Data Processing Agreement

UK GDPR  ·  Aim Automations Ltd  ·  weaim.io

Version 1.2  ·  Revised 21 August 2026

This Data Processing Agreement governs the processing of personal data and special category data by Aim Automations Ltd on behalf of its customers, in accordance with Article 28 of the UK GDPR and the Data Protection Act 2018.

  • Processor: Aim Automations Ltd (Company No. 16579415), registered in England and Wales
  • Controller: The Customer
  • Version: 1.2
  • Revised: 21 August 2026
  • Supersedes: Version 1.1, 25 June 2026
  • Effective: On execution of the Aim customer agreement
  • Contact: care@weaim.io

What changed in version 1.2.Breach notification to the Customer shortened from 72 hours to 24 hours, so the Customer retains time to meet its own regulatory deadline. Added: assistance with data protection impact assessments and prior consultation; the duty to flag an infringing instruction; express liability for sub-processors; a defined consequence where the Customer objects to a sub-processor; return or deletion at the Customer’s choice; a concrete audit right; and a record of processing. Section 4 sub-processor list updated.

1. Roles and Scope

1.1 Roles

For the purposes of the UK GDPR and the Data Protection Act 2018, the Customer acts as the Data Controller and Aim Automations Ltd acts as the Data Processor.

1.2 Scope

This Agreement applies to all personal data and special category data, including health and care records, processed by Aim on behalf of the Customer in the course of providing the Aim platform and related services.

1.3 Relationship with the customer agreement

This Agreement forms part of, and is subject to, the customer agreement between the Parties. Where the customer agreement contains a data protection obligation that is more protective of the Customer than this Agreement, that obligation prevails.

2. Processing Details

2.1 Subject matter

Provision of digital care management and business software, including care planning, medication records (eMAR), scheduling, rostering, finance, reporting, communication, recruitment, marketing and AI-assisted drafting features.

2.2 Duration

For the term of the customer agreement, plus the post-termination period set out in section 10.

2.3 Nature and purpose of processing

  • Storing and displaying care records
  • Generating care plans, risk assessments and reports
  • Scheduling visits and staff rotas
  • Supporting compliance and operational workflows
  • Communication between the Customer, its staff, service users and authorised family representatives
  • AI-assisted drafting and task execution, strictly under Customer control

2.4 Types of data

  • Personal data relating to service users, staff and family contacts
  • Special category data, being health information, care needs and medication records

2.5 Categories of data subject

  • Service users
  • Care workers
  • Office staff
  • Authorised family representatives
  • Job applicants and enquirers, where the Customer uses the recruitment and enquiry features

3. Processor Obligations

3.1 Documented instructions

Aim processes personal data only on the Customer’s documented instructions, including instructions given through use of the platform and through support requests, unless required to do otherwise by law, in which case Aim will inform the Customer of that requirement before processing unless the law prohibits it.

3.2 Infringing instructions

Aim will inform the Customer promptly if, in Aim’s opinion, an instruction from the Customer infringes the UK GDPR, the Data Protection Act 2018 or any other applicable data protection provision. Aim may suspend the affected processing until the instruction is confirmed, amended or withdrawn.

3.3 Confidentiality

Aim ensures that all personnel authorised to process personal data are subject to appropriate obligations of confidentiality, whether contractual or statutory, and that those obligations survive the end of their engagement.

3.4 Technical and organisational measures

Aim implements appropriate technical and organisational measures under Article 32, including:

  • AES-256 encryption at rest
  • TLS 1.2 or higher encryption in transit
  • Role-based access control on a least privilege basis
  • Multi-factor authentication support
  • Restricted internal access to production systems
  • Audit logging of access to personal data
  • Documented backup and restoration procedures
  • Annual review of these measures, and update where necessary to maintain an appropriate level of security

3.5 No commercial exploitation

Aim does not sell, rent or commercially exploit Customer data, and does not use it for any purpose other than providing and supporting the services, complying with law, and protecting the security and integrity of the platform.

