Aiome processes two very different categories of information, and the rules that apply to each are different. When you browse our website, request a demo, or sign your organization up, we determine how that information is used, and this Privacy Policy governs it. When your team submits messages, tasks, and time records within a workspace, we act solely as custodian. Your employer determines what is submitted and what happens to it. We store it securely and process it in accordance with the customer's instructions.
Data protection law distinguishes between the party that determines the purposes and means of processing personal information (a controller, or business under U.S. state law) and the party that processes personal information on that party's instructions (a processor, or service provider). Aiome acts in both capacities, depending on the information in question:
Section 4 describes what this distinction means in practice, and Section 15 is addressed to individuals whose employer has enrolled them in the Service.
Aiome is an all-in-one workspace for teams — team chat, projects and tasks, SOPs and training, time tracking, time off, and people and organizational management in a single product. This Privacy Policy applies to aiome.io, the Aiome application, and our sales and support communications (collectively, the Service).
This Section describes information for which Aiome is the controller. Customer Data is addressed separately in Section 4.
If a colleague invites you to a workspace, we receive your email address from that colleague in order to send the invitation. We do not purchase personal information from data brokers.
We do not read your team's messages. We do not mine your workspace to build products, to profile your personnel, or to sell anything. The content belongs to you, your employer controls it, and our access is limited to operating the Service and providing assistance when you request it.
When a customer uses Aiome, its personnel submit content into the workspace. Depending on which parts of the product the customer enables, Customer Data may include:
Important. A free-text note attached to a leave request may reveal health information — an illness, a medical procedure, a pregnancy, a disability, or a family emergency. The leave type alone may have the same effect, because a category such as sick leave discloses that a person was unwell. Under the UK GDPR and the EU GDPR this is special category data (Article 9), and several U.S. state privacy laws treat health information as sensitive.
Aiome does not ask for medical information and does not require a reason for any leave request. Where a note is provided, we process it solely as part of hosting the customer's workspace and apply the same access controls as all other Customer Data. The customer, as the employer and controller, is responsible for deciding whether to collect reasons for leave, for establishing a lawful basis for doing so, and for instructing its personnel on what to write. We recommend that customers do not solicit medical detail in this field.
Aiome personnel do not routinely access the contents of a customer workspace. Access occurs only where it is necessary to: operate and maintain the Service; investigate or remedy a fault, including one the customer has reported; respond to a support request from the customer; or comply with law. Such access is limited to personnel who need it, on a least-privilege basis, and is restricted to the smallest number of people consistent with operating the Service.
As a controller, we use personal information to:
| Purpose | UK/EU legal basis |
|---|---|
| Provide the Service — create and secure accounts, host workspaces, deliver features | Performance of a contract |
| Billing — process subscriptions, invoicing, and tax | Performance of a contract; legal obligation |
| Service communications — invitations, sign-in codes, security alerts, changes to terms | Performance of a contract; legitimate interests |
| Support — answer questions and resolve faults | Performance of a contract; legitimate interests |
| Security and abuse prevention — detect fraud, abuse, and unauthorized access | Legitimate interests; legal obligation |
| Improve the Service — understand which features are used, diagnose faults, and (after you are signed in) review session recordings in which on-screen text is masked and photos are hidden | Legitimate interests |
| Understand this website — which pages on aiome.io are visited, and (if you accept) session recordings and heatmaps so we can see where the site is confusing | Consent, for cookies and session recordings; legitimate interests, for cookieless page-view counts if you decline |
| Marketing — send information about Aiome to people who have asked to hear from us | Consent, or legitimate interests where permitted |
| Legal compliance — respond to lawful requests, enforce our terms, establish or defend claims | Legal obligation; legitimate interests |
Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights, and you may object at any time (Section 12).
We do not sell personal information, and we do not use Customer Data to build or improve products for anyone other than the customer to whom it belongs.
As of the date of this Privacy Policy, Aiome does not send Customer Data to any third-party AI or large language model provider, and no AI feature processes the contents of your workspace.
Teams that store employee records are entitled to a direct answer to this question, and we provide one. As of the date of this Privacy Policy:
We are developing features that would use third-party AI models to assist teams in working with their own content. If and when any such feature processes Customer Data, we commit that:
We separately use AI-assisted tools within our own business operations — for example, for writing and engineering work. Where those tools would process personal information belonging to our customers, they are subject to the same subprocessor controls described above.
Aiome is based in the United States and our infrastructure is located there. Your workspace content is stored in the western United States, our application runs on United States infrastructure, and our product analytics are hosted in the eastern United States. If you are in the United Kingdom, the European Economic Area, or another jurisdiction with data transfer restrictions, your information will be transferred to and processed in the United States and other countries where our subprocessors operate. Our Subprocessors page lists the location of each one.
For transfers of UK and EEA personal data, we rely on the European Commission's Standard Contractual Clauses and, for the UK, the UK International Data Transfer Addendum, together with supplementary technical and organizational measures including encryption in transit and at rest. These clauses are incorporated into our Data Processing Addendum, which is available to every customer without negotiation.
You may request further information about our transfer mechanisms, including a copy of the relevant clauses, through aiome.io/contact.
