Legal

Data Processing Addendum

BenchAGI · Effective 2026-07-15

This Data Processing Addendum (“DPA”) supplements, forms part of, and is incorporated by reference into the Terms and Conditions for Aerone Inc. (the “Terms”) and each Order Form entered into between Aerone Inc., a Delaware corporation (“Aerone,” “Provider,” or “Processor”), and the Customer identified on the applicable Order Form (“Customer” or “Controller”). This DPA is a universal addendum that applies to all customers by incorporation into the Order Form, and governs Aerone’s Processing of Customer Personal Data on Customer’s behalf. Where this DPA is accepted or incorporated by reference through an Order Form, “Customer” means the entity that has executed that Order Form, and the Customer-specific information contemplated by this DPA, including Annex 1, is that identified in the applicable Order Form.

Capitalized terms used but not defined in this DPA have the meanings given to them in the Terms. In the event of a conflict between this DPA and the Terms as to the Processing of Personal Data, this DPA controls, as provided in Section 14.1 of the Terms and Section 14.1 below.

1. Definitions

For purposes of this DPA:

“AI Model Provider” has the meaning given in the Terms and means any third-party provider of large language models or AI inference services utilized by the Platform, including Anthropic (Claude), OpenAI, and X.AI LLC (Grok).

“Applicable Privacy Law” means all U.S. federal and state privacy, data protection, and data security laws and regulations applicable to a Party’s Processing of Customer Personal Data under this DPA, as amended or replaced from time to time, including the U.S. State Privacy Laws identified below to the extent applicable.

“U.S. State Privacy Laws” means, as and to the extent applicable to the Processing, the Utah Consumer Privacy Act (“UCPA”), the Texas Data Privacy and Security Act (“TDPSA”), the Florida Digital Bill of Rights (“FDBR”), and the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act (“CCPA”), together with any other comprehensive U.S. state privacy law that becomes applicable to the Processing.

“Control”, “Controller”, “Consumer”, “Process”, “Processing”, “Processor”, “Sell”, “Share”, “Service Provider”, “Sensitive Data”, and “Deidentified Data” have the meanings given to those terms (or their closest analogues) under the applicable U.S. State Privacy Law. Where a term is not defined in the applicable U.S. State Privacy Law, it has its ordinary meaning in the context of data protection.

“Customer Personal Data” means the Personal Data contained within Customer Data that Aerone Processes on behalf of Customer under the Agreement and this DPA, including Third-Party Personal Data of homeowners and other third parties as described in the Terms and in Annex 1. As between the Parties, Customer Personal Data is and remains the property of Customer.

“Personal Data” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household, as further defined under Applicable Privacy Law. Personal Data does not include Deidentified Data or Aggregated Data.

“Data Subject” means an identified or identifiable natural person to whom Personal Data relates, including, with respect to an applicable U.S. State Privacy Law, a Consumer as defined under that law.

“Aggregated Data” means data that has been aggregated and deidentified such that it cannot reasonably be used to identify Customer or any individual, whether alone or in combination with other information, consistent with Section 6.3(c) of the Terms.

“Sub-processor” means any third party, including an Aerone affiliate but excluding an employee of Aerone, engaged by or on behalf of Aerone to Process Customer Personal Data in connection with the Services.

“Security Incident” means a breach of Aerone’s security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data Processed by Aerone. A Security Incident does not include unsuccessful attempts or activities that do not compromise the security of Customer Personal Data, including unsuccessful log-in attempts, pings, port scans, denial-of-service attacks, or other network attacks on firewalls or networked systems.

“Services”, “Platform”, “Gateway”, “Order Form”, “Outputs”, “Agents”, and “Third-Party Personal Data” have the meanings given to them in the Terms.

2. Roles of the Parties and Scope of Processing

2.1 Roles

With respect to Customer Personal Data, Customer is the Controller and Aerone is the Processor and, where the CCPA applies, a Service Provider. Where an Applicable Privacy Law uses terms other than Controller and Processor, the corresponding terms apply as the context requires. Aerone Processes Customer Personal Data only in its role as Processor or Service Provider, and not as a Controller, except as expressly permitted in Section 2.4.

