WorkHeroes OS
All legal documentsEspañol

Privacy Policy

AETERNUM AI LLC — WorkHeroes OS

Version 1.0 · Last updated 7 September 2026

This Privacy Policy explains how AETERNUM AI LLC ("Aeternum", "we", "us") handles personal data in connection with the WorkHeroes OS platform and the website through which it is offered.

We are a company organised in New Mexico, United States, but the platform's production data is hosted in the European Union and our customers are, for the most part, established in the European Economic Area. We therefore apply the General Data Protection Regulation (EU) 2016/679 ("GDPR") as our baseline standard.


1. Two different roles

Our obligations depend on which data we are talking about. Please read the section that applies to you.

A. Data we handle as a controller. We decide the purposes and means of processing for: visitors to our website, people who contact us or request a demonstration, the administrative and billing contacts of our customers, and the security and operational logs of the platform.

B. Data we handle as a processor. Everything our customers and their users put into their workspace — client records, matters and cases, documents, invoices, messages, calendar entries, notes — is processed on the instructions of the customer, who is the controller. If your personal data is in a customer's workspace because you are a client, patient, employee or contact of that organisation, the organisation is your point of contact, and the terms of our Data Processing Agreement apply. We will refer any request we receive directly to the relevant customer.

2. Controller and contact details

AETERNUM AI LLC 15442 Ventura Blvd., Ste 201-2085, Sherman Oaks, California 91403, United States New Mexico State ID: 8065967

  • Data protection contact: [email protected]
  • General legal contact: [email protected]

We have not appointed a Data Protection Officer, as we do not meet the criteria of Article 37 GDPR. Data protection questions are handled by the address above.

3. Personal data we process as controller

CategoryExamplesSource
Identification and contactname, business email, telephone, organisation, roleyou, or your organisation
Account datauser identifier, workspace membership, role and permissions, language and interface preferencesyou, or your organisation's administrator
Commercial dataplan subscribed, orders, invoices, payment status, communications about your subscriptionyou, or generated by us
Support and communicationsmessages you send us, incident reports, feedback about the productyou
Technical and security logsIP address, timestamps, user agent, actions performed in the platform, authentication events, errorsgenerated automatically
Demonstration dataactivity within a guest demonstration environment, which uses fictitious data onlygenerated automatically

We do not run advertising networks, we do not sell personal data, and we do not build behavioural profiles for marketing purposes.

4. Purposes and legal bases

PurposeLegal basis (GDPR Art. 6)
Providing, maintaining and supporting the platform for our customersPerformance of a contract (Art. 6.1.b), or legitimate interests where you are a user of our customer rather than a party to the contract (Art. 6.1.f)
Managing accounts, subscriptions, invoicing and collectionsPerformance of a contract (Art. 6.1.b) and legal obligation (Art. 6.1.c)
Keeping the service secure: authentication, abuse prevention, audit logs, incident investigationLegitimate interests in protecting the service and its users (Art. 6.1.f), and legal obligation (Art. 6.1.c)
Answering enquiries and providing demonstrationsSteps prior to entering a contract (Art. 6.1.b) and legitimate interests (Art. 6.1.f)
Improving the product using aggregated, non-identifying usage statisticsLegitimate interests (Art. 6.1.f)
Sending service communications (changes, incidents, maintenance)Performance of a contract (Art. 6.1.b)
Sending commercial communications about our own similar products to existing business contactsLegitimate interests (Art. 6.1.f), with an opt-out in every message
Complying with accounting, tax and legal obligationsLegal obligation (Art. 6.1.c)
Establishing, exercising or defending legal claimsLegitimate interests (Art. 6.1.f)

Where we rely on legitimate interests, we have carried out a balancing assessment; you may request a summary of it at [email protected].

5. Special categories of data

The platform is used by professional-services organisations, some of which handle sensitive information (for example health data in a clinic, or data revealing legal proceedings in a law firm). When that happens, the customer is the controller and is responsible for the legal basis under Articles 9 and 10 GDPR. We process such data only as a processor, under the DPA, with the additional security measures described there.

We do not ask for, and do not need, special categories of data in our own controller-side processing.

6. Artificial intelligence

The platform includes AI features that draft text, summarise documents and answer questions about a workspace's own content.

  • Prompts and the extracts of content included in them are transmitted to the model providers listed in our Subprocessors page for the sole purpose of producing a response.
  • We do not use customer content to train models, ours or anyone else's, and we contract with model providers on terms that prohibit training on the data we send them.
  • AI outputs are assistive. They may be wrong. A human must review them before they are relied upon or sent to a third party.
  • We do not carry out automated decision-making producing legal or similarly significant effects on individuals within the meaning of Article 22 GDPR.

