Privacy Policy

Version: 1.0 · Effective: 10 September 2026 · Controller: JJO Pentester Enterprise (business registration number 202003104298 (003107833-D)), a sole proprietorship registered in Malaysia, trading as CheckAI · Contact: privacy@checkai-cloud.com

1. Our role, and yours

CheckAI plays two different roles, and the distinction matters.

2. What we collect

CategoryExamplesSource
Account and identity Name, work email address, password hash, multi-factor enrolment state, role, last-active time You
Organization Organization name and profile, membership and role history, billing contact address You
Billing Business billing name, address, tax identifier, subscription and invoice records. We never see or store full card numbers — payment details go directly to Stripe. You, via Stripe
Security and audit Sign-in events, session records, role and membership changes, credential and integration changes, destructive-action records Generated by the service
Customer content Verified domains, asset inventory, findings, remediation records, uploaded reports and evidence, compliance assessments, saved AI conversations You, your connected systems, and public sources
AI usage metadata Request counts, token counts, model and provider identifiers, job success or failure, and who initiated each job. Not prompt content, document content or credentials. Generated by the service
Public scan preview The submitted domain, the assessment result, and abuse-control records including IP address for rate limiting Visitor
Access restrictions Where we restrict someone from using CheckAI under the Acceptable Use Policy, we keep a record so the restriction can be enforced. The identifier — an email address, a verified domain or a payment identifier — is stored as a one-way hash, not in readable form, alongside the reason and the date. We also keep a count of blocked attempts. Generated by the service
Contact form Your name, email address, optional company name, chosen subject and message. Your IP address is used for rate limiting only. The message body is not written to our general application logs — we record that a submission happened, its category and its length, not its contents. You

We deliberately do not collect coarse geolocation of session IP addresses. It would require an additional data source and subprocessor for marginal benefit, so it is omitted by choice.

3. Why we process it, and on what basis

PurposeLawful basis
Providing the service to your organizationPerformance of a contract
Authentication, MFA and session securityContract; legitimate interests in securing the service
Billing, invoicing and taxContract; legal obligation
Audit records and abuse preventionLegitimate interests in protecting the service and other customers
Rate limiting and challenge on the public scan previewLegitimate interests in preventing abuse
Replying to a contact-form enquiryLegitimate interests in responding to someone who asked us to; steps prior to entering a contract where the enquiry concerns purchasing. Submitting the form does not sign you up for marketing and we do not add you to any list.
Mandatory transactional notices — trial expiry, payment failure, access end, deletion warningsContract. These are not marketing and cannot be switched off.
Optional product emailsConsent, withdrawable at any time
Enforcing access restrictions, and preventing repeat abuse of the serviceLegitimate interests in protecting CheckAI, our customers and the owners of systems that would otherwise be assessed without authorization. This is the basis on which we retain restriction records even after an erasure request — see below.
Responding to legal requestsLegal obligation

Data protection law differs between countries, and the terms above follow the framework used in the European Economic Area and the United Kingdom because it is the most demanding. Where you are elsewhere — including Malaysia, where CheckAI is established — the equivalent local basis applies to the same processing, and nothing here reduces a right you have under your own law.

4. AI processing and your own provider — BYOK disclosure

CheckAI does not send your data to an AI provider on its own account

CheckAI's AI features operate on a bring-your-own-key basis. Your organization configures credentials for its own account with a third-party AI provider, and AI processing runs against that account.

5. Subprocessors

We use the following subprocessors. We will give notice before adding a new one, and the Data Processing Addendum sets out your objection rights.

SubprocessorPurposeData involved
Amazon Web Services Hosting, managed database, object storage, queues, key management All service data
Stripe Payment processing, hosted checkout, customer portal, tax calculation, invoicing Billing contact and business details, payment details. Card data goes to Stripe directly and is never held by CheckAI.
Amazon SES Transactional email — verification links, invitations, lifecycle and billing notices Recipient email address and message content
Cloudflare Turnstile challenge on the public scan preview, and edge protection Request metadata including IP address. Turnstile sets no tracking cookies.

Your AI provider is not a CheckAI subprocessor. Because AI runs on your own credentials and your own provider account, that provider is engaged by your organization, not by us. See section 4.

6. International transfers

Service data is hosted in Amazon Web Services' ap-southeast-1 region (Singapore). Our subprocessors may process data in other countries, and the website is served from content delivery locations worldwide. Where a transfer leaves a jurisdiction that restricts international transfers, we rely on the contractual protections our providers offer for that purpose, including the standard contractual clauses they incorporate. Where a business customer's own transfer to us requires a specific mechanism, we will enter into it — see the Data Processing Addendum.

7. How long we keep it

8. How we protect it

What we do not claim. CheckAI holds no security certification and claims none. We do not claim that our audit records are immutable or tamper-proof. No system is perfectly secure, and we do not guarantee that ours cannot be breached.

If a personal data breach occurs, we will notify those we are required to notify without undue delay. Where your organization is the controller and the breach affects data we process for you, we will tell you without undue delay and no later than 48 hours after becoming aware — deliberately shorter than the 72 hours a controller typically has to notify its regulator, so that you have time to act. Where we are the controller, we notify the relevant supervisory authority and affected individuals as the applicable law requires.

9. Cookies and tracking

We use essential cookies only — those required for authentication, session security and cross-site request forgery protection. We do not use advertising cookies, and we do not sell personal data.

Because we run no non-essential tracking, no consent banner is shown. Presenting an optional-consent flow for cookies that are strictly necessary would be misleading. If we ever introduce non-essential tracking, a consent mechanism will appear at that point and this policy will be updated first.

10. Your rights

Depending on where you are, you may have rights to access, correct, delete, restrict or object to processing of your personal data, to portability, and to withdraw consent where consent is the basis. Contact privacy@checkai-cloud.com.

One narrow exception applies to deletion. If your access to CheckAI has been restricted under the Acceptable Use Policy, we will keep the hashed identifier and the reason for that restriction even if you ask us to delete everything else, because otherwise the restriction could be defeated simply by asking. We keep the minimum needed to enforce it, in a form that cannot be read back, and nothing further. If you believe a restriction is wrong, you can appeal it at appeal@checkai-cloud.com — and if the appeal succeeds, the record is deleted.

If your request concerns content held inside a customer organization's workspace, we are the processor and will refer you to that organization, which is the controller. You may also lodge a complaint with your supervisory authority. In Malaysia the relevant authority is the Jabatan Perlindungan Data Peribadi (JPDP), the Department of Personal Data Protection, under the Ministry of Communications and Digital. If you are elsewhere, you may also complain to your own supervisory authority.

11. Children

CheckAI is a business product provided to organizations, and is not directed at children. We do not knowingly collect personal data from anyone under 18.

To create an account you must be at least 18, legally capable of entering a binding contract in your own jurisdiction, and authorised to bind the organization you represent. We set the threshold this way rather than naming a single children's-consent age because those differ by country — 13 in the United Kingdom and under COPPA, between 13 and 16 across the EU — and 18 sits above all of them while matching the contractual capacity the service actually requires.

If we learn that we hold personal data relating to a child, we will delete it. If you believe we hold such data, contact privacy@checkai-cloud.com.

12. Changes

We may update this policy. Where a change materially affects how we handle personal data we will give notice, and material changes may require an Administrator to accept the updated policy. The current version is always published here with its effective date.


Privacy enquiries: privacy@checkai-cloud.com