Data Processing Addendum

Version: 1.0 · Effective: 10 September 2026 · Processor: JJO Pentester Enterprise (business registration number 202003104298 (003107833-D)), a sole proprietorship registered in Malaysia, trading as CheckAI

This Addendum forms part of the Terms of Service between CheckAI and the customer organization ("Customer"). It applies where CheckAI processes personal data on the Customer's behalf. Where it conflicts with the Terms, this Addendum prevails on data-protection matters.

1. Roles

The Customer is the controller and CheckAI is the processor in respect of personal data contained in Customer content — asset inventories, findings, uploaded penetration-test reports, evidence, compliance material and related records.

CheckAI is an independent controller for account administration, authentication, billing and service-security data, as described in the Privacy Policy. This Addendum does not govern that processing.

2. Details of processing

Subject matterProvision of the CheckAI security, penetration-test management and compliance platform.
DurationThe term of the Terms of Service, plus the retention period in section 11.
Nature and purposeCollection, storage, normalization, correlation, prioritization, analysis, display, export and deletion of security and compliance information for the Customer.
Types of personal dataBusiness contact details of the Customer's personnel and assignees; names and identifiers appearing in uploaded penetration-test reports, evidence and compliance material; identifiers appearing in connector-derived records; any personal data the Customer chooses to include in content it uploads.
Categories of data subjectsThe Customer's personnel and contractors; penetration testers and auditors named in supplied documents; any individual identified in Customer-supplied content.
Special category dataProhibited. The service is not designed for special category data and the Customer must not upload it, nor instruct CheckAI to process it. Where the Customer does so in breach of this restriction, it does so on its own responsibility.

3. Processing on instructions

CheckAI processes personal data only on the Customer's documented instructions, including as to international transfers, unless required otherwise by law — in which case CheckAI will inform the Customer before processing, unless the law prohibits that notice. The Terms, this Addendum and the Customer's configuration and use of the service constitute those instructions.

CheckAI will tell the Customer if, in its opinion, an instruction infringes applicable data-protection law.

4. Personnel and confidentiality

CheckAI ensures that persons authorized to process personal data are bound by confidentiality obligations, are granted access on a need-to-know basis, and receive appropriate training.

Support access to Customer data requires the Customer's approval, with any emergency access capped, recorded and auditable.

5. Security measures

Taking account of the state of the art and the risks involved, CheckAI implements:

CheckAI may update these measures provided the level of protection is not reduced. CheckAI holds no security certification and does not claim one; the measures above are described as implemented, not as independently attested.

6. Subprocessors

The Customer gives general authorization for CheckAI to engage subprocessors. The current list is published in the Privacy Policy and comprises Amazon Web Services, Stripe, Amazon SES and Cloudflare.

CheckAI will give the Customer at least 30 days' notice before adding or replacing a subprocessor. The Customer may object on reasonable data-protection grounds within 30 days of that notice. If the parties cannot resolve the objection, the Customer may terminate the affected service without penalty and receive a pro-rata refund of prepaid fees for the unused remainder.

CheckAI imposes data-protection obligations on each subprocessor no less protective than those in this Addendum, and remains liable to the Customer for their performance.

7. AI providers are not our subprocessors

CheckAI's AI features run on the Customer's own credentials and the Customer's own account with a third-party AI provider. That provider is engaged by the Customer, not by CheckAI, and is therefore not a CheckAI subprocessor.

Where the Customer enables AI features, the Customer is responsible for its own relationship with that provider, including any processing agreement, transfer mechanism and retention terms required. CheckAI transmits content to that provider only as directed by the Customer's configuration and actions. CheckAI does not resell AI usage and holds no provider credit.

The categories of content that may be transmitted are described in the Privacy Policy.

8. Assistance to the Customer

Taking into account the nature of the processing, CheckAI will:

9. International transfers

Service data is hosted in Amazon Web Services' ap-southeast-1 region (Singapore). CheckAI's subprocessors — Amazon Web Services, Stripe, Amazon SES and Cloudflare — each provide contractual transfer protections in their own data processing terms, including standard contractual clauses where applicable, and CheckAI relies on those for the onward processing it arranges.

Where the Customer's own transfer of personal data to CheckAI is subject to a restriction under the law applying to the Customer — for example a transfer out of the European Economic Area or the United Kingdom — the parties will enter into the standard contractual clauses, or the other transfer mechanism that law requires, with the annexes completed using the processing details in section 2 and the security measures in section 5. A Customer requiring this should contact privacy@checkai-cloud.com before transferring such data, and those clauses then form part of this Addendum.

10. Personal data breach

CheckAI will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer content, and in any event no later than 48 hours after becoming aware. The notification will describe, so far as known, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point. CheckAI will provide further information as it becomes available and will cooperate reasonably with the Customer's own notification obligations.

11. Return and deletion

On termination or expiry, CheckAI deletes Customer content in accordance with the published retention rules: affected module data becomes read-only for 30 calendar days, during which authorized users may export it, and is then deleted. Exact access-end and deletion timestamps are shown in the product and notices are sent before deletion.

The Customer may request earlier deletion through a verified request. CheckAI may retain personal data where required by law, limited to what that requirement necessitates and subject to continued confidentiality and security obligations. Backups are deleted on their ordinary rotation cycle.

12. Audits and information

CheckAI will make available to the Customer the information reasonably necessary to demonstrate compliance with this Addendum, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates.

How the audit right is satisfied

In the first instance, CheckAI satisfies this right by providing written information — its security documentation, completed security questionnaires, the current subprocessor list, and written responses to the Customer's specific questions. In practice this answers what a Customer needs to know.

Where written information is genuinely insufficient to address a specific, identified concern, the Customer may conduct an inspection. Inspections are conducted remotely wherever practicable, and on site only where remote inspection cannot address the concern.

Conditions

CheckAI holds no independent security certification and cannot offer an attestation report in place of an audit. Where CheckAI later obtains one, a current report may be provided in satisfaction of this section.

13. Liability

Liability under this Addendum is subject to the limitations in the Terms of Service — the greater of 50% of the fees paid in the preceding twelve months or USD 100, applying in aggregate across the Customer and its affiliates, and subject to the twelve-month period for bringing a claim — except where applicable data-protection law does not permit that limitation.

No separate, higher cap applies to data-protection claims at this time. Enterprise customers commonly require one, and CheckAI may agree a different cap in an individually negotiated agreement. Nothing in this Addendum limits liability that cannot lawfully be limited, and this cap does not affect any regulator's powers, including those of the Personal Data Protection Commissioner under the Malaysian PDPA.


To request a signed copy, contact privacy@checkai-cloud.com. This Addendum is accepted in-product by an authorized Administrator, and takes effect on acceptance without signature. A countersigned copy is available on request for Customers whose procurement requires one.