Version 2026-07-01 · Effective 2026-07-01

Data Processing Agreement

Aimée LLC 30 N Gould St, Ste R, Sheridan, WY 82801, USA Email: founder@tryaimee.com EIN: 36-5184363

Effective Date: July 1, 2026 Version: 2026-07-01

This Data Processing Agreement ("DPA") is entered into between Aimée LLC ("Processor") and the Customer identified in the Aimée account registration ("Controller"). This DPA is incorporated by reference into the Terms of Service ("ToS") and forms part of the agreement between the parties. This DPA takes effect upon Customer's acceptance during the Owner signup flow.


1. Parties & Authority

1.1 Processor: Aimée LLC, a Wyoming limited liability company, 30 N Gould St, Ste R, Sheridan, WY 82801, USA.

1.2 Controller: The Customer (clinic or organization) identified during account registration, represented by the individual who completed the Owner signup flow.

1.3 Authority Warranty. The natural person who accepted this DPA during signup (the "Signing Party") warrants and represents that, at the time of acceptance, they: (a) were duly authorized to bind Customer to this DPA; (b) had reviewed this DPA in the language displayed at signup; and (c) understood that Customer's invited Authorized Users (employees, contractors) do not separately accept this DPA — instead, they are bound by it through their use of the Service under Customer's account.

1.4 Continuity. If the Signing Party leaves Customer's organization, Customer remains bound by this DPA. Customer is responsible for promptly notifying Aimée of any change in the person authorized to act on its behalf, via the contact channels in Section 13 of this DPA.

1.5 Scope of Invited Users. Authorized Users invited to Customer's account (employees, contractors) do not separately accept this DPA. Such individuals accept the Terms of Service and Privacy Policy for their personal use of the Service only. They are bound by this DPA as a consequence of their use of the Service under Customer's account, pursuant to the DPA accepted by the Signing Party on Customer's behalf.


2. Definitions

The following terms have the meanings set out below. Capitalized terms used but not defined herein have the meaning given in the Terms of Service.

  • "Personal Data" means any information relating to an identified or identifiable natural person, as defined in GDPR Article 4(1).
  • "Processing" means any operation or set of operations performed on Personal Data, whether or not by automated means, as defined in GDPR Article 4(2).
  • "Controller" means the natural or legal person which determines the purposes and means of the Processing of Personal Data, as defined in GDPR Article 4(7). For purposes of this DPA, the Controller is Customer.
  • "Processor" means a natural or legal person which processes Personal Data on behalf of the Controller, as defined in GDPR Article 4(8). For purposes of this DPA, the Processor is Aimée LLC.
  • "Subprocessor" means any natural or legal person engaged by Processor to carry out Processing activities on behalf of Controller.
  • "Data Subject" means an identified or identifiable natural person to whom Personal Data relates, as defined in GDPR Article 4(1).
  • "Supervisory Authority" means an independent public authority established pursuant to GDPR Article 51, or its equivalent under applicable national law.
  • "SCCs" means the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914.
  • "UK IDTA" means the UK International Data Transfer Addendum to the EU SCCs, issued by the UK Information Commissioner under Section 119A(1) of the Data Protection Act 2018, version B1.0 (in force 21 March 2022).
  • "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed, as defined in GDPR Article 4(12).
  • "GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council.
  • "UK GDPR" means the GDPR as retained in UK law by the European Union (Withdrawal) Act 2018, as amended.

3. Subject Matter & Duration

3.1 Subject Matter. This DPA governs the Processing of Personal Data by Processor on behalf of Controller in connection with the provision of the Aimée Service as described in the ToS.

3.2 Instructions. The ToS and this DPA together constitute Controller's documented instructions to Processor regarding the Processing of Personal Data. Processor shall not Process Personal Data for any purpose other than as necessary to provide the Service pursuant to these instructions, unless required by applicable law, in which case Processor shall inform Controller of that legal requirement before Processing (unless prohibited by law).

3.3 Duration. This DPA remains in effect for the duration of the underlying ToS and terminates automatically upon termination or expiry of the ToS, subject to the survival provisions in Section 12.


