Data Processing Addendum & Subprocessor Disclosure
Trust Center Navigation
1. This Addendum and how it applies
1.1 Parties. This Data Processing Addendum (the "DPA") is between Aetos Data Consulting LLC, a Delaware limited liability company at 8 The Green, Suite B, Dover, DE 19910 ("Aetos"), and the organization or other business customer identified as the client in the Agreement ("Client").
1.2 How it becomes binding. This DPA forms part of, and is incorporated into, each of the following that applies:
(a) the Master Services Agreement between Aetos and Client (the "MSA"), where it incorporates this DPA, without a separate signature;
(b) Aetos's applicable Free Terms of Use or Paid Terms of Use, when Client accepts them to submit the TPS Snapshot or buy a TPS Report; and
(c) a Free Services and Beta Agreement or another written service agreement that expressly incorporates this DPA.
The person accepting for Client represents that they have authority to bind Client. The applicable MSA, Terms, or Free Services and Beta Agreement is the "Agreement." This DPA takes effect when that Agreement becomes binding and applies to processing on Client's behalf, including where Client is a sole trader. Aetos will make this DPA available before acceptance and retain the accepted versions, date, and accepting person's identity and stated authority. If a later MSA covers further processing of the same data, it governs that further processing from its effective date without restarting retention periods unless Client expressly instructs otherwise.
1.3 Precedence. For Client Personal Data, if documents conflict, this order controls:
the Standard Contractual Clauses, as modified by the UK Addendum where applicable;
this DPA; then
the rest of the Agreement.
A Business Associate Agreement ("BAA") controls for protected health information, without displacing mandatory Data Protection Laws or applicable transfer safeguards. Nothing in this DPA permits processing of protected health information without the required BAAs and an approved processing route.
1.4 Terms. Capitalized terms not defined here have the meanings in the Agreement. In this DPA:
"Data Protection Laws" means all laws on privacy and personal data that apply to a party's processing under the Agreement, including, where applicable, the EU General Data Protection Regulation ("EU GDPR"), the UK GDPR and Data Protection Act 2018 ("UK GDPR"), the Swiss Federal Act on Data Protection ("FADP"), the California Consumer Privacy Act as amended ("CCPA"), and other US state privacy laws.
"Client Personal Data" means personal data that Aetos processes on Client's behalf in providing the Services, as described in Annex I.
"Personal data," "processing," "controller," "processor," "data subject," and "supervisory authority" have the meanings in the applicable Data Protection Laws, and include their equivalents, such as "personal information," "business," and "service provider" under the CCPA.
"Subprocessor" means a third party Aetos engages to process Client Personal Data.
"Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Client Personal Data.
2. Roles and scope
2.1 Aetos as processor. Client is the controller, or a processor acting for its own controller, and Aetos is Client's processor, for Client Personal Data in:
the TPS Snapshot and the TPS Report, including answers, scores, results, and reports;
Tabletop engagements conducted on Client's behalf, including client profiles, participant information, responses, decision logs, and deliverables, whether paid or provided under the Free Services and Beta Agreement; and
Aerie and other agreed free or beta services, including Client Content, account records, and workspace activity processed on Client's behalf.
2.2 Outside this DPA. Aetos is an independent controller, and this DPA does not apply, for:
Aetos-run public Tabletop sessions using fictional scenarios, to the extent Aetos determines the purposes and means for its own purposes;
Aetos's own business contact, marketing, billing, payment, account, and security records, to the extent processed for its own purposes rather than on Client's behalf; and
the activity described in Section 3.4.
Aetos's Product Privacy Notice at https://www.aetos-data.com/product-privacy-notice describes that processing.
2.3 Client's responsibilities. Client is responsible for:
the lawfulness of the Client Personal Data it or its users provide, including personal data about third parties, such as staff named in uploaded documents, exercise participants, and people Client invites into a Share Room;
any notices, consents, or other legal basis needed for Aetos to process that data under this DPA; and
the accuracy of its instructions. If Client is a processor, it confirms that its controller has authorized this processing, the applicable Subprocessors and transfers, and the instructions Client gives Aetos.
2.4 Sensitive data. Client must notify Aetos and obtain its prior written agreement, including all required BAAs for protected health information, before providing:
special category data, criminal-conviction or offence data, or other sensitive personal data under applicable Data Protection Laws;
government identification numbers;
payment card data;
health information; or
data about children.
An Order Form or SOW may give standing approval for specified sensitive-data categories, purposes, systems, and safeguards, including for Schedule C, incident-readiness, or incident-response work. Uploads within that approval need no separate approval from Aetos. All required BAAs must be in place before upload.
If such data reaches Aetos without that agreement, Aetos will promptly notify Client, restrict access, and process it only as necessary to secure it and arrange its lawful return or deletion. Aetos will not send it to an AI provider or other unapproved route. Advance notice alone does not authorize the upload.
