Aeion OS Policies & Legal Documents.
Every legal and compliance document procurement teams need, in one place. Privacy policy, terms of service, master service agreement, data-processing agreements, business-associate agreements for HIPAA tenants, sub-processor list with locations and BAA status, acceptable-use policy, and security disclosure terms. All versioned, dated, downloadable. No "request via sales" gating on policy documents.
Core Policies
Privacy Policy
How Aeion collects, processes, retains, and discloses personal data. Customer-data sovereignty stance, lawful basis tracking, retention defaults, right-to-erasure cascade, data residency options. Aligned with GDPR, CCPA / CPRA, PIPEDA, LGPD. Available: privacy@aeionos.com for full PDF or request through your sales contact.
Terms of Service
Plain-language summary plus full legal text. Governs use of the Aeion platform, payment terms, intellectual property, limitation of liability, dispute resolution. Available: in the admin UI under Account → Legal, or legal@aeionos.com for current version.
Master Service Agreement (MSA)
For paid plans. Defines contract term, payment terms, SLAs (where applicable), termination rights, data-export commitment on cancellation. Replaces ToS for tenants on the All-Access plan or a custom-negotiated contract. Available: auto-included with paid plan signup; full text via sales contact.
Acceptable Use Policy (AUP)
What you can and can't do with the platform. Covers spam, abuse, illegal content, attempting to compromise the platform. Available: in the admin UI under Account → Legal.
Data Protection Agreements
Data Processing Agreement (DPA)
For tenants processing data subject to GDPR Article 28 (controller-processor relationships). Pre-drafted on standard SCCs. Sub-processor list incorporated by reference. Available: self-serve in the admin UI under Account → Legal → Agreements, or via legal@aeionos.com.
Business Associate Agreement (BAA)
For any tenant processing protected health information under HIPAA — most commonly health module customers. No plan gating. Pre-drafted on the standard HHS template. Sub-processor BAA chain in place for AWS Bedrock, Azure OpenAI BAA, AWS Transcribe Medical. Available: download the template at /legal/baa-template, complete it, and email the executed PDF to legal@aeionos.com; Aeion's counter-sign target is 24 business hours.
Standard Contractual Clauses (SCCs)
Incorporated by reference into the DPA for international data transfers under GDPR. Aeion uses the EU Commission's 2021 SCCs.
Country-Specific Addenda
Available on request for PIPEDA (Canada), LGPD (Brazil), POPIA (South Africa), Australian Privacy Act, and other jurisdictions.
Sub-Processor List
Every sub-processor Aeion uses, with location, purpose, and BAA / DPA status. The full list — with announcement and effective dates for each pending or recent change — is at /sub-processors. New sub-processors get a 30-day advance notice via the customer's configured Aegis notification channels (email, Slack, webhook) plus an admin-UI banner. The 30-day advance-notice rule is enforced at the platform layer — operators cannot back-date an "added" or "modified" sub-processor change to take effect sooner.
Security Disclosure & Safe Harbor
Security Disclosure Program
Coordinated disclosure process, scope, response SLAs, monetary recognition for confirmed vulnerabilities. Non-prosecution commitment for good-faith researchers. Full program at /security.
Safe Harbor Commitment
Researchers following the rules-of-engagement in /security get non-prosecution commitment in writing covering DMCA, CFAA (US), and equivalent statutes globally.
Penetration Test Reports
Annual third-party penetration test results available under NDA. Executive summary available to any tenant; full report available to All-Access plan customers or by separate NDA arrangement. Request via security@aeionos.com.
Coordinated Disclosure Window
90 days from initial report. Researcher gets credit (with permission) at public disclosure. We communicate timeline within 7 days of report.
Document Versioning & Change History
Every Aeion policy is versioned and dated. Material changes trigger customer notification.
Frequently Asked Questions
Two places: in the admin UI under Account → Legal for the version currently in effect for your tenant; or by emailing privacy@aeionos.com for the latest version with change history. We don't gate the privacy policy behind a sales call.
Self-serve in the admin UI under Account → Legal → Agreements. Click "Generate DPA"; you fill in your contact details and we counter-sign within 24 hours. Or email legal@aeionos.com for a manually negotiated DPA if you have specific redlines.
Available to any tenant processing PHI under HIPAA — no plan gating required. Email legal@aeionos.com; we counter-sign within 24 hours on the standard HHS template. If your legal team needs redlines, we accommodate; redlines extend turnaround to typically 5-10 business days.
On this page (above), and continuously updated in the admin UI. Subscribe to change notifications by emailing legal@aeionos.com.
No — sandbox use is governed by the ToS that you accept implicitly at signup. No additional agreement required for non-production evaluation use.
ToS governs all platform users (trial, sandbox, paid) at a baseline. MSA replaces ToS for All-Access or custom-negotiated customers with custom terms (SLAs, custom contract length, custom indemnification, etc.). À-la-carte module customers use the standard ToS.
Yes on All-Access or custom-negotiated contracts. Common redlines: liability caps, audit rights, SLA credits, specific data-residency clauses, custom indemnification, IP assignment for jointly developed work. Email legal@aeionos.com with your redlines and we'll respond within 5 business days.
Aeion's DPA covers GDPR (EU), CCPA / CPRA (California), and most major regimes. Country-specific addenda available on request for PIPEDA (Canada), LGPD (Brazil), POPIA (South Africa), Australia Privacy Act, Singapore PDPA, Japan APPI. Email legal@aeionos.com with your jurisdiction.
Email privacy@aeionos.com — our DPO triages. We acknowledge within 24 hours. For data subject requests (DSR) — access, deletion, portability — there's also a self-serve flow in the admin UI under Account → Privacy.
Per ToS / MSA: self-serve export available during the cancellation grace period (90 days). After grace period, tenant data is securely wiped from Aeion's systems. Your Aegis backups in your own S3 bucket remain yours forever. See /trust for the full data-sovereignty stance.
Your data is yours. Your customizations (custom collections, workflows, AI agents) are yours. Aeion owns the platform; you own everything you build on top of it. ToS Section 6 (Intellectual Property) covers the full split.
Standard ToS includes Aeion's IP indemnification for platform-originated IP claims. Custom indemnification (e.g. broad data-breach indemnification beyond GDPR-required notifications) is negotiable on All-Access or custom-negotiated contracts.
ToS and standard DPA: Delaware law, US jurisdiction. Custom-negotiated MSA: negotiable. For tenants with regulatory constraints requiring local jurisdiction (EU public sector, etc.), we negotiate accordingly.