2.2 Details of Processing

The subject matter, nature and purpose of the Processing, the categories of Customer Personal Data and Data Subjects, and the duration of the Processing are set out in Annex 1.

2.3 Customer Instructions

Aerone shall Process Customer Personal Data only for the purposes described in Annex 1 and only in accordance with Customer’s documented instructions, which are set out in the Terms, the applicable Order Form, and this DPA, and as otherwise reasonably necessary to provide the Services. The Agreement, together with Customer’s use and configuration of the Platform, constitutes Customer’s complete and final instructions to Aerone regarding the Processing of Customer Personal Data. Aerone shall inform Customer if, in Aerone’s reasonable opinion, an instruction infringes Applicable Privacy Law, and may Process as required by a law to which Aerone is subject, in which case Aerone shall, where legally permitted, inform Customer of that legal requirement before Processing.

2.4 Aerone’s Limited Own Use

Nothing in this DPA prevents Aerone from collecting and using Aggregated Data derived from use of the Services to operate, maintain, and improve the Services, provided that such data does not identify Customer or any individual, consistent with Section 6.3(c) of the Terms. In addition, Aerone may Process business contact information of Customer’s personnel (such as name, business email address, title, and business telephone number) as a Controller solely as reasonably necessary to manage the business relationship with Customer, invoice for the Services, and comply with law, in each case in compliance with Applicable Privacy Law. Aerone does not Sell or Share Customer Personal Data and does not use Customer Personal Data to train or fine-tune any generative or general-purpose AI model.

3. Aerone’s Processing Obligations

Aerone shall comply with its obligations under Applicable Privacy Law and, with respect to Customer Personal Data, shall:

Process Customer Personal Data only on Customer’s documented instructions as described in Section 2.3, and only for the limited and specified purposes set out in Annex 1;

ensure that persons authorized to Process Customer Personal Data are subject to an appropriate duty of confidentiality and are granted access only to the extent necessary to perform the Services;

implement and maintain the technical and organizational measures set out in Annex 2, taking into account the nature, scope, context, and purposes of the Processing and the risks to Data Subjects;

taking into account the nature of the Processing and the information available to Aerone, provide reasonable assistance to Customer with Security Incident notification, Data Subject and Consumer rights requests, and any data protection assessment required of Customer under Applicable Privacy Law, as further described in Sections 7 and 8;

at Customer’s direction, delete or return Customer Personal Data in accordance with Section 9;

make available to Customer information reasonably necessary to demonstrate Aerone’s compliance with this DPA and Applicable Privacy Law, in the manner described in Section 10;

engage Sub-processors only in accordance with Section 5; and

not retain, use, or disclose Customer Personal Data other than as necessary to provide the Services or as otherwise permitted by Applicable Privacy Law, and not Sell or Share Customer Personal Data or combine it with Personal Data received from other sources except as permitted by Applicable Privacy Law.

4. U.S. State Privacy Law Terms

4.1 Service Provider and Processor Status

To the extent Aerone Processes Customer Personal Data subject to a U.S. State Privacy Law, Aerone acts as a Service Provider (under the CCPA) and a Processor (under the UCPA, the TDPSA, the FDBR, and other applicable U.S. State Privacy Laws). Customer discloses Customer Personal Data to Aerone only for the limited and specified business purposes described in the Agreement and Annex 1. Aerone shall:

not Sell or Share Customer Personal Data, and not retain, use, or disclose Customer Personal Data for any purpose other than the business purposes specified in the Agreement and Annex 1, or as otherwise permitted by Applicable Privacy Law, including retaining, using, or disclosing it outside the direct business relationship between the Parties;

not combine Customer Personal Data with Personal Data that Aerone receives from, or on behalf of, another person, or collects from its own interaction with an individual, except as permitted by Applicable Privacy Law;

comply with the applicable obligations under the U.S. State Privacy Laws and provide the same level of privacy protection as is required of Customer by those laws with respect to Customer Personal Data;

with respect to any Deidentified Data, take reasonable measures to ensure the data cannot be associated with an individual or household, publicly commit to maintaining and using it in deidentified form, not attempt to reidentify it, and obligate any recipient to the same;

notify Customer promptly if Aerone determines that it can no longer meet its obligations under an applicable U.S. State Privacy Law; and

certify that it understands and will comply with the restrictions in this Section 4.