4. Nature & Purpose of Processing

Processor carries out the following Processing activities on behalf of Controller:

  • Receiving, routing, and managing inbound telephone calls to Controller's clinic;
  • Transcribing call audio in real-time via speech-to-text Processing;
  • Generating AI-driven conversational responses to callers;
  • Scheduling, confirming, and managing appointments on Controller's behalf;
  • Storing call transcripts, metadata, and summaries in Controller's account;
  • Providing dashboard analytics and reporting on call activity;
  • Enabling Controller's Authorized Users to access, review, and manage call records;
  • Providing knowledge base retrieval to inform AI responses;
  • Facilitating CRM and calendar integrations as configured by Controller.

5. Categories of Data Subjects

The Personal Data Processed under this DPA relates to the following categories of Data Subjects:

  • Patients and Callers: individuals who telephone Controller's clinic and interact with the Aimée AI voice agent;
  • Controller's Authorized Users: employees, contractors, and other individuals who access the Service on Controller's behalf.

6. Categories of Personal Data

The categories of Personal Data Processed under this DPA are set out in Annex I to this DPA.

Special categories of Personal Data within the meaning of GDPR Article 9 may be incidentally disclosed by callers during telephone conversations. Such data is Processed solely pursuant to GDPR Article 9(2)(h) (provision of health or social care) at Controller's direction. Controller is responsible for ensuring that Processing of special categories of data under this DPA complies with applicable law in Controller's jurisdiction.


7. Processor Obligations

7.1 Instruction Compliance. Processor shall Process Personal Data only on documented instructions from Controller (as set out in the ToS and this DPA), unless Processing is required by applicable law. Processor shall inform Controller if it believes an instruction infringes applicable data protection law.

7.2 Confidentiality. Processor shall ensure that all personnel authorized to Process Personal Data are subject to binding confidentiality obligations and are informed of the confidential nature of the Personal Data. These obligations shall survive the termination of such personnel's engagement.

7.3 Technical and Organizational Measures. Processor shall implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as set out in Annex III of this DPA. Processor may update these measures from time to time, provided that any updates do not materially reduce the level of security.

7.4 Data Subject Requests. Processor shall, to the extent legally permitted, promptly notify Controller of any request from a Data Subject exercising their rights under applicable data protection law. Processor shall assist Controller in responding to such requests by providing relevant information and access to Personal Data within fourteen (14) days of receiving a written request from Controller. Processor shall not respond to Data Subject requests directly without Controller's prior written authorization.

7.5 Compliance Assistance. Processor shall provide reasonable assistance to Controller in fulfilling Controller's obligations under applicable data protection law, including in relation to: (a) data protection impact assessments (DPIAs) pursuant to GDPR Article 35; (b) prior consultation with Supervisory Authorities pursuant to GDPR Article 36; and (c) demonstrating compliance with Controller's obligations as a data controller.

7.6 Breach Notification. Processor shall notify Controller without undue delay and in any event within seventy-two (72) hours of becoming aware of a Personal Data Breach affecting Personal Data Processed under this DPA. Such notification shall, to the extent available at the time: (a) describe the nature of the Personal Data Breach including the categories and approximate number of Data Subjects concerned; (b) communicate the name and contact details of the data protection contact; (c) describe the likely consequences of the breach; and (d) describe the measures taken or proposed to address the breach and mitigate its effects. Notification under this Section 7.6 does not constitute an acknowledgment of fault or liability.

7.7 Deletion and Return. Upon termination of this DPA or expiry of the ToS, Processor shall, at Controller's documented choice: (a) delete all Personal Data Processed on Controller's behalf and certify such deletion in writing; or (b) return all Personal Data in a machine-readable format. Controller shall make such choice within thirty (30) days of termination. Processor shall complete deletion or return within thirty (30) days of receiving Controller's instructions. Processor may retain Personal Data where required by applicable law, in which case Processor shall notify Controller of such retention obligation and maintain the confidentiality of such data.

