GDPR Compliance

Last Updated: January 2025

Our Commitment to GDPR

At AIM, we are committed to protecting the privacy and personal data of all our users, including those in the European Union (EU) and European Economic Area (EEA). We comply with the General Data Protection Regulation (GDPR) and have implemented appropriate measures to ensure your rights are protected.

Your Rights Under GDPR

If you are a resident of the EU or EEA, you have the following rights regarding your personal data:

Right to Access

You have the right to request a copy of the personal data we hold about you. We will provide this information in a structured, commonly used, and machine-readable format.

Right to Rectification

You have the right to request correction of any inaccurate or incomplete personal data we hold about you. You can update most of your information directly in your account settings.

Right to Erasure (Right to be Forgotten)

You have the right to request deletion of your personal data under certain circumstances. This includes when the data is no longer necessary for the purpose it was collected or when you withdraw consent.

Right to Restrict Processing

You have the right to request that we restrict the processing of your personal data in certain situations, such as when you contest the accuracy of the data or object to processing.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used format and to transmit that data to another controller without hindrance.

Right to Object

You have the right to object to the processing of your personal data for direct marketing purposes or when processing is based on legitimate interests.

Right to Withdraw Consent

Where we rely on your consent to process personal data, you have the right to withdraw that consent at any time. This will not affect the lawfulness of processing based on consent before its withdrawal.

Right to Lodge a Complaint

You have the right to lodge a complaint with your local data protection authority if you believe we have not complied with applicable data protection laws.

How We Process Your Data

Legal Basis for Processing

We process your personal data only when we have a legal basis to do so:

  • Consent: You have given clear consent for us to process your data for a specific purpose
  • Contract: Processing is necessary to fulfill our contract with you (providing our services)
  • Legal obligation: Processing is necessary to comply with legal requirements
  • Legitimate interests: Processing is necessary for our legitimate interests, provided it does not override your rights

Data We Collect

We collect and process the following types of personal data:

  • Contact information (name, email address)
  • Account credentials
  • Payment information (processed by third-party payment processors)
  • Task and productivity data
  • Usage data and analytics
  • Device and technical information

Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:

  • Active accounts: Data is retained for the duration of your account
  • Deleted accounts: Personal data is deleted or anonymized within 30 days of account deletion
  • Legal requirements: Some data may be retained longer to comply with legal obligations (e.g., tax records)
  • Backup systems: Data in backup systems will be deleted according to our backup retention policy

International Data Transfers

Your personal data may be transferred to and processed in countries outside the EU/EEA, including the United States. When we transfer data internationally, we ensure appropriate safeguards are in place:

  • Standard Contractual Clauses approved by the European Commission
  • Adequacy decisions recognizing equivalent data protection standards
  • Privacy Shield certification (where applicable)
  • Binding corporate rules and codes of conduct

Data Security

We implement appropriate technical and organizational measures to protect your personal data:

  • Encryption of data in transit (TLS/SSL) and at rest
  • Regular security assessments and penetration testing
  • Access controls and authentication mechanisms
  • Employee training on data protection
  • Incident response procedures

For more information, see our Security page.

Third-Party Processors

We use carefully selected third-party service providers to help us provide our services. All processors are required to:

  • Process data only on our instructions
  • Implement appropriate security measures
  • Comply with GDPR requirements
  • Enter into data processing agreements with us

Our main processors include: Firebase (Google), Stripe (payment processing), and analytics providers.

Data Protection Officer

While we are not currently required to appoint a Data Protection Officer (DPO), we take data protection seriously and have designated a privacy team to handle GDPR-related matters. You can contact our privacy team at:

Email: [email protected]
Subject: GDPR Inquiry

How to Exercise Your Rights

To exercise any of your GDPR rights, please contact us at [email protected] with the subject line "GDPR Request."

We will respond to your request within 30 days. In some cases, we may need to verify your identity before fulfilling your request. We will not charge a fee for processing requests unless they are manifestly unfounded or excessive.

Updates to This Policy

We may update this GDPR compliance information from time to time. We will notify you of material changes by updating the "Last Updated" date and, where required, by providing additional notice.

Contact Us

If you have questions about our GDPR compliance or wish to exercise your rights, please contact us:

Email: [email protected]

For more information about your privacy rights, please also review our Privacy Policy.