We use a small number of cookies to run this site and to count page views. Choose Accept all to allow the optional ones, or Accept essential for only what the site needs. You can change your choice at any time. Learn more

Aiome
Products
Team chatChannels, threads, and direct messages Projects & tasksLists, boards, owners, and due dates SOPs & trainingDocument how the business runs Time offRequests, balances, and team coverage Time trackingClock in, timesheets, and approvals People & orgDirectory, roles, and org chart
See all features Compare plans Talk to sales
Our roadmapWhat we're building next Knowledge baseGuides, how-tos, and answers
Pricing Contact
Login Start free
Team chat Projects & tasks SOPs & training Time off Time tracking People & org See all features
Our roadmap Knowledge base
Pricing Contact Login Start free

Data Processing Addendum

Last updated August 9, 2026 Version 1.0 Aiome Systems LLC
Contents
1. Scope and execution 2. Definitions 3. Roles of the parties 4. Processing instructions 5. Customer obligations 6. Security 7. Personnel 8. Subprocessors 9. Data subject rights 10. Personal data breaches 11. DPIAs and consultation 12. Return and deletion 13. Audits and information 14. International transfers 15. Special category data 16. US state privacy laws 17. Liability and general Annex I — Processing details Annex II — Security measures Annex III — Subprocessors

You do not need to sign or request this document. It takes effect automatically as part of our Terms of Service when you create an Aiome workspace, and the Standard Contractual Clauses in Section 14 are deemed executed at the same moment. If your procurement team requires a countersigned copy for its records, contact us at aiome.io/contact.

1.Scope and execution

This Data Processing Addendum (DPA) forms part of the Terms of Service or other written agreement (the Agreement) between Aiome Systems LLC (Aiome) and the customer identified in that Agreement (Customer), and governs Aiome's processing of Personal Data on Customer's behalf.

This DPA is effective on Customer's acceptance of the Agreement. No signature is required. By accepting the Agreement, Customer enters into this DPA on its own behalf and, where applicable, on behalf of its affiliates that use the Service.

Where this DPA conflicts with the Agreement in respect of the processing of Personal Data, this DPA prevails. Where the Standard Contractual Clauses conflict with this DPA, the Standard Contractual Clauses prevail.

2.Definitions

Data Protection Laws
All laws applicable to the processing of Personal Data under this DPA, including the EU General Data Protection Regulation (EU GDPR), the UK GDPR and Data Protection Act 2018 (UK GDPR), the Swiss Federal Act on Data Protection, and U.S. state privacy laws including the California Consumer Privacy Act as amended (CCPA).
Personal Data
Any information relating to an identified or identifiable natural person contained in Customer Data and processed by Aiome on Customer's behalf.
Data Subject
The individual to whom Personal Data relates — for Aiome, principally Customer's employees, contractors, and other authorized Users.
Controller, Processor, Subprocessor, Processing, Personal Data Breach, Supervisory Authority
Have the meanings given in the EU GDPR. Business, Service Provider, Sell, Share, and Sensitive Personal Information have the meanings given in the CCPA.
Standard Contractual Clauses (SCCs)
The clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
UK Addendum
The International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.

3.Roles of the parties

Customer is the Controller and Aiome is the Processor in respect of Personal Data contained in Customer Data. Where Customer is itself a processor for a third-party controller, Aiome is a Subprocessor and Customer warrants that it has authority to appoint Aiome and to give the instructions in this DPA.

Under the CCPA, Aiome acts as a Service Provider to Customer as Business.

Aiome acts as an independent Controller for the limited Personal Data described in its Privacy Policy — account registration, billing contacts, marketing contacts, and support correspondence. That processing is outside the scope of this DPA.

4.Processing instructions

Aiome will process Personal Data only on Customer's documented instructions, including as to international transfers, unless required to do otherwise by law to which Aiome is subject. In that case Aiome will inform Customer of the legal requirement before processing, unless the law prohibits it.

