Avagance — Data Processing Agreement (DPA)
Last updated: 24 August 2026
1. Background and parties
This Data Processing Agreement ("DPA") forms part of, and is subject to, the Avagance Terms of Service (or any signed order form or master subscription agreement) between:
- Avagance Limited, a company registered in England and Wales under number 15991387, registered office 128 City Road, London, EC1V 2NX (the "Processor", "Avagance", "we" or "us"), formerly registered as Bro In Finance Ltd; and
- the customer firm that has agreed to the Terms of Service (the "Controller", "Customer" or "you"),
each a "party" and together the "parties".
This DPA applies where, in providing the Avagance platform and services (the "Services"), Avagance processes Personal Data on behalf of the Customer — principally the Customer's own client and prospect data. It does not cover Personal Data for which Avagance is itself the controller (for example, the Customer's account, billing and Website-visitor data), which is governed by the Avagance Privacy Policy.
Where there is any conflict between this DPA and the rest of the Terms of Service on the subject of the processing of Personal Data, this DPA prevails.
2. Definitions
Capitalised terms not defined here have the meaning given in the Terms of Service. In this DPA:
- "Data Protection Laws" means all laws applicable to the processing of Personal Data under this DPA, including the UK GDPR (Regulation (EU) 2016/679 as it forms part of UK law) and the Data Protection Act 2018, and any successor or amending legislation, together with guidance and codes of practice issued by the ICO.
- "UK GDPR", "personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "special category data" have the meanings given in the Data Protection Laws. "Personal Data" in this DPA means personal data processed by Avagance on the Customer's behalf under the Services.
- "Sub-processor" means any third party engaged by Avagance to process Personal Data in connection with the Services.
- "Restricted Transfer" means a transfer of Personal Data to a country outside the UK that is not covered by UK adequacy regulations.
- "UK Transfer Mechanism" means the ICO's International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or another lawful transfer mechanism recognised under the Data Protection Laws.
3. Roles of the parties
The parties acknowledge that, in respect of the Personal Data:
- the Customer is the controller (or, where the Customer itself acts as a processor for a third party, the Customer is a processor and Avagance is a sub-processor); and
- Avagance is the processor (or sub-processor, as applicable).
Each party will comply with its obligations under the Data Protection Laws. The Customer is responsible for establishing a lawful basis (and, for special category data, an Article 9 condition), for providing all required privacy information to data subjects, and for the accuracy, quality and legality of the Personal Data and of the instructions it gives.
4. Scope and details of processing
The subject matter, duration, nature and purpose of the processing, the types of Personal Data, and the categories of data subjects are set out in Annex 1. Avagance processes the Personal Data only to provide, secure, support and maintain the Services and as otherwise set out in this DPA.
5. Avagance's obligations as processor
Avagance will:
5.1 Processing on instructions. Process the Personal Data only on the Customer's documented instructions (including as set out in the Terms of Service, this DPA, and configuration of the Services), including for Restricted Transfers, unless required to do otherwise by law — in which case Avagance will inform the Customer of that legal requirement before processing, unless the law prohibits it. If Avagance believes an instruction infringes the Data Protection Laws, it will inform the Customer.
5.2 Confidentiality. Ensure that persons authorised to process the Personal Data are subject to an appropriate duty of confidentiality and are processing only on a need-to-know basis.
5.3 Security. Implement and maintain appropriate technical and organisational measures to protect the Personal Data against a personal data breach, taking into account the state of the art, costs, and the nature, scope, context and purposes of processing, and the risk to data subjects, as required by UK GDPR Article 32. Avagance's current measures are described in Annex 2. Avagance may update its measures provided the level of protection is not materially reduced.
5.4 Sub-processors.
(a) The Customer provides general authorisation for Avagance to engage Sub-processors to process the Personal Data. Avagance's current Sub-processors are listed in Annex 3 (and/or maintained at https://avagance.com/sub-processors).
(b) Avagance will impose on each Sub-processor, by written contract, data-protection obligations that are substantially the same as those in this DPA, and remains liable to the Customer for the acts and omissions of its Sub-processors.
