You do not need to sign or request this document. It takes effect automatically as part of our Terms of Service when you create an Aiome workspace, and the Standard Contractual Clauses in Section 14 are deemed executed at the same moment. If your procurement team requires a countersigned copy for its records, contact us at aiome.io/contact.
This Data Processing Addendum (DPA) forms part of the Terms of Service or other written agreement (the Agreement) between Aiome Systems LLC (Aiome) and the customer identified in that Agreement (Customer), and governs Aiome's processing of Personal Data on Customer's behalf.
This DPA is effective on Customer's acceptance of the Agreement. No signature is required. By accepting the Agreement, Customer enters into this DPA on its own behalf and, where applicable, on behalf of its affiliates that use the Service.
Where this DPA conflicts with the Agreement in respect of the processing of Personal Data, this DPA prevails. Where the Standard Contractual Clauses conflict with this DPA, the Standard Contractual Clauses prevail.
Customer is the Controller and Aiome is the Processor in respect of Personal Data contained in Customer Data. Where Customer is itself a processor for a third-party controller, Aiome is a Subprocessor and Customer warrants that it has authority to appoint Aiome and to give the instructions in this DPA.
Under the CCPA, Aiome acts as a Service Provider to Customer as Business.
Aiome acts as an independent Controller for the limited Personal Data described in its Privacy Policy — account registration, billing contacts, marketing contacts, and support correspondence. That processing is outside the scope of this DPA.
Aiome will process Personal Data only on Customer's documented instructions, including as to international transfers, unless required to do otherwise by law to which Aiome is subject. In that case Aiome will inform Customer of the legal requirement before processing, unless the law prohibits it.
The Agreement, this DPA, and Customer's use and configuration of the Service constitute Customer's complete documented instructions. Additional instructions must be agreed in writing.
Aiome will immediately inform Customer if, in its opinion, an instruction infringes Data Protection Laws. Aiome may suspend the affected processing until the instruction is confirmed, amended, or withdrawn.
Aiome will not: process Personal Data for its own purposes; sell or share Personal Data; use Personal Data for advertising or profiling; combine Personal Data with data from other sources except as permitted by Data Protection Laws; or use Personal Data to train, fine-tune, or improve any machine learning model. Aiome may generate aggregated and de-identified statistics as permitted by the Agreement, provided they cannot be used to identify any Data Subject and Aiome does not attempt re-identification.
Customer, as Controller, is responsible for:
Aiome will implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as required by Article 32 of the GDPR.
Those measures are described in Annex II and on our Security page. Aiome may update them provided the level of security is not materially reduced.
Aiome will ensure that persons authorized to process Personal Data are bound by an appropriate obligation of confidentiality, have received appropriate training, and are granted access only to the extent strictly necessary to perform their duties. Access to Customer Data by Aiome personnel is limited to the circumstances described in the Privacy Policy.
General authorization. Customer gives Aiome general authorization to engage Subprocessors to process Personal Data, subject to this Section. Aiome's current Subprocessors are listed at aiome.io/subprocessors, which forms Annex III.
Obligations imposed. Before engaging a Subprocessor, Aiome will carry out appropriate due diligence and enter into a written agreement imposing data protection obligations no less protective than those in this DPA, including the obligations required by Article 28(3) of the GDPR and, where relevant, the SCCs.
Liability. Aiome remains fully liable to Customer for the performance of each Subprocessor's obligations.
Notice of changes. Aiome will give Customer at least 30 days' notice before a new Subprocessor begins processing Personal Data. Customers may subscribe to these notifications from the Subprocessors page. In the case of an urgent replacement necessary to maintain the security or continuity of the Service, Aiome will give notice as soon as reasonably practicable.
Right to object. Customer may object to a new Subprocessor on reasonable data protection grounds by written notice within 30 days. The parties will discuss the objection in good faith. If it cannot be resolved, Customer may terminate the affected part of the Service without penalty and receive a pro-rata refund of prepaid fees for the unused period.
The Service provides Customer with controls to access, correct, export, and delete Personal Data in its Workspace, enabling it to respond to Data Subjects directly.
