Data Processing and Sub-processor Notice
Effective from: 1st January 2026
This Data Processing and Sub-processor Notice explains how AIMAI Ltd processes personal data when delivering its services, including PRISM, AI assistants, shared threads, client workspaces, knowledge features, approvals, audit records, integrations, and related support services.
1. Who we are
AIMAI Ltd provides governed AI systems and related platform services for business use. Depending on the engagement, AIMAI Ltd may act as a data controller or a data processor. Where AIMAI Ltd processes data on behalf of a client, the client remains responsible for determining the purpose and lawful basis of that processing.
AIMAI Ltd
Office 18, The Globe Innovation Centre, Slaithwaite, HD7 5JN
01484 767892
info@aimai.co.uk
2. How we process data
We process personal data only as needed to provide, secure, maintain, support, and improve our services. This may include account data, contact details, communications, workspace content, uploaded files, prompts, outputs, technical logs, usage data, and integration data made available through approved client systems.
Processing activities may include hosting, storage, retrieval, workflow execution, monitoring, authentication, audit logging, AI model processing, transcription, image generation, notifications, and support operations.
3. Data handling approach
AIMAI Ltd operates core platform functions in-house on AWS infrastructure. This includes user management, logging, workflow orchestration, and the API layer. Access is controlled on a least-privilege basis, and we use technical and organisational measures designed to protect confidentiality, integrity, and availability.
4. Current sub-processors
We use the following sub-processors and service providers to support delivery of our services:
- Amazon Web Services (AWS): cloud hosting and infrastructure services, including EC2, RDS, S3, SES, SNS, and CloudWatch.
- OpenAI: general large language model processing.
- Anthropic: large language model processing.
- Google: image generation services, including Imagen.
- Deepgram: audio transcription and speech processing.
- GitHub: source code hosting and deployment support.
- Fasthosts: DNS and domain management.
- Let's Encrypt: SSL/TLS certificate issuance.
- Stripe: payment processing, planned where applicable.
5. Client-specific integrations
Some third-party connectors, such as Sage 50, CRM systems, and accounting platforms, are integrated on a client-by-client basis. These are not enabled universally. Where such integrations are used, the relevant sub-processors or connected services will be disclosed as part of the specific client engagement.
6. International transfers
Where personal data is transferred outside the UK, AIMAI Ltd uses appropriate safeguards, which may include the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, as applicable.
7. Security and governance
We maintain security and governance controls appropriate to the nature of the services provided. These may include encryption in transit, access controls, permissions management, environment separation, monitoring, logging, audit records, and documented governance policies. Users are expected to use the service only for authorised and lawful business purposes.
8. Changes to sub-processors
We continuously evaluate emerging AI and platform capabilities. Additional AI providers, models, or service providers may be adopted over time where this supports service quality, security, resilience, or client outcomes. Any new sub-processors will be disclosed accordingly.
9. Client responsibilities
Clients are responsible for ensuring they have an appropriate lawful basis for the personal data they submit to AIMAI Ltd, for configuring access appropriately within their organisation, and for ensuring that any regulated, sensitive, or restricted data is only processed where authorised under the relevant agreement and internal policy framework.
10. Contact
If you have questions about this notice or AIMAI Ltd's data processing arrangements, contact info@aimai.co.uk or write to AIMAI Ltd at the address above.