3. Instructions
3.1 Documented instructions. Aetos processes Client Personal Data only on Client's documented instructions. Any legally required processing outside those instructions must comply with Data Protection Laws and Section 10. For processing subject to Article 28 of the EU GDPR or UK GDPR, the exception is limited to the law specified by the applicable Article 28(3)(a). Aetos will tell Client before that processing unless that law prohibits notice. Client's instructions are:
the Agreement;
this DPA, including Annex IV;
each Order Form or SOW;
Client's use and configuration of the Platforms; and
any other written instruction Aetos accepts that is consistent with the Agreement.
3.2 Instructions given by this DPA. Client instructs Aetos to process Client Personal Data to provide, support, and secure the Services, including to:
deliver the Snapshot, prepare the TPS Report, run Tabletop engagements, and operate Aerie;
send Aetos an internal notification when a Snapshot is submitted, and follow up as needed to deliver or explain results;
use the AI Features and providers described in Annex III as a standard part of delivery, unless an Order Form or SOW expressly provides otherwise, with Aetos reviewing every AI-drafted Deliverable before release;
record and transcribe service calls using the providers in Annex III, after notice to participants and any consent required by law; a participant who declines recording may request that Aetos use written notes instead; and
keep, return, and delete Client Personal Data as Annex IV and Section 9 describe.
3.3 Unlawful instructions. Aetos will tell Client promptly if, in its opinion, an instruction infringes Data Protection Laws. Aetos may suspend the affected processing while the parties address the issue and will not resume it unless the instruction is modified, withdrawn, or reasonably established to be lawful. Aetos's notice is not legal advice.
3.4 Aetos's own follow-up. Client acknowledges that Aetos acts as an independent controller for its own business contact records and lawful marketing activity. To tailor follow-up, Aetos may use only the submitter's name, work email, role, and company details independently collected for that purpose, and organization-level risk bands and top gaps that do not identify or relate to an identifiable person. For this use:
Aetos follows its Product Privacy Notice, identifies an applicable legal basis, and is responsible for its own compliance with Data Protection Laws;
Aetos will not use Client's answers, detailed scores, reports, or findings about identifiable people for its own marketing; a corporate label alone does not make a finding non-personal;
this acknowledgment is not a processor instruction or permission to use Client Personal Data contrary to Section 12, Data Protection Laws, or the Agreement's confidentiality duties; and
follow-up is limited to the item requested. Promotion of other offerings requires separate permission under the Agreement and applicable law. Newsletter enrollment requires a separate opt-in, and Aetos will honor applicable objections and unsubscribe requests.
3.5 De-identified, aggregated information. Client authorizes Aetos to create and use de-identified, aggregated information derived from Client Personal Data, which identifies no Client and no person, to improve its products and methods. Aetos will:
take reasonable measures to meet the applicable legal standard for de-identification and prevent association with a person or Client;
publicly commit to maintain and use it in de-identified form and not attempt to re-identify it; and
contractually bind any recipient to the same restrictions and safeguards, including the prohibition on re-identification.
Information ceases to be Client Personal Data only to the extent it meets the applicable legal standard. Aetos's confidentiality duties continue to protect Client information.
4. Aetos personnel
4.1 Need to know. Only Aetos personnel who need access to deliver, support, or secure the Services may access Client Personal Data. Each is bound by contractual or statutory confidentiality duties, may use the data only for authorized work, and must protect it from unauthorized disclosure. Those duties continue after their work for Aetos ends. Any more protective confidentiality terms in the Agreement also apply.
4.2 Facilitators and contractors. Facilitators and contractors are Aetos personnel only while acting under its direct authority and confidentiality controls. A separate provider processing Client Personal Data is a Subprocessor and is subject to Section 6. Aetos is responsible for its personnel's compliance with this DPA.
5. Security
5.1 Measures. Aetos implements and maintains the technical and organizational measures in Annex II, which are designed to give a level of security appropriate to the risk. Aetos may update them, provided an update does not materially reduce the overall protection of Client Personal Data.
5.2 Client's controls. Client is responsible for its own security choices within the Platforms, including:
whom it invites and the roles it assigns;
the files it restricts;
Share Room recipients and expiry dates; and
keeping its users' credentials and authenticator devices secure.
6. Subprocessors
6.1 General authorization. Client gives Aetos general written authorization to engage the Subprocessors listed in Annex III. Annex III is the initial list. Aetos publishes the current Subprocessor register with this DPA on its website and retains prior versions. Changes validly made under Section 6.4 update Annex III. The register identifies each receiving legal entity, its address and privacy contact, services, processing locations including remote access, transfer safeguards, and applicable retention terms. Aetos will provide the register to Client on request.
6.2 Contracts. Aetos will engage each Subprocessor under a written contract that imposes data protection obligations no less protective in substance than this DPA, to the extent applicable to the service it provides, including confidentiality, assistance, deletion, appropriate transfer safeguards, and equivalent obligations through any further processing chain. Aetos remains responsible to Client for each Subprocessor's performance of those obligations. Aetos will provide information and copies of relevant subprocessing agreements as required by Data Protection Laws or the SCCs, with appropriate redactions to protect unrelated confidential information.
