Documented instructions
Customer content is processed to provide the service and according to the customer’s documented configuration, use and support requests, unless applicable law requires otherwise.
Aetherion AI
Operating Workspace
This public overview explains the intended controller–processor relationship, processing scope and security commitments for customer data handled through Aetherion.
This web page is an explanatory summary. A binding DPA requires the applicable executed terms between Aetherion Labs and the customer.
Customer
Controller
Aetherion Labs
Processor
Approved providers
Subprocessors
Aetherion remains a controller for its own account, billing, security and service-administration data as described in the Privacy Policy.
Subject matter
Providing the Aetherion AI workspace, project storage, generation, preview, publishing, support and related platform operations.
Duration
For the subscription or service term, plus the limited period required for deletion, recovery, legal obligations and agreed transition.
Data subjects
Customer users, authorised team members, and people whose personal data the customer chooses to place in a project or connected workflow.
Data categories
Account and contact data, project content, prompts, files, uploaded assets, operational metadata, support communications and customer-selected integration data.
Processing operations
Hosting, storing, retrieving, organising, generating, transmitting, troubleshooting, securing, backing up and deleting data as needed to provide the service.
Purpose
To provide and secure the contracted Aetherion services in accordance with the customer’s documented use and configuration.
Customer content is processed to provide the service and according to the customer’s documented configuration, use and support requests, unless applicable law requires otherwise.
Access to customer personal data is limited to authorised people and service providers who need that access for their assigned responsibilities.
Aetherion applies technical and organisational controls appropriate to the service and risk, including authentication, access checks, encrypted project secrets and separated runtime boundaries.
Infrastructure, database, payment, communications and AI providers may support the service under contractual data-protection obligations appropriate to their role.
Aetherion will provide reasonable assistance so the customer can respond to applicable data-subject requests involving data processed through the service.
At the end of the service, customer personal data is returned or deleted according to the applicable agreement, product controls, recovery cycle and legal retention duties.
The executed DPA can incorporate the current security schedule applicable to the subscribed service and agreed customer use.
Authenticated access to private workspace functions
Project and resource ownership checks
Encrypted and masked server-only project variables
Separated generated preview runtime
Hashed external API keys with revocation
Read-only API v1 with per-request access validation
Secret-file and credential-field exclusions from API responses
Operational request identifiers and rate limiting
Tell us the contracting entity, service plan and review contact. We will provide the applicable execution version and supporting processing information.