1. Parties and effect
This Data Processing Addendum, or DPA, forms part of a written agreement for AiVante when that agreement incorporates these terms. “Customer” means the organization using AiVante under that agreement. “Provider” means the AiVante provider identified in the agreement or, if none is identified, the operator acting under the WholeStack AI brand.
This DPA applies when Provider processes personal data for Customer as a processor, service provider, or contractor. It does not replace terms that apply when Provider independently determines why and how account, security, billing, or direct support data is processed.
2. Definitions and priority
“Personal data,” “process,” “controller,” “processor,” and equivalent terms have the meanings given by applicable data-protection law. “Customer Data” means personal data processed by Provider on Customer’s behalf through AiVante. “Subprocessor” means a third party engaged by Provider to process Customer Data.
If this DPA conflicts with the service agreement on processing Customer Data, this DPA controls. A signed Business Associate Agreement controls for protected health information to the extent it imposes more specific obligations.
3. Processing details
The subject matter is operation of AiVante for Customer. Processing continues for the agreement term and any limited return, deletion, backup, security, or legal-retention period. The nature and purpose include hosting, organizing, calculating, displaying, securing, supporting, exporting, and deleting Customer Data according to Customer’s use and documented instructions.
- Data subjects may include Customer personnel, advisers, clients, prospective clients, household members, beneficiaries, authorized representatives, and other people whose records Customer lawfully submits.
- Data may include identity and contact data; role and organization data; planning assumptions; insurance, healthcare-cost, annuity, retirement-income, and financial-planning inputs; communications; approvals; audit events; and technical identifiers.
- Special-category, health, or similarly regulated data may be processed only where the agreement, feature configuration, and required additional terms expressly authorize it.
4. Customer instructions and obligations
Provider will process Customer Data only to provide and secure AiVante, comply with the agreement, follow Customer’s documented instructions, or meet applicable law. Use of configured features and authorized support requests are documented instructions. Provider will notify Customer if an instruction appears to violate applicable data-protection law, unless prohibited from doing so.
Customer is responsible for the lawfulness, accuracy, and quality of Customer Data; required notices and consents; the authority of its users; its account and role configuration; and limiting submitted data to what is necessary for an authorized purpose.
5. Confidentiality and security
Provider will ensure that people authorized to process Customer Data are subject to appropriate confidentiality obligations. Provider will maintain technical and organizational measures designed for the risk, nature, and context of processing.
- signed, protected sessions and role- and tenant-scoped authorization;
- encryption in transit using current transport-security protocols;
- audit records for sensitive and governed actions;
- environment and secret separation, access restriction, and provider-key isolation;
- input validation, request limits, cross-origin protections, and security headers;
- operational health checks, error monitoring, backup controls, and incident investigation procedures; and
- periodic testing and review proportionate to the service and risk.
6. Subprocessors
Customer generally authorizes Provider to use Subprocessors needed to deliver AiVante, including infrastructure, database, authentication, communications, security monitoring, payment, and expressly configured AI inference services. Provider will impose data-protection obligations appropriate to each Subprocessor’s role and remains responsible for its own obligations under this DPA.
Customer may request the current Subprocessor list at support@wholestack.ai. If Provider adds a Subprocessor that materially changes the processing of Customer Data, Provider will provide reasonable notice when required by the agreement or applicable law. A Customer with a reasonable data-protection objection may contact Provider to seek a commercially reasonable solution.
7. Data-subject requests
Taking into account the nature of processing, Provider will reasonably assist Customer in responding to verified requests to access, correct, delete, restrict, object to, or export Customer Data. If Provider receives a request relating to Customer Data, it may direct the requester to Customer unless law requires Provider to respond directly.
8. Security incidents
Provider will notify Customer without undue delay after confirming a breach of security that results in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Data. Notice will include available information reasonably needed for Customer’s legal obligations and will be supplemented as the investigation develops.
Notification is not an admission of fault. Customer is responsible for notices arising from its own systems, users, instructions, or legal role. The parties will cooperate in good faith on containment, remediation, and required communications.
9. Risk assessments and audits
Provider will provide information reasonably necessary to demonstrate compliance with this DPA and assist with legally required impact assessments or regulator consultations, taking into account the nature of processing and information available to Provider.
Audits will ordinarily be satisfied through current independent reports, security documentation, and written responses. If those materials are insufficient and law requires further review, Customer may conduct a focused audit on reasonable notice, no more than once annually unless a confirmed incident or regulator requires otherwise, subject to confidentiality, security, and non-disruption requirements.
10. International transfers
If Customer Data is transferred across borders and applicable law requires a transfer mechanism, the parties will use a legally recognized safeguard, which may include applicable Standard Contractual Clauses and a UK addendum. The parties will cooperate on reasonable transfer-impact information.
11. Return and deletion
At the end of the service, Provider will delete or return Customer Data as required by the agreement and Customer’s documented choice, except to the extent retention is required by law or reasonably necessary in protected backups, security records, dispute records, or evidence logs. Retained data remains protected and is not used for another purpose.
12. Healthcare data and public AI support
This DPA is not a Business Associate Agreement. Customer must not use AiVante to transmit protected health information unless a separate BAA is in effect and the relevant storage, workflow, and provider configuration is expressly approved for that data.
The public insurance-support chat is a non-BAA educational channel. It must not receive identifiers, policy or member numbers, personal financial information, or medical-record details. Protected AI workflows remain unavailable unless an approved provider, BAA, and required retention controls are configured.
13. Governing terms and contact
The governing law and dispute provisions of the service agreement apply to this DPA. If no written service agreement exists, applicable law determines the parties’ rights and forum.
DPA, Subprocessor, and security requests may be sent to support@wholestack.ai with the subject line “AiVante DPA request.” Do not attach live personal or health records to an ordinary email request.
