Aetherium Sales Assistant - AI-Powered CRM & Lead Management Platform
Aetherium Sales Assistant is an intelligent sales tool that helps B2B teams discover, research, and manage prospects — combining a traditional CRM pipeline with AI-driven lead scoring, company research, and automated outreach generation.
How It Works
Set Up Your Organisation — Configure your business profile, ideal customer profile (ICP), target industries, and sales tone so the AI understands who you're selling to.
Discover Leads — Use AI-powered search to find new prospects by sector, location, company size, and keywords — or find companies similar to your best existing clients.
Research Automatically — AI-assisted research uses available business information to prepare company summaries, identify possible buying signals, suggest relevant decision-maker roles and assess relevance against your organisation’s configured criteria.
Manage Your Pipeline — Move leads through customisable stages (e.g. New → Researching → Proposal → Won). Log calls, notes, and follow-up dates as you go.
Generate Outreach — Produce personalised email drafts and LinkedIn messages for specific contacts at each company, ready to send or refine.
Track Performance — Monitor daily tasks, overdue follow-ups, and weekly reports covering new leads, outreach activity, and top-performing sectors.
Data We Store
Organisation Profile: Business description, ideal customer profile, target industries, and sales configuration (tone, objectives, disqualification criteria).
Leads: Company name, website, location, sector, size, AI-generated summary, buying signals, relevance score, pipeline stage, and follow-up dates.
Contacts: Individual people at each company — name, email, role, LinkedIn URL, and primary contact designation.
Activities: A record of activities and changes logged within the Service, including notes, calls, status changes and timestamps.
Outreach Drafts: AI-generated email and LinkedIn messages saved against each lead.
Projects: Specific sales opportunities linked to a lead, including estimated value and status.
Saved Searches: Stored discovery parameters for repeating lead-generation queries.
Team & Access: User accounts (managed via Clerk), organisation memberships, and role assignments (Member / Admin).
Open Aetherium Sales Assistant in a new window
Aetherium Sales Assistant – Supplementary Privacy Notice & Terms of Use
Part A - Privacy Policy
Effective date: 16 July 2026
Last updated: 16 July 2026
Document version: 1.0
This Supplementary Privacy Notice applies specifically to Aetherium Sales Assistant (“the Service”). It supplements the general Aetherium Tools Privacy Policy, which should be read alongside this notice.
If this notice conflicts with the general Privacy Policy in relation to processing performed specifically through the Service, this supplementary notice will apply.
Customer organisations are responsible for ensuring that their use of the Service complies with the laws and regulatory requirements applicable to them. This does not limit Aetherium’s own obligations under applicable law.
1. About the Service
Aetherium Sales Assistant is a business-to-business sales and customer relationship management application. It helps organisations discover and research companies, manage leads and sales opportunities, record activities, and prepare AI-generated research and outreach drafts.
The Service is intended for business use and is not intended for processing information about children or private household activities.
2. Our data-protection roles
The organisation using the Service normally decides why and how information about its prospects, contacts, clients and sales activities is processed. That organisation is therefore normally the data controller for this information.
Aetherium processes this customer-controlled information on behalf of the organisation and normally acts as its data processor.
Aetherium acts as a separate data controller for information required to operate and protect the Service, including:
- User account and organisation membership information.
- Authentication and access-control information.
- Service administration and support communications.
- Security, audit and diagnostic information.
- Subscription and billing administration, where applicable.
- Essential communications concerning the Service.
Each customer organisation is responsible for informing its users, prospects and contacts about its own processing and for identifying an appropriate lawful basis.
3. Information processed through the Service
Depending on how a customer uses the Service, the following information may be processed.
Organisation information
- Organisation name and business description.
- Products, services and value proposition.
- Ideal customer profile and target markets.
- Sales objectives, tone and strategy.
- Qualification and disqualification criteria.
- Custom pipeline stages and other service settings.
Company and lead information
- Company name, website and business location.
- Industry, size and other company characteristics.
- Lead source, status and pipeline stage.
- Follow-up dates and assigned users.
- AI-generated summaries, relevance scores and buying signals.
- Research notes and publicly available business information.
Business contact information
- Name and business position.
- Work email address and telephone number.
- LinkedIn or other professional profile address.
- Employer or associated company.
- Primary-contact designation and relevant sales notes.
Names, work contact details and professional profiles may constitute personal data even where they are used solely in a business context.
Sales and activity information
- Calls, meetings, emails and other activities.
- Notes, timestamps and follow-up actions.
- Opportunities, projects, estimated values and outcomes.
- Pipeline and relationship-status changes.
- AI-generated email and LinkedIn message drafts.
- Saved searches and discovery criteria.
Account and technical information
- User name and email address.
- Organisation membership and assigned role.
- Authentication identifiers.
- Login, security and audit records.
- Technical information required to maintain and secure the Service.
Users should not enter special-category information, private personal information or other information that is unnecessary for legitimate business sales activity.
4. Where information comes from
Information processed through the Service may be:
- Entered directly by customer users.
