This DPA is between the business Customer identified in an Order (“Controller”) and Bennovate sp. z o.o., ul. Christiana Andersena 25, 94-118 Łódź, Poland, KRS 0000597272, NIP 7272799328, REGON 363700466, trading as Avantwerk (“Processor”). It forms part of the Avantwerk CRM contract.
In this DPA, Applicable Data Protection Law means the EU GDPR and relevant EEA law and, where the processing is subject to United Kingdom law, the UK GDPR and Data Protection Act 2018 as amended, including by the Data (Use and Access) Act 2025. A reference to an Article means the corresponding provision of the applicable regime unless the context requires otherwise.
1. Roles and boundaries
For personal data placed by the Controller or its users in a CRM account, the Controller normally determines purposes and means, Avantwerk processes on documented instructions, and HighLevel is Avantwerk’s subprocessor for the hosted platform. Where the Controller is itself a processor, Avantwerk and HighLevel occupy the corresponding downstream processor roles.
This DPA does not govern data for which Avantwerk independently determines purposes, including account administration, billing, security, fraud prevention and its own business records. In those contexts Avantwerk may be controller and its vendors processors under the Privacy Notice.
2. Processing details
- Subject: hosted CRM, contacts, communications, booking, websites, automation, reporting and only features identified in the Order.
- Duration: service term plus return, deletion and limited recovery periods in section 11 and the Retention Policy.
- Operations: collection, recording, organisation, storage, retrieval, consultation, transmission, matching, restriction, export and deletion through the configuration.
- Data subjects: prospects, customers, personnel, suppliers and other Controller contacts.
- Data: identity, contact, communication, appointment, transaction, form, consent, campaign, workflow and user-account data selected by the Controller.
- Special-category and criminal-offence data: not intended by default; processing requires a written amendment defining necessity, lawful condition, features and safeguards.
The actual scope must be completed in Annex A. A generic product description does not replace an incomplete Annex.
3. Documented instructions
Avantwerk processes CRM data only for the contracted service under the Order, configuration, authorised use and written instructions. It informs the Controller if an instruction may infringe data-protection law unless law prohibits notice. Extending a purpose or data category requires a documented amendment. Where Union or Member State law requires processing beyond instructions, Avantwerk gives prior notice unless prohibited on important public-interest grounds.
4. Processor duties and AI use
Avantwerk ensures authorised-person confidentiality; applies Article 32 measures proportionate to risk; assists with rights, security, breach assessment, DPIAs and consultation; keeps required records; does not sell CRM data, use it for unrelated marketing or train Avantwerk’s own models with it; and forwards direct data-subject requests to the Controller unless authorised to handle them.
HighLevel processes under its current DPA: https://www.gohighlevel.com/data-processing-agreement. Its documented instructions currently include providing and improving services, anonymising, deidentifying or aggregating data, and supplying enabled AI features. This does not authorise Avantwerk’s own unrelated purposes. Each AI feature, provider, knowledge source and input category must be identified in the Order or Annex A. Special-category, criminal-offence or other confidential data must not enter AI features unless separately assessed and agreed.
5. Controller duties
The Controller is responsible for lawful instructions, minimisation, accuracy, legal bases, notices, channel-specific consent, retention procedures, user permissions and data-subject rights. It must not place data in features the Order and safeguards are not designed to handle.
6. Subprocessors
The Controller grants general written authorisation for direct CRM subprocessors in the current Avantwerk CRM Register. Where reasonably possible, Avantwerk gives at least 30 days’ notice before adding a direct subprocessor. The Controller may object on reasonable data-protection grounds. The parties seek an alternative; if none is available, the affected feature or contract may end without charges for an unused future period.
Avantwerk imposes applicable equivalent duties on direct subprocessors and remains responsible to the extent required by Article 28(4) of Applicable Data Protection Law.
HighLevel maintains its downstream chain at https://www.gohighlevel.com/sub-processors. Those organisations are HighLevel subprocessors, not automatically Avantwerk direct vendors. HighLevel provides change notice and a 30-day objection period. Avantwerk relays a material notice it receives without undue delay and permits objection within the available period, but cannot promise notice earlier than its supplier provides it.
