Data Processing Agreement
HIPAA Disclosure Included
1. Roles
Customers act as Data Controllers. AIEmployee.com acts as a Data Processor.
2. Processing Scope
We process data only to provide and support the Services.
3. Security Measures
We maintain access controls, monitoring, and reasonable safeguards appropriate to the nature of the data.
4. Subprocessors
We may use third-party subprocessors for infrastructure, analytics, communications, and payments.
AI Employee image services
Data category: normalized image pixels and fixed policy text, without filename, tenant, user, or avatar-provider identifiers. Purpose: image safety moderation before avatar processing.
Data category: normalized source image and a non-PII label. Purpose: create-from-image avatar creation, operation, security, maintenance, and permitted service improvement. Images in the manual reference flow are moderated but are not automatically submitted for avatar creation.
5. Data Breach Notification
We will notify customers without undue delay upon discovery of a qualifying data breach.
6. Data Deletion
Upon termination, data may be deleted or anonymized unless retention is legally required.
Raw uploads are deleted after finalization succeeds or fails. Normalized sources follow authenticated owned deletion under the lifecycle below. Manual-reference normalized images for unpaid drafts are retained for seven days after binding; replacement, abandonment, cancellation, and completed fulfillment queue authenticated owned deletion. Checkout adds seven-day protection against payment and deletion races. Paid or in-progress requests are not deleted by stale-unpaid cleanup. Failed deletion will retry with exponential backoff starting at five minutes and capped at 24 hours. An assigned avatar that adopts the same image receives ownership by transfer instead of deletion. Limited consent, audit, and deletion-tombstone records may be retained where needed for compliance, security, or replay prevention.
7. HIPAA Disclaimer
AIEmployee.com is not a covered entity under HIPAA. The Services are not intended to process Protected Health Information unless a separate Business Associate Agreement is executed in advance.
Customers are responsible for ensuring PHI is not submitted without authorization.