3.6 Assistance with data subject rights

Taking into account the nature of the processing, Aim assists the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling the Customer’s obligation to respond to requests to exercise data subject rights, including access, rectification, erasure, restriction, portability and objection.

3.7 Assistance with security, breach and impact assessments

Taking into account the nature of the processing and the information available to Aim, Aim assists the Customer in ensuring compliance with its obligations under Articles 32 to 36 of the UK GDPR, including:

  • security of processing;
  • notification of a personal data breach to the Information Commissioner’s Office;
  • communication of a personal data breach to data subjects;
  • data protection impact assessments, including by providing information about the platform’s processing, data flows, sub-processors and security measures; and
  • prior consultation with the Information Commissioner’s Office where required.

3.8 Record of processing

Aim maintains a written record of all categories of processing carried out on behalf of the Customer, as required by Article 30(2), and makes it available to the Customer on request.

4. Sub-Processors

4.1 General authorisation

The Customer gives Aim general written authorisation to engage sub-processors, subject to this section 4. The sub-processors engaged at the date of this Agreement are:

Sub-processorPurposeLocation of processing
VercelApplication hosting, edge content delivery and DNSUnited Kingdom, with limited processing outside under transfer safeguards
NeonManaged database infrastructureUnited Kingdom
OpenAIAI text processing via API onlyUnited States, under transfer safeguards
AnthropicAI text processing via API onlyUnited States, under transfer safeguards
SendGrid (Twilio)Transactional email deliveryUnited States, under transfer safeguards
Firebase (Google)Real-time in-app messagingUnited Kingdom, with limited processing outside under transfer safeguards
StripePayment processingUnited Kingdom and European Economic Area
Amazon Web ServicesApplication and data hostingUnited Kingdom (London, eu-west-2)

The current list is maintained by Aim and available at any time on request to care@weaim.io.

4.2 Flow-down of obligations

Aim imposes on each sub-processor, by written contract, data protection obligations that are equivalent to those in this Agreement and that are sufficient to meet the requirements of Article 28.

4.3 Aim’s liability for sub-processors

Aim remains fully liable to the Customer for the performance of each sub-processor’s data protection obligations. Where a sub-processor fails to fulfil those obligations, Aim remains liable to the Customer for that failure as if it were Aim’s own.

4.4 Changes to sub-processors, and the Customer’s right to object

Aim will give the Customer at least 30 days’ written notice before adding or replacing a sub-processor. Where the Customer objects in writing within that period on reasonable data protection grounds:

  1. Aim will not appoint that sub-processor in respect of the Customer’s data during the notice period;
  2. the Parties will discuss the objection in good faith, and Aim will either agree a mitigation with the Customer or offer a reasonable alternative; and
  3. where no resolution is reached within 30 days of the objection and Aim proceeds regardless, the Customer may terminate the affected services on written notice without penalty, and Aim will refund any prepaid fees relating to the period after termination.

4.5 AI sub-processor safeguards

Aim’s AI sub-processors are engaged on enterprise API terms, not consumer terms. Where the provider offers it and the processing is eligible, Aim configures zero data retention so that Customer data is not retained by the provider after the request is served. Where a specific feature is not eligible for zero data retention, Aim will identify it to the Customer on request and confirm the retention period that applies at the provider. Aim holds a signed business associate agreement with its AI sub-processors where the provider offers one.

5. International Transfers

5.1 Primary hosting

Aim hosts production systems and Customer care data within the United Kingdom.

5.2 Position on transfers

Aim does not transfer Customer care data outside the United Kingdom or the European Economic Area except where an appropriate transfer mechanism is in place.

