Aiome processes two very different categories of information, and the rules that apply to each are different. When you browse our website, request a demo, or sign your organization up, we determine how that information is used, and this Privacy Policy governs it. When your team submits messages, tasks, and time records within a workspace, we act solely as custodian. Your employer determines what is submitted and what happens to it. We store it securely and process it in accordance with the customer's instructions.
Data protection law distinguishes between the party that determines the purposes and means of processing personal information (a controller, or business under U.S. state law) and the party that processes personal information on that party's instructions (a processor, or service provider). Aiome acts in both capacities, depending on the information in question:
Section 4 describes what this distinction means in practice, and Section 15 is addressed to individuals whose employer has enrolled them in the Service.
Aiome is an all-in-one workspace for teams — team chat, projects and tasks, SOPs and training, time tracking, time off, and people and organizational management in a single product. This Privacy Policy applies to aiome.io, the Aiome application, and our sales and support communications (collectively, the Service).
This Section describes information for which Aiome is the controller. Customer Data is addressed separately in Section 4.
If a colleague invites you to a workspace, we receive your email address from that colleague in order to send the invitation. We do not purchase personal information from data brokers.
We do not read your team's messages. We do not mine your workspace to build products, to profile your personnel, or to sell anything. The content belongs to you, your employer controls it, and our access is limited to operating the Service and providing assistance when you request it.
When a customer uses Aiome, its personnel submit content into the workspace. Depending on which parts of the product the customer enables, Customer Data may include:
Important. A free-text note attached to a leave request may reveal health information — an illness, a medical procedure, a pregnancy, a disability, or a family emergency. The leave type alone may have the same effect, because a category such as sick leave discloses that a person was unwell. Under the UK GDPR and the EU GDPR this is special category data (Article 9), and several U.S. state privacy laws treat health information as sensitive.
Aiome does not ask for medical information and does not require a reason for any leave request. Where a note is provided, we process it solely as part of hosting the customer's workspace and apply the same access controls as all other Customer Data. The customer, as the employer and controller, is responsible for deciding whether to collect reasons for leave, for establishing a lawful basis for doing so, and for instructing its personnel on what to write. We recommend that customers do not solicit medical detail in this field.
Aiome personnel do not routinely access the contents of a customer workspace. Access occurs only where it is necessary to: operate and maintain the Service; investigate or remedy a fault, including one the customer has reported; respond to a support request from the customer; or comply with law. Such access is limited to personnel who need it, on a least-privilege basis, and is restricted to the smallest number of people consistent with operating the Service.
As a controller, we use personal information to:
| Purpose | UK/EU legal basis |
|---|---|
| Provide the Service — create and secure accounts, host workspaces, deliver features | Performance of a contract |
| Billing — process subscriptions, invoicing, and tax | Performance of a contract; legal obligation |
| Service communications — invitations, password resets, security alerts, changes to terms | Performance of a contract; legitimate interests |
| Support — answer questions and resolve faults | Performance of a contract; legitimate interests |
| Security and abuse prevention — detect fraud, abuse, and unauthorized access | Legitimate interests; legal obligation |
| Improve the Service — understand which features are used, diagnose faults | Legitimate interests |
| Marketing — send information about Aiome to people who have asked to hear from us | Consent, or legitimate interests where permitted |
| Legal compliance — respond to lawful requests, enforce our terms, establish or defend claims | Legal obligation; legitimate interests |
Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights, and you may object at any time (Section 12).
We do not sell personal information, and we do not use Customer Data to build or improve products for anyone other than the customer to whom it belongs.
As of the date of this Privacy Policy, Aiome does not send Customer Data to any third-party AI or large language model provider, and no AI feature processes the contents of your workspace.
Teams that store employee records are entitled to a direct answer to this question, and we provide one. As of the date of this Privacy Policy:
We are developing features that would use third-party AI models to assist teams in working with their own content. If and when any such feature processes Customer Data, we commit that:
We separately use AI-assisted tools within our own business operations — for example, for writing and engineering work. Where those tools would process personal information belonging to our customers, they are subject to the same subprocessor controls described above.
Aiome is based in the United States and our infrastructure is located there. Your workspace content is stored in the western United States, our application runs on United States infrastructure, and our product analytics are hosted in the eastern United States. If you are in the United Kingdom, the European Economic Area, or another jurisdiction with data transfer restrictions, your information will be transferred to and processed in the United States and other countries where our subprocessors operate. Our Subprocessors page lists the location of each one.
For transfers of UK and EEA personal data, we rely on the European Commission's Standard Contractual Clauses and, for the UK, the UK International Data Transfer Addendum, together with supplementary technical and organizational measures including encryption in transit and at rest. These clauses are incorporated into our Data Processing Addendum, which is available to every customer without negotiation.
You may request further information about our transfer mechanisms, including a copy of the relevant clauses, through aiome.io/contact.