Customer may, upon notice, take reasonable and appropriate steps to stop and remediate unauthorized Processing of Customer Personal Data. For the avoidance of doubt, the purposes set out in Annex 1 constitute business purposes, and Aerone’s Processing of Customer Personal Data for those purposes does not constitute a Sale or Share of Customer Personal Data under Applicable Privacy Law.

4.2 Baseline Processor Obligations

The obligations set out in Section 3 apply to Customer Personal Data subject to a U.S. State Privacy Law and are intended to satisfy the processor and service-provider contracting requirements of those laws. In particular, and taking into account the context of the Processing, Aerone shall: (a) ensure that each person Processing Customer Personal Data is subject to a duty of confidentiality; (b) at Customer’s direction, delete or return Customer Personal Data at the end of the provision of the Services, unless retention is required by law, as provided in Section 9; (c) upon Customer’s reasonable request, make available to Customer information in Aerone’s possession necessary to demonstrate its compliance, in the manner described in Section 10; (d) allow for, and cooperate with, reasonable assessments as described in Section 10, or, at Aerone’s election, arrange for a qualified independent assessor to assess Aerone’s policies and measures and provide a report to Customer on request; and (e) engage any Sub-processor only pursuant to a written contract in accordance with Section 5. The Parties shall each implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk.

4.3 State-Specific Scope and Extensibility

Aerone’s initial customer footprint is Utah, Florida, and Texas, and this DPA is drafted to satisfy the processor and service-provider contracting requirements of the UCPA, the TDPSA, and the FDBR. The obligations in this DPA apply with respect to each such state to the extent Customer is a Controller subject to, and Customer Personal Data is within the scope of, the applicable U.S. State Privacy Law. Customer acknowledges that the UCPA and the FDBR apply only above defined revenue and other thresholds, and that the TDPSA applies to entities that are not small businesses as defined by the United States Small Business Administration, except that the TDPSA’s sensitive-data provisions may apply regardless of size. This DPA is intended to extend, without amendment, to additional U.S. State Privacy Laws as they become applicable to the Processing. Aerone will identify, before onboarding, any prospective customer that is subject to the CCPA or to another more heavily regulated state privacy law, so that the Parties may address any additional requirements.

5. Sub-processors

5.1 General Authorization

Customer provides Aerone with a general written authorization to engage Sub-processors to Process Customer Personal Data in connection with the Services. Aerone’s Sub-processors as of the date of this DPA are identified in Annex 3 and, when published, on Aerone’s Sub-processor list posted at https://benchagi.com/legal/sub-processors (the “Sub-processor List”). The Sub-processor List, once published, reflects Aerone’s then-current Sub-processors and is maintained through the notice process in this Section 5; until it is published, Annex 3 serves as that list. The Sub-processors identified in Annex 3 include the AI Model Providers (Anthropic, OpenAI, and X.AI LLC) for inference, Google Cloud for hosting and storage, and Stripe for payment processing.

5.2 AI Model Providers

Customer specifically authorizes Aerone to engage AI Model Providers as a category of Sub-processor. Consistent with Section 2.4 of the Terms, Aerone retains sole discretion to select, switch, add, or replace AI Model Providers at any time and without Customer’s prior approval. Aerone shall provide advance written notice (which may be given through the Sub-processor List or by email) before a new or replacement AI Model Provider begins Processing Customer Personal Data, but changes to AI Model Providers are not subject to the objection and termination right in Section 5.3, provided that Aerone binds each AI Model Provider (including any replacement) to terms that are materially equivalent to the data-protection terms of this DPA, including a prohibition on using Customer Personal Data to train, fine-tune, or improve any AI model, confidentiality, appropriate security, and Processing within the United States.