The Agreement, this DPA, and Customer's use and configuration of the Service constitute Customer's complete documented instructions. Additional instructions must be agreed in writing.

Aiome will immediately inform Customer if, in its opinion, an instruction infringes Data Protection Laws. Aiome may suspend the affected processing until the instruction is confirmed, amended, or withdrawn.

Aiome will not: process Personal Data for its own purposes; sell or share Personal Data; use Personal Data for advertising or profiling; combine Personal Data with data from other sources except as permitted by Data Protection Laws; or use Personal Data to train, fine-tune, or improve any machine learning model. Aiome may generate aggregated and de-identified statistics as permitted by the Agreement, provided they cannot be used to identify any Data Subject and Aiome does not attempt re-identification.

5.Customer obligations

Customer, as Controller, is responsible for:

  • the lawfulness of the Personal Data it submits and of Aiome's processing carried out on its instructions, including establishing a valid legal basis;
  • providing any privacy notice its Data Subjects are entitled to, and obtaining any consent required — including in respect of workplace monitoring and processing of employee data, which is regulated differently across jurisdictions;
  • the accuracy, quality, and integrity of Personal Data it submits;
  • configuring the Service appropriately, including deciding which features to enable, which fields to collect, and who holds administrator rights; and
  • responding to Data Subjects who exercise rights in respect of Customer Data.

6.Security

Aiome will implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as required by Article 32 of the GDPR.

Those measures are described in Annex II and on our Security page. Aiome may update them provided the level of security is not materially reduced.

7.Personnel and confidentiality

Aiome will ensure that persons authorized to process Personal Data are bound by an appropriate obligation of confidentiality, have received appropriate training, and are granted access only to the extent strictly necessary to perform their duties. Access to Customer Data by Aiome personnel is limited to the circumstances described in the Privacy Policy.

8.Subprocessors

General authorization. Customer gives Aiome general authorization to engage Subprocessors to process Personal Data, subject to this Section. Aiome's current Subprocessors are listed at aiome.io/subprocessors, which forms Annex III.

Obligations imposed. Before engaging a Subprocessor, Aiome will carry out appropriate due diligence and enter into a written agreement imposing data protection obligations no less protective than those in this DPA, including the obligations required by Article 28(3) of the GDPR and, where relevant, the SCCs.

Liability. Aiome remains fully liable to Customer for the performance of each Subprocessor's obligations.

Notice of changes. Aiome will give Customer at least 30 days' notice before a new Subprocessor begins processing Personal Data. Customers may subscribe to these notifications from the Subprocessors page. In the case of an urgent replacement necessary to maintain the security or continuity of the Service, Aiome will give notice as soon as reasonably practicable.

Right to object. Customer may object to a new Subprocessor on reasonable data protection grounds by written notice within 30 days. The parties will discuss the objection in good faith. If it cannot be resolved, Customer may terminate the affected part of the Service without penalty and receive a pro-rata refund of prepaid fees for the unused period.

9.Data subject rights

The Service provides Customer with controls to access, correct, export, and delete Personal Data in its Workspace, enabling it to respond to Data Subjects directly.

Taking into account the nature of the processing, Aiome will provide reasonable assistance by appropriate technical and organizational measures to help Customer fulfill its obligation to respond to requests to exercise rights of access, rectification, erasure, restriction, portability, and objection.

If Aiome receives a request directly from a Data Subject in respect of Customer Data, Aiome will not respond substantively except to confirm receipt and to direct the Data Subject to Customer. Aiome will notify Customer promptly, unless prohibited by law.

10.Personal data breaches

Aiome will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Personal Data processed under this DPA.

The notification will describe, to the extent known: the nature of the breach, including the categories and approximate number of Data Subjects and records concerned; the likely consequences; the measures taken or proposed to address it and mitigate its effects; and a contact point for further information. Where information is not available at the time, Aiome will provide it in phases as it becomes available.