7.8 Demonstration of Compliance. Processor shall make available to Controller all information reasonably necessary to demonstrate Processor's compliance with the obligations set out in GDPR Article 28, including by supporting and contributing to audits and inspections pursuant to Section 10 of this DPA.


8. Subprocessors

8.1 General Authorization. Controller hereby grants Processor general written authorization to engage the Subprocessors listed in Annex II to this DPA to carry out specific Processing activities on Controller's behalf.

8.2 Notice of Changes. Processor shall give Controller at least thirty (30) days' advance email notice before adding or replacing any Subprocessor. Such notice shall be sent to the email address on file for Controller's account. Controller may object to any new or replacement Subprocessor in writing within fourteen (14) days of receiving notice. If Controller objects and the parties cannot resolve the objection, Controller may terminate the ToS without penalty by providing written notice within thirty (30) days of the objection, and Processor shall not engage the objected Subprocessor pending resolution.

8.3 Subprocessor Obligations. Processor shall impose data protection obligations on each Subprocessor substantially equivalent to those imposed on Processor under this DPA. Where a Subprocessor fails to fulfil its data protection obligations, Processor remains fully liable to Controller for the performance of such Subprocessor's obligations under this DPA.

8.4 Updated Subprocessor List. An up-to-date list of Subprocessors is maintained at aimee.ai/legal/subprocessors and updated within seven (7) days of any change taking effect.


9. International Transfers

9.1 EU/EEA Personal Data. Where Processor transfers Personal Data of Data Subjects located in the EU/EEA to Subprocessors located in third countries (including the United States of America), such transfers are governed by the Standard Contractual Clauses (Module 2: Controller-to-Processor) adopted by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021, incorporated herein by reference. For the purposes of the SCCs:

  • The data exporter is Customer (Controller);
  • The data importer is the relevant US Subprocessor;
  • Annex I.A and I.B of the SCCs are completed by reference to Annex I of this DPA;
  • Annex I.C (competent supervisory authority) is the supervisory authority of the EU Member State in which Customer is established, or if Customer is not established in the EU, the Irish Data Protection Commission;
  • Annex II of the SCCs (technical and organizational measures) is completed by reference to Annex III of this DPA;
  • The docking clause (Clause 7) applies to enable Customer's Authorized Users to accede to the SCCs;
  • Clause 17 (Option 1) — the SCCs are governed by the law of Ireland.

9.2 UK Personal Data. Where Processor transfers Personal Data of Data Subjects located in the United Kingdom to Subprocessors located in third countries, such transfers are governed by the UK International Data Transfer Addendum to the EU SCCs, issued by the UK Information Commissioner under Section 119A(1) of the Data Protection Act 2018, version B1.0 (in force 21 March 2022), incorporated herein by reference. The UK IDTA supplements and modifies the SCCs described in Section 9.1 above. For the purposes of the UK IDTA:

  • Table 1 (Parties) is completed by reference to the parties identified in Section 1 of this DPA;
  • Table 2 (Selected SCCs, Modules and Selected Clauses) refers to Module 2 of Commission Implementing Decision (EU) 2021/914;
  • Table 3 (Appendix Information) is completed by reference to Annexes I–III of this DPA;
  • Table 4 (Ending the Addendum when the Approved Addendum Changes) — either party may end the UK IDTA as set out in Section 19 of the UK IDTA.

9.3 Supplementary Measures. In addition to the contractual safeguards above, Processor implements the supplementary technical and organizational measures described in Annex III of this DPA to address risks arising from the legal environment of third countries. These include encryption in transit and at rest, contractual prohibitions on unlawful government access, and requirements for Subprocessors to challenge governmental data requests where lawful to do so.

9.4 No Other Transfers. Processor shall not transfer Personal Data to any country or recipient outside the EU/EEA, UK, or a country benefiting from an adequacy decision, except as expressly authorized by this Section 9, and shall ensure that all Subprocessors are bound by equivalent transfer restrictions.


10. Audits

10.1 Third-Party Assessments. Processor shall make available to Controller, upon written request, the most recent SOC 2 Type II report (when obtained — see Tech Debt C1) or an equivalent third-party security assessment. Processor shall provide such assessments on an annual basis once obtained.