- Imported or copied from the customer’s existing business records.
- Obtained from company websites and other publicly accessible business sources.
- Produced or inferred through AI-assisted research.
- Generated through users’ activity within the Service.
The fact that information is publicly accessible does not remove the customer’s obligation to process it lawfully, fairly and transparently.
5. How information is used
Customer-controlled information is processed to provide the functions requested by the customer, including:
- Discovering and researching prospective companies.
- Assessing companies against the customer’s configured sales criteria.
- Managing leads, contacts, clients and opportunities.
- Recording interactions and follow-up actions.
- Preparing sales research and outreach drafts.
- Reporting on pipeline and sales activity.
- Maintaining organisation-specific records and settings.
- Providing support, security and service administration.
Aetherium will not use customer-controlled information for unrelated purposes except where required by law or expressly agreed with the customer.
6. Artificial intelligence
Some Service features use artificial intelligence to:
- Find or suggest potentially relevant companies.
- Summarise publicly available company information.
- Identify possible buying signals.
- Assess relevance against organisation-defined criteria.
- Suggest appropriate business roles to contact.
- Prepare email or LinkedIn outreach drafts.
- Assist with sales planning and reporting.
Information submitted to an AI feature may be sent to the AI service provider that supports that feature. This may include company information, professional contact information, organisation settings and relevant sales context.
AI-generated content may be incomplete, inaccurate or outdated. It does not represent a verified fact or professional recommendation. Users are responsible for reviewing AI-generated research, scores and outreach before relying on or sending it.
Users must not submit sensitive, confidential or unnecessary personal information to an AI feature.
AI service providers
The Service currently accesses OpenAI models through Replit AI Integrations. Replit provides and manages the connection to the selected OpenAI models; Aetherium does not currently maintain a separate OpenAI API account or API key for this integration.
When a user activates an AI feature, the information required to complete the request is transmitted through Replit’s managed integration and may then be processed by OpenAI to generate the requested result. This may include organisation settings, company information, professional contact information and relevant sales context.
Aetherium does not intentionally submit special-category personal data to the AI service, and users must not include sensitive, confidential or unnecessary personal information in AI requests.
Replit and its relevant AI providers process this information under their applicable contractual and data-protection arrangements. Further information is provided in our Subprocessor Information below.
7. Customer responsibilities
Each customer organisation is responsible for its use of the Service and must:
- Have a lawful basis for collecting, researching, recording and using personal data.
- Provide privacy information where required, including where information was obtained indirectly.
- Comply with applicable data-protection, privacy and direct-marketing laws.
- Ensure that its users enter only relevant and appropriate information.
- Take reasonable steps to keep information accurate and current.
- Respect objections, unsubscribe requests and do-not-contact instructions.
- Restrict access to authorised users and remove access when it is no longer required.
- Review AI-generated content before using or sending it.
- Respond appropriately to requests from individuals concerning their information.
- Delete information when it is no longer required.
Customers must not use the Service:
- To send unlawful or indiscriminate marketing.
- To store special-category or highly sensitive personal data.
- To knowingly process children’s information.
- For unlawful surveillance, harassment or discriminatory profiling.
- To collect information through unlawful scraping or other prohibited methods.
- In a manner that infringes another person’s privacy or legal rights.
Aetherium may restrict or suspend access where it reasonably believes the Service is being used unlawfully or in material breach of these requirements.
8. Lawful basis and direct marketing
Customer organisations are responsible for selecting and documenting the lawful basis applicable to their use of prospect and contact information.
A lawful basis for storing or researching a business contact does not automatically authorise every form of marketing communication. Customers must separately consider the rules applying to email, telephone, social-media and other direct marketing.
The Service helps users prepare and organise sales activity but does not determine whether a particular communication is lawful.
9. Service providers and international transfers
Aetherium uses selected service providers to operate the Service. These may provide:
- Hosting and database infrastructure.
- User authentication.
- Artificial-intelligence functionality.
- Security, monitoring or technical support.
- Service communications.
Some providers may process information outside the United Kingdom. Where required, Aetherium uses an appropriate transfer mechanism and associated safeguards.
Current service providers
| Provider | Purpose | Information potentially processed |
|---|---|---|
| Replit, Inc. | Application hosting, infrastructure and managed AI integration | Customer records, account information, technical information and AI requests |
| OpenAI, L.L.C. and/or applicable OpenAI entity | AI model processing accessed through Replit | Information included in AI prompts and generated responses |
| Clerk, Inc. | Authentication and user-account management | User name, email address, authentication identifiers, organisation membership and role |
Provider information
Further information about our current providers and their data-processing arrangements is available from:
- Replit: Data Processing Agreement and Subprocessor List.
- OpenAI: Business Data Privacy. OpenAI is used as a downstream AI provider through Replit AI Integrations.
- Clerk: Privacy Policy, Data Processing Addendum and Subprocessor List.
These providers may update their documents and subprocessors from time to time. Aetherium will provide notice of material changes affecting the Service in accordance with Schedule 1.
