Data Processing Addendum

This DPA forms part of the Terms of Service and governs the processing of personal data under GDPR, CCPA, and HIPAA.

1. Scope and Roles

The customer is the Controller; Aimform is the Processor. This DPA applies wherever Aimform processes personal data on the Controller's behalf under applicable data protection laws.

2. Nature and Purpose of Processing

Aimform processes personal data to provide the Service: AI-powered workspaces, document editing, workflow automation, and app integrations. Processing is limited to the Controller's documented instructions.

3. Subprocessors

The Controller authorizes the following subprocessors. New platform subprocessors are announced at least 14 days in advance.

SubprocessorPurposeLocation
CloudflareHosting, CDN, D1 database, R2 storage, Workers computeGlobal
StripePayment processing, subscription managementUSA
DeepSeekAI model inference (non-HIPAA organizations)Global
AWS BedrockAI model inference (HIPAA-eligible organizations)USA

Additional subprocessors may be added when you install marketplace apps. Each app's subprocessors are disclosed before installation and listed in your Compliance tab.

4. Data Subject Rights (GDPR)

  • Right of access (Art. 15) — export all workspace data via Compliance tab
  • Right to erasure (Art. 17) — soft-delete with configurable retention before permanent erasure
  • Right to data portability (Art. 20) — machine-readable JSON export
  • Right to rectification (Art. 16) — update data directly in the Service
  • Right to restrict processing (Art. 18) — contact us to request processing restriction

5. CCPA Compliance

  • We do not sell personal data — no opt-out required
  • Data collection and use practices are disclosed in our Privacy Policy
  • Deletion and access requests honored within 45 days
  • No discrimination against users exercising CCPA rights

6. COPPA Compliance

  • Organization administrators configure minimum age requirements
  • Parental consent verification is the organization's responsibility
  • Data minimization: auto-purge policies available for child data
  • Parental data review and deletion via standard data subject request endpoints

7. Security Measures

  • Encryption at rest (D1 database, R2 storage — Cloudflare-managed)
  • Encryption in transit (TLS 1.3)
  • Role-based access controls with per-organization data isolation
  • Audit logging of all data access events
  • Regular security assessments and incident response procedures

8. Breach Notification

Aimform shall notify the Controller without undue delay and within 72 hours of becoming aware of a personal data breach.

9. Data Retention and Deletion

Data is retained while the account is active. Upon termination, data is soft-deleted immediately and permanently erased after the configured retention period (default 30 days). Daily automated hard-delete workflow ensures final erasure.

10. Cross-Border Transfers

Data residency is configurable per organization (US or EU). For EEA transfers, Standard Contractual Clauses apply.

11. Audit Rights

Controllers may request the audit log, request a compliance report (within 30 days), or conduct an on-site audit (30 days notice, once per year).

12. Acceptance

This DPA is accepted when you create an Aimform account and is always available for download in Workspace Settings → Compliance.

Universal Reason LLC · [email protected]