Data Processing Agreement
AETERNUM AI LLC — WorkHeroes OS
Version 1.0 · Last updated 7 September 2026
This Data Processing Agreement ("DPA") is entered into between the customer identified in the Order Form (the "Controller" or "Customer") and AETERNUM AI LLC, a New Mexico limited liability company with address at 15442 Ventura Blvd., Ste 201-2085, Sherman Oaks, California 91403, United States (the "Processor" or "Aeternum").
It forms an integral part of the Terms of Service and reflects Article 28(3) of Regulation (EU) 2016/679 ("GDPR"). Where the Customer is subject to the UK GDPR or the Swiss FADP, the corresponding provisions apply with the adaptations set out in clause 11.
It takes effect automatically when the Customer subscribes to the Service. A separate signed counterpart is available on request at [email protected] for customers whose procurement process requires one.
1. Definitions
Terms such as "personal data", "processing", "controller", "processor", "sub-processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given in the GDPR.
- "Customer Personal Data" — personal data contained in Customer Data, processed by Aeternum on behalf of the Customer through the Service.
- "SCCs" — the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
- "Affiliate" — an entity controlling, controlled by, or under common control with a party.
2. Roles and scope
2.1 The Customer is the controller of Customer Personal Data (or, where it acts on behalf of a third party, the processor and Aeternum the sub-processor; in that case, the Customer warrants it has the authority to give the instructions in this DPA).
2.2 Aeternum is the processor, and processes Customer Personal Data only on the Customer's documented instructions.
2.3 Aeternum acts as an independent controller for: its own account, billing and administrative contact data; security and audit logs it must keep for its own accountability; and aggregated, non-identifying usage statistics. That processing is governed by the Privacy Policy, not by this DPA.
2.4 The subject matter, duration, nature, purpose, categories of data and categories of data subjects are set out in Annex I.
3. Instructions
3.1 Aeternum will process Customer Personal Data only on the Customer's documented instructions, including with regard to transfers to third countries, unless required to do otherwise by Union or Member State law to which it is subject; in that case, Aeternum will inform the Customer of that legal requirement before processing, unless the law prohibits it on important grounds of public interest.
3.2 The following constitute the Customer's documented instructions: (a) this DPA and the Terms; (b) the configuration the Customer chooses in the Service, including which integrations and AI features it activates; and (c) the actions of the Customer's Users through the interfaces and APIs of the Service.
3.3 Additional instructions outside this scope require a written agreement and may be subject to a charge for the work involved.
3.4 Aeternum will inform the Customer if, in its opinion, an instruction infringes the GDPR or other data protection provisions, and may suspend the execution of that instruction until it is confirmed or amended.
3.5 Aeternum will not: sell Customer Personal Data; use it for its own purposes; use it for advertising; or use it to train, fine-tune or improve foundation models, whether its own or a third party's.
4. Confidentiality
4.1 Aeternum will ensure that persons authorised to process Customer Personal Data are bound by an appropriate obligation of confidentiality, contractual or statutory, that survives the end of their engagement.
4.2 Access is granted on a need-to-know basis, to named personnel, and is revoked when no longer necessary.
4.3 Where the Customer is subject to professional secrecy obligations (legal privilege, medical confidentiality or equivalent), Aeternum will treat Customer Personal Data as covered by that duty and will not disclose it except as required by law under clause 9.
5. Security
5.1 Aeternum implements the technical and organisational measures described in Annex II, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risks to the rights and freedoms of natural persons (Article 32 GDPR).
5.2 Aeternum may update those measures provided the level of security is not reduced.
5.3 The Customer is responsible for the security decisions within its own control: the roles and permissions it assigns, the strength and handling of credentials, the third-party integrations it activates, and the categories of data it chooses to upload.
6. Sub-processors
6.1 The Customer gives general written authorisation for Aeternum to engage sub-processors, subject to this clause.
6.2 The current list of sub-processors, including name, role, processing location and transfer mechanism, is published at /legal/subprocessors and forms Annex III.
6.3 Aeternum will impose on each sub-processor, by written contract, data protection obligations that are materially equivalent to those in this DPA, and remains fully liable to the Customer for its sub-processors' performance.