Aetherium will appoint subprocessors in accordance with its Data Processing Terms.
10. Security
Aetherium uses appropriate technical and organisational measures intended to protect information against unauthorised access, alteration, disclosure, loss or destruction.
These measures include organisation-based access controls, authenticated user access and other security measures appropriate to the nature of the Service.
No online system can guarantee absolute security. Customers must protect their login credentials, assign access appropriately and notify Aetherium promptly if they suspect unauthorised access.
11. Retention and deletion
Customer information is normally retained for as long as the customer maintains an active account or requires the information for its permitted use of the Service.
Customers can manage and delete individual records using the available Service controls. Organisation administrators may also request export or deletion of their organisation’s information.
When an organisation is scheduled for deletion:
- Access may be restricted during the 30-day pending-deletion period.
- The organisation and its associated records will be deleted from the active Service after 30 days, unless deletion is cancelled where the Service permits this.
- Following deletion from the active Service, residual copies may remain in protected infrastructure backups for up to a further 30 days before being overwritten or deleted. Backup retention may be shorter depending on the applicable deployment configuration.
- Backup copies are maintained for recovery and continuity purposes and are not routinely accessed or restored except where operationally necessary.
- Limited records may be retained for longer where required for security, dispute resolution or legal compliance.
Account, security and audit information for which Aetherium is the controller will be retained only for as long as reasonably required for the relevant operational, security or legal purpose.
12. Individual rights
Individuals may have rights to access, correct, delete or restrict the use of their personal data, and to object to certain processing.
Where information was entered or generated by a customer organisation, the individual should normally contact that organisation first because it is the controller responsible for deciding how the information is used.
Requests may also be sent to Aetherium. Where Aetherium acts as processor, we will refer the request to the relevant customer organisation and provide reasonable assistance in accordance with our Data Processing Terms.
Where Aetherium is the controller—for example, for user-account or security information—we will handle the request under the general Aetherium Tools Privacy Policy.
13. Data incidents
Customers should promptly report suspected unauthorised access, disclosure or loss affecting information held within the Service.
Where Aetherium becomes aware of a personal-data breach affecting customer-controlled information, it will notify the affected customer organisation without undue delay and provide available information reasonably required to support the customer’s response.
14. Data Processing Terms
Aetherium’s processing of Customer-controlled personal data is governed by Schedule 1 — Data Processing Terms below. Schedule 1 forms part of the agreement between Aetherium and each Customer organisation using the Service.
Schedule 1 describes the parties’ responsibilities, security obligations, use of subprocessors, assistance with individual rights and arrangements for returning or deleting information.
15. Changes to this notice
We may update this Supplementary Privacy Notice when the Service, its providers or applicable requirements change.
Material changes will be published on this page and identified by an updated revision date. Where appropriate, registered customers may also be notified through the Service or by email.
16. Contact
Questions about this notice or Aetherium’s processing can be sent to:
Aetherium Engineering Ltd
Email: admin@aetherium-tools.co.uk
Address: Aetherium Engineering, 1.30 Repton House, Bretby Business Park, Ashby Road, Burton-on-Trent, DE15 0YZ
Individuals may also raise concerns with the UK Information Commissioner’s Office. Further information is available at ico.org.uk.
Part B - Terms of Use
1. About these Terms
These application-specific Terms govern access to and use of Aetherium Sales Assistant (“the Service”).
They supplement the general Aetherium Tools Terms of Use. The general Terms, these application-specific Terms and Schedule 1 together form the agreement between Aetherium Engineering Ltd (“Aetherium”) and the organisation using the Service (“the Customer”).
If these application-specific Terms conflict with the general Terms in relation to the Service, these application-specific Terms will apply.
The Supplementary Privacy Notice in Part A explains how information is processed. Schedule 1 contains the contractual Data Processing Terms applying where Aetherium processes personal data on behalf of the Customer.
2. Business use
The Service is provided for business-to-business sales, prospect research, customer relationship management, sales planning and related professional activities.
The Service is not intended for:
- Personal or household use.
- Use by children.
- Processing special-category or highly sensitive personal data.
- Regulated decision-making concerning employment, credit, insurance, healthcare, housing or access to essential services.
A person using the Service on behalf of an organisation confirms that they are authorised to act for that organisation and comply with these Terms.
3. Organisation registration and authority
A user who creates or administers an organisation within the Service confirms that:
- The organisation details supplied are accurate.
- They are authorised to establish and administer the organisation’s account.
- They are authorised to accept these Terms on the organisation’s behalf.
- They will grant access only to users authorised by the organisation.
- They will keep organisation membership and user roles reasonably current.
The Customer is responsible for activity performed through its organisation account, except to the extent that the activity results from a failure of Aetherium’s security obligations.
4. User accounts and security
Users must:
- Provide accurate account information.
- Keep authentication credentials and access methods secure.
- Not share an individual user account with another person.
- Use appropriate security controls for devices accessing the Service.
- Notify Aetherium promptly if they suspect unauthorised access or compromise.
