Autm Workflows

Autm Workflows

Autm Workflows

Autm

Data Processing Agreement

Effective date: 14th September 2026

Last updated: 14 September 2026
Version 1.0

This Data Processing Agreement (“DPA”) forms part of the agreement between Autm Limited (“Autm”, “Processor”, “we”, “us” or “our”) and the organisation or other legal entity using the Autm service (“Customer” or “Controller”) where Autm processes Personal Data on behalf of that Customer.

This DPA supplements the Autm Terms of Service, Order Form, enterprise agreement or other written agreement governing the Customer’s use of Autm (the “Agreement”).

Where there is a conflict between this DPA and the Agreement concerning the processing of Personal Data, this DPA takes precedence in relation to that processing.

1. Parties

Processor

Autm Limited
Company number: 16543162
Registered in England and Wales

Little Wood House
Linley
Bishop’s Castle
Shropshire
SY9 5HP
United Kingdom

Email: support@autm.ai

Controller

The Customer identified in the applicable Autm account, Order Form, enterprise agreement or other Agreement.

2. Definitions

For the purposes of this DPA:

“Applicable Data Protection Law” means data protection and privacy law applicable to the processing of Personal Data under the Agreement, including, where applicable, the UK GDPR, the Data Protection Act 2018 and relevant regulations made under or replacing them.

“Controller”, “Data Subject”, “Personal Data”, “Personal Data Breach”, “Processing” and “Processor” have the meanings given to them under Applicable Data Protection Law.

“Customer Data” means information and data submitted to, uploaded to, connected to, generated within or otherwise made available to Autm by or on behalf of the Customer through use of the service.

“Customer Personal Data” means Personal Data contained within Customer Data that Autm processes on behalf of the Customer.

“Sub-processor” means another Processor engaged by Autm to process Customer Personal Data on behalf of the Customer.

“UK GDPR” means the United Kingdom General Data Protection Regulation as it forms part of UK law.

3. Roles of the Parties

For Customer Personal Data processed through the Autm service:

  • the Customer is the Controller; and

  • Autm is the Processor,

except where either party independently determines the purposes and means of a particular processing activity, in which case that party acts as Controller in relation to that activity.

Autm may separately act as Controller for certain information necessary to operate its own business, including account administration, billing, security, fraud prevention, legal compliance, service management and permitted communications. Such processing is governed by Autm’s Privacy Policy and is not processing carried out by Autm on behalf of the Customer under this DPA.

Nothing in this DPA relieves either party of its own obligations or liabilities under Applicable Data Protection Law.

4. Details of the Processing

The details of the processing carried out under this DPA are set out in Schedule 1.

The Customer acknowledges that its configuration and use of Autm determine the specific Customer Personal Data made available to Autm and the processing activities Autm performs.

The Customer may provide additional documented instructions in accordance with this DPA.

5. Customer Instructions

Autm will process Customer Personal Data only:

  • on the Customer’s documented instructions;

  • as necessary to provide, secure, support and maintain the Autm service in accordance with the Agreement;

  • to perform workflows, integrations, AI-assisted processing and actions authorised by the Customer;

  • as otherwise documented through the Customer’s configuration and use of the service; or

  • where required by applicable law.

The Agreement, this DPA, the Customer’s authorised configuration of the service and documented instructions issued through authorised use of Autm constitute the Customer’s documented instructions to Autm.

If applicable law requires Autm to process Customer Personal Data other than on the Customer’s documented instructions, Autm will inform the Customer of that legal requirement before processing unless the law prohibits such notification on important grounds of public interest.

Autm will immediately inform the Customer if, in Autm’s opinion, a documented instruction infringes Applicable Data Protection Law.

Autm is not required to comply with an instruction that would require Autm to violate applicable law.

6. Customer Responsibilities

The Customer is responsible for:

  • complying with its obligations as Controller;

  • determining the lawful basis for processing Customer Personal Data;

  • providing appropriate privacy information to Data Subjects;

  • ensuring that Customer Personal Data is collected and processed lawfully, fairly and transparently;

  • ensuring that it has authority to provide Customer Personal Data to Autm;

  • ensuring that authorised users have permission to connect relevant systems and information;

  • configuring permissions and access appropriately;

  • determining whether particular processing requires consent, a Data Protection Impact Assessment or other safeguards;

  • determining whether its use of AI or automated processing is lawful and appropriate; and

  • providing Autm with lawful documented instructions.