Taking into account the nature of the processing, Aiome will provide reasonable assistance by appropriate technical and organizational measures to help Customer fulfill its obligation to respond to requests to exercise rights of access, rectification, erasure, restriction, portability, and objection.
If Aiome receives a request directly from a Data Subject in respect of Customer Data, Aiome will not respond substantively except to confirm receipt and to direct the Data Subject to Customer. Aiome will notify Customer promptly, unless prohibited by law.
Aiome will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Personal Data processed under this DPA.
The notification will describe, to the extent known: the nature of the breach, including the categories and approximate number of Data Subjects and records concerned; the likely consequences; the measures taken or proposed to address it and mitigate its effects; and a contact point for further information. Where information is not available at the time, Aiome will provide it in phases as it becomes available.
Aiome will take reasonable steps to contain and investigate the breach, and will cooperate with Customer and provide reasonable assistance with any notification Customer must make to a Supervisory Authority or Data Subjects. Aiome will not make any public statement identifying Customer in relation to a breach without Customer's prior written consent, unless legally required.
Aiome's notification is not an acknowledgement of fault or liability.
Taking into account the nature of the processing and the information available to it, Aiome will provide reasonable assistance to Customer with data protection impact assessments and prior consultation with Supervisory Authorities under Articles 35 and 36 of the GDPR. Our Security page and Annex II are intended to supply much of the information typically required.
Customer may export Personal Data through the Service at any time during the term.
On termination or expiry of the Agreement, Aiome will delete Personal Data from live systems within 30 days of termination, except where retention is required by law. During that period Customer may request return or export of the Personal Data.
Personal Data may persist in encrypted backups after deletion from live systems. It remains protected by this DPA and is deleted when those backups expire on the ordinary rolling cycle operated by Aiome's database provider. Aiome does not extend that cycle and holds no separate copies of its own.
Aiome will certify deletion in writing on request.
Aiome will make available to Customer the information reasonably necessary to demonstrate compliance with Article 28 of the GDPR, including this DPA, Annex II, and our Security page.
Customer may audit Aiome's compliance no more than once in any 12-month period, or more often following a Personal Data Breach affecting Customer or where required by a Supervisory Authority. Audits are subject to at least 30 days' written notice, are conducted during business hours in a manner that does not unreasonably disrupt Aiome's operations, are limited to information relevant to Customer's Personal Data, exclude other customers' data and information whose disclosure would compromise security, and are subject to confidentiality obligations. Customer bears its own costs and those of any third-party auditor, who must not be a competitor of Aiome.
Aiome may satisfy an audit request by providing a current third-party audit report or certification where one is available and reasonably addresses the scope of the request.
Aiome is established in the United States and processes Personal Data there and in other countries where its Subprocessors operate, as identified on the Subprocessors page.
Where Aiome processes Personal Data protected by the EU GDPR and transfers it to a country without an adequacy decision, the SCCs are incorporated into this DPA by reference and are deemed executed by the parties on acceptance of the Agreement, as follows:
For Personal Data protected by the UK GDPR, the UK Addendum is incorporated and deemed executed. In Table 4, neither party may end the Addendum as set out in Section 19.
For Personal Data protected by Swiss law, the SCCs apply with references to the GDPR read as references to the Swiss FADP, the Swiss Federal Data Protection and Information Commissioner as the competent authority, and "member state" not preventing Data Subjects in Switzerland from bringing proceedings in Switzerland.
If Aiome receives a legally binding request from a public authority for Personal Data, it will — unless legally prohibited — notify Customer promptly, seek to redirect the authority to Customer, and challenge requests that are unlawful or overbroad. Aiome will disclose only the minimum amount of data lawfully required.
This Section exists because Aiome includes a time off module. A free-text note on a leave request may reveal an illness, a medical procedure, a pregnancy, or a disability — special category data under Article 9 of the GDPR and sensitive personal information under several U.S. state laws. Both parties should treat that possibility deliberately.