Aiome will take reasonable steps to contain and investigate the breach, and will cooperate with Customer and provide reasonable assistance with any notification Customer must make to a Supervisory Authority or Data Subjects. Aiome will not make any public statement identifying Customer in relation to a breach without Customer's prior written consent, unless legally required.

Aiome's notification is not an acknowledgement of fault or liability.

11.Data protection impact assessments

Taking into account the nature of the processing and the information available to it, Aiome will provide reasonable assistance to Customer with data protection impact assessments and prior consultation with Supervisory Authorities under Articles 35 and 36 of the GDPR. Our Security page and Annex II are intended to supply much of the information typically required.

12.Return and deletion

Customer may export Personal Data through the Service at any time during the term.

On termination or expiry of the Agreement, Aiome will delete Personal Data from live systems within 30 days of termination, except where retention is required by law. During that period Customer may request return or export of the Personal Data.

Personal Data may persist in encrypted backups after deletion from live systems. It remains protected by this DPA and is deleted when those backups expire on the ordinary rolling cycle operated by Aiome's database provider. Aiome does not extend that cycle and holds no separate copies of its own.

Aiome will certify deletion in writing on request.

13.Audits and information

Aiome will make available to Customer the information reasonably necessary to demonstrate compliance with Article 28 of the GDPR, including this DPA, Annex II, and our Security page.

Customer may audit Aiome's compliance no more than once in any 12-month period, or more often following a Personal Data Breach affecting Customer or where required by a Supervisory Authority. Audits are subject to at least 30 days' written notice, are conducted during business hours in a manner that does not unreasonably disrupt Aiome's operations, are limited to information relevant to Customer's Personal Data, exclude other customers' data and information whose disclosure would compromise security, and are subject to confidentiality obligations. Customer bears its own costs and those of any third-party auditor, who must not be a competitor of Aiome.

Aiome may satisfy an audit request by providing a current third-party audit report or certification where one is available and reasonably addresses the scope of the request.

14.International transfers

Aiome is established in the United States and processes Personal Data there and in other countries where its Subprocessors operate, as identified on the Subprocessors page.

Standard Contractual Clauses

Where Aiome processes Personal Data protected by the EU GDPR and transfers it to a country without an adequacy decision, the SCCs are incorporated into this DPA by reference and are deemed executed by the parties on acceptance of the Agreement, as follows:

  • Module Two (Controller to Processor) applies where Customer is a Controller.
  • Module Three (Processor to Processor) applies where Customer is itself a Processor.
  • Clause 7 (docking) applies. In Clause 9, Option 2 (general written authorization) applies with the notice period in Section 8. In Clause 11, the optional independent dispute resolution language does not apply. In Clause 17, the SCCs are governed by the law of Ireland. In Clause 18(b), disputes are resolved before the courts of Ireland.
  • Annex I to the SCCs is completed by Annex I of this DPA; Annex II by Annex II; and the list of Subprocessors by Annex III.

United Kingdom

For Personal Data protected by the UK GDPR, the UK Addendum is incorporated and deemed executed. In Table 4, neither party may end the Addendum as set out in Section 19.

Switzerland

For Personal Data protected by Swiss law, the SCCs apply with references to the GDPR read as references to the Swiss FADP, the Swiss Federal Data Protection and Information Commissioner as the competent authority, and "member state" not preventing Data Subjects in Switzerland from bringing proceedings in Switzerland.

Government access requests

If Aiome receives a legally binding request from a public authority for Personal Data, it will — unless legally prohibited — notify Customer promptly, seek to redirect the authority to Customer, and challenge requests that are unlawful or overbroad. Aiome will disclose only the minimum amount of data lawfully required.

15.Special category and sensitive data

This Section exists because Aiome includes a time off module. A free-text note on a leave request may reveal an illness, a medical procedure, a pregnancy, or a disability — special category data under Article 9 of the GDPR and sensitive personal information under several U.S. state laws. Both parties should treat that possibility deliberately.

Aiome does not request special category data and does not require a reason for any leave request. The Service is not designed or marketed as a repository for health data, and Aiome does not process any Personal Data for the purpose of inferring characteristics about a Data Subject.