We retain personal information only for as long as we need it for the purposes described in this Privacy Policy, or for as long as required by law.
| Information | Retention |
|---|---|
| Customer Data in an active workspace | For as long as the workspace is active, and as directed by the customer |
| Customer Data after cancellation | 30 days from the end of the subscription, so that you can export your data or reactivate. After 30 days it is deleted from live systems |
| Inactive free workspaces | Retained. We do not delete a Free workspace because it has become inactive, and we have no plans to do so. If that ever changes we will publish the policy and give notice first |
| Backups | Deleted data can persist in encrypted backups until those backups expire on our database provider's ordinary rolling cycle, after which it is gone. We do not extend that cycle or keep separate copies of our own |
| Contact and marketing records | Until you unsubscribe or ask us to delete them, and for a reasonable period afterwards to honor your preference |
| Billing and tax records | As required by law, generally seven years |
| Server and security logs | Retained by our hosting provider for the period set by its platform, which is a matter of days to weeks rather than months, and then deleted automatically. We do not archive them |
| Product analytics events | Retained by our analytics provider for the period set by its plan, which ranges from 12 months to 7 years. We do not extend it, and we keep no separate copy of these events ourselves |
We maintain technical and organizational measures designed to protect personal information against unauthorized access, alteration, disclosure, and destruction. These include encryption in transit using TLS 1.2 or higher, encryption at rest using AES-256, role-based access controls enforced in the database itself rather than only in the interface, least-privilege access for Aiome personnel, and an append-only record of every change made to a time entry.
Our Security page describes these measures in detail. If we become aware of a personal data breach affecting Customer Data, we will notify the affected customer without undue delay and in any event within 72 hours of becoming aware of it, as set out in our Data Processing Addendum.
No system is perfectly secure. You are responsible for keeping your account credentials confidential and for the security of the devices you use to access Aiome.
If you are in the UK or the EEA, you have the following rights in relation to personal information for which Aiome is the controller:
To exercise a right, contact us at aiome.io/contact or [email protected]. We respond within one month and may extend by two further months for complex requests, telling you if we do. We may need to verify your identity. Exercising these rights is free unless a request is manifestly unfounded or excessive.
If your employer uses Aiome, your rights over the content of that workspace are exercised against your employer, not us — see Section 15.
Residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Tennessee, Maryland, Indiana, Kentucky, Rhode Island, and other states with comprehensive privacy laws have rights that may include:
How to submit a request. Use aiome.io/contact or email [email protected]. We will verify your request using the information we already hold about you, and will respond within the period your state's law requires — generally 45 days, extendable once where permitted.
Authorized agents. You may use an authorized agent to submit a request. We will ask for proof of the agent's authority and may ask you to verify your own identity directly.
California "Shine the Light." California residents may request information about disclosures of personal information to third parties for their direct marketing purposes. We do not make such disclosures.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We do not process personal information for targeted advertising, and we do not sell or share the personal information of anyone we know to be under 16.
Some state privacy laws define "sale" and "sharing" broadly enough to capture the use of certain advertising and analytics technologies, even where no money changes hands. As of the date of this Privacy Policy, Aiome does not operate advertising pixels or trackers on aiome.io that would constitute a sale or sharing under those definitions.
If that changes, we will update this Section and provide a clearly labelled "Do Not Sell or Share My Personal Information" link in our website footer, honor Global Privacy Control signals as an opt-out, and offer a means to limit the use of sensitive personal information.
Sensitive personal information. We do not collect or process sensitive personal information for the purpose of inferring characteristics about you. Where Customer Data submitted by a customer's personnel happens to contain sensitive information — for example a health-related note in a leave request (Section 4) — we process it only to provide the Service and never for advertising or profiling.
This Section applies to you if you did not choose Aiome — your employer did. You may never have visited our website or agreed to anything, and you are nonetheless entitled to understand your position.
When an organization signs up for Aiome and adds you to its workspace, your employer is the controller of the information in that workspace and Aiome is only the processor. That distinction has practical consequences for you:
We make the following commitments to you directly: we do not sell your information; we do not use your employer's workspace content for our own purposes; we do not send Customer Data to AI model providers (Section 6); and Aiome's time tracking records only start and stop times — it does not take screenshots, track your location, or monitor your activity (Section 4).
Where Aiome is the controller of information about you — for example the login credentials and profile you maintain to access the Service — the rights in Sections 12 and 13 apply to us directly.
Aiome is a business product and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child under 16 has provided us with personal information, contact us and we will delete it. Customers are responsible for ensuring that they do not add members under 16 to their workspace.
We may update this Privacy Policy as the Service and applicable law change. We will post the revised policy on this page and update the "Last updated" date above.
If a change is material — for example, a new category of personal information, a new purpose, or the introduction of AI processing of Customer Data (Section 6) — we will give notice before it takes effect, by email to workspace administrators, by notice in the Service, or both. Where the law requires your consent for a change, we will obtain it.
We keep prior versions of this Privacy Policy and will provide one on request.
For any privacy inquiry, to exercise a right, or to send a legal notice:
Related documents: Terms of Service · Data Processing Addendum · Subprocessors · Security · Acceptable Use Policy