Aiome does not request special category data and does not require a reason for any leave request. The Service is not designed or marketed as a repository for health data, and Aiome does not process any Personal Data for the purpose of inferring characteristics about a Data Subject.
Customer acknowledges and agrees that:
Aiome recommends that Customers configure leave types so that a category alone is sufficient, and that they avoid soliciting diagnosis or treatment information anywhere in the Service. Customer should note that a leave type can itself disclose health information — a category such as sick leave records that a person was unwell — and should treat the visibility of leave categories with the same care as the notes attached to them. Access to leave notes in the Service is restricted to the requesting member, Workspace administrators, and the people the Customer has designated to approve that leave; a Workspace member's manager does not see them by virtue of being a manager.
The Service is not intended for the processing of protected health information subject to HIPAA, payment card data subject to PCI DSS, government-classified information, or data subject to sector-specific regimes not addressed in the Agreement. Customer will not submit such data without a prior written agreement with Aiome.
This Section applies to Personal Data subject to the CCPA and comparable U.S. state privacy laws. Aiome acts as a Service Provider (or Processor, where that term is used) and certifies that it will:
Customer may take reasonable steps to ensure Aiome uses Personal Data in a manner consistent with these obligations. Aiome will assist Customer in responding to verifiable consumer requests and in meeting its obligations regarding sensitive personal information.
Liability. Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement. Nothing in this DPA limits a Data Subject's rights under Data Protection Laws or the SCCs.
Term. This DPA takes effect with the Agreement and continues until Aiome has deleted all Personal Data in accordance with Section 12.
Changes. Aiome may update this DPA where necessary to reflect a change in Data Protection Laws, a new transfer mechanism, or a change to the Service, provided the update does not materially reduce the protections afforded to Personal Data. Material changes will be notified at least 30 days in advance.
Governing law. Except as stated in Section 14 for the SCCs, this DPA is governed by the law stated in the Agreement.
This Annex completes Annex I of the Standard Contractual Clauses.
This Annex completes Annex II of the Standard Contractual Clauses. Our Security page describes these measures in greater detail.
| Measure | Implementation |
|---|---|
| Encryption in transit | TLS 1.2 or higher for all connections to the Service and between infrastructure components. HSTS enforced. |
| Encryption at rest | AES-256 for databases, file storage, and backups. |
| Pseudonymisation | Internal identifiers used in logs and analytics in place of directly identifying data where practicable. |
| Access control — Customer | Role-based permissions within each Workspace, administered by Customer. Workspace isolation enforced at the data layer. |
| Access control — Aiome | Least-privilege access limited to personnel who require it; multi-factor authentication required on administrative accounts; an append-only audit record of every change made to a time entry, recording who made it, what changed, and any reason given. |
| Confidentiality | All personnel bound by written confidentiality obligations that survive the end of engagement. |
| Availability and resilience | Managed, redundant infrastructure with automated backups. See Security. |
| Restoration | Automated backups operated by Aiome's managed database provider, encrypted at rest, restorable through that provider. Aiome does not currently maintain a restore process of its own beyond that provider's tooling. |
| Incident response | Documented process for detecting, escalating, containing, and notifying security incidents. Customer notification within 72 hours (Section 10). |
| Secure development | Version control; changes reviewed and tested before deployment, including an automated test suite that verifies workspace isolation; automated dependency vulnerability scanning; segregated development, preview and production environments; production data not used in development. |
| Subprocessor governance | Due diligence before engagement; written data protection terms no less protective than this DPA; list published and change notice given (Section 8). |
| Deletion | Deletion controls available in the Service; deletion on termination under Section 12; certification on request. |
| Data minimization | Time tracking records start and stop times only — no screenshots, location, keystroke, or activity monitoring. No reason required for leave requests. |
Aiome's current Subprocessors, the processing each performs, and the countries in which each processes Personal Data are published and kept current at aiome.io/subprocessors. That page forms part of this DPA and is incorporated by reference.
Customer's authorization of these Subprocessors, and the notice and objection procedure that applies before a new one is added, are set out in Section 8.
Related documents: Terms of Service · Privacy Policy · Subprocessors · Security