(c) Avagance will give the Customer prior notice of any intended addition or replacement of a Sub-processor (for example, by updating the list and/or by email). The Customer may object on reasonable data-protection grounds within 10 business days. The parties will work in good faith to resolve the objection; if they cannot, the Customer's remedy is to terminate the affected Services in accordance with the Terms of Service.
5.5 Data-subject rights. Taking into account the nature of the processing, assist the Customer by appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights under the Data Protection Laws. If Avagance receives such a request directly, it will (unless prohibited) promptly notify the Customer and will not respond except on the Customer's instructions or as legally required.
5.6 Assistance. Taking into account the nature of processing and the information available to Avagance, provide reasonable assistance to the Customer with: (a) security of processing; (b) notification of personal data breaches to the ICO and data subjects; and (c) data protection impact assessments and prior consultation with the ICO (UK GDPR Articles 32–36).
5.7 Personal data breach. Notify the Customer without undue delay after becoming aware of a personal data breach affecting the Personal Data, and provide the Customer with information reasonably available to it to enable the Customer to meet its breach-notification obligations. Such notification is not an acknowledgement of fault.
5.8 Deletion or return. At the Customer's choice, delete or return the Personal Data at the end of the provision of the Services, and delete existing copies, unless retention is required by law. Avagance may retain Personal Data in routine backups for a limited period until they are overwritten in the ordinary course, during which it remains protected by this DPA. See also Terms of Service section 15.3.
5.9 Records, information and audits. Make available to the Customer information reasonably necessary to demonstrate compliance with this Article-28 obligation, and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates. Audits: (a) may occur once per 12-month period (or more often following a personal data breach or where required by a regulator); (b) require reasonable prior written notice (at least 30 days, except where a regulator requires sooner); (c) must be conducted during business hours, subject to confidentiality, and in a manner that does not unreasonably disrupt Avagance's operations; and (d) may, in the first instance, be satisfied by Avagance providing up-to-date certifications, third-party audit reports (for example, of its infrastructure providers), or completed security questionnaires.
6. The Customer's obligations as controller
The Customer will:
- comply with its own obligations as controller under the Data Protection Laws;
- ensure it has a valid lawful basis and, for special category data, an Article 9 condition, for the processing it instructs;
- provide all required privacy information / notices to its data subjects and obtain any consents required;
- ensure its instructions to Avagance are lawful, and that the Personal Data it provides is accurate and lawfully obtained;
- configure and use the Services (including access controls, roles, retention settings and integrations) appropriately for the sensitivity of the Personal Data; and
- not instruct Avagance to process Personal Data in a way that would put Avagance in breach of the Data Protection Laws.
7. International transfers
Avagance will not carry out a Restricted Transfer of the Personal Data except where it has put in place a UK Transfer Mechanism (or the transfer otherwise complies with the Data Protection Laws) together with any supplementary measures required. Where a Sub-processor is located outside the UK, Avagance will ensure an appropriate UK Transfer Mechanism is in place. Details of transfers and the mechanisms relied on are, or will be, reflected in Annex 3 and are available on request.
8. Liability
Each party's liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service (or applicable order form / master agreement). Nothing in this DPA limits any liability that cannot be limited under the Data Protection Laws (including any rights a data subject may have).
9. Term, termination and precedence
9.1 This DPA takes effect on the date the Customer accepts the Terms of Service (or the effective date of the applicable order form) and continues for as long as Avagance processes Personal Data on the Customer's behalf.
9.2 Obligations that by their nature should survive (including sections 5.8, 5.9, 7 and 8) survive termination.
9.3 This DPA supplements the Terms of Service. Except as expressly stated (see section 1), the Terms of Service continue in full force. This DPA is governed by the laws of England and Wales and subject to the jurisdiction provisions of the Terms of Service.
Annex 1 — Description of the processing
To be completed / confirmed against the Services as actually configured for the Customer.
Parties
- Controller: the Customer (the financial-advice firm accepting the Terms of Service).
- Processor: Avagance Limited.
Subject matter of processing Provision of the Avagance software platform and services (adviser portal, client portal, AI assistant "Ava", analytics, compliance, document and workflow tooling, and related applications and APIs) to the Customer.
Duration of processing For the duration of the Customer's subscription to the Services, plus the limited post-termination period described in section 5.8 and Terms of Service section 15.3.