5.3 Transfer safeguards

Certain sub-processors identified in section 4.1 process limited personal data outside the United Kingdom. Each such transfer is covered by the provider’s data processing terms incorporating the UK International Data Transfer Agreement, or the Standard Contractual Clauses together with the UK Addendum, and by a transfer risk assessment carried out by Aim. Copies of the relevant safeguards are available to the Customer on request.

6. Security Incidents and Breach Notification

6.1 Incident response

Aim maintains documented incident response procedures to identify, investigate, contain and remediate security incidents, and tests them periodically.

6.2 Notification to the Customer

Aim notifies the Customer without undue delay, and in any event within 24 hours of becoming aware of a personal data breach affecting the Customer’s data. This period is deliberately shorter than the Customer’s own 72 hour deadline for notifying the Information Commissioner’s Office under Article 33, so that the Customer retains sufficient time to assess and report.

6.3 Content of the notification

So far as the information is available to Aim at the time, the notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a point of contact. Where the full information is not available at the time, Aim provides it in phases without further undue delay.

6.4 Assistance

Aim provides reasonable assistance to support the Customer’s regulatory obligations, including any notification the Customer must make to the Information Commissioner’s Office or to affected data subjects, and does not require the Customer to bear Aim’s costs of investigating a breach caused by Aim.

7. Audits and Demonstrating Compliance

7.1 Information

Aim makes available to the Customer all information necessary to demonstrate compliance with Article 28 and with this Agreement, including its security overview, its NHS Data Security and Protection Toolkit submission, its record of processing under section 3.8, and its current sub-processor list.

7.2 Audit right

The Customer, or an auditor mandated by the Customer, may audit Aim’s compliance with this Agreement once in any twelve month period, and additionally following any personal data breach affecting the Customer’s data. Audits are subject to reasonable written notice of at least 30 days, are conducted during normal business hours, must not disrupt service availability or the confidentiality of Aim’s other customers, and are subject to confidentiality undertakings.

7.3 Regulatory audits

Nothing in this section limits any audit or inspection right of the Information Commissioner’s Office or any other competent supervisory authority.

8. AI Processing Safeguards

8.1 Enterprise API only

AI features are provided only via enterprise application programming interfaces operated by Aim’s AI sub-processors. Customer data is never entered into consumer AI tools.

8.2 Customer data and model training

Customer data is not used to train, fine-tune or evaluate any AI model, whether Aim’s or a sub-processor’s. Data is transmitted on the minimum necessary principle, limited to what the requested feature requires.

8.3 Retention at the AI sub-processor

Where the provider offers it and the processing is eligible, zero data retention is configured so that no Customer data persists at the provider after the request is served. Where a feature is not eligible, Aim identifies it and the applicable provider retention period to the Customer on request, in accordance with section 4.5.

8.4 Storage of outputs

AI-generated outputs are stored only within Aim’s United Kingdom hosted systems and are encrypted at rest.

8.5 Human control

AI-assisted drafting and task execution operate under the Customer’s control. Outputs affecting care documentation are produced as proposals requiring human review and approval before publication, and the Customer remains responsible for every decision to accept, amend or reject an output.

9. Customer Responsibilities

The Customer is responsible for:

  • the lawful collection and entry of data, and having a lawful basis for all processing it instructs;
  • providing appropriate privacy information to data subjects;
  • managing user access and permissions within its own environments;
  • ensuring its staff use secure devices and credentials, and do not share logins;
  • notifying Aim promptly of any user who should no longer have access;
  • meeting its own regulatory obligations, including to the Information Commissioner’s Office, the Care Quality Commission, the Care Inspectorate, Care Inspectorate Wales and local authorities; and
  • where it operates a franchise or group structure, the acts and omissions of each entity within it that acts as a controller.

10. Retention, Return and Deletion

10.1 Customer’s choice

On termination or expiry of the customer agreement, and at the Customer’s written election, Aim will either return the Customer’s personal data to the Customer or delete it. This choice is the Customer’s, in accordance with Article 28(3)(g).