We retain personal information only for as long as we need it for the purposes described in this Privacy Policy, or for as long as required by law.
| Information | Retention |
|---|---|
| Customer Data in an active workspace | For as long as the workspace exists, and as directed by the customer |
| Customer Data after a paid plan is cancelled | Retained. Cancelling or downgrading moves the workspace to the Free plan. We do not delete Customer Data because a subscription ended. It stays so it is still there if you upgrade again |
| Customer Data after the organization is deleted | Scheduled for 30 days after the owner confirms deletion in Settings → Org Settings. The workspace stays available and the owner can undo until then. After 30 days it is deleted from live systems without undue delay |
| A deactivated member's data, on the customer's instruction | Scheduled for 30 days after an administrator confirms the wipe in Settings → Org Settings, during which it can be undone. After 30 days it is deleted from live systems without undue delay. Data of an active member cannot be wiped this way |
| A member who leaves the workspace | Retained. Leaving from Profile Settings deactivates them — the same as an administrator deactivating them. Their data stays until an administrator schedules a wipe as above, or the organization is deleted |
| Inactive free workspaces | Retained. We do not delete a Free workspace because it has become inactive, and we have no plans to do so. If that ever changes we will publish the policy and give notice first |
| Backups | Deleted data can persist in encrypted backups until those backups expire on our database provider's ordinary rolling cycle, after which it is gone. We do not extend that cycle or keep separate copies of our own |
| Contact and marketing records | Until you unsubscribe or ask us to delete them, and for a reasonable period afterwards to honor your preference |
| Billing and tax records | As required by law, generally seven years |
| Server and security logs | Retained by our hosting provider for the period set by its platform, which is a matter of days to weeks rather than months, and then deleted automatically. We do not archive them |
| Product analytics events | Retained by our analytics provider for the period set by its plan, which ranges from 12 months to 7 years. We do not extend it, and we keep no separate copy of these events ourselves |
| Website analytics | Retained by PostHog for the period set by its plan, which ranges from 12 months to 7 years — the same as product analytics events. If you decline, there is no lasting cookie; a hash that distinguishes a cookieless visit rotates about once a day, so visits on different days are not stitched together. We do not keep a separate copy |
We maintain technical and organizational measures designed to protect personal information against unauthorized access, alteration, disclosure, and destruction. These include encryption in transit using TLS 1.2 or higher, encryption at rest using AES-256, role-based access controls enforced in the database itself rather than only in the interface, least-privilege access for Aiome personnel, and an append-only record of every change made to a time entry.
Our Security page describes these measures in detail. If we become aware of a personal data breach affecting Customer Data, we will notify the affected customer without undue delay and in any event within 72 hours of becoming aware of it, as set out in our Data Processing Addendum.
No system is perfectly secure. You are responsible for keeping access to the email address on your account, and to the devices you use to sign in, secure.
If you are in the UK or the EEA, you have the following rights in relation to personal information for which Aiome is the controller:
To exercise a right, contact us at aiome.io/contact or hello@aiome.io. We respond within one month and may extend by two further months for complex requests, telling you if we do. We may need to verify your identity. Exercising these rights is free unless a request is manifestly unfounded or excessive.
If your employer uses Aiome, your rights over the content of that workspace are exercised against your employer, not us — see Section 15.
Residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Tennessee, Maryland, Indiana, Kentucky, Rhode Island, and other states with comprehensive privacy laws have rights that may include:
How to submit a request. Use aiome.io/contact or email hello@aiome.io. We will verify your request using the information we already hold about you, and will respond within the period your state's law requires — generally 45 days, extendable once where permitted.
Authorized agents. You may use an authorized agent to submit a request. We will ask for proof of the agent's authority and may ask you to verify your own identity directly.
California "Shine the Light." California residents may request information about disclosures of personal information to third parties for their direct marketing purposes. We do not make such disclosures.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We do not process personal information for targeted advertising, and we do not sell or share the personal information of anyone we know to be under 16.
Some state privacy laws define "sale" and "sharing" broadly enough to capture the use of certain advertising and analytics technologies, even where no money changes hands. As of the date of this Privacy Policy, Aiome does not operate advertising pixels or trackers on aiome.io that would constitute a sale or sharing under those definitions.
If that changes, we will update this Section and provide a clearly labelled "Do Not Sell or Share My Personal Information" link in our website footer, honor Global Privacy Control signals as an opt-out, and offer a means to limit the use of sensitive personal information.
Sensitive personal information. We do not collect or process sensitive personal information for the purpose of inferring characteristics about you. Where Customer Data submitted by a customer's personnel happens to contain sensitive information — for example a health-related note in a leave request (Section 4) — we process it only to provide the Service and never for advertising or profiling.
This Section applies to you if you did not choose Aiome — your employer did. You may never have visited our website or agreed to anything, and you are nonetheless entitled to understand your position.
When an organization signs up for Aiome and adds you to its workspace, your employer is the controller of the information in that workspace and Aiome is only the processor. That distinction has practical consequences for you:
We make the following commitments to you directly: we do not sell your information; we do not use your employer's workspace content for our own purposes; we do not send Customer Data to AI model providers (Section 6); and Aiome's time tracking records only start and stop times — it does not take screenshots, track your location, or monitor your activity (Section 4).
Where Aiome is the controller of information about you — for example the account and profile you maintain to access the Service — the rights in Sections 12 and 13 apply to us directly.
Aiome is a business product and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child under 16 has provided us with personal information, contact us and we will delete it. Customers are responsible for ensuring that they do not add members under 16 to their workspace.
We may update this Privacy Policy as the Service and applicable law change. We will post the revised policy on this page and update the "Last updated" date above.
If a change is material — for example, a new category of personal information, a new purpose, or the introduction of AI processing of Customer Data (Section 6) — we will give notice before it takes effect, by email to workspace administrators, by notice in the Service, or both. Where the law requires your consent for a change, we will obtain it.
We keep prior versions of this Privacy Policy and will provide one on request.
For any privacy inquiry, to exercise a right, or to send a legal notice:
Related documents: Terms of Service · Data Processing Addendum · Subprocessors · Security · Acceptable Use Policy