- Comply with the access permissions assigned by their organisation.
Organisation administrators are responsible for managing membership and roles, including removing access when a user leaves the organisation or no longer requires the Service.
Aetherium may require password resets, additional verification or other reasonable security measures where necessary to protect the Service.
5. Permitted use
Subject to these Terms, the Customer may use the Service to:
- Discover and research potentially relevant businesses.
- Store and organise company, lead and professional contact information.
- Manage sales pipelines, opportunities, activities and follow-ups.
- Prepare company research and sales-planning material.
- Generate draft emails, LinkedIn messages and other outreach content.
- Produce reports relating to the Customer’s sales activity.
- Invite authorised team members to collaborate within the Customer’s organisation.
The Customer must use the Service only for lawful professional purposes and in accordance with applicable data-protection, privacy and direct-marketing requirements.
6. Customer information
As between Aetherium and the Customer, the Customer retains its rights in information entered, imported or stored by its users.
The Customer grants Aetherium permission to host, copy, transmit, analyse and otherwise process that information only as reasonably required to:
- Provide the Service and requested functionality.
- Maintain, secure and support the Service.
- Comply with documented Customer instructions.
- Meet legal obligations applying to Aetherium.
The Customer is responsible for:
- The accuracy, relevance and legality of information it enters or imports.
- Having an appropriate lawful basis for processing personal data.
- Providing any privacy information required to prospects and contacts.
- Keeping information reasonably current.
- Respecting objections, opt-outs and do-not-contact instructions.
- Deleting information when it is no longer required.
- Responding to individuals who exercise their data-protection rights.
Aetherium’s processing of Customer-controlled personal data is further governed by Schedule 1.
7. Artificial-intelligence features
The Service includes features that use artificial intelligence. These features may produce research, summaries, relevance scores, suggested contacts, buying signals, sales recommendations and outreach drafts.
The Customer acknowledges that AI-generated content:
- May be incomplete, inaccurate, outdated or misleading.
- May not accurately describe a company or individual.
- May not reflect information published after the relevant model or source was accessed.
- Is not legal, financial or other professional advice.
- Does not determine whether contacting a particular person is lawful or appropriate.
Users must review AI-generated content before relying on, saving, publishing or sending it. The Customer remains responsible for decisions and communications made using AI-generated content.
Users must not intentionally submit passwords, payment information, special-category personal data, confidential client material or other unnecessary sensitive information to an AI feature.
Aetherium may change the models or providers used by the Service where reasonably necessary, subject to the Supplementary Privacy Notice and Schedule 1.
8. Prohibited use
The Customer and its users must not use the Service:
- For unlawful, fraudulent, deceptive or abusive activity.
- To send spam or unlawful direct marketing.
- To harass, threaten or unlawfully monitor another person.
- To knowingly store or process children’s information.
- To store special-category or highly sensitive personal data.
- To make solely automated decisions producing legal or similarly significant effects on individuals.
- To create discriminatory profiles or unlawfully discriminate against individuals.
- To collect information through unlawful scraping or unauthorised access.
- To impersonate another person or organisation.
- To introduce malware or other harmful code.
- To bypass security, access, usage or AI-consumption limits.
- To access another organisation’s information without authorisation.
- To interfere with the availability or operation of the Service.
- To reverse engineer or copy the Service except where applicable law expressly permits it.
- To use generated content in a manner that infringes intellectual-property, privacy or other legal rights.
9. Confidentiality
Each party must take reasonable care to protect confidential information received from the other and must use it only for purposes connected with the Service.
This obligation does not apply to information that:
- Is already lawfully public.
- Was lawfully known without a confidentiality restriction.
- Is independently developed without using the other party’s confidential information.
- Is lawfully received from another source.
- Must be disclosed under law or a binding order.
Where disclosure is legally required, the receiving party should give reasonable advance notice where legally permitted.
10. Intellectual property
Aetherium and its licensors retain all rights in the Service, including its software, interface, design, documentation, branding and underlying technology.
The Customer does not acquire ownership of the Service by using it. The Customer may not reproduce, sell, sublicense or commercially exploit the Service except as expressly authorised by Aetherium.
The Customer retains its rights in information it provides to the Service.
Subject to applicable law and third-party rights, the Customer may use outputs generated specifically for it through the Service. Aetherium does not guarantee that AI-generated outputs are unique or that similar outputs will not be generated for other users.
11. Feedback
If a user provides suggestions or feedback about the Service, Aetherium may use that feedback to maintain and improve its products and services.
Aetherium will not identify the Customer publicly as the source of feedback without permission.
12. Service changes, availability and support
Aetherium may maintain, update or change the Service to improve functionality, security, compliance or performance.
The Service may occasionally be unavailable because of maintenance, provider outages, security incidents or circumstances outside Aetherium’s reasonable control.
Unless a separate written service-level agreement applies:
- Continuous or uninterrupted availability is not guaranteed.
- Particular AI models or third-party integrations are not guaranteed to remain available.
