Data Processing Addendum
This Addendum forms part of the Terms of Service between CheckAI and the customer organization ("Customer"). It applies where CheckAI processes personal data on the Customer's behalf. Where it conflicts with the Terms, this Addendum prevails on data-protection matters.
Contents
1. Roles
The Customer is the controller and CheckAI is the processor in respect of personal data contained in Customer content — asset inventories, findings, uploaded penetration-test reports, evidence, compliance material and related records.
CheckAI is an independent controller for account administration, authentication, billing and service-security data, as described in the Privacy Policy. This Addendum does not govern that processing.
2. Details of processing
| Subject matter | Provision of the CheckAI security, penetration-test management and compliance platform. |
|---|---|
| Duration | The term of the Terms of Service, plus the retention period in section 11. |
| Nature and purpose | Collection, storage, normalization, correlation, prioritization, analysis, display, export and deletion of security and compliance information for the Customer. |
| Types of personal data | Business contact details of the Customer's personnel and assignees; names and identifiers appearing in uploaded penetration-test reports, evidence and compliance material; identifiers appearing in connector-derived records; any personal data the Customer chooses to include in content it uploads. |
| Categories of data subjects | The Customer's personnel and contractors; penetration testers and auditors named in supplied documents; any individual identified in Customer-supplied content. |
| Special category data | Prohibited. The service is not designed for special category data and the Customer must not upload it, nor instruct CheckAI to process it. Where the Customer does so in breach of this restriction, it does so on its own responsibility. |
3. Processing on instructions
CheckAI processes personal data only on the Customer's documented instructions, including as to international transfers, unless required otherwise by law — in which case CheckAI will inform the Customer before processing, unless the law prohibits that notice. The Terms, this Addendum and the Customer's configuration and use of the service constitute those instructions.
CheckAI will tell the Customer if, in its opinion, an instruction infringes applicable data-protection law.
4. Personnel and confidentiality
CheckAI ensures that persons authorized to process personal data are bound by confidentiality obligations, are granted access on a need-to-know basis, and receive appropriate training.
Support access to Customer data requires the Customer's approval, with any emergency access capped, recorded and auditable.
5. Security measures
Taking account of the state of the art and the risks involved, CheckAI implements:
- tenant isolation with row-level security and organization-scoped access control;
- encryption of personal data in transit and at rest, with managed key material;
- private object storage with short-lived authorized retrieval;
- mandatory multi-factor authentication for Administrator and Contributor roles;
- read-only connectors operating under least-privilege permission boundaries;
- secrets encrypted, never returned to the browser and never written to logs;
- isolated background-job and document-rendering environments;
- managed database with point-in-time recovery and tested restoration;
- audit recording of security-relevant events;
- role-based access control with least privilege.
CheckAI may update these measures provided the level of protection is not reduced. CheckAI holds no security certification and does not claim one; the measures above are described as implemented, not as independently attested.
6. Subprocessors
The Customer gives general authorization for CheckAI to engage subprocessors. The current list is published in the Privacy Policy and comprises Amazon Web Services, Stripe, Amazon SES and Cloudflare.
CheckAI will give the Customer at least 30 days' notice before adding or replacing a subprocessor. The Customer may object on reasonable data-protection grounds within 30 days of that notice. If the parties cannot resolve the objection, the Customer may terminate the affected service without penalty and receive a pro-rata refund of prepaid fees for the unused remainder.
CheckAI imposes data-protection obligations on each subprocessor no less protective than those in this Addendum, and remains liable to the Customer for their performance.
7. AI providers are not our subprocessors
CheckAI's AI features run on the Customer's own credentials and the Customer's own account with a third-party AI provider. That provider is engaged by the Customer, not by CheckAI, and is therefore not a CheckAI subprocessor.
Where the Customer enables AI features, the Customer is responsible for its own relationship with that provider, including any processing agreement, transfer mechanism and retention terms required. CheckAI transmits content to that provider only as directed by the Customer's configuration and actions. CheckAI does not resell AI usage and holds no provider credit.
The categories of content that may be transmitted are described in the Privacy Policy.
