Legal
Channel DPA
How distributors and resellers must handle personal data.
What this document is
This Channel Data Processing Addendum (the "Channel DPA") applies between AXTRACTION AI SDN BHD (Company No. 202301042335 (1536252-X)) ("Axtraction AI") and each distributor or reseller that accepts it through an agreement with Axtraction AI (the "Channel Party").
It governs Personal Data handled in the channel relationship. It does not replace the End User Data Processing Addendum at https://axtraction.ai/end-user-dpa (the "End User DPA"), under which Axtraction AI acts as Processor for an End User.
1. Definitions and roles
1.1 "Applicable Data Protection Law" means the Malaysian Personal Data Protection Act 2010 as amended and any other privacy or data-protection law applicable to the relevant Processing.
1.2 "Axtraction AI Managed API" means the AI inference service selected and managed by Axtraction AI using paid enterprise cloud and AI services approved under the End User DPA.
1.3 "Axtraction AI Product" means an Axtraction AI software product identified in an End User SOW.
1.4 "Business Day" means a day other than Saturday, Sunday or a public holiday in Kuala Lumpur, Malaysia.
1.5 "Customer-Provided LLM" means an LLM service selected, licensed, paid for and controlled by an End User.
1.6 "Deal Registration" means Axtraction AI's written protection for an identified channel opportunity under the Underlying Agreement.
1.7 "End User" means the customer entity authorised to use an Axtraction AI Product for its own internal business purposes.
1.8 "End User Data" means Personal Data in or submitted to an End User's Axtraction AI Product, including uploaded content, extracted output, generated response, history and audit information.
1.9 "Fully Managed" means deployment in infrastructure controlled by Axtraction AI. "Self-Hosted" and "On-Premises" mean deployment in infrastructure controlled by the End User or its appointed operator.
1.10 "Personal Data", "Personal Data Breach", "Controller", "Processor", "Process", "Processing", "Data Subject" and "Subprocessor" have the meanings given by Applicable Data Protection Law.
1.11 "Underlying Agreement" means the master distributor agreement, master reseller agreement or other channel agreement through which the Channel Party accepts this Channel DPA.
1.12 Axtraction AI and the Channel Party each act as an independent Controller for business-contact, contracting, Deal Registration, pricing, invoicing, collection, support-contact and channel-administration data that each determines to Process for its own purposes.
1.13 Axtraction AI acts as Processor for End User Data only under the End User DPA accepted by the End User. The Channel Party is not a party to that End User DPA and receives no access right under it.
1.14 This Channel DPA does not appoint the Channel Party as Axtraction AI's Subprocessor. Any exceptional Axtraction AI Subprocessor appointment requires a separate written subprocessing agreement before Processing begins.
2. Independent-Controller obligations
2.1 Each party will independently comply with Applicable Data Protection Law for Personal Data it controls, including lawful basis, notices, Data Subject rights, security, retention and cross-border transfer.
2.2 Each party will Process channel business-contact data only for legitimate contracting, relationship, sales, Deal Registration, transaction, invoicing, compliance, support and security purposes, and will not sell it or use it for unrelated advertising.
2.3 A party disclosing Personal Data to the other confirms it has authority to make the disclosure and has provided required notices.
2.4 If either party receives a Data Subject request concerning data controlled by the other, it will forward the request within two Business Days and will not respond for the other party unless instructed or required by law.
2.5 The parties will reasonably cooperate on correction, deletion, restriction, regulatory enquiry and Personal Data Breach response relating to shared channel data.
3. No access to End User Data by default
3.1 The Channel Party shall not access, view, download, copy, extract, use or otherwise Process End User Data merely because it is a distributor, reseller, commercial seller, support coordinator or infrastructure supplier.
3.2 A Channel Party may access End User Data only where:
- the End User directly and expressly authorises and engages it for a defined service;
- that access is necessary for the authorised service;
- the Channel Party enters appropriate confidentiality and Controller–Processor terms directly with the End User before access; and
- Axtraction AI approves and technically enables the access where it concerns an environment controlled by Axtraction AI.