The Customer will not instruct Autm to process Personal Data in a manner that violates Applicable Data Protection Law.

7. Confidentiality

Autm will ensure that persons authorised to process Customer Personal Data:

  • have committed themselves to confidentiality or are subject to an appropriate statutory duty of confidentiality;

  • receive access only where necessary for their role; and

  • process Customer Personal Data only as authorised.

Autm will maintain appropriate internal controls designed to restrict access to Customer Personal Data on a need-to-know basis.

8. Security of Processing

Taking into account the state of the art, costs of implementation and the nature, scope, context and purposes of processing, as well as the risks to the rights and freedoms of individuals, Autm will implement and maintain appropriate technical and organisational measures designed to provide a level of security appropriate to the risk.

These measures include, where applicable:

  • encryption of data in transit using TLS;

  • encryption of data at rest;

  • secure cryptographic key and credential management;

  • role- and permission-based access controls;

  • authentication controls;

  • two-factor and additional authentication controls where enabled;

  • secure handling of authentication and integration tokens;

  • monitoring and audit logging;

  • data minimisation;

  • redaction, tokenisation or pseudonymisation of Personal Data where appropriate and technically feasible;

  • logical separation of Customer workspaces;

  • restricted access to production systems;

  • secure development and operational practices;

  • processes for identifying and responding to security incidents; and

  • measures designed to support the confidentiality, integrity, availability and resilience of processing systems and services.

Further details of Autm’s current technical and organisational measures are set out in Schedule 2.

Autm may update its technical and organisational measures as technology and risks evolve, provided that such changes do not materially reduce the overall level of protection afforded to Customer Personal Data.

9. Authentication and Connections

Autm accounts are managed using ASP.NET Core Identity.

Users may authenticate using email and password or, where available, Google or Microsoft (Entra ID) as external identity providers.

Where Google or Microsoft is used for authentication, Autm requests only the identity scopes required for authentication, such as openid, profile and email.

Authentication using Google or Microsoft does not itself authorise Autm to access email, calendars, files or other business information held within those services.

Connecting a supported third-party business service to Autm is a separate OAuth or authorisation process.

Where the Customer authorises such a connection, Autm processes information within the permissions or scopes expressly granted, the technical capabilities of the integration and the applicable Autm workspace permissions.

Authentication tokens and integration tokens are handled separately and protected using appropriate credential-management and access controls.

10. Sub-processors

The Customer provides Autm with general written authorisation to engage Sub-processors where reasonably necessary to provide the Autm service.

Autm will:

  • maintain information identifying its relevant Sub-processors;

  • make that information available to the Customer;

  • notify the Customer of intended material additions or replacements of Sub-processors that process Customer Personal Data;

  • provide the Customer with a reasonable opportunity to object on legitimate data-protection grounds;

  • enter into a written agreement with each Sub-processor imposing data-protection obligations that provide an equivalent level of protection for Customer Personal Data as required by Applicable Data Protection Law; and

  • remain responsible to the Customer for the performance of its Sub-processors’ applicable data-protection obligations.

Autm’s principal Sub-processors currently include the providers identified in Schedule 3.

Objections to new Sub-processors

If the Customer has reasonable data-protection grounds for objecting to a proposed Sub-processor, it must notify Autm in writing within the notice period specified in Autm’s notification, or if no period is specified, within 14 days of receiving notice.

The parties will work in good faith to identify a commercially reasonable solution.

If no reasonable solution is available and the proposed Sub-processor is necessary for Autm to continue providing the affected service, either party may terminate the affected part of the service in accordance with the Agreement.

An objection must relate to genuine data-protection concerns and may not be used solely to avoid contractual or payment obligations.

11. International Transfers

Autm’s primary customer data infrastructure and data residency are hosted within Microsoft Azure in the United Kingdom.

Some Sub-processors, including AI service providers, may process Customer Personal Data outside the United Kingdom or European Economic Area where necessary to provide their services.