6.4 Changes. Aeternum will notify the Customer of any intended addition or replacement of a sub-processor at least thirty (30) days in advance, by email to the administrative contact and by updating the subprocessors page. The Customer may object on reasonable data-protection grounds within that period. The parties will discuss in good faith; if no solution is found, the Customer may terminate the affected part of the subscription without penalty and receive a pro-rata refund of prepaid unused fees.
6.5 Where a change of sub-processor is urgently required to preserve the security or availability of the Service, Aeternum may make it immediately and notify the Customer without undue delay; the objection right in clause 6.4 then applies retrospectively.
6.6 AI providers. Model providers used to deliver AI features are sub-processors and are listed in Annex III. The Customer acknowledges that activating AI features means transmitting the relevant extracts of Customer Personal Data to the applicable provider. AI features can be disabled at workspace level.
7. Assistance to the Customer
7.1 Data subject rights. Taking into account the nature of the processing, Aeternum will assist the Customer by appropriate technical and organisational measures, insofar as possible, to respond to requests to exercise data subject rights. The Service itself provides functions to search, correct, export and delete records, which will usually be sufficient. If Aeternum receives a request directly from a data subject relating to Customer Personal Data, it will not respond substantively, and will redirect it to the Customer without undue delay.
7.2 Articles 32 to 36. Aeternum will assist the Customer in ensuring compliance with the obligations on security, breach notification, data protection impact assessments and prior consultation, taking into account the nature of processing and the information available to it. This includes providing the documentation the Customer needs for a DPIA.
7.3 Assistance is provided at no additional charge where it is a routine part of operating the Service. Extraordinary assistance requiring significant engineering effort may be charged at Aeternum's standard rates, notified in advance.
8. Personal data breaches
8.1 Aeternum will notify the Customer without undue delay and in any event within seventy-two (72) hours of becoming aware of a personal data breach affecting Customer Personal Data.
8.2 The notification will include, to the extent known: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point for further information. Where the information cannot all be provided at once, it will be supplied in phases without undue delay.
8.3 Aeternum will cooperate with the Customer and take reasonable steps to mitigate the effects of the breach. Notification to supervisory authorities and to data subjects is the Customer's responsibility as controller, unless the law provides otherwise.
8.4 Aeternum's notification is not, in itself, an acknowledgement of fault or liability.
9. Government and law-enforcement requests
9.1 If Aeternum receives a legally binding request from a public authority for disclosure of Customer Personal Data, it will: (a) assess whether the request is valid, and challenge it where there are reasonable grounds to consider it unlawful under the law of the requesting country or under EU law; (b) disclose only the minimum amount of data necessary; and (c) notify the Customer before disclosure, or as soon as possible afterwards, unless legally prohibited from doing so.
9.2 Aeternum will use lawful means to obtain a waiver of any prohibition on notification, and will document its efforts so as to make them available to the Customer.
9.3 Aeternum has not created, and will not create, any back door or similar mechanism enabling access to Customer Personal Data, and it has no reason to believe that the laws applicable to it prevent it from fulfilling this DPA.
10. Deletion and return
10.1 On termination of the Service, Aeternum will, at the Customer's choice, delete or return Customer Personal Data. The Service provides export in a structured, commonly used, machine-readable format.
10.2 Unless the Customer requests otherwise in writing, Aeternum will make the data available for export for thirty (30) days after termination and will then delete it from active systems.
10.3 Copies held in backups are deleted on the normal backup rotation cycle of our hosting provider, during which they remain encrypted and are not used for any purpose other than disaster recovery.
10.4 Aeternum may retain Customer Personal Data to the extent, and for as long as, required by Union or Member State law, applying the same protections during that period.
10.5 Aeternum will certify deletion in writing on request.
11. International transfers
11.1 Customer Personal Data is hosted at rest in the European Union. Aeternum, as a US entity, and certain sub-processors access it from outside the EEA as described in Annex III.
11.2 For those transfers, the parties adopt the SCCs, which are incorporated into this DPA by reference and completed as follows:
- Module Two (controller to processor) applies where the Customer is a controller; Module Three (processor to sub-processor) applies where the Customer is itself a processor.
- Clause 7 (docking clause): applies.
- Clause 9 (sub-processors): Option 2, general written authorisation, with a notice period of thirty (30) days as set out in clause 6.4.
- Clause 11 (redress): the optional independent dispute-resolution paragraph does not apply.