- Features may be changed, replaced or withdrawn where reasonably necessary.
- Support is provided on a reasonable-efforts basis through the published contact route.
Aetherium will try to provide reasonable notice of material changes where practical.
13. Usage limits
The Service may apply limits to:
- AI requests and generated content.
- User or organisation numbers.
- Storage or record volumes.
- Automated activity.
- Other resource-intensive functionality.
Applicable limits may depend on the Customer’s plan or current Service configuration. Users must not attempt to evade or circumvent these limits.
Aetherium may temporarily restrict unusually high usage where reasonably necessary to protect security, availability or other customers.
14. Charges
Where the Service is offered on a paid basis, applicable prices, billing periods and usage allowances will be presented before the Customer commits to payment or will be set out in a separate order or written agreement.
Unless otherwise stated:
- Charges exclude applicable taxes.
- The Customer is responsible for authorised charges incurred through its organisation.
- Aetherium may change future charges by giving reasonable advance notice.
- A change will not retrospectively alter charges already due.
If the Service is provided free of charge or for evaluation, Aetherium may introduce charges in the future but will provide notice before payment is required.
15. Suspension
Aetherium may suspend or restrict access where reasonably necessary to:
- Protect the security or integrity of the Service.
- Investigate suspected unauthorised access.
- Prevent harm to another customer, individual or service provider.
- Address material breach of these Terms.
- Comply with a legal obligation or binding request.
- Address unpaid charges, where applicable.
Where appropriate and legally permitted, Aetherium will notify the Customer and provide a reasonable opportunity to remedy the issue.
16. Ending use of the Service
The Customer may stop using the Service and request deletion of its organisation in accordance with the available account controls.
Aetherium may terminate access where:
- The Customer materially or repeatedly breaches these Terms.
- Use presents a material security or legal risk.
- Required fees remain unpaid after reasonable notice.
- Aetherium discontinues the Service.
- Aetherium is legally required to do so.
Where practical, Aetherium will provide reasonable notice before terminating the Service, except where immediate action is required for security, legal or abuse-prevention reasons.
Deletion of organisation information will follow the retention and deletion process described in Part A and Schedule 1.
17. Data export
Organisation administrators may request an export of their organisation’s information before deletion or termination.
Aetherium will provide exports in an available commonly used format where reasonably practicable. The Customer is responsible for securely storing any exported information and for its subsequent use.
Aetherium may be unable to provide information that has already been permanently deleted or overwritten in accordance with the published retention process.
18. Warranties and reliance
Aetherium will provide the Service with reasonable care and skill.
However, unless expressly agreed otherwise, Aetherium does not guarantee:
- That the Service will always be uninterrupted or error-free.
- That company or contact information is complete or current.
- That AI-generated content is accurate, unique or suitable for a particular purpose.
- That a suggested company will become a customer.
- That outreach will receive a response or produce a commercial result.
- That use of the Service alone ensures compliance with law.
Nothing in these Terms excludes obligations or warranties that cannot lawfully be excluded.
19. Responsibility and liability
Each party remains responsible for losses caused by its breach of these Terms, negligence or failure to comply with applicable law.
Aetherium is not responsible for:
- Customer decisions based on unverified AI-generated information.
- Messages sent or actions taken by Customer users.
- The Customer’s choice of lawful basis or marketing method.
- Information entered by the Customer without appropriate authority.
- Loss resulting from a Customer’s failure to protect its accounts or devices.
- Third-party services outside Aetherium’s reasonable control.
Nothing in these Terms excludes or limits liability where doing so would be unlawful, including liability for fraud, fraudulent misrepresentation, or death or personal injury caused by negligence.
20. Changes to these Terms
Aetherium may update these Terms to reflect changes to the Service, providers, security requirements, law or business arrangements.
Material changes will be published with an updated revision date. Where appropriate, registered customers will also be notified through the Service or by email.
If a material change requires renewed acceptance, the Customer’s organisation administrator will be asked to accept the updated Terms before continuing to use the Service.
21. Notices and contact
Notices or questions concerning the Service may be sent to:
Aetherium Engineering Ltd, trading as Aetherium Tools
Email: admin@aetherium-tools.co.uk
Address: 1.30 Repton House, Bretby Business Park, Ashby Road, Burton-on-Trent, DE15 0YZ
Company number: 15338606
Aetherium may send Service notices to the email address associated with the Customer’s organisation administrator.
22. Governing law
These Terms and any non-contractual disputes arising from them are governed by the laws of England and Wales.
The courts of England and Wales will have jurisdiction, except where applicable law requires otherwise.
23. Acceptance
By creating an organisation, accepting these Terms through the Service or continuing to use the Service after being asked to accept them, the Customer agrees to:
- The general Aetherium Tools Terms of Use.
- These Aetherium Sales Assistant Terms of Use.
- Schedule 1 — Data Processing Terms.
The Customer acknowledges that it has been provided with the Supplementary Privacy Notice in Part A.
The user accepting the Terms confirms that they are authorised to accept them for the Customer organisation.