Autm will not transfer Customer Personal Data internationally except:

  • on the Customer’s documented instructions;

  • where necessary to provide the service in accordance with the Agreement and this DPA; or

  • where required by applicable law.

Where a restricted international transfer occurs, Autm will ensure that an appropriate lawful transfer mechanism is in place as required by Applicable Data Protection Law.

Depending on the circumstances, safeguards may include:

  • applicable UK adequacy regulations;

  • recognised adequacy decisions;

  • Standard Contractual Clauses;

  • the UK International Data Transfer Agreement or UK Addendum to approved Standard Contractual Clauses;

  • another legally recognised transfer mechanism; and

  • supplementary technical and organisational measures where appropriate.

Such supplementary measures may include encryption, access controls, data minimisation, redaction, tokenisation or pseudonymisation.

12. AI Processing

Autm may use AI model providers as Sub-processors where necessary to provide AI-assisted functionality.

Depending on the feature being used, Customer Personal Data may be processed for purposes including:

  • inference;

  • reasoning;

  • classification;

  • summarisation;

  • extraction;

  • generation;

  • contextual analysis; and

  • supporting authorised workflows or agent activity.

Autm will apply appropriate data-minimisation and security controls to AI processing.

Where appropriate and technically feasible:

  • only information necessary for the relevant task will be provided for AI processing;

  • Personal Data may be redacted, tokenised or pseudonymised;

  • mappings required to associate protected identifiers with authorised operational information will be secured separately; and

  • access to AI-assisted functionality will be governed by applicable user and workspace permissions.

Autm does not permit Customer Data to be used to train public AI models unless the Customer has explicitly agreed to this in writing.

Where an AI provider processes Customer Personal Data on Autm’s behalf, that provider will be treated as a Sub-processor for the purposes of this DPA where required by Applicable Data Protection Law.

13. Data Subject Rights

Taking into account the nature of the processing, Autm will provide reasonable assistance to the Customer through appropriate technical and organisational measures, insofar as reasonably possible, to enable the Customer to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Law.

These may include rights relating to:

  • access;

  • rectification;

  • erasure;

  • restriction;

  • objection;

  • data portability; and

  • certain automated decision-making or profiling.

If Autm receives a request directly from a Data Subject relating to Customer Personal Data for which the Customer is Controller, Autm will, where reasonably identifiable and legally permitted:

  • notify or direct the Data Subject to the relevant Customer; and

  • not independently respond to the substance of the request except on the Customer’s documented instructions or where required by law.

The Customer remains responsible for determining how to respond to a Data Subject request.

14. Assistance with Compliance

Taking into account the nature of the processing and the information available to Autm, Autm will provide reasonable assistance to the Customer in meeting applicable obligations relating to:

  • security of processing;

  • Personal Data Breaches;

  • notification of breaches to supervisory authorities;

  • notification of breaches to affected Data Subjects;

  • Data Protection Impact Assessments; and

  • prior consultation with a supervisory authority where required.

Autm may provide information about its platform, processing activities, security measures and Sub-processors reasonably necessary to support the Customer’s compliance obligations.

15. Personal Data Breaches

Autm will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.

The notification will, to the extent information is available at the relevant time, provide information reasonably required to assist the Customer in meeting its obligations under Applicable Data Protection Law, which may include:

  • the nature of the Personal Data Breach;

  • the categories and approximate number of affected Data Subjects, where known;

  • the categories and approximate number of affected Personal Data records, where known;

  • likely consequences of the breach, where known;

  • measures taken or proposed to address or mitigate the breach; and

  • an appropriate contact point for further information.

Where all relevant information is not immediately available, Autm may provide information in phases as its investigation progresses.

Notification of a Personal Data Breach does not constitute an admission of fault or liability.

Autm will take reasonable steps to contain, investigate and mitigate Personal Data Breaches affecting Customer Personal Data.

16. Data Protection Impact Assessments

Where processing by Autm is relevant to a Data Protection Impact Assessment required by the Customer, Autm will provide reasonable information and assistance concerning its processing activities and safeguards, taking into account the nature of the processing and information available to Autm.

The Customer remains responsible for determining whether a DPIA is required and for completing that assessment as Controller.

Where required by Applicable Data Protection Law, Autm will also provide reasonable assistance with prior consultation with the relevant supervisory authority.