5.3 Other Sub-processors; Notice and Objection

For Sub-processors other than AI Model Providers, Aerone shall provide Customer with at least thirty (30) days’ prior notice (which may be given through the Sub-processor List or by email) before a new Sub-processor begins Processing Customer Personal Data. If Customer reasonably objects to a new Sub-processor on data-protection grounds within that thirty (30) day period, the Parties shall work together in good faith to find a commercially reasonable alternative. If no alternative can be agreed, Customer’s sole and exclusive remedy is to terminate the affected Order Form as it relates to the Services that cannot be provided without the objected-to Sub-processor. If Customer does not object within the notice period, the Sub-processor is deemed authorized.

5.4 Sub-processor Terms and Liability

With respect to each Sub-processor, Aerone shall: (a) enter into a written contract that imposes data-protection obligations that are, in substance, materially equivalent to those in this DPA and that meet the requirements of Applicable Privacy Law; (b) remain fully liable to Customer for the acts and omissions of its Sub-processors to the same extent Aerone would be liable if performing the Services directly, subject to the limitations of liability in the Terms; and (c) upon Customer’s reasonable request, provide a summary of the Processing undertaken by each Sub-processor, or a copy of the relevant Sub-processor terms, which Aerone may redact to protect confidential or proprietary information. Local open-source models that run on the Gateway (for example, models accessed through Ollama for functions such as text embeddings) operate on Customer’s host machine and are not third-party Sub-processors.

6. Security

Aerone shall implement and maintain the technical and organizational measures set out in Annex 2, which are appropriate to the nature of the Services and the risks to Customer Personal Data, consistent with Section 5.5 of the Terms. Aerone shall not make changes to those measures that materially reduce the overall level of security of the Platform during the Subscription Term. Aerone shall ensure that personnel with access to Customer Personal Data are subject to an appropriate duty of confidentiality.

As disclosed in Annex 2 and in Section 5.4 of the Terms, Aerone maintains secure remote access to the Gateway and to cloud-hosted Customer Personal Data for the purposes of software updates and patching, system health monitoring, troubleshooting, technical support, and Agent configuration management. Aerone and Customer share responsibility for security as described in Annex 2, with Customer responsible for the physical security and network connectivity of the customer-owned Gateway.

7. Security Incidents

Aerone shall notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a confirmed Security Incident affecting Customer Personal Data. The notice shall include, to the extent then known and as information becomes available in stages: (a) a description of the nature of the Security Incident, including, where possible, the categories and approximate number of Data Subjects and records concerned and any Sub-processor involved; (b) the name and contact details of an Aerone contact from whom further information can be obtained; (c) the likely consequences of the Security Incident; and (d) the measures taken or proposed to address the Security Incident and mitigate its effects.

Aerone shall cooperate with Customer and take commercially reasonable steps to assist in the investigation, containment, and remediation of the Security Incident, and, at Customer’s request, shall provide commercially reasonable assistance with any legally required notifications to regulators, individuals, or other persons. Aerone shall not notify any regulator, Consumer, or other third party of a Security Incident involving Customer Personal Data without Customer’s prior consent, unless required by a law to which Aerone is subject, in which case Aerone shall, to the extent permitted, avoid identifying Customer and shall inform Customer of the legal requirement. As Controller, Customer retains the sole right and responsibility to determine whether and how to provide notification of a Security Incident. Aerone’s obligation to notify is not, and shall not be construed as, an acknowledgment by Aerone of fault or liability.

8. Assistance to Customer

Taking into account the nature of the Processing, Aerone shall provide reasonable assistance, including through the functionality of the Platform and appropriate technical and organizational measures, to enable Customer to respond to requests from Consumers or Data Subjects to exercise their rights under Applicable Privacy Law (“Rights Requests”). If Aerone receives a Rights Request or related complaint directly from an individual regarding Customer Personal Data, Aerone shall promptly forward it to Customer and shall not respond to it, except to direct the individual to Customer, unless authorized by Customer or required by law.

Taking into account the nature of the Processing and the information available to Aerone, Aerone shall also provide reasonable assistance to Customer with any data protection assessment that Customer is required to conduct under Applicable Privacy Law with respect to Customer Personal Data Processed under this DPA.

