, transmit, or make accessible Client Data to any system, person, or entity located outside the United States. This prohibition is absolute and applies to all forms of transfer, including remote access, cloud processing, and data replication.

This provision does not apply to data that has been anonymized or de-identified such that it can no longer be associated with the Client or any individual, and that is used solely for aggregate, non-identifiable statistical purposes. However, Avondale.AI does not currently engage in such anonymization during or after Engagements.

14. Audit Rights

The Client may audit Avondale.AI's compliance with this Data Handling Agreement upon thirty (30) days written notice. Audits may include:

Audits will be conducted during business hours, at the Client's expense, and will not unreasonably interfere with Avondale.AI operations. The Client may audit no more than once per twelve (12) month period unless a documented security incident has occurred. Audit results are confidential and subject to the confidentiality provisions of the Terms of Service.

15. Liability for Data Incidents

Avondale.AI's liability for any data security incident involving Client Data is governed by the limitation of liability provisions in the Terms of Service, Section 11. The Client acknowledges that:

16. Changes to This Agreement

Avondale.AI may update this Data Handling Agreement from time to time. The effective date at the top of this page indicates when the current version was posted. Changes apply to new Engagements entered into after the effective date. Engagements already in progress are governed by the Agreement in effect at the time the Engagement was initiated, unless the Engagement expressly provides otherwise.

17. Execution

This Data Handling Agreement may be executed electronically or in writing. Execution may be by: (a) signing an Engagement that references this Agreement, (b) written acknowledgment of this Agreement, or (c) making payment for Services, which constitutes acceptance of this Agreement as part of the Terms of Service.

Avondale.AI

By: _________________________________
Name: Stephen Sargent
Title: Founder & CTO
Date: _______________________________

Client

By: _________________________________
Name: _______________________________
Title: ______________________________
Date: _______________________________

Relationship to Terms of Service: This Data Handling Agreement is incorporated by reference into the Avondale.AI Terms of Service. In the event of a conflict between this Agreement and the Terms of Service, the Terms of Service control. This Agreement does not create any warranty or right not expressly stated in the Terms of Service or the applicable Engagement.