3.3 When Clause 3.2 applies, the Channel Party acts as the End User's separate Processor for its own service, not as Axtraction AI's Subprocessor. The Channel Party is independently responsible for that service and Processing. Axtraction AI remains responsible for Axtraction AI systems and access controls under its control.
3.4 For a Fully Managed environment, authorised Channel Party access must be named, least-privilege, logged and time-limited. Axtraction AI may revoke access when no longer necessary or where required for security or the End User's instruction.
3.5 For Self-Hosted or On-Premises deployment, the End User controls the primary infrastructure and database. A Channel Party operating that infrastructure does so under its direct arrangement with the End User and is responsible for operating-system, database, network, VPN, IAM, backup, disaster-recovery and infrastructure security obligations allocated to it.
3.6 The Channel Party shall not disclose End User Data to Axtraction AI beyond what is required for the approved Axtraction AI Product, SOW, support or incident purpose and the End User's instructions.
4. Security obligations
4.1 Each party will maintain technical and organisational measures appropriate to the Personal Data and risk under its control.
4.2 Without limiting Clause 4.1, the Channel Party will maintain:
- least-privilege access and unique user identities;
- multifactor authentication for privileged and remote access;
- secure credential and leaver management;
- encryption in transit and at rest where the Channel Party stores End User Data;
- logging appropriate to its access and service;
- current security patching and malware protection for systems it controls;
- incident-response and escalation procedures; and
- secure retention and deletion.
4.3 The Channel Party shall not disable or bypass Axtraction AI security, logging, licence or access controls, and shall not use an End User credential assigned to another person.
4.4 The Channel Party must promptly notify Axtraction AI of suspected credential compromise, unauthorised access to an Axtraction AI environment, security weakness or misuse affecting an Axtraction AI Product.
4.5 Axtraction AI may temporarily restrict Channel Party access where reasonably necessary to contain an active security risk. Axtraction AI will notify the Channel Party and End User as appropriate and restore authorised access when the risk is resolved.
5. Personal Data Breach
5.1 The Channel Party will notify Axtraction AI without undue delay and in any event within 24 hours after becoming aware of a confirmed or reasonably suspected Personal Data Breach affecting End User Data, Personal Data controlled by Axtraction AI or shared channel data.
5.2 The notice will provide available details of the event, affected data and persons, likely consequences, containment, remediation and contact point. Incomplete initial information may be supplemented through rolling updates.
5.3 The Channel Party will promptly contain, investigate and remediate a breach in systems it controls, preserve relevant evidence and reasonably cooperate with Axtraction AI and the affected End User.
5.4 The relevant Controller determines regulatory and Data Subject notification unless law independently requires another party to notify. No party will make a notification naming another without consultation unless legally required.
5.5 Axtraction AI's obligations for a breach in Axtraction AI systems are governed by the End User DPA and the Underlying Agreement.
6. Retention and deletion
6.1 Each party will retain channel contracting, signed agreement, accepted transaction, invoice, credit, tax and payment records for seven years or longer where law requires.
6.2 Unsuccessful pipeline and failed Deal Registration data will be deleted or anonymised within 12 months after closure unless required for an active dispute, legal obligation or genuine compliance investigation.
6.3 A Channel Party authorised under Clause 3.2 will retain End User Data only for the period agreed directly with the End User and will return or delete it when the authorised purpose ends, subject to law.
6.4 On termination of the Underlying Agreement or withdrawal of End User authorisation, the Channel Party will stop access, return or delete End User Data under its control, revoke credentials and confirm deletion on reasonable request.
6.5 Inaccessible routine backups and legally required records may remain protected until overwritten or the legal purpose ends. They may not be restored or used for another purpose.
7. International transfers and external providers
7.1 Each party is responsible for a lawful transfer mechanism and appropriate safeguards for Personal Data it transfers as independent Controller or as the End User's separate Processor.