7. International transfers
Avantwerk documents the known chain and transfer mechanism. Depending on recipient and scope, a transfer outside the EEA relies on: (1) an applicable adequacy decision, including active and in-scope EU–US Data Privacy Framework certification; (2) the European Commission’s 2021 Standard Contractual Clauses; or (3) another lawful mechanism. A restricted transfer from the United Kingdom relies, as applicable, on UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful UK mechanism. Effectiveness is assessed for the actual transfer, with supplementary measures where that assessment requires them.
The documents do not assume all data stays in the EEA or UK, or that one transfer mechanism governs every recipient. HighLevel currently discloses processing in the United States and India, among other locations.
8. Security and breaches
The Security Statement allocates controls. Avantwerk is responsible for its configuration, access and operational practices; HighLevel for contractually described hosted-platform measures; and the Controller for its users, devices, instructions and use.
Avantwerk notifies the Controller without undue delay after becoming aware of a breach affecting CRM data, consistently with Article 33(2) of Applicable Data Protection Law. To the extent available, the initial notice describes the nature, categories and approximate numbers of subjects and records, likely consequences, measures taken or proposed and a contact point. Missing information is supplied in phases.
HighLevel currently commits to notice without undue delay and no later than 72 hours after awareness. That is a supplier boundary, not a grace period for Avantwerk. Avantwerk does not accept an absolute 12-hour deadline unsupported by its supplier chain.
9. Rights, assistance and audits
Avantwerk provides reasonable assistance through available search, export, correction, restriction and deletion functions. The Controller may request current security and compliance information and, if insufficient, conduct a proportionate audit through an independent specialist with reasonable notice, confidentiality and protection of other customers.
Scheduled audits ordinarily occur no more than annually. This does not restrict an audit required by a regulator, law, a substantiated material incident or reasonable evidence of non-compliance. The Controller bears extraordinary costs unless the audit establishes Avantwerk’s material breach or law requires otherwise. Access to supplier systems, documents and reports is subject to availability, confidentiality and HighLevel terms, which currently charge audit time at professional-services rates.
10. Retention during service
The Controller determines lawful active retention. HighLevel currently does not provide customers with universal custom retention policies. Avantwerk implements instructions using available deletion functions or a documented manual process and does not promise unavailable platform functionality.
11. Return, deletion and recovery
Before access ends, the Controller exports required data. On termination and at its written choice, Avantwerk returns or requests deletion of CRM data and copies, except limited retention required by law. Earlier deletion within the supplier’s 90-day window is requested where available.
Current HighLevel boundaries are: ordinary access ends on cancellation; cancelled account and subaccount data may persist for up to 90 days; telephone numbers and A2P registrations for 14 days; and record-recovery windows vary, with contacts potentially recoverable for up to 60 days. Official supplier materials are inconsistent across record types and associated data. Archived backups are isolated and protected from further processing except legal requirements. These windows are not active Avantwerk use or a recovery guarantee.
12. Priority, law and contact
This DPA controls CRM processing in a conflict. Polish law governs without limiting mandatory rights or regulator powers under Applicable Data Protection Law. Contact: [email protected].
Annex A — processing configuration
| Field | Agreed value |
|---|---|
| Business purposes and processes | [complete] |
| Data-subject categories | [complete] |
| Data categories and exact fields | [complete] |
| Sources and legal basis | [complete] |
| Forms and communication channels | [complete] |
| Recording / transcription | [no / yes — describe] |
| Profiling / scoring / automated decisions | [no / yes — describe effect and oversight] |
| AI features, provider, knowledge sources and inputs | [disabled / complete] |
| Special, criminal, financial or vulnerable-person data | [none / describe condition and safeguards] |
| Integrations and marketplace applications | [complete] |
| Communications and payment providers | [complete] |
| Active retention and deletion mechanism | [complete] |
| Locations and transfer mechanisms | [complete] |
| User roles and access control | [complete] |
| Export, return and deletion approver | [complete] |
