Data Processing Addendum
Effective July 2026 · Aethon AI, LLC · New York
Plain-English summary up top, always. When we process personal data on your behalf, this addendum applies: you are the controller, we are the processor, and the obligations below are standard, GDPR-aligned, and not negotiable downward.
1. Roles
For personal data in your workspace, you are the data controller and Aethon AI, LLC is the data processor. We process only on your documented instructions, which these terms and your plan configuration constitute.
2. Scope of processing
Categories are deliberately narrow: your team members’ business contact data, and pixel-derived technical data from your website visitors (referrer, page, timestamp, session signature). We instruct customers not to transmit special-category data, and the product does not ask for it.
3. Security measures
Encryption in transit (TLS 1.2+) and at rest (AES-256), role-scoped least-privilege access, access logging, environment separation, and vulnerability response within one business day of a report. Details are on the Security & Trust page and in our questionnaire responses.
4. Subprocessors
We use major cloud infrastructure and email providers as subprocessors, listed with the current DPA document. We give 30 days’ notice before adding one, and you may object on reasonable data-protection grounds.
5. Data subject requests
If a request under GDPR, CCPA, or similar law reaches us but belongs to you as controller, we forward it within two business days and assist with fulfillment at no charge.
6. Breach notification
We notify affected customers without undue delay and within 72 hours of confirming a personal data breach, with what we know, what we are doing, and a named human to talk to.
7. International transfers
Where transfers from the EEA, UK, or Switzerland occur, we rely on Standard Contractual Clauses incorporated into the signed DPA.
8. Audit and deletion
Enterprise customers may audit via questionnaire and, where legally required, deeper review under NDA. On termination, personal data is deleted or returned per section 6 of the Privacy Policy. A signed copy of this DPA is available on request from daniel.arons@aiaethon.com.
Questions about any of this go to daniel.arons@aiaethon.com and get answered by a person.