10.2 Controller Audit Rights. Controller may request additional written information necessary to verify Processor's compliance with this DPA once per calendar year. Such requests shall be made in writing and Processor shall respond within thirty (30) days. Where Controller requires an on-site audit or inspection: (a) Controller shall provide Processor at least thirty (30) days' prior written notice; (b) the audit shall be conducted at Controller's sole expense; (c) the audit shall not unreasonably interfere with Processor's operations; and (d) Controller and Processor shall agree in advance on the scope, timing, and duration of the audit.

10.3 Audit Reports. The results of any audit conducted pursuant to this Section 10 are the confidential information of Processor. Controller shall not disclose audit reports to third parties without Processor's prior written consent, except as required by applicable law or Supervisory Authority.


11. Liability

11.1 General. Liability under this DPA is subject to the limitations and exclusions set out in the ToS (see Section 13 of the ToS — Limitation of Liability), as between Processor and Controller.

11.2 GDPR Liability. Nothing in this DPA or the ToS limits the liability of either party to the extent that such liability cannot be excluded or limited under GDPR Article 82 or any equivalent provision of applicable data protection law. In the event of a claim brought by a Data Subject against either party under GDPR Article 82, the parties shall cooperate in good faith to determine each party's respective liability based on responsibility for the damage caused.

11.3 Indemnification. Each party shall indemnify the other in accordance with the indemnification provisions of the ToS (see Section 14 of the ToS — Indemnification). In addition: (a) Controller shall indemnify Processor against claims arising from Controller's instructions that cause Processor to act in breach of applicable data protection law; and (b) Processor shall indemnify Controller against claims arising from Processor's breach of this DPA.


12. Term & Termination

12.1 Term. This DPA is coterminous with the ToS. It enters into force upon acceptance of the ToS during the Owner signup flow and terminates automatically upon termination or expiry of the ToS.

12.2 Post-Termination Obligations. Sections 7.2 (Confidentiality), 7.7 (Deletion and Return), 10 (Audits), 11 (Liability), and 13 (Governing Law) of this DPA, and all Annexes, survive termination of this DPA.

12.3 Effect of Termination. Termination of this DPA does not relieve either party of obligations that accrued prior to termination, nor does it limit the rights or remedies available to either party in connection with any breach of this DPA occurring before termination.


13. Governing Law

13.1 Governing Law. This DPA is governed by the laws of the State of Wyoming, USA, without regard to conflict-of-laws rules, except to the extent that mandatory provisions of EU or UK data protection law apply to the Processing of Personal Data of EU/EEA or UK Data Subjects.

13.2 EU/UK Data Protection Law. Notwithstanding Section 13.1, the SCCs incorporated in Section 9.1 are governed by the law of Ireland (pursuant to Clause 17, Option 1 of the SCCs). The UK IDTA incorporated in Section 9.2 is governed by the law of England and Wales.

13.3 Conflict. In the event of a conflict between this DPA and the SCCs or UK IDTA with respect to international transfers, the SCCs or UK IDTA (as applicable) shall prevail.

13.4 Notices. Legal notices under this DPA shall be sent in accordance with the notices provisions of the ToS (see Section 19 of the ToS — General & Notices). Data protection inquiries may also be sent to founder@tryaimee.com with subject line "DPA — Legal Notice."


Annex I — Processing Details

I.A — Parties

Details
Data Exporter (Controller)Customer (clinic / organization identified in the Aimée account registration)
Data Exporter RoleController — determines purposes and means of Processing
Data Importer (Processor)Aimée LLC, 30 N Gould St, Ste R, Sheridan, WY 82801, USA
Data Importer RoleProcessor — processes Personal Data on Controller's behalf
Contactfounder@tryaimee.com

I.B — Description of Transfer and Processing

Categories of Data Subjects:

  • Patients and callers: individuals who telephone Controller's clinic and interact with the Aimée AI voice agent;
  • Controller's Authorized Users: employees, contractors, and other individuals who access the Service under Controller's account.

