AIMYABLE DATA PROCESSING ADDENDUM (DPA)
Effective Date: July 31, 2026
This Data Processing Addendum (“DPA”) forms part of the Aimyable Master Subscription Agreement (“Agreement”) between Aimyable, Inc. (“Aimyable”) and the Customer.
This DPA applies only to the extent Aimyable processes Personal Data on behalf of Customer in connection with the Services.
If there is a conflict between this DPA and the Agreement regarding the processing of Personal Data, this DPA controls.
—
1. Purpose and Applicability
This DPA governs Aimyable’s processing of Personal Data on behalf of Customer while providing the Services.
The parties intend this DPA to satisfy applicable contractual requirements under privacy and data protection laws, including, where applicable, the General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), and other substantially similar privacy laws.
Nothing in this DPA expands either party’s obligations beyond those required by applicable law.
—
2. Definitions
Unless otherwise defined in this DPA, capitalized terms have the meanings given in the Agreement.
For purposes of this DPA:
Controller, Processor, Business, Service Provider, Personal Data, and Processing have the meanings assigned under applicable privacy laws.
Security Incident means unauthorized access to, acquisition of, disclosure of, alteration of, or destruction of Personal Data processed by Aimyable, excluding unsuccessful attempts that do not compromise the security of Personal Data.
—
3. Roles of the Parties
Customer determines the purposes and means for which Personal Data is collected and submitted to the Services.
Accordingly:
· Customer acts as the Controller or Business, as applicable.
· Aimyable acts as the Processor or Service Provider solely for purposes of providing the Services.
Aimyable will not sell Personal Data or use Personal Data for advertising or any purpose unrelated to providing the Services requested by Customer.
—
4. Scope of Processing
Aimyable processes Personal Data only as necessary to:
· provide the Services;
· perform customer-authorized automation;
· maintain and secure the Services;
· provide technical support;
· comply with applicable law;
· fulfill Customer’s documented instructions consistent with the Agreement.
Customer represents that it has all necessary rights and authority to provide Personal Data to Aimyable.
—
5. Customer Instructions
Customer instructs Aimyable to process Personal Data solely for the purposes described in the Agreement, this DPA, and Customer’s authorized use of the Services.
If Aimyable believes a Customer instruction violates applicable law, Aimyable may suspend the affected processing and notify Customer.
—
6. Confidentiality
Aimyable will ensure that personnel authorized to process Personal Data:
· are subject to appropriate confidentiality obligations;
· receive access only to the extent reasonably necessary to perform their responsibilities;
· are trained regarding the proper handling of confidential information where appropriate.
These obligations survive termination of employment or engagement.
—
7. Security Measures
Aimyable maintains commercially reasonable administrative, technical, and organizational safeguards designed to protect Personal Data against unauthorized access, disclosure, alteration, or destruction.
These safeguards include, where appropriate:
· encryption in transit;
· encryption at rest;
· authentication and access controls;
· security monitoring and logging;
· limited personnel access;
· secure cloud infrastructure;
· incident response procedures.
Additional information regarding Aimyable’s security practices is available at: https://aimyable.com/security-and-compliance/
—
8. Subprocessors
Customer grants Aimyable general authorization to engage subprocessors necessary to provide the Services.
Aimyable shall:
· use reasonable care when selecting subprocessors;
· require subprocessors to protect Personal Data through contractual obligations appropriate to the services provided;
· remain responsible for the performance of its subprocessors to the extent required by applicable law.
A current list of material subprocessors will be made available by Aimyable upon reasonable request or through Aimyable’s website.
—
9. International Data Transfers
Customer acknowledges that Personal Data may be processed in the United States and other countries where Aimyable, its personnel, or authorized subprocessors operate.
Where required by applicable law, Aimyable will implement appropriate safeguards for international transfers of Personal Data.
—
10. Assistance with Data Subject Requests
Taking into account the nature of the processing, Aimyable will provide reasonable assistance to Customer in responding to lawful requests from individuals exercising rights under applicable privacy laws.
If Aimyable receives such a request directly, Aimyable may:
· refer the individual to Customer;
· notify Customer of the request;
· respond directly where required by applicable law.
—
11. Security Incident Notification
If Aimyable becomes aware of a confirmed Security Incident affecting Customer’s Personal Data, Aimyable will notify Customer without undue delay.
Notification may occur in stages as additional information becomes available.
Aimyable will use commercially reasonable efforts to:
· investigate the Security Incident;
· mitigate its effects;
· remediate the underlying cause where appropriate;
· provide information reasonably necessary for Customer to satisfy applicable legal obligations.
—
12. Audits and Information Requests
Upon reasonable written request, and no more than once annually unless required by applicable law or following a confirmed Security Incident, Aimyable will provide information reasonably necessary to demonstrate compliance with this DPA.
Such information may include:
· security documentation;
· written policies;
· security questionnaires;
· summaries of security practices.
Nothing in this DPA requires Aimyable to disclose information that would compromise the security of its systems, other customers, confidential information, or trade secrets.
—
13. Return or Deletion of Personal Data
Upon termination of the Agreement, Customer may request that Aimyable return or delete Personal Data.
Unless otherwise required by law, Aimyable will delete Personal Data within a commercially reasonable period following such request or termination of the Services.
Aimyable may retain information where required by law or necessary to establish, exercise, or defend legal claims.
—
14. Term and Termination
This DPA remains effective for as long as Aimyable processes Personal Data on behalf of Customer.
Termination of the Agreement automatically terminates this DPA, except for provisions that by their nature survive termination.
—
15. Order of Precedence
In the event of a conflict regarding the processing of Personal Data:
1. this DPA controls;
2. the Master Subscription Agreement controls;
3. the Privacy Policy provides additional information regarding Aimyable’s general privacy practices.
Nothing in the Privacy Policy limits Customer’s contractual rights under this DPA.
—
Contact Information
Questions regarding this DPA may be directed to:
Aimyable, Inc. 8 The Green #26639 Dover, DE 19901 United States
Phone: (949) 414-7215
Email: info@aimyable.com