- Clause 17 (governing law): the law of the EU Member State in which the Customer is established; where the Customer is not established in an EU Member State, the law of Spain.
- Clause 18(b) (forum): the courts of the EU Member State in which the Customer is established; where the Customer is not established in an EU Member State, the courts of Spain.
- Annex I.A (parties), Annex I.B (description of transfer) and Annex II (security measures) of the SCCs are populated by Annexes I and II of this DPA. Annex III (sub-processors) is populated by the subprocessors page.
- Competent supervisory authority: that of the Member State in which the Customer is established; where the Customer is not established in the Union, the authority of the Member State in which its Article 27 representative is established.
11.3 United Kingdom. Where the UK GDPR applies, the parties adopt the International Data Transfer Addendum issued by the ICO (version B1.0), appended to the SCCs, with the tables completed by reference to this DPA and Start Date equal to the effective date of the Agreement.
11.4 Switzerland. Where the Swiss FADP applies, the SCCs apply with the adaptations recognised by the Federal Data Protection and Information Commissioner: references to the GDPR are read as references to the FADP, "Member State" includes Switzerland, and the FDPIC is the competent authority.
11.5 Transfer impact assessment. Aeternum has carried out an assessment of the laws of the destination countries and of the supplementary measures applied (Annex II). A summary is available to the Customer on request.
11.6 Conflict. In the event of any conflict between this DPA and the SCCs, the SCCs prevail.
12. Audits
12.1 Aeternum will make available to the Customer all information necessary to demonstrate compliance with Article 28 GDPR.
12.2 Compliance may be demonstrated in the first instance by: this DPA and its annexes; the security documentation and sub-processor list published by Aeternum; and written responses to a reasonable security questionnaire, once per twelve-month period.
12.3 Where that is not sufficient for the Customer to fulfil its own obligations, the Customer may conduct an audit, or mandate an independent auditor who is not a competitor of Aeternum and who is bound by confidentiality. Audits: take place once per twelve-month period, unless a personal data breach or an instruction from a supervisory authority requires more; are notified at least thirty (30) days in advance; take place during business hours; are limited to the systems and documentation relevant to Customer Personal Data; and must not compromise the security or confidentiality of other customers' data.
12.4 Each party bears its own audit costs. Aeternum may charge for engineering time exceeding two (2) working days per audit, at rates notified in advance.
12.5 A supervisory authority's right of audit is unaffected.
13. Liability
13.1 Each party's liability under this DPA is subject to the limitations and exclusions in clause 15 of the Terms, except where the GDPR or other mandatory law provides otherwise.
13.2 Nothing in this DPA limits a data subject's rights under Article 82 GDPR, nor the parties' liability towards supervisory authorities.
14. Term, precedence and general
14.1 This DPA applies for as long as Aeternum processes Customer Personal Data, and its provisions on confidentiality, deletion and liability survive.
14.2 In case of conflict, this DPA prevails over the Terms in matters of personal data protection, and the SCCs prevail over both for transfers.
14.3 If a provision of this DPA is found invalid, the remainder stays in force and the parties will replace it with a valid provision of equivalent effect.
14.4 This DPA may be updated by Aeternum where necessary to reflect a change in law, in a decision of a supervisory authority, or in the Service, on thirty (30) days' notice, provided the level of protection is not reduced.
Annex I — Description of the processing
A. Parties
- Data exporter / Controller: the customer identified in the Order Form. Contact details: those stated in the Order Form. Activities relevant to the transfer: use of the WorkHeroes OS platform to run its professional-services business.
- Data importer / Processor: AETERNUM AI LLC, 15442 Ventura Blvd., Ste 201-2085, Sherman Oaks, California 91403, United States. Contact: [email protected]. Activities relevant to the transfer: provision, operation, support and maintenance of the WorkHeroes OS platform.
B. Description of the processing
Subject matter. Provision of the WorkHeroes OS platform as a service.
Duration. The term of the subscription, plus the export and deletion periods in clause 10.
Nature and purpose. Hosting, storage, structuring, retrieval, display, transmission, backup and deletion of Customer Data, so that the Customer can manage its clients, matters, tasks, documents, calendar, communications, time recording and invoicing; delivery of AI-assisted features on the Customer's content; and delivery of messages through the channels the Customer activates.
Frequency. Continuous, for the duration of the subscription.