17. Records and Regulatory Cooperation

Autm will maintain records of processing activities where required by Applicable Data Protection Law.

Autm will cooperate with the Information Commissioner’s Office and other competent supervisory authorities as required by applicable law.

Autm will make available to the Customer information reasonably necessary to demonstrate compliance with the obligations imposed on Autm by Article 28 of the UK GDPR and this DPA.

18. Audits and Inspections

Autm will allow for and contribute to reasonable audits and inspections relating to its processing of Customer Personal Data as required by Applicable Data Protection Law.

Where possible, the parties will first seek to satisfy audit requirements through:

  • current security and compliance documentation;

  • responses to reasonable due-diligence questionnaires;

  • independent audit or assurance reports, where available; and

  • other relevant information reasonably sufficient to demonstrate compliance.

Where this information is insufficient and the Customer reasonably requires an additional audit, the Customer may conduct an audit itself or appoint an independent auditor.

Unless required urgently by a supervisory authority or following a material Personal Data Breach, audits must:

  • be requested with reasonable prior written notice;

  • take place during normal business hours;

  • be limited to information and systems relevant to the Customer’s Personal Data;

  • avoid unreasonable disruption to Autm’s business;

  • not compromise the security, confidentiality or data of another Autm customer;

  • be conducted by persons subject to appropriate confidentiality obligations; and

  • comply with Autm’s reasonable security and access requirements.

Each party will normally bear its own costs associated with routine compliance activity.

If a Customer requests an additional bespoke audit that is not required because of Autm’s material breach of this DPA or Applicable Data Protection Law, Autm may charge reasonable costs associated with facilitating that audit, provided those costs are disclosed in advance.

Nothing in this section limits the rights of a competent supervisory authority.

19. Return and Deletion of Customer Personal Data

Upon termination or expiry of the processing services, and at the Customer’s choice, Autm will:

  • return applicable Customer Personal Data to the Customer; or

  • securely delete Customer Personal Data,

unless applicable law requires continued storage.

The Customer should communicate its return or deletion instruction within the applicable termination or exit process.

Where the Customer requests return of Customer Personal Data, the return will be provided in accordance with the technical capabilities of the service and any applicable agreed exit arrangements.

Following completion of any requested return, Autm may delete remaining Customer Personal Data in accordance with this DPA and the Data Retention Policy.

Where the Customer instructs deletion, or where deletion applies following completion of the agreed exit process, relevant Customer Personal Data in active Autm systems will generally be scheduled for permanent deletion within 30 days.

Certain information may be retained where required by applicable law or where Autm independently has a lawful basis and acts as Controller in relation to that information.

Backups

Customer Personal Data contained within protected backup or disaster-recovery systems may not be capable of immediate selective deletion.

Where Customer Personal Data remains within backups following an instruction to delete:

  • it will be put beyond normal operational use;

  • it will remain subject to appropriate security and confidentiality safeguards;

  • it will not be restored to active processing except where necessary for legitimate disaster-recovery purposes; and

  • it will be permanently deleted or overwritten in accordance with Autm’s applicable backup lifecycle.

If backup data is restored before expiry of that lifecycle, applicable deletion instructions will be reapplied to the restored environment.

The parties acknowledge that this approach is intended to ensure secure and practicable deletion while maintaining necessary business-continuity safeguards.

20. Data Portability and Exit Assistance

Autm will provide reasonable assistance to enable the Customer to retrieve or export applicable Customer Data before deletion, subject to:

  • the functionality and technical capabilities of the service;

  • the nature and volume of the information;

  • security requirements;

  • third-party rights; and

  • any applicable contractual arrangements.

The Customer’s underlying data within connected source systems remains within those systems and is not dependent upon continued use of Autm.

Termination of Autm does not itself delete or terminate data held within Microsoft, Google, CRM, project-management or other connected third-party services.

Additional bespoke migration or exit assistance may be agreed separately and may be chargeable where it requires material technical or professional services beyond standard functionality.

21. Data Residency

Autm’s primary customer data infrastructure and data residency are hosted within Microsoft Azure in the United Kingdom.