7.2 Axtraction AI's Subprocessors for Fully Managed hosting and the Axtraction AI Managed API are listed and governed under the End User DPA. They apply to a particular End User only when Axtraction AI uses them for that deployment.
7.3 Infrastructure or LLM providers selected and controlled by an End User or Channel Party for Self-Hosted, On-Premises or Customer-Provided LLM use are not Axtraction AI Subprocessors. The selecting party is responsible for its provider agreement, DPA, location, security, retention and transfer mechanism.
7.4 The Channel Party shall not route End User Data to an unapproved model, AI service, endpoint or other provider in performing a service related to Axtraction AI.
8. Audit and assurance
8.1 Each party will provide information reasonably necessary to demonstrate compliance with this Channel DPA for Processing under its control, subject to confidentiality, privilege and security restrictions.
8.2 Axtraction AI may conduct a documentary audit of the Channel Party's data practices relating to Axtraction AI normally once in 12 months on at least 10 Business Days' notice. Additional audit is permitted after a Personal Data Breach, regulator request or reasonable evidence of material non-compliance.
8.3 An on-site or independent audit is available only where documentary information is reasonably insufficient. It must occur during business hours, avoid unreasonable disruption, use a non-competing auditor bound by confidentiality and remain limited to relevant systems and records.
8.4 The audit does not permit access to unrelated customer data, privileged material, another End User's information, source code, prompt text or information whose disclosure would materially weaken security.
8.5 Axtraction AI bears its ordinary audit cost unless a material breach is identified, in which case the Channel Party bears reasonable incremental cost and promptly remediates the breach.
9. Government requests
9.1 A party receiving a government or law-enforcement demand for the other's Personal Data will, unless prohibited, give prior notice, reasonably verify the demand, seek clarification or challenge where lawful and appropriate, and disclose only the minimum required.
9.2 If notice is temporarily prohibited, delayed notice will be provided when lawful.
10. Liability and priority
10.1 Liability under this Channel DPA is subject to the exclusions and single liability cap in the Underlying Agreement, in aggregate with all other claims under it.
10.2 Ordinary Personal Data, confidentiality and security claims remain within that cap. The Underlying Agreement's carve-outs from its liability cap continue to apply, including any indemnity obligation that the Underlying Agreement places outside that cap.
10.3 If this Channel DPA conflicts with the Underlying Agreement on a data-protection matter, this Channel DPA prevails for that matter. The Underlying Agreement prevails on commercial, pricing, appointment, IP ownership and other non-data matters.
10.4 Nothing in this Channel DPA requires insurance, source-code escrow, access to End User Data, a fixed penalty or a separate super-cap.
11. Privacy contact and change control
11.1 Axtraction AI's privacy contact is privacy@axtraction.ai.
11.2 This Channel DPA is published at https://axtraction.ai/channel-dpa. The then-current version applies through the Underlying Agreement, and Axtraction AI retains an archive and evidence of the version and acceptance date relevant to the Channel Party.
11.3 Axtraction AI may update this Channel DPA for legal, regulatory, security, operational or clarification reasons. Axtraction AI will give the Channel Party at least 30 days' advance email notice of a material change. Minor corrections may apply on publication, and urgent legal or critical-security changes may apply sooner with notice as soon as practicable.
11.4 An update may not automatically create a right for the Channel Party to access End User Data, appoint it as Axtraction AI's Subprocessor, add a Processing purpose or materially reduce security. Such a change requires an express written amendment to the relevant role and agreement.
11.5 Continued performance after a properly notified effective date constitutes acceptance to the extent permitted by law. If Applicable Data Protection Law requires affirmative acceptance of a material Processor contract change, the change takes effect only when validly accepted.
11.6 The signed Underlying Agreement remains fixed in the form signed and is amended only as that agreement permits. A website update to this Channel DPA does not amend its commercial terms.
This is the current version published on this page under Clause 11.2. Axtraction AI keeps an archive of each version and a record of the version and acceptance date that applies to each channel partner.
Write to legal@axtraction.ai.