6.3 AI providers. Aetos:
uses AI providers only under business or API terms and settings that prohibit training on Client Personal Data; Aetos will not enable optional training or feedback sharing that permits training, or use the data to train reusable Aetos models, without separate lawful written authorization;
sends them only the content a task needs and requires the necessary restrictions through their downstream processing chain;
records each approved product, model, feature, retention setting, and retention exception in Annex III or the register maintained under Section 6.1;
will not send protected health information to an AI provider unless an approved workflow and all required BAAs cover the actual provider, product, feature, and downstream processing; and
will notify Client in advance of a material adverse change in a listed AI provider's processing or retention terms and apply Section 6.4's notice, objection, and exit process. An online update alone does not authorize a new purpose or reduced protection.
6.4 Subprocessor changes. Aetos follows this process before adding or replacing a Subprocessor or materially expanding its processing of Client Personal Data:
Notice. Aetos gives Client at least 30 days' notice, by email to Client's notice contact and by updating the register in Section 6.1, with information sufficient to assess the change.
Objection. Client may object in writing within that period on reasonable data protection grounds, and the parties will discuss the objection in good faith. Aetos will not send Client's data to the objected-to provider or implement the objected-to expansion while a timely objection remains unresolved, unless the required parties lawfully agree otherwise in writing.
Termination. If the parties cannot resolve the objection within 30 days after it is made, Client may end the affected Service on written notice. Aetos will refund prepaid fees for the undelivered portion of the affected Service, including an undelivered fixed-price TPS Report, and for any prepaid service period after termination. Aetos may offer a lawful alternative or suspend affected processing pending resolution or exit.
Notice contacts. If Client has not designated a notice contact, Aetos will email the person who accepted the Agreement. Posting alone is not notice. For SCC Module 3, Aetos will ensure timely written notice to the controller under Clause 9(a), directly or through an agreed delivery process with Client, and inform Client of engagement.
6.5 Urgent replacement. If urgent replacement is needed to protect security or availability, Aetos may use a provider already authorized for the affected processing or obtain the required specific written authorization for an earlier start. Otherwise Aetos will preserve the applicable notice period, including under the SCCs, and suspend affected processing if necessary. Urgency does not remove the objection rights in Section 6.4.
7. Assistance
7.1 Data subject requests. When Aetos receives a request from a data subject about Client Personal Data:
Aetos will promptly tell Client;
Aetos will not respond except to confirm receipt, to point the person to Client, or as Client authorizes; and
taking into account the nature of the processing, Aetos will help Client respond, including through the Platforms' export and deletion features.
For Snapshot and TPS Report data, Client authorizes Aetos to carry out verified deletion requests concerning the requester's own personal data within 30 days of receipt, or sooner if law requires, under Client's documented request-handling instructions, and to notify Client. An individual request does not authorize deletion of the organization's entire assessment or unrelated people's data. Aetos will refer questions of scope or applicable exceptions to Client without delaying required assistance.
7.2 Assessments and authorities. Aetos will give Client reasonable information and help, taking into account the nature of the processing and the information available to Aetos, for Client's security and breach-response obligations, legally required privacy assessments and compliance reviews, and:
data protection impact assessments;
transfer impact assessments; and
prior consultations with supervisory authorities about the Services.
7.3 Cost. Help under this Section is included in the fees to the extent it is reasonable and occasional. Aetos may charge reasonable fees for additional assistance only after agreeing the scope and fees with Client in writing. Aetos will not charge for assistance needed to remedy its breach of this DPA or delay legally required help because fees remain disputed.
8. Security Incidents
8.1 Notice. Aetos will notify Client without undue delay, and in any event within 48 hours, after becoming aware of a Security Incident. Aetos will not wait to complete its investigation before notifying Client.
8.2 Content and updates. The notice will describe, as far as then known:
the nature of the incident;
the categories and approximate number of data subjects and records concerned;
the likely consequences;
the measures taken or proposed to address it and limit its effects; and
a contact point.
Aetos will give material updates without undue delay as more information becomes available.
8.3 Response. Aetos will take reasonable steps to contain, investigate, and remediate the incident, and will cooperate with Client's own response. Client decides whether to notify authorities or affected people, except where the law requires Aetos to do so directly.
8.4 No admission. Notice of a Security Incident is not an acknowledgement of fault or liability.
9. Return and deletion
9.1 Retention and choice. At the end of the relevant processing service, Client may choose return or deletion of Client Personal Data. If Client does not instruct otherwise, it instructs Aetos to retain only the limited archive described in Annex IV to permit later retrieval for Client, for no longer than the stated period. Client may shorten that period at any time. The schedule applies per engagement, so an unrelated active Order does not extend it. Retention required by law is subject to Data Protection Laws and the safeguards in this Section.
9.2 Return. Client may export its content from the Platforms during the engagement and for 30 days after it ends. If access ends immediately, Aetos will securely deliver a usable copy on written request. A return instruction includes deletion of remaining copies after return, subject only to the lawful exceptions in this Section. Longer-lived download links do not extend the post-engagement export window or any retention period.