Categories of Personal Data:

  • Caller phone numbers (caller ID);
  • Names of callers and patients (as disclosed during calls);
  • Appointment topics, dates, times, and preferences (may include health-related information);
  • Call transcripts: full text records of conversations;
  • Call metadata: timestamps, call duration, call status;
  • Account credentials of Authorized Users: email addresses, hashed passwords, session tokens;
  • Usage analytics: login times, feature usage, IP addresses (truncated per privacy policy), user-agent strings.

Special Categories of Personal Data (GDPR Article 9): Health-related information may be incidentally disclosed by callers during conversations (e.g., symptoms, medical history, prescription details). Such data is Processed solely under GDPR Article 9(2)(h) — provision of health or social care — at Controller's direction and under Controller's responsibility.

Nature of Processing: Automated transcription of voice calls; AI-driven dialog management and response generation; storage and retrieval of transcripts and call records; appointment scheduling and management; analytics and reporting; delivery of customer communication.

Purpose of Processing: Appointment scheduling and management; inbound call handling and routing; customer communication on Controller's behalf; service analytics and operational reporting; maintenance of call records for Controller's review.

Duration of Processing: Processing is continuous during active calls. Stored data (transcripts, call metadata) is retained in accordance with the retention periods set out in the Privacy Policy: default 90 days for transcripts and caller phone numbers (configurable by Controller via the auto_delete_days setting), and for the duration of the subscription plus applicable statutory retention periods for account and billing data.

Frequency of Processing: Continuous during active telephone calls; on-demand for stored records.

I.C — Competent Supervisory Authority

The supervisory authority of the EU Member State in which Customer is established. If Customer is not established in the EU/EEA, the competent supervisory authority is the Irish Data Protection Commission (An Coimisiún um Chosaint Sonraí).

For UK Data Subjects: the UK Information Commissioner's Office (ICO).


Annex II — Approved Subprocessors

Controller grants general authorization for Processor to engage the following Subprocessors. This list is maintained and updated at aimee.ai/legal/subprocessors. Processor shall provide thirty (30) days' advance email notice before adding or replacing any Subprocessor, and Controller may object within fourteen (14) days of receiving such notice.

ProviderLegal EntityPurposeData LocationSafeguards
SupabaseSupabase Inc.Database hosting & authenticationEU (Frankfurt, Germany)DPA signed; EU data storage; no transfer to third countries
DeepgramDeepgram Inc.Speech-to-text transcriptionUSADPA signed; EU SCCs Module 2 (Decision 2021/914) + UK IDTA
ElevenLabsElevenLabs Inc.Text-to-speech voice synthesisUSADPA signed; EU SCCs Module 2 + UK IDTA
GroqGroq Inc.LLM inference (primary)USADPA accepted; EU SCCs Module 2 + UK IDTA
xAIxAI Corp.LLM inference (fallback)USADPA accepted; EU SCCs Module 2 + UK IDTA
VercelVercel Inc.Frontend hosting & CDNUSA (with EU edge nodes)DPA signed (Pro plan); EU SCCs Module 2
RailwayRailway Corp.Backend hostingUSADPA signed; EU SCCs Module 2 + UK IDTA
TelnyxTelnyx LLCTelephony infrastructure (EU/US)EU + USADPA signed; EU SCCs for US-routed traffic + UK IDTA
StripeStripe Inc.Payment processingUSADPA signed; EU SCCs Module 2 + UK IDTA; PCI-DSS Level 1 certified

Annex III — Technical and Organizational Measures

The following technical and organizational measures are implemented by Processor to ensure a level of security appropriate to the risk:

Encryption

  • In transit: TLS 1.2 or higher for all data transmitted between Processor's infrastructure components, between the Service and Authorized Users, and between the Service and Subprocessors;
  • At rest: AES-256 encryption for all databases, backups, and stored data at Supabase and Railway.

Access Control

  • Role-based access control (RBAC): access to Personal Data is restricted based on the users.role field; the principle of least privilege is applied throughout;
  • Authorized User management: Controller controls access permissions for Authorized Users via the dashboard; Controller is responsible for promptly deactivating access for individuals no longer affiliated with the organization;
  • Multi-factor authentication (MFA): required for administrative and platform-level access to production systems.