Customer acknowledges and agrees that:

  • it decides whether to collect reasons for leave and what its Users are asked or permitted to enter;
  • where such data is submitted, Customer is responsible for establishing a lawful basis and a condition for processing under Article 9(2) — typically in the employment context, Article 9(2)(b) — and for any additional safeguards its national law requires;
  • Aiome processes such data only as part of hosting the Workspace, applying the same access controls and security measures as to all other Customer Data; and
  • Customer should not use free-text fields in the Service to record medical detail, and should instruct its Users accordingly.

Aiome recommends that Customers configure leave types so that a category alone is sufficient, and that they avoid soliciting diagnosis or treatment information anywhere in the Service. Customer should note that a leave type can itself disclose health information — a category such as sick leave records that a person was unwell — and should treat the visibility of leave categories with the same care as the notes attached to them. Access to leave notes in the Service is restricted to the requesting member, Workspace administrators, and the people the Customer has designated to approve that leave; a Workspace member's manager does not see them by virtue of being a manager.

The Service is not intended for the processing of protected health information subject to HIPAA, payment card data subject to PCI DSS, government-classified information, or data subject to sector-specific regimes not addressed in the Agreement. Customer will not submit such data without a prior written agreement with Aiome.

16.US state privacy laws

This Section applies to Personal Data subject to the CCPA and comparable U.S. state privacy laws. Aiome acts as a Service Provider (or Processor, where that term is used) and certifies that it will:

  • not sell or share Personal Data as those terms are defined;
  • not retain, use, or disclose Personal Data for any purpose other than the specific business purpose of providing the Service under the Agreement, or as otherwise permitted by the CCPA;
  • not retain, use, or disclose Personal Data outside the direct business relationship between Aiome and Customer;
  • not combine Personal Data with personal information received from another source, except as permitted by the CCPA;
  • comply with the obligations applicable to Service Providers and provide the same level of privacy protection the CCPA requires;
  • notify Customer if it determines it can no longer meet these obligations; and
  • permit Customer to take reasonable and appropriate steps to stop and remediate unauthorized use.

Customer may take reasonable steps to ensure Aiome uses Personal Data in a manner consistent with these obligations. Aiome will assist Customer in responding to verifiable consumer requests and in meeting its obligations regarding sensitive personal information.

17.Liability, term, and changes

Liability. Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement. Nothing in this DPA limits a Data Subject's rights under Data Protection Laws or the SCCs.

Term. This DPA takes effect with the Agreement and continues until Aiome has deleted all Personal Data in accordance with Section 12.

Changes. Aiome may update this DPA where necessary to reflect a change in Data Protection Laws, a new transfer mechanism, or a change to the Service, provided the update does not materially reduce the protections afforded to Personal Data. Material changes will be notified at least 30 days in advance.

Governing law. Except as stated in Section 14 for the SCCs, this DPA is governed by the law stated in the Agreement.

Annex I — Details of processing

This Annex completes Annex I of the Standard Contractual Clauses.