9.3 Deletion. At the end of each retention period, or within 30 days after Client's authorized deletion instruction unless law requires sooner, Aetos will delete Client Personal Data from its active systems and require deletion from its Subprocessors' systems. The limited exceptions in Sections 9.4 and 9.5 and for provider security logs identified in Annex III apply only to the extent lawful and consistent with this DPA and applicable transfer safeguards. In addition:
Aerie gives Client's administrators at least 7 days' notice before scheduled deletion and confirms it afterwards;
a documented legal requirement or valid Client instruction may pause deletion only for the affected data and necessary period; Aetos will review the hold and delete when its basis ends; and
once Platform access closes, retained copies are archived, kept confidential, protected by this DPA, and used only for the authorized retention purpose.
9.4 Backups and residual copies. Where immediate erasure is not practicable and delayed erasure is lawful, the following outer limits apply:
Aerie's backups: within 7 days after deletion from active systems;
other Aetos and Subprocessor backups, except Google Workspace: within 40 days after deletion from active systems; and
Google Workspace email and files, including client correspondence, shared files, and internal Snapshot notifications: residual copies are removed from Google's systems within 180 days after Aetos completes deletion through the service controls so that Aetos can no longer recover the data.
Aetos will complete the deletion steps within its control, including removing recoverable copies and addressing retention settings, within Section 9.3's deadline. Pending erasure, retained copies are isolated from ordinary use and used only for recovery or as legally required. If restored, the data is promptly deleted again. These exceptions do not authorize new processing or displace a stricter legal requirement.
9.5 AI provider records. Aetos will apply available deletion controls, require its AI Subprocessors to meet their deletion obligations, and assist Client with requests. Disclosed provider safety or legal retention applies only to the extent consistent with Data Protection Laws, this DPA, and applicable transfer safeguards, and does not release Aetos from its obligations. A material adverse change follows Sections 6.3 and 6.4. If Aetos determines that an affected processing route cannot meet those obligations, it will promptly notify Client and suspend further affected disclosures until compliance is restored or the affected Service ends, with the exit and refund provisions in Section 6.4 applying where relevant. A request for earlier deletion alone does not invalidate a lawful, agreed retention exception. Mandatory suspension and termination duties under the SCCs remain unaffected.
9.6 Certification. On Client's written request, Aetos will confirm in writing that deletion under this Section is complete, and identify any data retained and why.
10. International transfers
10.1 Location. Aetos and its main Subprocessors store Client Personal Data in the United States. Some Subprocessors process it in other locations listed in Annex III. Aetos will not transfer Client Personal Data except in compliance with this Section and Data Protection Laws.
10.2 From Client to Aetos. Where Client's transfer of Client Personal Data to Aetos is a restricted transfer under the EU GDPR, UK GDPR, or FADP, and no adequacy decision or certification Aetos holds covers it, the parties incorporate the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 (the "SCCs"), to the extent those clauses are available for the relevant processing. If they are not, the parties must establish another lawful mechanism before the transfer. The SCCs are completed as follows:
| SCC clause | Selection |
|---|---|
| Modules | Module 2 (controller to processor) where Client is a controller. Module 3 (processor to processor) where Client acts as a processor for its own controller. |
| Clause 7 (docking clause) | Not included. |
| Clause 9(a) (subprocessors) | Option 2, general written authorization, with at least 30 days' notice under Section 6.4 to the exporter for Module 2 and the controller for Module 3. |
| Clause 11(a) (redress) | The optional independent dispute resolution body is not included. |
| Clause 13 (supervision) | As Annex I, Part C states. |
| Clause 17 (governing law) | Option 1, the law of Ireland. |
| Clause 18(b) (forum) | The courts of Ireland. |
| Annexes I, II, and III | Annexes I, II, and III of this DPA. |
10.3 UK transfers. For restricted transfers under the UK GDPR, the parties incorporate Part 2 Mandatory Clauses of the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner (version B1.0, in force March 21, 2022), as revised under its own terms (the "UK Addendum"). Its modifications to the SCCs, including law, courts, and supervision, apply to those transfers. Part 1 is completed as follows:
Table 1: the parties, contacts, acceptance or signatures, and effective date identified in Annex I and Section 1.2;
Table 2: the SCC modules and options in Section 10.2;
Table 3: Annexes I, II, and III; and
Table 4: neither party may end the UK Addendum under its Section 19.
10.4 Swiss transfers. To the extent the FADP applies, the SCCs apply with these changes, without reducing EU GDPR protection where both laws apply:
the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority;
references to member states include Switzerland for Swiss data-subject rights, so Swiss data subjects may bring claims in Switzerland; and
references to the EU GDPR include the FADP to the extent needed for the Swiss transfer.
10.5 Onward transfers. Aetos will make onward transfers only on documented instructions and with valid safeguards. Aetos will obtain appropriate written subprocessing terms, including the applicable SCC module and UK Addendum where needed. It may rely on an adequacy decision, including a relevant DPF certification, only after verifying that it covers the receiving legal entity, the data, and the particular onward transfer. The EU-U.S. DPF, UK Extension, and Swiss-U.S. DPF require separate coverage checks. A provider's certification does not cover Client's preceding transfer to Aetos. The register in Section 6.1 records the verified mechanism, and Aetos will perform required transfer assessments, apply supplementary measures where necessary, and suspend any route that cannot comply.