Schedule 1 - Data Processing Terms
1. Status and scope
These Data Processing Terms form part of the agreement between:
- Aetherium Engineering Ltd, trading as Aetherium Tools (“Aetherium”); and
- The organisation using Aetherium Sales Assistant (“the Customer”).
They apply where Aetherium processes personal data on behalf of the Customer through Aetherium Sales Assistant (“the Service”).
For that processing:
- The Customer is the controller and Aetherium is the processor; or
- Where the Customer processes personal data for another controller, the Customer is a processor and Aetherium is its subprocessor.
Aetherium remains a separate controller for information it processes for its own account-administration, security, support, billing and legal-compliance purposes, as explained in Part A.
2. Definitions
In this Schedule:
Customer Personal Data means personal data processed by Aetherium on behalf of the Customer through the Service.
Data Protection Law means applicable United Kingdom data-protection and privacy law, including the UK GDPR, the Data Protection Act 2018 and applicable rules concerning privacy and electronic communications, in each case as amended or replaced.
Data Subject, personal data, personal data breach, processing, processor, controller and special-category personal data have the meanings given in applicable Data Protection Law.
Subprocessor means another processor appointed by Aetherium to process Customer Personal Data in connection with the Service.
3. Processing instructions
Aetherium will process Customer Personal Data only:
- On the Customer’s documented instructions.
- As reasonably necessary to provide, secure and support the Service.
- As described in the agreement, these Terms and the Customer’s use and configuration of the Service.
- As required by applicable law.
The Customer’s documented instructions include:
- Entering, importing, editing and deleting information.
- Configuring organisation and sales settings.
- Activating AI research or generation features.
- Requesting reports, exports, support or organisation deletion.
- Other instructions submitted through authorised use of the Service.
If applicable law requires Aetherium to process Customer Personal Data other than on the Customer’s instructions, Aetherium will inform the Customer before processing unless the law prohibits that notification.
Aetherium will promptly inform the Customer if, in its reasonable opinion, a Customer instruction infringes applicable Data Protection Law. Aetherium may suspend the affected processing until the parties clarify or amend the instruction.
4. Customer responsibilities
The Customer is responsible for:
- Complying with its obligations as controller or processor.
- Ensuring that its instructions comply with Data Protection Law.
- Having an appropriate lawful basis for processing Customer Personal Data.
- Providing required privacy information to Data Subjects.
- Ensuring that Customer Personal Data is adequate, relevant and reasonably accurate.
- Responding to objections, opt-outs and direct-marketing preferences.
- Ensuring that authorised users do not enter prohibited or unnecessary information.
- Determining appropriate retention periods for its records.
- Obtaining any permissions required to instruct Aetherium to process Customer Personal Data.
- Assessing whether the Service is appropriate for the Customer’s intended processing.
The Customer must not intentionally use the Service to process:
- Special-category personal data.
- Criminal-conviction or offence data.
- Children’s personal data.
- Government identification numbers.
- Payment-card or bank-account information.
- Passwords or authentication secrets belonging to third parties.
- Medical, genetic or biometric information.
- Other highly sensitive information not reasonably necessary for legitimate B2B sales activity.
5. Confidentiality
Aetherium will ensure that persons authorised to process Customer Personal Data:
- Are subject to an appropriate duty of confidentiality.
- Receive access only where reasonably necessary for their role.
- Process Customer Personal Data only in accordance with these Terms and applicable instructions.
- Receive appropriate information concerning their data-protection and security responsibilities.
These obligations will continue after the authorised person’s access or engagement ends.
6. Security
Taking account of the nature, scope, context and purpose of the processing, as well as the risks to individuals, Aetherium will maintain appropriate technical and organisational measures intended to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
The measures currently applicable to the Service are described in Annex 2.
Aetherium may update its security measures as technology, risks and the Service change, provided that the overall protection of Customer Personal Data is not materially reduced.
The Customer acknowledges that no online service can guarantee absolute security and remains responsible for securely configuring and using its organisation account.
7. Personal data breaches
Aetherium will notify the Customer without undue delay after becoming aware of a confirmed personal data breach affecting Customer Personal Data.
Where available, the notification will describe:
- The nature of the breach.
- The categories of information and individuals potentially affected.
- The likely consequences of the breach.
- Measures taken or proposed to contain, investigate and mitigate it.
- A contact route for further information.
Where all information is not immediately available, Aetherium may provide it in phases as the investigation progresses.
Aetherium will take reasonable steps to contain, investigate and mitigate the breach and will provide reasonable assistance required for the Customer to meet applicable notification obligations.
Aetherium’s notification of an incident does not constitute an admission of fault or liability.
The Customer is responsible for deciding whether it must notify affected individuals, the Information Commissioner’s Office or another regulator, except where Aetherium has an independent legal obligation to make a notification.
8. Data-subject requests
Taking account of the nature of the processing, Aetherium will provide reasonable assistance to help the Customer respond to requests concerning Customer Personal Data.