10.2 Retention window

Aim retains the Customer’s data for 6 months from the effective date of termination so that the Customer may export it. Where the Customer makes no election within that period, Aim permanently deletes the data at the end of it.

10.3 Deletion

On deletion, data is permanently removed from production systems and residual copies are removed from backups through normal rotation. Aim confirms deletion in writing on request.

10.4 Export format

Exports are provided in structured, commonly used, machine-readable formats, and Aim provides a complete export within 20 business days of written request, at no charge for a single export.

10.5 Retention required by law

Where Aim is required by law to retain any personal data beyond the period in section 10.2, it will inform the Customer, retain only what the law requires, and continue to protect it under this Agreement until deletion is permitted.

10.6 No withholding

Aim will not withhold the Customer’s data as leverage in a commercial dispute. Where a dispute exists, Aim will provide the export against payment of undisputed amounts only.

11. Liability

Each Party remains responsible for its own compliance with data protection law. Nothing in this Agreement limits liability where such limitation is not permitted by law, including liability to a data subject under Article 82. Any limitation of liability in the customer agreement applies to claims under this Agreement, save where the law does not permit it.

12. Governing Law

This Agreement is governed by the laws of England and Wales, and the Parties submit to the exclusive jurisdiction of the courts of England and Wales.

13. Contact

Data protection and security queries: care@weaim.io

Annex 1: Article 28 Compliance Map

This annex records where each requirement of Article 28 of the UK GDPR is met, so that a controller or auditor can verify compliance without reading the whole document.

Article 28 requirementWhere met
28(3)(a) Process only on documented instructions, including on transfers3.1, 5.2, 5.3
28(3) Final paragraph: inform controller of an infringing instruction3.2
28(3)(b) Confidentiality commitments from authorised personnel3.3
28(3)(c) Article 32 security measures3.4
28(2) and 28(4) Sub-processor authorisation, flow-down and liability4.1, 4.2, 4.3, 4.4
28(3)(e) Assist with data subject rights3.6
28(3)(f) Assist with Articles 32 to 36, including DPIAs and prior consultation3.7, 6.4
28(3)(g) Delete or return at the controller’s choice10.1, 10.2
28(3)(h) Make information available and allow audits and inspections7.1, 7.2, 7.3
Article 30(2) Processor record of processing3.8
Article 33(2) Notify the controller of a breach without undue delay6.2, 6.3

Annex 2: Technical and Organisational Measures

AreaMeasure
Encryption at restAES-256 across production databases and object storage
Encryption in transitTLS 1.2 or higher for all connections
Access controlRole-based, least privilege, enforced at tenancy boundary so that no customer can access another customer’s environment
AuthenticationMulti-factor authentication supported for all user accounts
Production accessRestricted to named personnel, logged, and reviewed periodically
Audit loggingAccess to personal data is logged and retained for investigation
BackupsEncrypted, with documented restoration procedures and defined rotation
SegregationMulti-tenant architecture with logical separation between customer environments
Incident responseDocumented procedures for identification, investigation, containment, remediation and notification
PersonnelConfidentiality obligations, and data protection training for personnel with access to personal data
AssuranceNHS Data Security and Protection Toolkit submission maintained at Standards Met; ICO registration maintained
ReviewThese measures are reviewed at least annually and updated where necessary

Version history.Version 1.0, initial issue. Version 1.1, revised 25 June 2026. Version 1.2, revised 21 August 2026: breach notification to the Customer shortened to 24 hours; added assistance with data protection impact assessments and prior consultation; added the duty to flag an infringing instruction; added express liability for sub-processors; added a defined consequence where the Customer objects to a sub-processor; added return or deletion at the Customer’s choice; added a concrete audit right and a record of processing; expanded the technical and organisational measures; added the Article 28 compliance map.

Aim Automations Ltd, company number 16579415, registered in England and Wales. care@weaim.io  ·  weaim.io