7. Recipients and subprocessors

We share personal data only with:

  • Subprocessors who help us run the platform (hosting, database, AI model providers, messaging channels, email delivery). The current list, with location and role, is published at /legal/subprocessors.
  • Professional advisers (lawyers, accountants, auditors) bound by confidentiality.
  • Public authorities, where we are legally required to disclose. We assess each request, require valid legal process, disclose the minimum necessary and, unless prohibited, inform the affected customer.
  • An acquirer, in the event of a merger, acquisition or sale of assets, subject to this Policy continuing to apply.

We do not sell or rent personal data, and we do not share it for third-party advertising.

8. International transfers

Where the data lives. The production database, file storage and authentication service are hosted in the European Union. Our aim is that customer content remains at rest in the EU.

Why data nonetheless reaches the United States. Aeternum is a United States company. Our personnel and administrative systems access the platform from outside the EEA for operation, support and development. Some subprocessors (for example, application hosting and certain AI providers) also process data outside the EEA.

Safeguards. Transfers outside the EEA rely on:

  • the Standard Contractual Clauses approved by the European Commission (Implementing Decision (EU) 2021/914), incorporated into our DPA, Module Two (controller to processor) or Module Three (processor to processor) as applicable;
  • the UK International Data Transfer Addendum and, for Switzerland, the adaptations recognised by the FDPIC, where relevant;
  • a transfer impact assessment, and supplementary measures including encryption in transit and at rest, access controls limited to named personnel, and a policy of challenging overbroad government requests.

You may request a copy of the relevant transfer mechanism, with commercial terms redacted, at [email protected].

9. Retention

DataRetention
Account and workspace data of an active customerFor the duration of the subscription
Customer content after terminationAvailable for export for 30 days, then deleted from active systems; copies held in backups expire on our hosting provider's normal rotation cycle
Invoices and accounting recordsAs required by applicable tax and accounting law (as a general rule, 6 years)
Security and audit logsFor the duration of the subscription, and deleted with the workspace
Support correspondence3 years from the last interaction
Enquiries that do not lead to a contract12 months
Guest demonstration environmentsDeleted automatically by the cleanup routine; they contain fictitious data only

10. Security

We apply technical and organisational measures appropriate to the risk, including:

  • encryption in transit (TLS) and at rest for the database and file storage;
  • multi-tenant isolation enforced both in the database (row-level security) and in server-side authorisation checks, with automated tests that fail the build if a tenant boundary regresses;
  • least-privilege access: administrative credentials are held server-side only and are never exposed to the browser;
  • authentication managed by a specialised provider, with session cookies restricted to HttpOnly and Secure;
  • audit logging of relevant actions, recording who did what and when;
  • integrations disabled by default, activated only by the customer with the customer's own credentials;
  • separation of environments, and code review before changes reach production.

A fuller description is in Annex II of the DPA. No system is perfectly secure; we cannot guarantee absolute security.

11. Cookies

The website and the application use only cookies that are strictly necessary to keep you signed in and to keep the service secure. We do not use advertising or third-party analytics cookies. See the Cookie Policy for the full list.

12. Your rights

If you are in the EEA, the United Kingdom or Switzerland, you have the right to: access your data; rectify it; erase it; restrict processing; object to processing based on legitimate interests; receive your data in a portable format; and, where processing is based on consent, withdraw that consent at any time without affecting prior processing.

To exercise these rights in respect of data we hold as a controller, write to [email protected]. We will respond within one month, extendable by two further months for complex requests. We may ask for information to verify your identity.

If your data is in a customer's workspace, please contact that organisation; it is the controller. We will assist it as required by the DPA.

Complaints. You may lodge a complaint with your supervisory authority. In Spain this is the Agencia Española de Protección de Datos (www.aepd.es); in other countries, the authority of your habitual residence or place of work.

13. Children

The platform is a professional business tool and is not directed at children. We do not knowingly collect data from anyone under 16 in our controller-side processing.

14. Changes to this Policy

We may update this Policy. The version and date at the top always identify the current text, and we keep previous versions on file. We will notify customers of material changes by email or through the platform at least 30 days before they take effect.

15. Contact

AETERNUM AI LLC — 15442 Ventura Blvd., Ste 201-2085, Sherman Oaks, California 91403, United States [email protected]

Terms of ServicePrivacy PolicyData Processing AgreementSubprocessorsCookie PolicyAcceptable Use Policy

AETERNUM AI LLC · 15442 Ventura Blvd., Ste 201-2085, Sherman Oaks, California 91403, USA · [email protected]