Aerone shall promptly notify Customer if it receives a subpoena, warrant, court order, audit notice, or other request from a regulator, law enforcement, court, or tribunal concerning Customer Personal Data, and shall not respond to the request except as authorized by Customer or required by law, in each case after giving Customer a reasonable opportunity to respond where legally permitted. Where assistance under this Section 8 or Section 10 would require Aerone to incur material costs or commit material resources beyond a reasonable scope, the Parties shall agree in good faith on the scope and any reasonable, pre-agreed costs before the assistance is provided, and Aerone shall not unreasonably condition or delay such assistance.

9. Retention, Return, and Deletion

Upon termination or expiration of the Agreement, Aerone shall make Customer Personal Data available for export for a period of sixty (60) days, and shall delete Customer Personal Data from its systems within thirty (30) days following the end of that export period, in each case consistent with Section 5.6 of the Terms, except (a) for copies stored in routine backups, which are deleted in accordance with Aerone’s backup and retention cycles, and (b) as Aerone is required to retain by law. The applicable Order Form or Annex 1 may set different retention periods for particular categories of Customer Personal Data. Any Customer Personal Data that Aerone retains as permitted above remains subject to this DPA and shall be Processed only for the purpose and duration required. Upon Customer’s reasonable request, Aerone shall certify in writing that it has deleted Customer Personal Data in accordance with this Section 9.

10. Demonstrating Compliance and Audit

Aerone shall make available to Customer the information reasonably necessary to demonstrate compliance with this DPA. Upon Customer’s reasonable request, and no more than once per twelve (12) month period, Aerone shall make available a summary of its technical and organizational security measures or respond to a reasonable security questionnaire, in lieu of an on-site audit, consistent with Section 5.5 of the Terms. Because Aerone does not currently hold a SOC 2 or ISO 27001 certification, Aerone satisfies its make-available obligation through this summary or questionnaire process.

Customer, or a qualified independent third-party auditor bound by confidentiality, may conduct an audit or assessment of Aerone’s Processing only where (a) required by Applicable Privacy Law, (b) a Security Incident has occurred, or (c) Aerone is unable to demonstrate compliance through the summary or questionnaire process described above. Any such audit shall be conducted on reasonable prior written notice, during normal business hours, no more than once in any twelve (12) month period, following a risk-based approach, in a manner that does not unreasonably interfere with Aerone’s operations, and limited to information relevant to Customer’s Processing. Where an audit could create a risk to another customer’s environment, the Parties shall agree on an alternative means of providing a comparable level of assurance. If an audit identifies a deficiency in Aerone’s controls, that finding does not constitute a breach of this DPA or the Agreement provided that Aerone remediates the deficiency within thirty (30) business days.

11. Controller Warranties and Obligations

Customer represents, warrants, and covenants that, with respect to all Customer Personal Data it loads into, or instructs Aerone to Process through, the Platform:

Customer has provided all notices and obtained all consents and authorizations required under Applicable Privacy Law from homeowners and other Data Subjects for the Processing, communications, and Agent actions performed through the Platform, including the transmission of Customer Personal Data to AI Model Providers for inference;

Customer’s instructions to Aerone are lawful, and Customer is responsible for establishing and maintaining a lawful basis for the Processing and for the accuracy, quality, and legality of the Customer Personal Data;

Customer will not submit to the Platform, and will use commercially reasonable efforts to prevent the submission of, Sensitive Data except to the extent expressly agreed in writing or as inherent in the Customer Data described in Annex 1; Customer acknowledges that the Platform is not designed for the management of Sensitive Data, that some Customer Data described in Annex 1 may be, or may over time become, treated as sensitive or otherwise regulated under Applicable Privacy Laws, and that Customer is responsible for providing required notices, obtaining required consents, and maintaining a lawful basis for such data;

Customer is responsible for the Agent permission configurations it reviews, approves, or requests, and for obtaining any consents required for the actions taken under those configurations, consistent with Sections 3.4 and 4.1 of the Terms; and

Customer shall secure its own systems and the Gateway as described in Annex 2, including managing user credentials, maintaining network connectivity, and maintaining appropriate backups of Customer Data.

