Data Privacy Agreement

AIMYABLE DATA PROCESSING ADDENDUM (DPA)

Effective Date: July 31, 2026

This Data Processing Addendum (“DPA”) forms part of the Aimyable Master Subscription Agreement (“Agreement”) between Aimyable, Inc. (“Aimyable”) and the Customer.

This DPA applies only to the extent Aimyable processes Personal Data on behalf of Customer in connection with the Services.

If there is a conflict between this DPA and the Agreement regarding the processing of Personal Data, this DPA controls.

1. Purpose and Applicability

This DPA governs Aimyable’s processing of Personal Data on behalf of Customer while providing the Services.

The parties intend this DPA to satisfy applicable contractual requirements under privacy and data protection laws, including, where applicable, the General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), and other substantially similar privacy laws.

Nothing in this DPA expands either party’s obligations beyond those required by applicable law.

2. Definitions

Unless otherwise defined in this DPA, capitalized terms have the meanings given in the Agreement.

For purposes of this DPA:

Controller, Processor, Business, Service Provider, Personal Data, and Processing have the meanings assigned under applicable privacy laws.

Security Incident means unauthorized access to, acquisition of, disclosure of, alteration of, or destruction of Personal Data processed by Aimyable, excluding unsuccessful attempts that do not compromise the security of Personal Data.

3. Roles of the Parties

Customer determines the purposes and means for which Personal Data is collected and submitted to the Services.

Accordingly:

· Customer acts as the Controller or Business, as applicable.

· Aimyable acts as the Processor or Service Provider solely for purposes of providing the Services.

Aimyable will not sell Personal Data or use Personal Data for advertising or any purpose unrelated to providing the Services requested by Customer.

4. Scope of Processing

Aimyable processes Personal Data only as necessary to:

· provide the Services;

· perform customer-authorized automation;

· maintain and secure the Services;

· provide technical support;

· comply with applicable law;

· fulfill Customer’s documented instructions consistent with the Agreement.

Customer represents that it has all necessary rights and authority to provide Personal Data to Aimyable.

5. Customer Instructions

Customer instructs Aimyable to process Personal Data solely for the purposes described in the Agreement, this DPA, and Customer’s authorized use of the Services.

If Aimyable believes a Customer instruction violates applicable law, Aimyable may suspend the affected processing and notify Customer.

6. Confidentiality

Aimyable will ensure that personnel authorized to process Personal Data:

· are subject to appropriate confidentiality obligations;

· receive access only to the extent reasonably necessary to perform their responsibilities;

· are trained regarding the proper handling of confidential information where appropriate.

These obligations survive termination of employment or engagement.

7. Security Measures

Aimyable maintains commercially reasonable administrative, technical, and organizational safeguards designed to protect Personal Data against unauthorized access, disclosure, alteration, or destruction.

These safeguards include, where appropriate:

· encryption in transit;

· encryption at rest;

· authentication and access controls;

· security monitoring and logging;

· limited personnel access;

· secure cloud infrastructure;

· incident response procedures.

Additional information regarding Aimyable’s security practices is available at: https://aimyable.com/security-and-compliance/

8. Subprocessors

Customer grants Aimyable general authorization to engage subprocessors necessary to provide the Services.

Aimyable shall:

· use reasonable care when selecting subprocessors;

· require subprocessors to protect Personal Data through contractual obligations appropriate to the services provided;

· remain responsible for the performance of its subprocessors to the extent required by applicable law.

A current list of material subprocessors will be made available by Aimyable upon reasonable request or through Aimyable’s website.

9. International Data Transfers

Customer acknowledges that Personal Data may be processed in the United States and other countries where Aimyable, its personnel, or authorized subprocessors operate.

Where required by applicable law, Aimyable will implement appropriate safeguards for international transfers of Personal Data.

10. Assistance with Data Subject Requests

Taking into account the nature of the processing, Aimyable will provide reasonable assistance to Customer in responding to lawful requests from individuals exercising rights under applicable privacy laws.

If Aimyable receives such a request directly, Aimyable may:

· refer the individual to Customer;

· notify Customer of the request;

· respond directly where required by applicable law.

11. Security Incident Notification

If Aimyable becomes aware of a confirmed Security Incident affecting Customer’s Personal Data, Aimyable will notify Customer without undue delay.

Notification may occur in stages as additional information becomes available.

Aimyable will use commercially reasonable efforts to:

· investigate the Security Incident;

· mitigate its effects;

· remediate the underlying cause where appropriate;

· provide information reasonably necessary for Customer to satisfy applicable legal obligations.

12. Audits and Information Requests

Upon reasonable written request, and no more than once annually unless required by applicable law or following a confirmed Security Incident, Aimyable will provide information reasonably necessary to demonstrate compliance with this DPA.

Such information may include:

· security documentation;

· written policies;

· security questionnaires;

· summaries of security practices.

Nothing in this DPA requires Aimyable to disclose information that would compromise the security of its systems, other customers, confidential information, or trade secrets.

13. Return or Deletion of Personal Data

Upon termination of the Agreement, Customer may request that Aimyable return or delete Personal Data.

Unless otherwise required by law, Aimyable will delete Personal Data within a commercially reasonable period following such request or termination of the Services.

Aimyable may retain information where required by law or necessary to establish, exercise, or defend legal claims.

14. Term and Termination

This DPA remains effective for as long as Aimyable processes Personal Data on behalf of Customer.

Termination of the Agreement automatically terminates this DPA, except for provisions that by their nature survive termination.

15. Order of Precedence

In the event of a conflict regarding the processing of Personal Data:

1. this DPA controls;

2. the Master Subscription Agreement controls;

3. the Privacy Policy provides additional information regarding Aimyable’s general privacy practices.

Nothing in the Privacy Policy limits Customer’s contractual rights under this DPA.

Contact Information

Questions regarding this DPA may be directed to:

Aimyable, Inc. 8 The Green #26639 Dover, DE 19901 United States

Phone: (949) 414-7215

Email: info@aimyable.com

Scroll to Top