Privacy Policy
Contents
1. Our role, and yours
CheckAI plays two different roles, and the distinction matters.
- We are the controller for personal data about the people who create and administer accounts, and about visitors to our website — names, work email addresses, authentication and billing contact details, and support correspondence.
- We are a processor for the content your organization puts into CheckAI — asset inventories, findings, uploaded penetration-test reports, evidence, compliance material and anything else you supply. Your organization decides what goes in and why. If that content contains personal data, your organization is the controller and the Data Processing Addendum governs our processing of it.
2. What we collect
| Category | Examples | Source |
|---|---|---|
| Account and identity | Name, work email address, password hash, multi-factor enrolment state, role, last-active time | You |
| Organization | Organization name and profile, membership and role history, billing contact address | You |
| Billing | Business billing name, address, tax identifier, subscription and invoice records. We never see or store full card numbers — payment details go directly to Stripe. | You, via Stripe |
| Security and audit | Sign-in events, session records, role and membership changes, credential and integration changes, destructive-action records | Generated by the service |
| Customer content | Verified domains, asset inventory, findings, remediation records, uploaded reports and evidence, compliance assessments, saved AI conversations | You, your connected systems, and public sources |
| AI usage metadata | Request counts, token counts, model and provider identifiers, job success or failure, and who initiated each job. Not prompt content, document content or credentials. | Generated by the service |
| Public scan preview | The submitted domain, the assessment result, and abuse-control records including IP address for rate limiting | Visitor |
| Access restrictions | Where we restrict someone from using CheckAI under the Acceptable Use Policy, we keep a record so the restriction can be enforced. The identifier — an email address, a verified domain or a payment identifier — is stored as a one-way hash, not in readable form, alongside the reason and the date. We also keep a count of blocked attempts. | Generated by the service |
| Contact form | Your name, email address, optional company name, chosen subject and message. Your IP address is used for rate limiting only. The message body is not written to our general application logs — we record that a submission happened, its category and its length, not its contents. | You |
We deliberately do not collect coarse geolocation of session IP addresses. It would require an additional data source and subprocessor for marginal benefit, so it is omitted by choice.
3. Why we process it, and on what basis
| Purpose | Lawful basis |
|---|---|
| Providing the service to your organization | Performance of a contract |
| Authentication, MFA and session security | Contract; legitimate interests in securing the service |
| Billing, invoicing and tax | Contract; legal obligation |
| Audit records and abuse prevention | Legitimate interests in protecting the service and other customers |
| Rate limiting and challenge on the public scan preview | Legitimate interests in preventing abuse |
| Replying to a contact-form enquiry | Legitimate interests in responding to someone who asked us to; steps prior to entering a contract where the enquiry concerns purchasing. Submitting the form does not sign you up for marketing and we do not add you to any list. |
| Mandatory transactional notices — trial expiry, payment failure, access end, deletion warnings | Contract. These are not marketing and cannot be switched off. |
| Optional product emails | Consent, withdrawable at any time |
| Enforcing access restrictions, and preventing repeat abuse of the service | Legitimate interests in protecting CheckAI, our customers and the owners of systems that would otherwise be assessed without authorization. This is the basis on which we retain restriction records even after an erasure request — see below. |
| Responding to legal requests | Legal obligation |
Data protection law differs between countries, and the terms above follow the framework used in the European Economic Area and the United Kingdom because it is the most demanding. Where you are elsewhere — including Malaysia, where CheckAI is established — the equivalent local basis applies to the same processing, and nothing here reduces a right you have under your own law.
4. AI processing and your own provider — BYOK disclosure
CheckAI does not send your data to an AI provider on its own account
CheckAI's AI features operate on a bring-your-own-key basis. Your organization configures credentials for its own account with a third-party AI provider, and AI processing runs against that account.
- Your organization contracts with the provider directly and pays them directly. CheckAI does not resell AI usage, hold provider credit, or mark up provider charges.
- The provider's terms, privacy policy and data-retention practices apply to content processed under your credentials. That relationship is between your organization and the provider. You should satisfy yourself that it meets your obligations before enabling AI features.
- What may be transmitted: security findings and their descriptions, asset and organization names, text extracted from uploaded penetration-test reports, evidence and compliance material, framework content you supplied, and earlier messages in a saved conversation.
- The interface identifies the provider and model before sensitive report or telemetry content is transmitted, and an Administrator authorizes automatic or background AI spending separately.
- Your provider credentials are encrypted at rest, never returned to the browser and never written to logs. No AI operation runs without the relevant paid-module entitlement, even where credentials are configured.
- Usage pages show token and request counts. They never expose prompts, document content or credentials. Any monetary figure shown is an estimate — the provider's own billing is authoritative.
5. Subprocessors
We use the following subprocessors. We will give notice before adding a new one, and the Data Processing Addendum sets out your objection rights.
| Subprocessor | Purpose | Data involved |
|---|---|---|
| Amazon Web Services | Hosting, managed database, object storage, queues, key management | All service data |
| Stripe | Payment processing, hosted checkout, customer portal, tax calculation, invoicing | Billing contact and business details, payment details. Card data goes to Stripe directly and is never held by CheckAI. |
| Amazon SES | Transactional email — verification links, invitations, lifecycle and billing notices | Recipient email address and message content |
| Cloudflare | Turnstile challenge on the public scan preview, and edge protection | Request metadata including IP address. Turnstile sets no tracking cookies. |
Your AI provider is not a CheckAI subprocessor. Because AI runs on your own credentials and your own provider account, that provider is engaged by your organization, not by us. See section 4.