If Aetherium receives a request relating to Customer Personal Data, it will normally:
- Direct the individual to the relevant Customer; or
- Notify the Customer and await its instructions.
Aetherium will not independently fulfil a request concerning Customer Personal Data unless:
- The Customer instructs it to do so.
- The Service provides a function through which the Customer can fulfil the request.
- Applicable law requires Aetherium to respond directly.
The Customer remains responsible for verifying the requester’s identity, determining whether the request is valid and responding within the applicable period.
9. Regulatory assistance
Taking account of the nature of the processing and information available to Aetherium, Aetherium will provide reasonable assistance with:
- Data-protection impact assessments.
- Prior consultation with a supervisory authority.
- Security and breach assessments.
- Enquiries from the Information Commissioner’s Office or another competent authority.
The Customer must provide sufficient information for Aetherium to understand and respond to the request.
Aetherium may charge reasonable costs for extensive or unusual assistance that goes beyond the ordinary provision of the Service, unless the assistance is required because Aetherium breached these Terms or Data Protection Law.
10. Subprocessors
The Customer gives Aetherium general written authorisation to appoint subprocessors to support the Service.
Aetherium will:
- Select subprocessors using reasonable care.
- Enter into written terms requiring each subprocessor to protect Customer Personal Data to a standard appropriate to the services it provides.
- Ensure that applicable data-protection obligations are passed to the subprocessor.
- Remain responsible for the subprocessor’s performance of its data-processing obligations to the extent required by Data Protection Law.
Current subprocessors are identified in Annex 3 and in Part A.
Changes to subprocessors
Aetherium may add, remove or replace a subprocessor.
Aetherium will provide reasonable advance notice of a material new subprocessor through the Service, by email or by updating the published provider list. Where practical, Aetherium will provide at least 14 days’ notice before the new subprocessor begins processing Customer Personal Data.
The Customer may object during the notice period where it has reasonable data-protection grounds. The parties will work in good faith to address the concern.
If the concern cannot reasonably be resolved, Aetherium may:
- Avoid using the subprocessor for that Customer where technically and commercially practical;
- Offer an alternative arrangement; or
- Allow the Customer to stop using the affected Service and request deletion of its information.
An objection does not permit the Customer to continue using an affected feature while preventing the processing reasonably required to provide it.
11. International transfers
Aetherium will ensure that a legally recognised transfer mechanism applies where Customer Personal Data is transferred outside the United Kingdom to a country that is not covered by applicable UK adequacy regulations.
Depending on the provider and processing arrangement, this may include:
- The UK International Data Transfer Agreement.
- The UK Addendum to the European Commission’s Standard Contractual Clauses.
- Applicable adequacy regulations.
- Another transfer mechanism permitted by Data Protection Law.
Where Aetherium relies upon a subprocessor’s transfer mechanism, Aetherium will take reasonable steps to ensure that the mechanism applies to the relevant processing.
Information about provider locations and transfer arrangements may be provided through the published subprocessor information or on reasonable request.
12. Return, export and deletion
During the Customer’s use of the Service, authorised users may delete individual records using available controls.
Organisation administrators may request an export of their organisation’s information in an available, commonly used format where reasonably practicable.
When an organisation is scheduled for deletion:
- A 30-day pending-deletion period will normally apply.
- Access may be restricted during that period.
- The organisation and its associated records will be deleted from the active Service after the pending-deletion period unless deletion is cancelled where permitted.
- Residual copies may remain in protected infrastructure backups for up to a further 30 days.
- Backup retention may be shorter depending on the applicable deployment configuration.
- Backup copies are retained for recovery and continuity and are not routinely accessed or restored except where operationally necessary.
Following termination of the Service, Aetherium will delete or return Customer Personal Data in accordance with the Customer’s request and the process above.
Aetherium may retain limited information where required by law or reasonably necessary for security, fraud prevention, dispute resolution or establishing, exercising or defending legal claims. Any retained Customer Personal Data will remain protected by these Terms and will not be processed for unrelated purposes.
The Customer should request any required export before permanent deletion. Aetherium cannot restore information that has already been permanently deleted or overwritten.
13. Compliance information
Aetherium will make available information reasonably necessary to demonstrate compliance with its processor obligations under applicable Data Protection Law.
This may include:
- These Data Processing Terms.
- Published privacy and subprocessor information.
- Descriptions of relevant security measures.
- Provider compliance documentation available to Aetherium.
- Reasonable written responses to compliance enquiries.
The parties will seek to satisfy compliance enquiries through existing documentation and written responses before requesting a formal audit.
14. Audits and inspections
Where the information provided under section 13 is insufficient, the Customer may conduct a reasonable audit concerning Aetherium’s processing of Customer Personal Data.
Unless a personal data breach, regulator or reasonable evidence of material non-compliance requires otherwise:
- The Customer must provide at least 30 days’ written notice.
- An audit may occur no more than once in any 12-month period.
- The scope must be limited to processing relevant to the Customer.
- The audit must occur during normal business hours.
- The audit must not compromise another customer’s information, security or confidentiality.