Nature and purpose of processing Hosting, storage, retrieval, organisation, structuring, analysis, generation of drafts and summaries (including via AI features), transmission, back-up, security, and deletion of Personal Data, in each case to provide and support the Services on the Customer's instructions.
Categories of data subjects
- the Customer's clients and prospective clients (and, where relevant, their family members, dependants, joint account holders, trustees, beneficiaries, and connected parties);
- the Customer's staff and authorised users of the Services.
Types of Personal Data May include, depending on how the Customer uses the Services:
- identity and contact details (name, address, date of birth, email, telephone);
- identifiers and reference numbers (for example, National Insurance number, client/account references);
- financial and circumstances data (income, assets, liabilities, holdings, portfolios, transactions, objectives, risk profile, fact-find information);
- meeting notes, communications, documents, and correspondence;
- suitability, compliance and audit records; and
- where the Customer records it, special category data relevant to client vulnerability (for example, health information) — see below.
Special category data The Services may be used by the Customer to record special category data (for example, health data relevant to financial vulnerability under UK GDPR Article 9). Where processed, it is processed only on the Customer's instructions, and the Customer is responsible for the applicable Article 9 condition. Additional safeguards (access controls, logging) apply.
Frequency of processing Continuous, for the duration of the subscription.
Annex 2 — Technical and organisational measures (Article 32)
Summary of Avagance's current security measures. To be kept current and confirmed against the live environment.
- Encryption — Personal Data encrypted in transit (TLS) and sensitive data encrypted at rest; managed key/secrets handling.
- Access control — role-based access and least-privilege permissions; unique user accounts; multi-factor authentication support; administrative access restricted and logged.
- Tenant isolation — logical multi-tenancy controls to segregate one Customer's data from another's.
- Network and infrastructure security — hardened cloud infrastructure, private networking for internal services, restricted ingress, and monitoring.
- Audit logging — logging of access and significant actions to support accountability and investigation.
- Resilience and back-ups — regular back-ups and measures to restore availability after an incident.
- Vulnerability and patch management — dependency and platform updates, and remediation of identified issues.
- Secure development — code review, automated checks, and separation of environments.
- Sub-processor controls — contractual data-protection obligations flowed down to Sub-processors (section 5.4).
- Incident response — procedures to detect, assess, respond to, and where required notify personal data breaches (section 5.7).
- Personnel — confidentiality obligations and security awareness for staff with access to Personal Data.
Annex 3 — Sub-processors
Our policy is to keep Personal Data in the United Kingdom or the European Economic Area wherever the provider offers it, and to rely on the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses where a provider processes outside the UK.
| Sub-processor | Purpose | Location | Transfer basis |
|---|---|---|---|
| Google Cloud Platform | Cloud hosting, database, storage | UK / EEA region | Data stays in the UK/EEA. UK Addendum to the EU SCCs applies to any support access from outside the UK |
| OpenAI | Language-model processing for assistant and drafting features | United States | UK Addendum to the EU SCCs. Enterprise/API terms: inputs and outputs are not used to train shared models |
| Modal | Machine-learning compute | United States | UK Addendum to the EU SCCs |
| Deepgram | Speech-to-text for voice and note-taking features | United States | UK Addendum to the EU SCCs |
| Stripe | Subscription billing and payment processing | United States, with EEA processing for EEA/UK customers | UK Addendum to the EU SCCs |
| Cloudflare | Hosting, security, bot protection for web forms | Global edge network, UK/EEA where configurable | UK Addendum to the EU SCCs |
| Resend | Transactional email delivery | United States | UK Addendum to the EU SCCs |
For each transfer outside the UK we carry out a transfer risk assessment and apply supplementary measures where the assessment calls for them. The Customer may request the transfer mechanism and assessment for any named sub-processor.
Maintained list. This annex is the position at the date above. The current list is kept at https://avagance.com/sub-processors, and changes are notified in accordance with section 5.4.
Customer-initiated integrations (for example, Intelliflo, Voyant, an e-signature provider) are connected at the Customer's instruction; where they process Personal Data, the Customer's relationship with that provider governs that processing, as described in Terms of Service section 12.