Data Processing Agreement

HIPAA Disclosure Included

1. Roles

Customers act as Data Controllers. AIEmployee.com acts as a Data Processor.

2. Processing Scope

We process data only to provide and support the Services.

3. Security Measures

We maintain access controls, monitoring, and reasonable safeguards appropriate to the nature of the data.

4. Subprocessors

We may use third-party subprocessors for infrastructure, analytics, communications, and payments.

AI Employee image services

Data category: normalized image pixels and fixed policy text, without filename, tenant, user, or avatar-provider identifiers. Purpose: image safety moderation before avatar processing.

Data category: normalized source image and a non-PII label. Purpose: create-from-image avatar creation, operation, security, maintenance, and permitted service improvement. Images in the manual reference flow are moderated but are not automatically submitted for avatar creation.

5. Data Breach Notification

We will notify customers without undue delay upon discovery of a qualifying data breach.

6. Data Deletion

Upon termination, data may be deleted or anonymized unless retention is legally required.

Raw uploads are deleted after finalization succeeds or fails. Normalized sources follow authenticated owned deletion under the lifecycle below. Manual-reference normalized images for unpaid drafts are retained for seven days after binding; replacement, abandonment, cancellation, and completed fulfillment queue authenticated owned deletion. Checkout adds seven-day protection against payment and deletion races. Paid or in-progress requests are not deleted by stale-unpaid cleanup. Failed deletion will retry with exponential backoff starting at five minutes and capped at 24 hours. An assigned avatar that adopts the same image receives ownership by transfer instead of deletion. Limited consent, audit, and deletion-tombstone records may be retained where needed for compliance, security, or replay prevention.

7. HIPAA Disclaimer

AIEmployee.com is not a covered entity under HIPAA. The Services are not intended to process Protected Health Information unless a separate Business Associate Agreement is executed in advance.

Customers are responsible for ensuring PHI is not submitted without authorization.

Data Processing Agreement | AI Employee | AI Employee