This does not mean that every processing operation carried out by every authorised Sub-processor necessarily occurs exclusively within the United Kingdom.

Where a Sub-processor processes Customer Personal Data in another jurisdiction, the international-transfer provisions of this DPA apply.

22. Government and Law-Enforcement Requests

If Autm receives a legally binding request from a public authority for Customer Personal Data, Autm will, to the extent legally permitted:

  • notify the Customer;

  • review the request for legal validity;

  • seek to limit disclosure to information legally required; and

  • take reasonable steps to protect the confidentiality of Customer Personal Data.

Autm will not voluntarily provide Customer Personal Data to a public authority except where authorised by the Customer or permitted or required by applicable law.

23. Special Category and High-Risk Personal Data

Autm may technically be capable of processing information that includes special category or otherwise sensitive Personal Data where such information is contained within Customer Data.

The Customer is responsible for determining whether it is lawful and appropriate to process such information using Autm and for establishing any additional lawful basis, condition, safeguards or DPIA required by Applicable Data Protection Law.

Autm will process such information only in accordance with the Customer’s documented instructions and the Agreement.

The Customer must not use Autm to process Personal Data where such processing is prohibited by law or by an applicable written restriction agreed with Autm.

24. Automated Decision-Making

Autm provides AI-assisted operational intelligence, workflows and agent functionality.

The Customer is responsible for determining whether its particular configuration or use of Autm constitutes solely automated decision-making or profiling subject to additional requirements under Applicable Data Protection Law.

Where Autm processes Customer Personal Data on behalf of the Customer in connection with such functionality, Autm will process that information only in accordance with the Customer’s documented instructions and will provide reasonable assistance with relevant compliance obligations where required by this DPA and applicable law.

Autm does not determine on the Customer’s behalf whether a particular decision about an individual should be made solely by automated means.

25. Liability

The liability of each party arising from or in connection with this DPA is subject to the limitations and exclusions of liability contained in the Agreement, except to the extent that liability cannot lawfully be excluded or limited.

Nothing in this DPA limits either party’s direct statutory responsibilities or liabilities under Applicable Data Protection Law.

26. Duration

This DPA takes effect when Autm begins processing Customer Personal Data on behalf of the Customer and continues for as long as Autm processes such Personal Data.

Obligations that by their nature are intended to continue after termination, including confidentiality, security, return or deletion and applicable audit or regulatory obligations, will survive termination for as long as relevant.

27. Changes to this DPA

Autm may update this DPA where reasonably necessary to:

  • comply with changes in Applicable Data Protection Law;

  • reflect regulatory guidance;

  • reflect changes to the service or processing arrangements;

  • update Sub-processor or transfer arrangements; or

  • improve data-protection safeguards.

Autm will not materially reduce the protections provided to Customer Personal Data during a committed contractual term without appropriate notice or agreement, except where required by law.

Where a material change requires Customer agreement under Applicable Data Protection Law, Autm will obtain that agreement before the relevant change takes effect.

28. Governing Law

Unless otherwise specified in an applicable written agreement, this DPA is governed by the laws of England and Wales.

The courts of England and Wales will have jurisdiction in relation to disputes arising from this DPA, subject to the rights and jurisdiction of competent supervisory authorities under Applicable Data Protection Law.

Schedule 1 – Details of Processing

1. Subject Matter

Processing of Customer Personal Data as necessary to provide the Autm operational intelligence platform and the functionality selected, configured and authorised by the Customer.

This may include processing required to provide:

  • organisational memory and operational context;

  • AI-assisted analysis, reasoning, classification, summarisation and generation;

  • meeting and document intelligence;

  • workflow and task orchestration;

  • integrations with authorised third-party systems;

  • natural-language workflows;

  • agent-assisted or automated actions;

  • organisational knowledge and contextual relationships;

  • permissions, governance and audit capabilities; and

  • related support, security and platform functionality.

2. Duration

For the duration of the Customer’s use of the Autm service and any subsequent period required to return, export or delete Customer Personal Data in accordance with the Agreement, this DPA, the Customer’s documented instructions and applicable law.