10.6 Requests from authorities. If a public authority asks Aetos for Client Personal Data, Aetos will:
redirect the request to Client where it can;
notify Client unless the law prohibits it; and
disclose only what it is legally required to disclose, after reviewing legality and challenging the request where there are reasonable grounds to consider it unlawful, in accordance with the applicable SCC requirements.
11. Audits and information
11.1 Information. Aetos will make available to Client all information necessary to show compliance with this DPA and applicable processor obligations, including Article 28 of the EU GDPR and UK GDPR. Routine reviews begin with written answers to a reasonable security questionnaire once a year and available relevant attestations. This process does not limit additional information required by law, the SCCs, an authority, or reasonable evidence of noncompliance.
11.2 Audits. Client may audit Aetos's compliance with this DPA, itself or through an independent auditor bound by confidentiality, including inspections where appropriate. The parties will use existing relevant reports and questionnaires first where these reasonably meet the purpose, without making their insufficiency a condition to required audit rights. Audits:
happen no more than once in any 12 months, unless a Security Incident, reasonable evidence of noncompliance, an authority, Data Protection Laws, or the SCCs requires otherwise;
normally require 30 days' notice and reasonable advance coordination of scope; neither party may unreasonably withhold or delay agreement, and coordination will not prevent a legally required audit;
take place during business hours without unreasonable disruption; and
are at Client's own cost, except to the extent required by law or reasonably needed to verify remediation of Aetos's material breach.
Subprocessor reviews ordinarily use relevant reports and contractual audit procedures, without limiting mandatory rights. Where applicable US state law permits, Aetos may arrange a qualifying assessment by an independent assessor using an appropriate accepted control standard or framework and assessment procedure, and provide the report on request. That alternative does not limit separate EU/UK or SCC audit rights.
12. US state privacy laws
12.1 Service provider terms. Client discloses Client Personal Data only for the limited and specified purposes in Section 3.2 and Annex I. For Client Personal Data subject to the CCPA or a similar US state law, Aetos acts as Client's service provider or processor and will not:
sell or share it, as those terms are defined in the CCPA;
retain, use, or disclose it for any purpose other than those limited and specified business purposes or as the law otherwise expressly permits;
retain, use, or disclose it outside the direct business relationship with Client; or
combine it with personal information Aetos receives from others or collects itself, except as the law permits.
Section 3.4 does not authorize use of Client Personal Data contrary to this Section. This Section controls over any inconsistent permission in this DPA.
12.2 Compliance. Aetos will:
comply with the obligations that apply to it under those laws;
provide the same level of privacy protection they require; and
notify Client if it determines it can no longer meet them.
Client may take reasonable and appropriate steps to verify that Aetos uses Client Personal Data consistently with its applicable obligations and, on notice, to stop and remediate unauthorized use. These rights do not depend on Aetos first reporting noncompliance. Aetos certifies that it understands and will comply with the restrictions in this Section.
13. General
13.1 Liability. Each party's liability under this DPA is subject to the limitations in the Agreement, except where the SCCs or Data Protection Laws do not permit a limitation.
13.2 Term. This DPA lasts as long as Aetos processes Client Personal Data under the Agreement, including during any retention period in Annex IV.
13.3 Changes. Aetos may update this DPA to reflect changes in Data Protection Laws, Subprocessors (under Section 6), or the Services, provided the update does not materially reduce the protection of Client Personal Data. Notice and silence do not authorize a new processing purpose, controller use, or training use. Such changes require separate lawful agreement. The SCCs and UK Addendum may change only as those instruments permit. For another material change:
Aetos gives Client at least 30 days' advance notice by email to the contact identified under Section 6.4 and by publishing the updated DPA with its version and effective date;
Client may object in writing within that period on reasonable data protection grounds, and the parties will discuss the objection in good faith; and
Aetos will not implement an objected-to change for Client while a timely objection remains unresolved. If the parties cannot resolve it before the proposed effective date, Client may end the affected Service and receive the refund described in Section 6.4. The parties may agree a lawful alternative, and affected processing may be suspended where necessary.
Subprocessor and material adverse AI-provider changes follow Section 6.4 instead. Aetos will preserve earlier accepted versions.
13.4 Governing law. This DPA is governed by the law that governs the Agreement, except as the SCCs and UK Addendum require.
This DPA binds Client by incorporation and acceptance under Section 1.2. That acceptance also binds the parties to the applicable SCCs and UK Addendum. No separate signature is needed.
Annex I: Description of the processing
A. Parties
Data exporter: Client, with its legal name, address, and notice contact recorded in the Agreement or acceptance record. For online users, the contact is the person who accepted the Terms unless replaced. Role: controller (or processor for Module 3). Activities: the Services in Part B. Signature and date: acceptance of the Agreement as recorded under Section 1.2, or the signature block above.