Authentication

  • Password hashing: user passwords are hashed using Argon2 via Supabase Auth; plaintext passwords are never stored;
  • Session tokens: session tokens have a limited time-to-live (TTL) and are rotated on each authentication event;
  • Magic link expiry: invite links expire within 24 hours of issuance.

Audit Logging

  • Immutable audit log: all administrative actions and data access events are recorded in an append-only audit log; rows cannot be deleted or modified (enforced at database trigger level — see migration 050);
  • Compliance log: AI-assisted decisions affecting Data Subjects are logged in call_compliance_logs;
  • Consent audit log: all consent events (acceptance, re-acceptance, marketing opt-in/out) are recorded in legal_consent_log with truncated IP, user-agent, timestamp, and document version hash; retained for seven (7) years.

Pseudonymization and Data Minimization

  • Caller phone numbers: can be pseudonymized (hashed) at Controller's option via clinic settings;
  • Call audio: processed in real-time and not stored — audio is transcribed during the call and the audio stream is discarded immediately; only the text transcript is retained;
  • IP addresses: stored in truncated form only (IPv4: last octet zeroed; IPv6: first 48 bits retained, remainder zeroed), consistent with post-2018 GDPR guidance.

Backup and Recovery

  • Daily encrypted backups: retained for 30 days with geographic redundancy;
  • Recovery testing: backup restoration is tested quarterly.

Incident Response

  • Detection: Personal Data Breaches are detected via Sentry error monitoring and uptime monitoring;
  • Notification: Controller will be notified within 72 hours of Processor becoming aware of a breach, per Section 7.6 of this DPA;
  • Remediation: Processor maintains a documented incident response plan; post-incident reviews are conducted and remediation measures are implemented.

Supplementary Measures for International Transfers

All US-based Subprocessors are contractually obligated to:

  • Challenge any governmental request for access to Personal Data where such challenge is lawful;
  • Notify Processor of any governmental request for access to Personal Data where permitted by law;
  • Provide transparency reports disclosing the number and categories of governmental requests received;
  • Implement encryption and access controls that make Personal Data inaccessible to Subprocessors' infrastructure staff without additional key material.

Personnel and Training

  • All Processor personnel with access to Personal Data are subject to binding written confidentiality obligations;
  • Security awareness training is conducted on at least an annual basis for all personnel with access to production systems.

Vulnerability Management

  • Automated dependency scanning is performed in CI/CD pipelines for known vulnerabilities;
  • Third-party security postures of Subprocessors are reviewed on a quarterly basis;
  • Penetration testing is conducted annually (or following material architectural changes).

Annex IV — SCCs and UK IDTA (Incorporated by Reference)

The full text of the following legal instruments is incorporated into this DPA by reference:

EU Standard Contractual Clauses (Module 2: Controller-to-Processor) Commission Implementing Decision (EU) 2021/914 of 4 June 2021 Official Journal of the European Union, L 199, 7.6.2021 Available at: https://eur-lex.europa.eu/eli/dec_impl/2021/914

UK International Data Transfer Addendum Issued by the Information Commissioner under Section 119A(1) of the Data Protection Act 2018 Version B1.0, in force 21 March 2022 Available at: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/international-data-transfer-agreement-and-guidance/

Conflict Resolution. In the event of any conflict or inconsistency between this DPA (including its Annexes) and the SCCs or UK IDTA with respect to the Processing of Personal Data subject to international transfer requirements, the SCCs or UK IDTA (as applicable) shall prevail to the extent of such conflict.

Completeness. The parties acknowledge and agree that this Annex IV, together with Annexes I, II, and III, contains all information necessary to complete the SCCs and UK IDTA as between Controller and Processor. No further separate document is required to give effect to the international transfer safeguards contemplated by this DPA.


This Data Processing Agreement is effective as of July 1, 2026. Questions regarding this DPA should be directed to founder@tryaimee.com.