3. Nature of Processing

Processing activities may include:

  • collection;

  • receipt;

  • access;

  • recording;

  • organisation;

  • structuring;

  • storage;

  • retrieval;

  • consultation;

  • analysis;

  • classification;

  • summarisation;

  • extraction;

  • generation;

  • contextualisation;

  • linking and relationship mapping;

  • transmission;

  • disclosure to authorised Sub-processors;

  • workflow orchestration;

  • modification where authorised;

  • use in authorised agent actions;

  • redaction;

  • tokenisation;

  • pseudonymisation;

  • restriction;

  • export;

  • return; and

  • deletion.

4. Purpose of Processing

To provide, secure, maintain and support the Autm service and perform the functionality selected and authorised by the Customer.

5. Categories of Personal Data

Depending on the Customer’s use of Autm, Customer Personal Data may include:

  • names;

  • business and personal email addresses;

  • telephone numbers;

  • job titles and roles;

  • employer or organisational information;

  • business contact information;

  • calendar and meeting information;

  • meeting transcripts and notes;

  • email content and metadata;

  • documents and file content;

  • tasks, actions and commitments;

  • CRM records;

  • customer, supplier and member information;

  • project and workflow information;

  • communications;

  • operational records;

  • organisational knowledge;

  • relationships between people, organisations, information and activities;

  • AI prompts, instructions and outputs;

  • information contained within authorised connected systems;

  • technical identifiers and metadata; and

  • other Personal Data that the Customer chooses or authorises to process through Autm.

Customer Data may also contain special category or other sensitive Personal Data where included by the Customer or contained within authorised connected systems.

6. Categories of Data Subjects

Depending on the Customer’s activities, Data Subjects may include:

  • employees;

  • workers and contractors;

  • directors and officers;

  • customers and prospective customers;

  • clients;

  • members;

  • suppliers and service providers;

  • business partners;

  • advisers;

  • investors;

  • event attendees;

  • contacts and correspondents; and

  • other individuals whose Personal Data is lawfully processed by the Customer.

7. Frequency of Processing

Processing may occur continuously or intermittently during the Customer’s use of the service, depending on the Customer’s configuration, connected systems, workflows and authorised activity.

8. Controller Rights and Obligations

The Customer retains the rights and obligations of Controller under Applicable Data Protection Law, including responsibility for:

  • determining the purposes of processing;

  • determining the lawful basis;

  • providing appropriate privacy information;

  • responding to Data Subject requests;

  • determining appropriate retention requirements;

  • determining whether DPIAs are required;

  • providing lawful documented instructions to Autm; and

  • supervising and assessing its processors.

Schedule 2 – Technical and Organisational Measures

Autm maintains technical and organisational measures designed to protect Customer Personal Data appropriate to the nature of the processing and associated risks.

These include, where applicable:

1. Infrastructure and Data Residency

  • Primary customer data infrastructure hosted within Microsoft Azure in the United Kingdom.

  • Controlled access to production infrastructure.

  • Cloud security and monitoring controls.

  • Secure cryptographic key and secret management, including Azure Key Vault where applicable.

2. Encryption

  • Encryption of information in transit using TLS.

  • Encryption of stored data at rest where applicable.

  • Secure handling of authentication and integration credentials.

  • Separation and protection of sensitive cryptographic material.

3. Identity and Access Management

  • Account management through ASP.NET Core Identity.

  • Email/password authentication with one-way password hashing.

  • Google OAuth identity authentication.

  • Microsoft Entra ID OAuth identity authentication.

  • Role- and permission-based access controls.

  • Two-factor authentication where enabled.

  • TOTP authenticator support where enabled.

  • WebAuthn/FIDO2 passkey support where enabled.

  • Server-tracked authenticated sessions.

  • Session expiry and revocation controls.

  • Access restrictions based on legitimate operational need.

4. OAuth and Connected Systems

  • Separation between identity-authentication OAuth and Connections OAuth.

  • Authentication using Google or Microsoft requests identity scopes only, such as openid, profile and email.

  • Broader permissions for email, calendar, files and other business systems require separate user authorisation.

  • Secure handling and storage of integration access and refresh tokens.

  • Access limited according to granted scopes, integration capabilities and workspace permissions.

5. Data Minimisation and Privacy Controls

  • Data-minimisation principles applied to processing.

  • Redaction, tokenisation or pseudonymisation of Personal Data where appropriate and technically feasible.