Data importer: Aetos Data Consulting LLC, 8 The Green, Suite B, Dover, DE 19910. Contact: H. Shayne Adler, CEO, privacy@aetos-data.com. Role: processor. Activities: the Services in Part B. Signature and date: Aetos's entry into the Agreement under Section 1.2, or the signature block above.
B. Description of the transfer
| Snapshot and TPS Report | Client Tabletop | Aerie | Delivery tools | |
|---|---|---|---|---|
| Data subjects | The person who submits the Snapshot or buys the report, and anyone named in answers | Client's named participants and backups, and people named in the client profile or uploaded documents | Client staff and contractors who use Aerie, people named in Client documents, Share Room visitors, and staff whose policy acceptances are recorded | Client personnel who correspond, message, or meet with Aetos |
| Personal data | Name, work email, role, company details, answers, scores, results, the report, payment status (no card data), and a keyed hash of the IP address with browser type | Nicknames (deleted at session end); team, role, choices, ratings, and written responses; acceptance times; client profile with names, titles, and exercise roles (no emails or phone numbers), insurer, breach coach, and notice clauses; policies, plans, contracts, and risk registers Client provides | Names, work emails, roles, and phone numbers; sign-in and audit records (IP addresses as salted hashes); credentials and authenticator setup; uploaded documents and checklist answers; names typed to accept a Share Room NDA; staff policy acceptances and whether a background check was completed (no reports) | Emails and shared files, messages, call recordings and transcripts, meeting details, form responses, task names, and time entries |
| Sensitive data | None intended | None intended | None permitted without the prior written approval and safeguards in Section 2.4, including for incident records | None intended |
| Nature and purpose | Score answers; show and email the Snapshot; notify Aetos; draft the TPS Report with AI Features and Aetos review; deliver it through signed links | Run the exercise; for a custom scenario only, build it with AI Features (standard scenarios use no AI); prepare the after-action report, evidence pack, and 60-day scorecard | Run the engagement: checklist, gap analysis, Deliverables, document library, remediation tracking, staff policy records, Share Rooms, and notices | Communicate with Client, record calls under Section 3.2, schedule, collect forms, and track work |
| Retention | Annex IV | Annex IV | Annex IV and valid Client instructions under Section 9 | Annex IV |
Frequency: as needed to provide the applicable Service. Duration: the relevant processing service plus any lawful instructed archive under Section 9 and Annex IV. This table covers data processed on Client's behalf, including agreed free or beta services. Own-purpose records fall under Section 2.2 only to that extent. Before any permitted sensitive-data processing, the parties will record the categories and additional safeguards in writing.
C. Competent supervisory authority
Before the first restricted transfer, Client will identify, and the parties will record in the Agreement or acceptance record, the competent authority selected under SCC Clause 13. For EU transfers:
where Client is established in the EU, the authority responsible for its compliance with the EU GDPR for the transfer;
where Client is not established in the EU but falls under Article 3(2) and has an Article 27 representative, the authority of that representative's member state;
where Client falls under Article 3(2) but is exempt from appointing a representative, the authority of a member state where the relevant data subjects are located. Any other case must be resolved under Clause 13 before transfer;
for UK transfers, the UK Information Commissioner; and
for Swiss transfers, the Swiss Federal Data Protection and Information Commissioner.
Annex II: Technical and organizational measures
Access and identity
Aerie accounts are invitation-only and require a password and an authenticator code at every sign-in, with recovery codes issued at setup.
Aerie sessions end after 12 hours and lock after 30 minutes of inactivity, and accounts lock after 5 failed sign-ins.
Access follows the contract: Client sees a Platform feature only while an active Order grants it, and Client's administrator controls roles and who sees each file.
Aetos access to Client Personal Data is limited to named Aetos personnel who need it.
Separation and storage
Each client's data is separated in the database through tenant access controls. Aetos tests those controls periodically and after material changes that may affect separation.
Files are held in private storage and opened through short-lived links issued after a permission check.
Data is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256) by Aetos's hosting and database providers.
Uploads and content
Aerie uploads are type-checked and scanned for malware before other users can open them. Scanning and conversion copies are discarded after processing.
Share Room visitors confirm their email with a one-time code on every visit, every page they see is watermarked with their email and the date, and access ends when the room closes or expires.
Tabletop screens carry a watermark with the participant's nickname and session code, and nicknames and join tokens are deleted when a session ends.
IP addresses stored in the Aerie application database and TPS assessment database are salted or keyed hashes. Infrastructure providers may separately process raw IP addresses in traffic and security logs as described in Annex III; hashing alone does not make a record anonymous.
Logging and recovery
Aerie audit logs record sign-ins, file views, downloads, and changes. Access to administer the logs is restricted to authorized personnel, and Aetos uses controls to prevent and detect unauthorized alteration.
Production data is backed up daily, with recovery procedures tested periodically.
Network and geography
Aerie and the TPS tools block access from China, Russia, Iran, North Korea, Pakistan, Belarus, Cuba, and Syria.
DNS and network protection for Talon Peak and aetos-data.com run through Cloudflare.
AI and review
AI output is a suggestion only. Nothing AI-drafted reaches Client until Aetos reviews and releases it.