12. Data Location and U.S. Processing

Aerone stores and Processes Customer Personal Data within the United States. Aerone’s cloud infrastructure is hosted on Google Cloud Platform in a United States region (Firestore in the us-east4 region, with file and image storage in Google Cloud Storage), and the AI Model Providers Process Customer Personal Data using United States infrastructure. Aerone does not undertake to transfer Customer Personal Data outside the United States in the ordinary course of providing the Services. Aerone shall notify Customer in writing if a material change in the location of Processing occurs, consistent with Section 5.3 of the Terms.

13. Liability

Each Party’s liability under or in connection with this DPA is subject to the disclaimers, exclusions, and limitations of liability set out in Section 9 of the Terms, including the per-Order-Form limitation of liability, which apply to this DPA as if set out in full here. Aerone is not liable for any cost or damage to the extent caused by an act or omission of Customer, including a Security Incident resulting from Customer’s failure to meet its obligations under Section 11 or Annex 2.

14. General

14.1 Precedence

This DPA is incorporated into and forms part of the Terms and each Order Form. As to the Processing of Personal Data, this DPA controls over the Terms in the event of a conflict. For all other matters, the order of precedence set out in Section 14.1 of the Terms applies (Order Form, then this DPA, then any applicable SOW, then the Terms).

14.2 Amendment

Aerone may update this DPA to reflect changes in Applicable Privacy Law or regulatory guidance, subject to the notice and objection procedures set out in Section 14.2.2 and Section 14.2.3 of the Terms.

14.3 Survival

Any obligation imposed on Aerone under this DPA in relation to the Processing of Customer Personal Data survives termination or expiration of the Agreement for as long as Aerone Processes Customer Personal Data.

14.4 Governing Law and Dispute Resolution

This DPA is governed by, and disputes are resolved in accordance with, the governing law and dispute resolution provisions of the Terms (Section 13), including Delaware governing law and arbitration administered by the American Arbitration Association with the seat in Salt Lake City, Utah.

14.5 Incorporation; No Separate Signature

This DPA is a universal addendum that takes effect through its incorporation by reference into the applicable Order Form and does not require separate signature. The Parties’ execution of the Order Form constitutes their agreement to this DPA.

Annex 1 - Description of the Processing

Roles. Customer is the Controller; Aerone is the Processor and, where the CCPA applies, a Service Provider.

Subject matter. Aerone’s provision of the Platform, an agentic AI platform that deploys AI Agents to perform automated tasks and generate Outputs for Customer’s internal business operations, initially for small and mid-sized businesses in roofing and insurance restoration.

Nature and purpose of the Processing. Processing of Customer Personal Data to provide the Services, including customer relationship management (CRM) and pipeline management, Agent functionality, and the generation of reports, briefings, and other Outputs. In the ordinary course of Agent operation, contextual Customer Personal Data is transmitted to AI Model Providers over encrypted API connections for inference. Aerone also Processes Aggregated Data to operate, maintain, and improve the Services, consistent with Section 6.3(c) of the Terms.

Duration. The Subscription Term, plus the retention and deletion period described in Section 9 (a sixty (60) day export period followed by deletion within thirty (30) days), unless a longer period is required by law.

Frequency. Continuous, for the duration of the Subscription Term.

Categories of Data Subjects.

Homeowners and other end customers of Customer whose Personal Data is processed through the Platform (Third-Party Personal Data); and

Customer’s Permitted Users, employees, contractors, and other personnel who access or are recorded in the Platform.

Categories of Customer Personal Data.

Contact and identity data: names, physical addresses, telephone numbers, and email addresses;

Insurance and claim data: insurance carrier, policy numbers, and claim numbers;

Property and project data: property details, project photographs, and measurement data (including drone-based and AI-assisted measurement or scoping data);

Financial data: project-related financial information, such as estimates and contract values; and

CRM, pipeline, and operational data: deal, contact, and activity records, and internal communications context processed by the Agents.

Sensitive Data. The Platform is not intended for the Processing of health information or other categories of Sensitive Data, and Customer is instructed not to submit such data except as expressly agreed in writing. Customer acknowledges that certain insurance and claim data Processed through the Platform, such as insurance carrier, policy number, claim number, and loss details, may be treated as sensitive or otherwise regulated under some Applicable Privacy Laws, and Customer is responsible for the lawful basis for that data.