6. International transfers
Service data is hosted in Amazon Web Services' ap-southeast-1 region (Singapore). Our subprocessors may process data in other countries, and the website is served from content delivery locations worldwide. Where a transfer leaves a jurisdiction that restricts international transfers, we rely on the contractual protections our providers offer for that purpose, including the standard contractual clauses they incorporate. Where a business customer's own transfer to us requires a specific mechanism, we will enter into it — see the Data Processing Addendum.
7. How long we keep it
- Paid module data: when paid access ends, it becomes read-only for 30 calendar days, then is deleted. Exact access-end and deletion timestamps are shown on the billing page, and notices are sent before deletion.
- Free scan history: 30 days. If you replace your monitored domain, the previous domain's remaining history is deleted after 30 days.
- Account and organization records: retained while the account is active, then deleted or anonymized within 90 days of closure.
- Audit records: retained for 12 months for security and accountability.
- Billing, tax and fraud records: retained for the period required by law, and limited to what that requirement needs.
- Access restriction records: kept for as long as the restriction remains in force. Where a restriction is permanent, that is indefinite. The identifier is held only as a one-way hash, so the record cannot be read back to identify anyone — it can only be matched against a new registration attempt. If a restriction is lifted, the record is deleted.
- Contact-form enquiries: the message is delivered to our support mailbox and kept for as long as it is needed to answer you and to deal with any follow-up on the same matter, and for any period we are required to keep it for legal or accounting reasons. We do not keep support correspondence indefinitely, and you may ask us to delete an enquiry at any time by writing to privacy@checkai-cloud.com. Rate-limiting records expire automatically within two hours.
- A verified legal or support deletion request may require earlier deletion.
8. How we protect it
- Tenant isolation with row-level security and organization-scoped access.
- Encryption in transit and at rest, with managed key material.
- Private object storage with short-lived authorized retrieval.
- Managed PostgreSQL with point-in-time recovery and tested restoration.
- Mandatory multi-factor authentication for Administrator and Contributor roles.
- Read-only connectors with least-privilege permission boundaries.
- Secrets encrypted, never returned to the browser and never logged.
- Isolated background-job and rendering environments.
What we do not claim. CheckAI holds no security certification and claims none. We do not claim that our audit records are immutable or tamper-proof. No system is perfectly secure, and we do not guarantee that ours cannot be breached.
If a personal data breach occurs, we will notify those we are required to notify without undue delay. Where your organization is the controller and the breach affects data we process for you, we will tell you without undue delay and no later than 48 hours after becoming aware — deliberately shorter than the 72 hours a controller typically has to notify its regulator, so that you have time to act. Where we are the controller, we notify the relevant supervisory authority and affected individuals as the applicable law requires.
9. Cookies and tracking
We use essential cookies only — those required for authentication, session security and cross-site request forgery protection. We do not use advertising cookies, and we do not sell personal data.
Because we run no non-essential tracking, no consent banner is shown. Presenting an optional-consent flow for cookies that are strictly necessary would be misleading. If we ever introduce non-essential tracking, a consent mechanism will appear at that point and this policy will be updated first.
10. Your rights
Depending on where you are, you may have rights to access, correct, delete, restrict or object to processing of your personal data, to portability, and to withdraw consent where consent is the basis. Contact privacy@checkai-cloud.com.
One narrow exception applies to deletion. If your access to CheckAI has been restricted under the Acceptable Use Policy, we will keep the hashed identifier and the reason for that restriction even if you ask us to delete everything else, because otherwise the restriction could be defeated simply by asking. We keep the minimum needed to enforce it, in a form that cannot be read back, and nothing further. If you believe a restriction is wrong, you can appeal it at appeal@checkai-cloud.com — and if the appeal succeeds, the record is deleted.
If your request concerns content held inside a customer organization's workspace, we are the processor and will refer you to that organization, which is the controller. You may also lodge a complaint with your supervisory authority. In Malaysia the relevant authority is the Jabatan Perlindungan Data Peribadi (JPDP), the Department of Personal Data Protection, under the Ministry of Communications and Digital. If you are elsewhere, you may also complain to your own supervisory authority.
11. Children
CheckAI is a business product provided to organizations, and is not directed at children. We do not knowingly collect personal data from anyone under 18.
To create an account you must be at least 18, legally capable of entering a binding contract in your own jurisdiction, and authorised to bind the organization you represent. We set the threshold this way rather than naming a single children's-consent age because those differ by country — 13 in the United Kingdom and under COPPA, between 13 and 16 across the EU — and 18 sits above all of them while matching the contractual capacity the service actually requires.
If we learn that we hold personal data relating to a child, we will delete it. If you believe we hold such data, contact privacy@checkai-cloud.com.
12. Changes
We may update this policy. Where a change materially affects how we handle personal data we will give notice, and material changes may require an Administrator to accept the updated policy. The current version is always published here with its effective date.
Privacy enquiries: privacy@checkai-cloud.com