- The auditor must be independent and subject to appropriate confidentiality obligations.
- The Customer must bear its audit costs and Aetherium’s reasonable costs of providing exceptional assistance.
Aetherium may propose an independent audit report, certification, provider report or other reasonable evidence instead of direct access where that evidence adequately addresses the Customer’s request.
Nothing in this section limits the powers of the Information Commissioner’s Office or another competent authority.
15. Processing records
Aetherium will maintain records concerning processing performed on behalf of customers where required by Data Protection Law.
The Customer is responsible for maintaining its own processing records and for documenting its purposes, lawful bases, retention decisions and relevant assessments.
16. Conflict and precedence
If this Schedule conflicts with another part of the agreement concerning Aetherium’s processing of Customer Personal Data, this Schedule will take precedence to the extent of that conflict.
If this Schedule conflicts with a mandatory requirement of applicable Data Protection Law, that mandatory requirement will apply.
17. Liability
Liability arising under this Schedule is subject to Part B and the general Aetherium Tools Terms, except where applicable law does not permit liability to be excluded or limited.
Nothing in this Schedule limits either party’s responsibility to comply with Data Protection Law or the powers of a competent regulator.
18. Duration
This Schedule begins when the Customer accepts the agreement or first instructs Aetherium to process Customer Personal Data, whichever occurs first.
It continues for as long as Aetherium processes Customer Personal Data on the Customer’s behalf.
Provisions concerning confidentiality, deletion, retained information, audits and liability will continue for as long as reasonably necessary after termination.
Annex 1 — Processing particulars
| Item | Description |
|---|---|
| Subject matter | Provision, operation, security and support of Aetherium Sales Assistant |
| Duration | The period during which the Customer uses the Service, followed by the applicable active deletion and backup-retention periods |
| Nature of processing | Collection, recording, organisation, storage, retrieval, consultation, analysis, generation, transmission, restriction, export and deletion |
| Purposes | B2B lead discovery, company research, CRM management, sales-pipeline management, activity recording, opportunity management, reporting and preparation of outreach drafts |
| Data Subjects | Customer users, organisation administrators, prospective business contacts, existing business contacts, client representatives and other individuals recorded by authorised users |
| Company and lead data | Company association, professional role, lead source, relationship status, pipeline stage, assigned user, follow-up information and research notes |
| Business contact data | Name, work email address, business telephone number, job title, employer, professional profile URL and relevant business-contact notes |
| Sales activity data | Logged calls, meetings, messages, notes, timestamps, follow-ups, opportunities, estimated values and outcomes |
| AI-related data | Organisation sales settings, relevant company and professional contact information, prompts, generated summaries, relevance assessments and outreach drafts |
| User data | User name, email address, organisation membership, role, authentication identifier and relevant audit information |
| Special-category data | Not intended or permitted |
| Processing frequency | As initiated by authorised users and as required for the continuous hosting, security and operation of the Service |
Annex 2 — Technical and organisational measures
Aetherium’s measures include, as applicable:
Access control
- Authenticated user access.
- Organisation-based separation of customer records.
- Role-based organisation permissions.
- Administrative controls for organisation membership.
- Restrictions intended to prevent users accessing another organisation’s information.
- Removal or restriction of access when no longer authorised.
Application and infrastructure security
- Hosting through managed infrastructure providers.
- Use of encrypted network connections where supported by the relevant service.
- Secure handling of application credentials and provider secrets.
- Security updates and dependency maintenance.
- Input validation and controls intended to reduce unauthorised access or modification.
- Monitoring, diagnostic logging and investigation of suspected security events where available.
Data protection and resilience
- Database and infrastructure backup arrangements provided through the applicable deployment configuration.
- Organisation deletion controls and a pending-deletion period.
- Protected residual backups subject to limited retention.
- Recovery and continuity arrangements appropriate to the Service and provider configuration.
Organisational measures
- Access to customer information limited to persons who reasonably require it.
- Confidentiality obligations for authorised personnel.
- Processes for responding to rights requests and security incidents.
- Review of service providers handling Customer Personal Data.
- Documentation of material providers and processing purposes.
- Periodic review of privacy, access and security arrangements.
The Customer is responsible for its own devices, networks, user access, exports and subsequent use of information obtained from the Service.
Annex 3 — Current subprocessors
| Provider | Purpose | Information potentially processed |
|---|---|---|
| Replit, Inc. | Application hosting, infrastructure, database-related services and managed AI integration | Customer records, account information, technical information, AI requests and generated responses |
| OpenAI, L.L.C. and/or the applicable OpenAI entity | AI model processing accessed through Replit AI Integrations | Information included in AI prompts and generated responses |
| Clerk, Inc. | Authentication, user-account management and organisation access control | User name, email address, authentication identifiers, organisation membership and role |
The providers’ own subprocessors may also process limited information where necessary to supply their respective services. Current provider information and links to applicable privacy, data-processing and subprocessor documents are provided in Part A, section 9 — Service providers and international transfers.