Aetherion AI

Operating Workspace

Data processing addendum

A clear framework forcustomer-controlled data.

This public overview explains the intended controller–processor relationship, processing scope and security commitments for customer data handled through Aetherion.

This web page is an explanatory summary. A binding DPA requires the applicable executed terms between Aetherion Labs and the customer.

Processing relationship
Overview

Customer

Controller

Aetherion Labs

Processor

Approved providers

Subprocessors

Aetherion remains a controller for its own account, billing, security and service-administration data as described in the Privacy Policy.

Customer instructions define project processing
Processing details

What the processingcovers.

Subject matter

Providing the Aetherion AI workspace, project storage, generation, preview, publishing, support and related platform operations.

Duration

For the subscription or service term, plus the limited period required for deletion, recovery, legal obligations and agreed transition.

Data subjects

Customer users, authorised team members, and people whose personal data the customer chooses to place in a project or connected workflow.

Data categories

Account and contact data, project content, prompts, files, uploaded assets, operational metadata, support communications and customer-selected integration data.

Processing operations

Hosting, storing, retrieving, organising, generating, transmitting, troubleshooting, securing, backing up and deleting data as needed to provide the service.

Purpose

To provide and secure the contracted Aetherion services in accordance with the customer’s documented use and configuration.

Documented instructions

Customer content is processed to provide the service and according to the customer’s documented configuration, use and support requests, unless applicable law requires otherwise.

Confidentiality

Access to customer personal data is limited to authorised people and service providers who need that access for their assigned responsibilities.

Security measures

Aetherion applies technical and organisational controls appropriate to the service and risk, including authentication, access checks, encrypted project secrets and separated runtime boundaries.

Subprocessors

Infrastructure, database, payment, communications and AI providers may support the service under contractual data-protection obligations appropriate to their role.

Rights assistance

Aetherion will provide reasonable assistance so the customer can respond to applicable data-subject requests involving data processed through the service.

Return and deletion

At the end of the service, customer personal data is returned or deleted according to the applicable agreement, product controls, recovery cycle and legal retention duties.

Technical and organisational measures.

The executed DPA can incorporate the current security schedule applicable to the subscribed service and agreed customer use.

Authenticated access to private workspace functions

Project and resource ownership checks

Encrypted and masked server-only project variables

Separated generated preview runtime

Hashed external API keys with revocation

Read-only API v1 with per-request access validation

Secret-file and credential-field exclusions from API responses

Operational request identifiers and rate limiting

Need the DPA for procurement or compliance review?

Tell us the contracting entity, service plan and review contact. We will provide the applicable execution version and supporting processing information.

Request DPA