Sub-processors. As set out in Annex 3.

Annex 2 - Technical and Organizational Measures

Aerone maintains the technical and organizational measures described below in relation to the Platform. Aerone shall not make changes that materially reduce the overall level of security of the Platform during the Subscription Term. These measures are described truthfully and reflect Aerone’s current security posture; they do not include measures that Aerone does not currently maintain.

Security measures currently maintained

Encryption: Customer Personal Data is encrypted in transit (using industry-standard transport encryption, such as TLS) and at rest.

Access control: role-based, least-privilege access to Customer Personal Data; access is granted only to personnel who require it to perform their functions, using individual credentials.

Patching and updates: Aerone applies software patches and updates to the gateway software, Agent suite, and platform application, and manages operating-system updates on the Gateway, through secure remote access.

Monitoring: automated heartbeat and health monitoring of the Gateway and platform infrastructure, with basic anomaly detection for system health and availability.

Secure configuration: secure configuration and operating-system hardening of the Gateway and the local Agent environment.

Tenant separation: Customer Data is logically separated within a shared, multi-tenant Google Cloud (Firestore) environment by a customer or instance identifier and enforced through access controls; Aerone does not provision a separate database or project for each customer.

Local and private data: data that a user designates as private, or stores in the local vault feature, remains on the customer-owned Gateway under Customer’s control and is not stored in Aerone’s multi-tenant cloud environment.

Hosting: Customer Personal Data is hosted on Google Cloud Platform in a United States region (Firestore in the us-east4 region, with file and image storage in Google Cloud Storage), and cached locally on the customer-owned Gateway.

Remote access: Aerone maintains secure remote access to the Gateway and cloud-hosted data (for example, by SSH or a secure gateway protocol) for updates, monitoring, troubleshooting, support, and configuration, consistent with Section 5.4 of the Terms.

Shared responsibility

Aerone is responsible for the software security configuration, operating-system hardening, and application-level security of the deployed gateway and Agent suite. Customer is responsible for the physical security of the Gateway (physical access, power, and network connectivity), for maintaining network connectivity to enable remote updates, and for the Customer responsibilities described below.

Current limitations

Customer acknowledges that, as of the date of this DPA, Aerone does not hold a SOC 2 or ISO 27001 certification; does not operate a formal Security Operations Center (SOC), security information and event management (SIEM) system, or intrusion detection or prevention system; does not maintain a regular penetration-testing cadence; conducts security monitoring limited to platform health and availability; and maintains limited business-continuity and disaster-recovery capabilities.

Customer responsibilities

Customer shall: (a) ensure that its Permitted Users comply with the Terms; (b) secure the systems and devices in its possession or control, including the Gateway, from threats to the security, confidentiality, availability, and privacy of data; (c) protect the confidentiality of each user’s login credentials, manage user access, and prohibit credential sharing; (d) maintain appropriate backups of Customer Data; and (e) use commercially reasonable efforts to prevent the introduction of malicious code into the Platform.

Annex 3 - Sub-processors

Customer authorizes the Sub-processors listed below, which are Aerone’s Sub-processors as of the date of this DPA. When published, the Sub-processor List will be available at https://benchagi.com/legal/sub-processors, and Aerone will provide notice of new Sub-processors as described in Section 5. Once available, the Sub-processor List reflects Aerone’s then-current Sub-processors; until then, this Annex 3 serves as that list.

Sub-processorCategory and purposeProcessing location
Anthropic, PBC (Claude)AI Model Provider; AI inference for Agent functionalityUnited States
OpenAI, L.L.C.AI Model Provider; supplementary AI inferenceUnited States
X.AI LLC (Grok)AI Model Provider; AI inference for Agent functionalityUnited States
Google LLC (Google Cloud Platform)Cloud hosting and storage (Firestore; Google Cloud Storage)United States (us-east4)
Stripe, Inc.Payment processing for subscription billingUnited States

Note. Local open-source models that run on the customer-owned Gateway (for example, models accessed through Ollama for functions such as text embeddings) operate on Customer’s host machine and are not third-party Sub-processors.

Related: Subscription Terms · Terms of Use · Privacy Policy · Sub-processors