A. Parties
Data exporter: the Customer identified in the Agreement, acting as Controller (or Processor). Contact details are those in Customer's account. Data importer: Aiome Systems LLC, 1401 21st St Ste R, Sacramento, CA 95811, United States — aiome.io/contact — acting as Processor (or Subprocessor), providing the Service described in the Agreement.
B. Categories of Data Subjects
Customer's employees, contractors, and other individuals whom Customer authorizes to access its Workspace, and any individual whose Personal Data Customer chooses to include in Customer Data.
Categories of Personal Data
Identification and contact data (name, email address, profile photo, job title); authentication data; organizational data (team, role, permissions, reporting lines, employment start date, employment type); communications content (chat messages and attachments); work records (projects, tasks, comments, SOPs, and records of SOP assignment and completion); time records (start and stop times of work periods and breaks, notes and reasons attached to an entry, and timesheets with their approval status); leave records (leave type, dates, approval status, any reason given for a decision, and any free-text note supplied by the Data Subject); and usage and log data (a pseudonymous identifier, the names of actions taken, device and browser information, timestamps, and — in server logs only — IP address).
Special categories of data
Not requested by Aiome and not required by the Service. Health-related information may incidentally be included by a Data Subject in a free-text note on a leave request, or be disclosed by the leave category itself. See Section 15. Where present, it is subject to the same access restrictions, encryption, and confidentiality obligations as all other Customer Data.
Frequency of transfer
Continuous, for the duration of the Agreement.
Nature and purpose of processing
Hosting, storage, transmission, display, backup, and deletion of Customer Data for the purpose of providing, securing, maintaining, and supporting the Service, in accordance with Customer's instructions. Aiome additionally processes pseudonymous usage data about how the Service is used — which features are used and when, never the content inside them — in order to operate and improve the Service. Aiome does not use Personal Data for advertising, for profiling Data Subjects, or to train any machine learning model.
Duration of processing
For the term of the Agreement, plus the deletion period in Section 12.
Subprocessor transfers
Subject matter, nature, and duration as described above. See Annex III.
C. Competent supervisory authority
Determined in accordance with Clause 13 of the SCCs, based on Customer's place of establishment or the location of its EU representative.

Annex II — Technical and organizational measures

This Annex completes Annex II of the Standard Contractual Clauses. Our Security page describes these measures in greater detail.

MeasureImplementation
Encryption in transitTLS 1.2 or higher for all connections to the Service and between infrastructure components. HSTS enforced.
Encryption at restAES-256 for databases, file storage, and backups.
PseudonymisationInternal identifiers used in logs and analytics in place of directly identifying data where practicable.
Access control — CustomerRole-based permissions within each Workspace, administered by Customer. Workspace isolation enforced at the data layer.
Access control — AiomeLeast-privilege access limited to personnel who require it; multi-factor authentication required on administrative accounts; an append-only audit record of every change made to a time entry, recording who made it, what changed, and any reason given.
ConfidentialityAll personnel bound by written confidentiality obligations that survive the end of engagement.
Availability and resilienceManaged, redundant infrastructure with automated backups. See Security.
RestorationAutomated backups operated by Aiome's managed database provider, encrypted at rest, restorable through that provider. Aiome does not currently maintain a restore process of its own beyond that provider's tooling.
Incident responseDocumented process for detecting, escalating, containing, and notifying security incidents. Customer notification within 72 hours (Section 10).
Secure developmentVersion control; changes reviewed and tested before deployment, including an automated test suite that verifies workspace isolation; automated dependency vulnerability scanning; segregated development, preview and production environments; production data not used in development.
Subprocessor governanceDue diligence before engagement; written data protection terms no less protective than this DPA; list published and change notice given (Section 8).
DeletionDeletion controls available in the Service; deletion on termination under Section 12; certification on request.
Data minimizationTime tracking records start and stop times only — no screenshots, location, keystroke, or activity monitoring. No reason required for leave requests.

Annex III — Subprocessors

Aiome's current Subprocessors, the processing each performs, and the countries in which each processes Personal Data are published and kept current at aiome.io/subprocessors. That page forms part of this DPA and is incorporated by reference.

Customer's authorization of these Subprocessors, and the notice and objection procedure that applies before a new one is added, are set out in Section 8.

Related documents: Terms of Service · Privacy Policy · Subprocessors · Security

Aiome

The all-in-one workspace that brings your team — and every tool it runs on — into one place.

Product Team chat Projects & tasks SOPs & training Time off Time tracking People & org Features Pricing
Company Contact Talk to sales
Get started Start free Compare plans
Legal Privacy Policy Terms of Service Data Processing Addendum Subprocessors Security Acceptable Use Refunds & Cancellation Accessibility
© 2026 Aiome Systems LLC. All rights reserved. Aiome Systems LLC · 1401 21st St Ste R, Sacramento, CA 95811