Categories of data subjects
- the Customer's own clients and their contacts, and where applicable the counterparties or third parties recorded in a matter;
- the Customer's employees, partners and collaborators who use the platform;
- individuals appearing in documents, messages or notes uploaded by the Customer;
- the Customer's suppliers' contacts.
Categories of personal data
- identification and contact data: name, national ID or tax number, postal address, email, telephone;
- professional data: organisation, position, relationship to the matter;
- matter and case data: subject, status, dates, deadlines, notes, internal history;
- documents uploaded by the Customer and their content;
- communications: emails, messages sent through the activated channels, chat with the AI assistant, client-portal messages;
- economic and billing data: rates, hours recorded, invoices, payment status, bank details where the Customer records them;
- audit metadata: who did what and when within the workspace.
Special categories of data (Articles 9 and 10 GDPR)
The Service is not designed as a repository for special categories of data, but the Customer may, depending on its sector, include them — for example health data in a clinical practice, or data relating to criminal convictions and offences in a legal practice. Where that is the case: the Customer is responsible for the legal basis under Articles 9 and 10; the additional measures in Annex II apply; and the Customer must declare this in the Order Form so the processing is documented. Restrictions: access limited to the Customer's own workspace and to named Aeternum personnel; no use for any purpose other than providing the Service.
Transfers to sub-processors. As set out in Annex III (the subprocessors page): the subject matter, nature and duration of each sub-processing operation are the ones stated there.
Retention. As set out in clause 10 and in the Privacy Policy.
C. Competent supervisory authority
The supervisory authority of the EU Member State in which the Customer is established. Where the Customer is established in Spain, this is the Agencia Española de Protección de Datos.
Annex II — Technical and organisational measures
Aeternum applies at least the following measures. The description is deliberately specific so that it can be verified.
1. Pseudonymisation and encryption
- TLS for all traffic between users, the application and the database.
- Encryption at rest for the database, file storage and backups, managed by the hosting provider.
- Secrets and API keys held exclusively server-side, in the platform's environment configuration; never exposed to the browser and never written to logs.
- Client-portal access links use single-use, expiring tokens rather than shared credentials.
2. Confidentiality — tenant isolation
- Every workspace is a separate tenant, identified by an organisation identifier that is mandatory on every record.
- Isolation is enforced twice: by row-level security policies in the database, and by server-side authorisation checks in every route that uses elevated credentials.
- No route may resolve a tenant from a default or environment variable; the tenant is always derived from the authenticated session or from a verified token.
- Automated tests cover the tenant boundary and fail the build if a route regresses. Guest demonstration environments run against fictitious data with write access, storage, AI, administration and integrations denied by default.
3. Integrity
- Audit trail of relevant actions, recording the acting user, the affected record and the timestamp.
- Server-side validation of input; parameterised database access.
- Protection against server-side request forgery on any outbound request built from user input.
- Rate limiting on public and webhook endpoints.
4. Availability and resilience
- Managed hosting with redundancy at infrastructure level.
- Automated backups of the production database, managed by the hosting provider, encrypted at rest and deleted on its normal rotation cycle.
- Ability to export the entire workspace on demand.
5. Access control
- Authentication managed by a specialised provider; session cookies marked
HttpOnlyandSecure. - Role and permission model within each workspace, administered by the Customer.
- Least privilege for Aeternum personnel: administrative access is limited to named individuals, justified by a support or operational need, and logged.
6. Secure development
- Version control with review before changes reach production.
- Automated test suite covering security invariants (tenant isolation, authorisation, absence of secrets in logs) executed before release.
- Separation of development, preview and production environments; production data is not copied into development environments.
- Dependencies are pinned and updated.
7. Governance
- Confidentiality obligations for all personnel and subcontractors.
- Sub-processor list maintained and published.
- Incident response procedure with the 72-hour notification commitment in clause 8.
- Integrations disabled by default; each one is activated by the Customer using its own credentials.
8. Measures for special categories of data
Where the Customer declares that it will process special categories of data: access by Aeternum personnel only on a documented support request from the Customer; no export outside the platform; and, on request, additional restrictions agreed in the Order Form.
Annex III — Sub-processors
The current list is published and maintained at /legal/subprocessors and forms part of this DPA. The version in force at the date of this DPA is the one published on that page.