Legal
Data Processing Agreement
Last updated 4 September 2026 · Aventura Virtual Solutions Inc. (Canada), operating CloseRev
When you upload customer records to CloseRev, you are the controller and we are your processor. This sets out what we may do with that data and what we owe you.
1. Scope
This DPA forms part of the Terms of Service between you ("Controller") and Aventura Virtual Solutions Inc. ("Processor"). It applies to personal data contained in the files you upload and the results derived from them ("Customer Data").
2. Subject matter and duration
We process Customer Data solely to provide the matching and reporting service, for as long as your account is active or until you delete the data — whichever comes first.
3. Nature of the processing
| Category | Detail |
|---|---|
| Data subjects | Your customers and leads |
| Data types | Name, phone number, email address, transaction amount and date, marketing channel and campaign, and any other column you choose to map |
| Operations | Storage, normalisation, matching, aggregation, display, export and deletion |
| Special categories | None requested. Do not upload health, biometric or other special-category data — the service is not designed for it |
4. Our obligations
- Process Customer Data only on your documented instructions — using the product is such an instruction.
- Never sell it, use it for our own marketing, or use it to train machine-learning models.
- Bind everyone with access to confidentiality.
- Apply the technical and organisational measures in section 6.
- Help you respond to data-subject requests, and with DPIAs and regulator consultations where relevant.
- Notify you without undue delay, and in any case within 72 hours of becoming aware, of a personal data breach affecting your data.
- Delete or return Customer Data on termination, per section 8.
5. Your obligations
You confirm you have a lawful basis to collect the data and to have us process it, that you've given any notices your customers are owed, and that you upload only the fields the service needs.
6. Security measures
- Encryption in transit (TLS 1.2+) and at rest.
- Per-workspace isolation, with every query scoped so one tenant cannot reach another's records.
- Passwords hashed with PBKDF2-HMAC-SHA256 at 600,000 iterations with per-password salts; sessions are opaque, expiring and server-revocable.
- Single-use, expiring, hashed tokens for email verification and password reset.
- Card data never touches our servers — payment is handled entirely by Stripe.
- An audit log of uploads, matches, overrides, exports and deletions within each workspace.
- Least-privilege access for staff, granted only where needed to operate or support the service.
7. Sub-processors
You give general authorisation for the sub-processors listed on our Subprocessors page. We'll give at least 30 days' notice before adding or replacing one, and you may object on reasonable data-protection grounds — if we can't resolve it, you may terminate the affected service and receive a pro-rata refund. Each sub-processor is bound by terms no less protective than these.
8. Deletion and return
You can delete any import at any time from the product; doing so removes its records, its match results and the original uploaded file from storage. On account closure we delete Customer Data within 30 days, except where law requires retention. You can export your data at any point before then.
9. International transfers
We are established in Canada, which the European Commission recognises as providing adequate protection for commercial organisations subject to PIPEDA. Where Customer Data is transferred from the EEA or UK to a sub-processor outside an adequate jurisdiction, the transfer relies on the Standard Contractual Clauses (and the UK Addendum where applicable), together with supplementary technical measures including encryption.
10. Audit
On reasonable written request, and no more than once a year unless a regulator requires otherwise, we'll provide the information needed to demonstrate compliance with this DPA.
11. Signature
Accepting the Terms of Service accepts this DPA — no signature required. If your compliance process needs a countersigned copy or your own paper, email legal@closerev.com.