In deploying the Talon Peak builder, Aetos replaces real client and personnel names with placeholders and removes other identifying details unless they are necessary for the authorized task. Aetos checks the finished scenario before release.
A standing rule keeps real client data out of source code, tests, and logs.
Organizational measures
Personnel confidentiality duties, need-to-know access, and prompt removal of access when someone's work for Aetos ends.
Vendor review before a new Subprocessor is engaged, with each provider's data processing terms recorded in Aetos's vendor index.
Documented retention and deletion procedures, automated or manual, with notice, confirmation, and legal hold as Section 9 describes. Aetos assigns responsibility and verifies completion within the agreed periods.
Aetos maintains incident-response procedures, risk-based vulnerability remediation, multi-factor authentication for privileged access, appropriate device protections, and periodic checks that these measures remain effective.
Annex III: Subprocessors
Initial list at acceptance under Section 1.2, updated only under Section 6. "DPF" refers to the relevant EU-U.S., UK Extension, or Swiss-U.S. framework only where verified to cover the transfer. "SCCs" includes the applicable module and UK Addendum or Swiss adaptations where required. Aetos must complete and keep current the legal entities, contacts, locations, safeguards, and retention settings in the register under Section 6.1 before affected processing begins. No entry permits processing that fails Sections 6, 9, or 10.
A. Platform subprocessors (Aerie, Talon Peak, and TPS)
| Subprocessor | Purpose | Client Personal Data | Where | Transfer basis | Retention and AI terms |
|---|---|---|---|---|---|
| Supabase (on AWS) | Database, sign-in, file storage, and server functions for Aerie, Talon Peak, and the TPS tools | All Platform data in Annex I | US East | SCCs in Supabase DPA | Annex IV and Section 9; daily backups |
| Vercel | Hosting for Aerie | Traffic in transit; request logs (IP address, page, time); no documents stored | US East | DPF; SCCs | Security logs under verified provider settings, subject to Section 9 |
| Resend | Invitations, alerts, one-time sign-in codes, and the Snapshot email | Recipient name and email, organization name, links, one-time codes, and the Snapshot PDF; never Aerie documents or findings | US | DPF; SCCs | Annex IV; provider copies subject to Section 9 |
| Fly.io | Malware scanning, document conversion, and text extraction for Aerie uploads | File contents, in memory only | US East (Virginia) | Section 10 safeguards required before transfer | Discarded after processing |
| Anthropic (Claude API) | TPS Reports; custom Tabletop scenarios; Aerie gap analysis off until written ZDR approval and eligible settings are verified | Snapshot answers and scores; necessary profile text and documents with identifiers minimized; Aerie document text only after approval | US | SCCs (Modules 2 and 3) with UK Addendum | No training. API retention terms below; Section 9.5 applies. |
| Netlify | Hosting for Talon Peak pages | Request logs (IP address, page, time); no client documents stored | Global network | Section 10 safeguards required before transfer | Security logs under verified provider settings, subject to Section 9 |
| Cloudflare | DNS and network protection for Talon Peak and aetos-data.com, including the TPS pages | All traffic in transit (IP address and request data) | Global network | DPF; SCCs | Traffic and security logs subject to verified settings and Section 9 |
Claude API retention. Standard API inputs and outputs are retained for up to 30 days. Flagged content may be retained for up to 2 years and safety scores for up to 7 years. Legal exceptions are subject to Section 9.5. Files and other persistent features require separate deletion controls. Before relying on zero data retention (ZDR), Aetos will verify written approval for the relevant organization and the eligibility of each model and feature. The approved settings and any additional feature-specific retention periods must be recorded under Section 6.1 before use.