  • Separate protection of mappings associated with protected identifiers where applicable.

  • Limitation of AI processing to information reasonably necessary for the relevant authorised task where technically feasible.

6. AI Processing Controls

  • AI providers used under appropriate contractual arrangements where acting as Sub-processors.

  • Customer Data not permitted to be used for training public AI models unless explicitly agreed in writing.

  • Permissions and governance applied to AI-assisted functionality.

  • Auditability of relevant AI and agent activity where supported by the service.

  • Human approval or confirmation controls for relevant actions where configured or required.

7. Logging and Monitoring

  • Security and authentication logging.

  • Application and operational monitoring.

  • Audit logging of relevant platform activity.

  • Incident detection and investigation processes.

  • Restricted access to logs.

8. Secure Development and Operations

  • Secure software-development practices.

  • Access controls around development and production environments.

  • Review and management of vulnerabilities and security issues.

  • Controlled deployment and change-management practices.

  • Appropriate separation of responsibilities and access.

9. Business Continuity and Recovery

  • Cloud-based infrastructure designed to support service resilience.

  • Backup and recovery arrangements appropriate to the service.

  • Processes designed to restore access following relevant operational incidents.

  • Customer source systems remain independent of Autm.

10. Personnel and Confidentiality

  • Confidentiality obligations for personnel with access to Customer Personal Data.

  • Access granted according to role and operational requirement.

  • Appropriate security awareness and internal controls.

Autm may update these measures as the service and security environment evolve, provided that the overall level of protection is not materially reduced.

Schedule 3 – Sub-processors

Autm currently uses the following principal Sub-processors in connection with the service:

Microsoft Azure

Purpose: Cloud infrastructure, hosting, storage, monitoring, secure key and credential management and associated platform services.

Primary Autm customer data residency: United Kingdom.

Data processed: Customer Data and associated platform information as required to host and provide the service.

OpenAI

Purpose: AI model inference and associated AI-processing functionality.

Data processed: Information required for the relevant authorised AI task, which may include Customer Personal Data depending on the Customer’s use and configuration of Autm.

Autm applies data-minimisation and privacy controls and does not permit Customer Data to be used to train public AI models unless explicitly agreed in writing.

Processing location: May include processing outside the United Kingdom or EEA, subject to applicable contractual and international-transfer safeguards.

Stripe

Purpose: Payment processing and subscription billing.

Data processed: Billing, transaction and related account information required to process payments.

Autm does not store full payment card numbers or sensitive payment credentials.

Additional Sub-processors may be used where necessary to provide particular features or supporting services. Autm will maintain information about applicable Sub-processors and provide notification of material changes in accordance with this DPA.

Schedule 4 – Return, Retention and Deletion

Unless otherwise agreed in writing:

During the Agreement

Customer Personal Data is retained for as long as necessary to provide the service, according to the Customer’s configuration, documented instructions and Autm’s Data Retention Policy.

On Termination or Workspace Closure

The Customer may instruct Autm to:

  1. return applicable Customer Personal Data; or

  2. delete Customer Personal Data.

Where return is requested, the Customer should make the request before the applicable deletion process is completed.

Following completion of an agreed return, or where deletion is instructed, relevant Customer Personal Data in active Autm systems will generally be permanently deleted within 30 days, subject to applicable legal requirements.

Connected Source Systems

Data held in the Customer’s underlying Microsoft, Google, CRM, project-management or other connected systems is not deleted merely because the Customer stops using Autm.

Those systems remain independent and are governed by the Customer’s arrangements with their respective providers.

Backups

Deleted Customer Personal Data may remain temporarily within protected backups until the applicable backup retention cycle expires.

During that period, the information will remain protected, will be put beyond normal operational use and will not be processed except where necessary for legitimate recovery purposes.

The applicable maximum backup retention period will be governed by Autm’s documented backup lifecycle.

Legally Required Retention

Autm may retain information where required by applicable law.

Where Autm independently retains Personal Data as Controller for a lawful purpose, that processing falls outside the Customer’s processor instructions and will be governed by Applicable Data Protection Law and Autm’s Privacy Policy.



Autm

Privacy Policy

Effective date: 27th April 2025