Data Processing Addendum
Effective: August 21, 2026
This Data Processing Addendum ("DPA") forms part of the Ervona Terms of Service or other agreement between Ervona LLC ("Ervona") and the customer using the Service ("Customer"). It applies whenever Ervona processes Customer Personal Data as a processor, subprocessor, service provider, or contractor on Customer's behalf.
1. Roles and instructions
Customer is the controller or business for Customer Personal Data and Ervona is its processor or service provider. If Customer acts as a processor for another controller, Ervona acts as Customer's subprocessor. Customer instructs Ervona to process Customer Personal Data only to provide, secure, support, and improve the reliability of the Service as described in the agreement, this DPA, the Privacy Policy, and Customer's documented configuration. Ervona will notify Customer if it believes an instruction violates applicable data-protection law, unless prohibited from doing so.
Ervona does not sell Customer Personal Data, share it for cross-context behavioral advertising, use it for targeted advertising, combine it with personal data received from another person except as legally permitted for a service provider, or use it to train or improve an AI model.
2. Processing details
- Subject matter and duration. Processing the data needed to provide the Service for the term of the agreement and the deletion periods described in the Privacy Policy.
- Nature and purpose. Account operation; browser-extension configuration and reporting; optional mailbox and calendar connection; AI drafting and reply classification; Desk prospecting, campaign operation, sending, reply handling, meeting booking, CRM writeback, reporting, security, support, and legal compliance.
- Data subjects. Customer's authorized users, employees and contractors; prospects, leads, recipients, correspondents, meeting attendees, and other people whose information Customer makes available through a connected CRM, mailbox, calendar, campaign, or file.
- Personal data. Account and device identifiers, business profile and settings, CRM fields and records, names, business contact details, company and job information, campaign membership and activity, email and SMS metadata and content where the enabled feature requires it, calendar availability and event details, reply classifications, suppression status, and technical or security logs.
- Sensitive data. The Service is not designed for special-category data, protected health information, payment-card data, government identifiers, or consumer financial information. Customer must not submit such data unless the parties have agreed in writing to additional safeguards.
3. Confidentiality and security
Ervona will ensure that people authorized to process Customer Personal Data are bound by confidentiality obligations and receive access only where necessary. Ervona maintains appropriate technical and organizational measures, including encryption in transit, encryption at rest for server-side storage, row-level access controls, credential encryption with keys held separately from the database, server-side secret management, least-privilege browser permissions, authenticated and signed webhook handling, suppression checks, and self-service deletion. Additional detail is available on the Security page.
4. Subprocessors
Customer gives general authorization for Ervona to use the subprocessors below. Ervona remains responsible for their processing to the extent required by law and imposes data-protection obligations appropriate to each service.
- Supabase: authentication, database, serverless functions, and account, campaign, lead, message, credential, and settings storage.
- Cloudflare: hosting, content delivery, security, DNS, Turnstile, technical request logs, cookieless site analytics, and Workers AI reply classification or drafting where configured.
- Nylas: connected mailbox and calendar access, email sending and receipt, and meeting creation.
- Anthropic: AI drafting, reply summarization, and business-profile extraction where configured.
- Stripe: subscription payment, billing management, and fraud prevention.
- Zoho/ZeptoMail and Resend: transactional, security, account, and handoff-notification email.
- Email-verification providers: recipient-address verification where Ervona, rather than Customer's own vendor account, performs the check.
A CRM, texting provider, lead-data vendor, or verification vendor that Customer connects under Customer's own account and contract acts at Customer's direction and is not an Ervona subprocessor. Ervona will update the public subprocessor list before a new subprocessor begins processing Customer Personal Data and will provide reasonable notice of a material addition. Customer may object on reasonable data-protection grounds by contacting legal [at] ervona.ai. The parties will work in good faith on a reasonable solution; if none is available, Customer may stop the affected feature.
5. Assistance and requests
Taking into account the nature of processing, Ervona will reasonably assist Customer with data-subject requests, security obligations, breach notifications, data-protection impact assessments, and regulator consultations. If Ervona receives a request concerning Customer Personal Data, Ervona will direct the requester to Customer or notify Customer, unless law requires Ervona to respond directly.
6. Personal-data breaches
Ervona will notify Customer without undue delay after confirming a personal-data breach affecting Customer Personal Data and will provide available information reasonably needed for Customer's notification and investigation obligations. Notification is not an admission of fault or liability.
7. Return and deletion
Customer may export available data and use the Service's deletion controls during the subscription term. On account deletion, Ervona will revoke connected credentials and delete Customer Personal Data from active systems, except information that applicable law requires Ervona to retain and data rendered anonymous so it can no longer be linked to a person. If an external revocation or deletion cannot be completed, Ervona will keep the account recoverable and retry rather than representing that deletion succeeded. Provider backups, where present, expire through their ordinary protected backup cycle.
8. Audit information
On reasonable written request, Ervona will provide information necessary to demonstrate compliance with this DPA. If that information is insufficient, Customer may request an audit by an independent qualified auditor no more than once annually, or after a confirmed breach affecting Customer Personal Data, subject to reasonable scope, confidentiality, scheduling, security, and cost protections.
9. International transfers
For restricted transfers from the EEA to a country without an adequacy decision, the European Commission Standard Contractual Clauses adopted by Decision 2021/914 are incorporated by reference: Module Two applies where Customer is a controller and Ervona is a processor; Module Three applies where both parties act as processors. Docking applies, Clause 7 is included, optional Clause 9(a) uses general written authorization, and the competent authority and governing law are those of the EEA country where the exporter is established. Annex I is completed by the parties and processing details in this DPA; Annex II is completed by Section 3. For UK restricted transfers, the UK International Data Transfer Addendum applies to those Clauses. Ervona will provide a completed copy on request.
10. U.S. state privacy terms
Where U.S. state privacy law applies, Ervona acts as Customer's service provider or contractor. Ervona will process personal data only for the limited and specified purposes in the agreement, provide the same level of privacy protection required by applicable law, notify Customer if it can no longer meet those obligations, and permit Customer to take reasonable steps to verify and stop unauthorized use.
11. Conflict and contact
This DPA controls over the Terms on processing of Customer Personal Data. The remainder of the agreement, including its liability provisions to the extent legally permitted, continues to apply. Questions and requests may be sent to legal [at] ervona.ai.