8. Assistance to the Customer
Taking into account the nature of the processing, CheckAI will:
- assist the Customer, by appropriate technical and organizational measures and so far as possible, in responding to data-subject requests. The Customer manages its own members directly in Organization Settings, and can view, export and delete the material its organization holds. Where a request concerns an individual the Customer cannot locate through those tools — for example a person named inside an uploaded penetration-test report — CheckAI will assist on request, at privacy@checkai-cloud.com;
- promptly inform the Customer if it receives a request directly from a data subject relating to Customer content, and will not respond substantively except on the Customer's instruction or as legally required;
- assist the Customer with security obligations, breach notification, data protection impact assessments and prior consultation, taking into account the information available to CheckAI.
9. International transfers
Service data is hosted in Amazon Web Services' ap-southeast-1 region (Singapore). CheckAI's subprocessors — Amazon Web Services, Stripe, Amazon SES and Cloudflare — each provide contractual transfer protections in their own data processing terms, including standard contractual clauses where applicable, and CheckAI relies on those for the onward processing it arranges.
Where the Customer's own transfer of personal data to CheckAI is subject to a restriction under the law applying to the Customer — for example a transfer out of the European Economic Area or the United Kingdom — the parties will enter into the standard contractual clauses, or the other transfer mechanism that law requires, with the annexes completed using the processing details in section 2 and the security measures in section 5. A Customer requiring this should contact privacy@checkai-cloud.com before transferring such data, and those clauses then form part of this Addendum.
10. Personal data breach
CheckAI will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer content, and in any event no later than 48 hours after becoming aware. The notification will describe, so far as known, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point. CheckAI will provide further information as it becomes available and will cooperate reasonably with the Customer's own notification obligations.
11. Return and deletion
On termination or expiry, CheckAI deletes Customer content in accordance with the published retention rules: affected module data becomes read-only for 30 calendar days, during which authorized users may export it, and is then deleted. Exact access-end and deletion timestamps are shown in the product and notices are sent before deletion.
The Customer may request earlier deletion through a verified request. CheckAI may retain personal data where required by law, limited to what that requirement necessitates and subject to continued confidentiality and security obligations. Backups are deleted on their ordinary rotation cycle.
12. Audits and information
CheckAI will make available to the Customer the information reasonably necessary to demonstrate compliance with this Addendum, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates.
How the audit right is satisfied
In the first instance, CheckAI satisfies this right by providing written information — its security documentation, completed security questionnaires, the current subprocessor list, and written responses to the Customer's specific questions. In practice this answers what a Customer needs to know.
Where written information is genuinely insufficient to address a specific, identified concern, the Customer may conduct an inspection. Inspections are conducted remotely wherever practicable, and on site only where remote inspection cannot address the concern.
Conditions
- Notice: at least 30 days' written notice, stating the scope and the specific concern to be addressed.
- Frequency: no more than once in any twelve-month period, except where a personal data breach affecting the Customer has occurred, or a supervisory authority requires an audit, in which case a further audit may be conducted.
- Timing: during normal business hours, without unreasonably disrupting CheckAI's operations.
- Confidentiality: the Customer and any auditor it mandates are bound by confidentiality. CheckAI may require an auditor to sign a confidentiality undertaking before access, and may reasonably object to an auditor that is a competitor of CheckAI.
- Tenant isolation: an audit must not access, and CheckAI will not provide access to, any other customer's data, systems or confidential information. This limit is absolute.
- Costs: the Customer bears its own costs and CheckAI's reasonable costs of preparing for and supporting the audit, including staff time.
CheckAI holds no independent security certification and cannot offer an attestation report in place of an audit. Where CheckAI later obtains one, a current report may be provided in satisfaction of this section.
13. Liability
Liability under this Addendum is subject to the limitations in the Terms of Service — the greater of 50% of the fees paid in the preceding twelve months or USD 100, applying in aggregate across the Customer and its affiliates, and subject to the twelve-month period for bringing a claim — except where applicable data-protection law does not permit that limitation.
No separate, higher cap applies to data-protection claims at this time. Enterprise customers commonly require one, and CheckAI may agree a different cap in an individually negotiated agreement. Nothing in this Addendum limits liability that cannot lawfully be limited, and this cap does not affect any regulator's powers, including those of the Personal Data Protection Commissioner under the Malaysian PDPA.
To request a signed copy, contact privacy@checkai-cloud.com. This Addendum is accepted in-product by an authorized Administrator, and takes effect on acceptance without signature. A countersigned copy is available on request for Customers whose procurement requires one.