1. What this page is
This page explains Avantwerk's data-protection architecture. It is not a certification and does not replace the Website Privacy Notice, Customer notice, DPA or Order.
2. Roles
Bennovate sp. z o.o. is controller for its own website, business, account, billing and security administration. For personal data a Customer places in Avantwerk CRM, the Customer normally acts as controller and Bennovate as processor. The hosted-platform supplier and any approved project vendor occupy the downstream role stated in the DPA and project annex. A Bennovate business tool is not automatically a Customer CRM subprocessor.
3. Contractual controls
The CRM DPA states the subject, duration, nature, purpose, data categories, persons, instructions, confidentiality, security cooperation, data-subject support, breach assistance, deletion or return, audit and subprocessor rules. The Order and its annex identify the project-specific scope. Customer data must not be submitted to an optional AI, productivity or implementation provider until that flow, account, region, contract and approval are documented where required.
4. Security and incidents
Security is shared. Bennovate is responsible for its access, configuration and operational measures; platform and infrastructure providers for their contracted layers; and the Customer for its users, endpoints, permissions, instructions, connected services and lawful use. No security measure makes a system risk-free. Report a suspected incident promptly to [email protected].
5. Rights and contact
For Bennovate-controlled data, requests go to [email protected]. For data inside a Customer CRM, contact that Customer first; Bennovate assists under the DPA. Complaints may be made to UODO and, where UK GDPR applies, the ICO.
6. UK status
The current corporate SSOT contains no recorded UK representative appointment. The Website Privacy Notice explains the resulting Article 27 gap. No page should imply that a UK representative exists until the appointment is documented.