B. Delivery tools that receive Client Personal Data
| Subprocessor | Purpose | Client Personal Data | Where | Transfer basis | Retention and AI terms |
|---|---|---|---|---|---|
| Google Workspace | Email, file sharing, calendar, and video calls | Client emails, shared documents, meeting invites, and internal Snapshot notifications | US, EU, and global | DPF; SCCs | Annex IV; email and file residual copies under Section 9.4 |
| Slack | Messaging, where Client joins a shared channel | Client conversations and shared files | US and global | DPF; SCCs | Under Aetos's workspace settings |
| Fireflies.ai | Recording and transcribing calls under Section 3.2 | Recordings, transcripts, and participant names | US | DPF; SCCs (Modules 2 and 3) with UK Addendum | No training; restrictions extend to downstream AI providers. Aetos deletes recordings and transcripts on the Annex IV schedule, subject to Section 9. |
| Anthropic (Claude business account, including Claude Cowork) | AI assistant in Aetos's own work | Client Materials Aetos opens in it | US | SCCs with UK Addendum | No training. Aetos deletes chats, files and local/cloud artifacts under Annex IV. Provider deletion and safety exceptions are subject to Section 9.5. Approved plan and feature retention recorded under Section 6.1. |
| OpenAI (ChatGPT Business) | AI assistant | Content Aetos personnel enter | US | SCCs with UK Addendum | Training and optional training feedback off. Aetos sets retention and separately deletes chats, files and project copies under Annex IV. Provider deletion normally within 30 days, with safety/legal exceptions subject to Section 9.5. |
| Asana | Task tracking | Organization names, checklist item and document titles, due dates, Aerie links, and task notes; never files or answers | US (AWS) | DPF; SCCs | Under Aetos's workspace settings |
| Toggl Track (Toggl OÜ) | Time tracking against the engagement budget | Client names, task notes, and time entries | EU (Germany) | Processed in the EU | Under Aetos's workspace settings |
| HubSpot | Contacts and engagement support, to the extent processed on Client's behalf | Names, emails, company and necessary engagement notes; own-purpose use limited by Section 3.4 | US, EU, and global | DPF; SCCs | Client Personal Data follows Annex IV. Own controller records are governed by Sections 2.2 and 3.4 only to that extent. |
| Jotform | Forms and e-signatures | Form responses, and signer names and emails | US and EU (Germany) | Section 10 safeguards required before transfer | Under Aetos's account settings |
| Zapier | Automation between the tools above | Data moving between those tools | US (AWS) | DPF; SCCs | Task history under Zapier's terms; no health information |
| Reclaim.ai | Calendar scheduling | Meeting details and attendees | US (Google Cloud) | DPF; SCCs | AI features off unless enabled |
C. Providers that are not Subprocessors (information only)
These providers are outside Section 6 only to the extent they handle Aetos's own controller records or receive no Client Personal Data. If a provider processes data on Client's behalf, Section 6 applies before that use. Listing a provider here does not determine its role for other processing.
| Provider | Use | Why not a Subprocessor |
|---|---|---|
| Stripe | TPS Report checkout and card payments | Aetos's own billing records. Stripe also acts as an independent controller for fraud prevention and tax |
| GoCardless | Bank debit payments | Aetos's own billing records |
| Xero and Hubdoc | Accounting, invoices, and receipts | Aetos's own billing records |
| Wise, Relay, and Capital One | Payments and banking | Aetos's own payment records |
| Squarespace | Hosts aetos-data.com and the TPS pages | TPS answers go directly to Supabase, not through Squarespace; page visits fall under the website privacy notice |
| Cookiebot, Simple Analytics, and Google Search Console | Website consent and analytics | No Client Personal Data |
| GitHub | Source code | A standing rule keeps client data out of code, tests, and logs |
| Slab, Canva, LinkedIn Sales Navigator, Bulk Signature, and Amazon Business | Internal tools | No Client Personal Data |
Annex IV: Retention schedule (Client's instructions)
The periods below are maximum periods for the relevant engagement, subject to Client's earlier return or deletion choice under Section 9. Any post-service archive is limited to retrieval for Client. Section 9 governs lawful exceptions, notice, holds, and backups. Aetos's own records are identified for information only and are not Client instructions.
| Material | Kept for |
|---|---|
| Snapshot answers and results | Until an authorized deletion request, completed within 30 days or sooner if law requires, or 24 months after submission, whichever comes first |
| Hashed IP address and browser type (Snapshot and TPS Report) | 30 days, even when the related report is kept longer |
| Internal Snapshot notification email | Deleted with the Snapshot record; residual Google Workspace copies follow Section 9.4 |
| Paid TPS Report and its data | 24 months after delivery, subject to earlier return or deletion under Section 9 or a different lawful written instruction |
| Report download links | Expire 90 days after sending or earlier deletion of the report; do not extend Section 9.2 |
| Project files and prior document versions | 90 days after the project closes |
| Retainer and hourly-engagement files | During the engagement and no more than 2 years after it ends |
| Designated role files | During the role and no more than 2 years after it ends, subject to Section 9 and any applicable BAA |
| Call recordings and transcripts | The period for the relevant engagement's files, unless Client instructs earlier deletion |
| Latest version of an Aerie document | The period for the relevant engagement's files; an unrelated active Order does not extend it |
| Aerie account and activity records processed on Client's behalf | During the relevant engagement, then 90 days after it closes, subject to Section 9 |
| Aetos's signed agreements and invoices (own controller records; information only) | 7 years after the agreement ends |
| Tabletop nicknames and join tokens | Until the session ends |
| Tabletop exercise logs | 90 days after the project closes |
| Talon Peak client profiles, uploaded documents, and custom exercises | 90 days after the relevant engagement closes, subject to earlier deletion under Section 9 |
| Paid Tabletop deliverables kept in Aerie | The period for the relevant engagement files, measured from that engagement's close; copying into Aerie does not restart or extend the clock |
| Copies held by AI providers | Only the lawful, disclosed retention periods and safeguards under Sections 6 and 9; Aetos applies available deletion controls |
Schedule C HIPAA records. Client keeps the HIPAA documentation it must retain under 45 C.F.R. 164.530(j). Aetos's retention periods are not Client's legal record schedule unless the Order Form makes Aetos the records custodian.
Copies. Each type of information keeps the same schedule wherever it is stored. Copying a record into Aerie or another system does not restart or extend its retention period without a separate lawful Client instruction.