Legal
Data Processing Addendum
Our standard terms for handling personal information.
Purpose and incorporation
This Data Processing Addendum (the "DPA") sets out the terms on which Axtraction AI processes Personal Data as a Processor for an End-User Controller in the Approved Products. It is incorporated by reference into, and forms part of, the End-User Licence Terms and the applicable Order under which those products are licensed (together, the "Underlying Agreement").
The customer that executes or accepts an Underlying Agreement (the "End-User") thereby accepts this DPA. Capitalised terms not defined here have the meaning given in the Underlying Agreement. On a data-protection or security matter this DPA prevails over the Underlying Agreement and over any marketing material, demonstration, or product description; on all other matters the Underlying Agreement prevails. The version incorporated is, at any time, the Current Version published on the DPA Page, amended only under Clause 9.
Details of Processing
These are Axtraction AI's standard data processing terms, not negotiated per customer, so this page carries no party names. Each End-User accepts them with its Underlying Agreement, and its particulars are recorded in Annex 1 and the applicable Order:
- End-User (legal name and company number).
- Deployment Model: Fully Managed or Self-Hosted.
- Processing particulars: per Annex 1.
- Effective date.
1. Definitions and roles
1.1 "Data Protection Laws" means the Malaysian Personal Data Protection Act 2010 as amended by the Personal Data Protection (Amendment) Act 2024, with its subsidiary legislation and guidelines (the "PDPA"), and, where applicable, the EU General Data Protection Regulation (GDPR) and any other applicable data-protection or privacy law.
1.2 "Controller", "Processor", "Personal Data", "Processing", "Data Subject", "Personal Data Breach", and "Sub-processor" have the meanings given under the Data Protection Laws; under the PDPA, references to a "data controller" and "data processor" are read accordingly.
1.3 "End-User Personal Data" means Personal Data processed within an End-User's deployment of the Approved Products. The End-User (or its own controller) is the Controller of it and Axtraction AI is the Processor, acting on the End-User's documented instructions under Clause 3.
1.4 "Approved Products" means the Axtraction AI products licensed to the End-User under the applicable Order, with the releases, updates, and modules of them Axtraction AI makes available under that Order. An "Approved Product" is any one of them.
1.4A "Order" means the order form, statement of work, schedule, or equivalent ordering record executed or accepted by the End-User under which the Approved Products are licensed, and in which the particulars this DPA assigns to it are recorded.
1.5 "Client Data" means all data, content, and materials provided by or on behalf of the End-User (or its own controller) to, or Processed within, the Approved Products, including AI input data (prompts, uploaded files, and workflow inputs) and the AI output generated from it. Client Data includes End-User Personal Data but is not limited to it.
1.6 "Sensitive Data" means Personal Data as to the physical or mental health or condition of a Data Subject, political opinions, religious or other similar beliefs, the commission or alleged commission of an offence, or any other category treated as "sensitive personal data" under the PDPA. For the gate in Clause 2.6 it also includes the further categories listed in the table in that clause.
1.7 "Regulated Sector" means any government or statutory body, government-linked company, listed company, financial institution, insurer, healthcare provider, education institution, legal-sector user, or defence or critical-infrastructure operator; any deployment involving employment, credit, insurance, healthcare, or public-sector eligibility decisioning; or any other sector or use case requiring enhanced data-protection, security, or governance review.
1.8 "Security Incident" means a confirmed or reasonably suspected event affecting the confidentiality, integrity, or availability of Client Data or of Axtraction AI systems, whether or not it is a Personal Data Breach. Every Personal Data Breach is a Security Incident; not every Security Incident is a Personal Data Breach.
1.9 "Fully Managed" and "Self-Hosted" are the Deployment Models identified in the applicable Order. Under a Fully Managed deployment Axtraction AI hosts and operates the Approved Product in a cloud environment it controls and supplies the Infrastructure Layer itself. Under a Self-Hosted deployment it runs in an Infrastructure Layer controlled by the End-User or another party it engages; what that party controls is the Infrastructure Layer, not the Axtraction Solution, which Axtraction AI alone delivers, configures, orchestrates, and supports in either model. Clause 2.11 allocates responsibility between the two layers.
1.10 "Axtraction Solution" means the Approved Products together with the prompts, templates, orchestration and model-selection logic, agent and tool definitions, guardrails, model weights, AI configuration, data-pipeline mapping, and product support, in each case as delivered by Axtraction AI.
1.11 "Infrastructure Layer" means the hardware, compute, storage, network, connectivity, public-cloud accounts, virtualisation and container platform, operating systems, identity provider, and other underlying environment on or in which an Approved Product runs, with their administration. It excludes the Axtraction Solution, and may be supplied or operated by Axtraction AI (as in a Fully Managed deployment), by the End-User, or by another party the End-User engages.
2. General obligations
2.1 Each party shall comply with the Data Protection Laws applicable to it in respect of all Processing under the Underlying Agreement.
2.2 Each party is responsible for establishing its own lawful basis for the Processing it carries out as a Controller, and for issuing its own privacy notices to its Data Subjects.
2.3 Where required by the PDPA, each party shall appoint and maintain one or more Data Protection Officers and register/notify as required by law, and shall make the relevant contact point available to the other party.
2.4 Client Data readiness warranty
The End-User represents and warrants that it has the lawful basis, authority, consent, notice, internal approval, and rights required to provide Client Data to Axtraction AI and to permit its Processing for the purposes of the Underlying Agreement. It is responsible for the accuracy, relevance, and lawful minimisation of that Client Data, and for giving each individual any notice, and obtaining any consent, the Data Protection Laws require before deployment.
2.5 Prohibited data upload; acceptable use
The End-User shall not upload or transmit to, or cause Axtraction AI to Process within, the Approved Products any data that is unlawful, stolen, or misappropriated; that it has no right or authority to provide or Process; that infringes a third party's rights; that has been improperly scraped; that contains malware; or that is export-controlled, state-secret, official-secret, or highly classified, unless Axtraction AI has approved the upload in writing and the details are recorded in Annex 1.
2.6 Sensitive Data pre-approval gate
The End-User shall not upload, or instruct Axtraction AI to Process, any Sensitive Data unless the category, purpose, hosting route, security controls, retention position, and approval status are first recorded in Annex 1 or a written processing schedule and Axtraction AI has approved the Processing in writing. The per-type requirements are:
| Sensitive Data type | Pre-approval requirement |
|---|---|
| Health / medical data | Enhanced security review and End-User confirmation of lawful basis. |
| Biometric data | Specific written approval and legal/security review. |
| Financial / payment data | Regulated Sector review (Clause 2.7) and security confirmation. |
| HR / employment-decision data | AI-output limitation and human-review controls (Clause 2.8 and the End-User Licence Terms). |
| Children's / student data | Education-sector and consent/notice review. |
| Government / official data | Enhanced confidentiality handling and access restrictions, recorded in the applicable Order. |
| Critical-infrastructure data | Security and business-continuity review. |
2.7 Regulated Sector pre-deployment review
Before an Approved Product is deployed for, or to Process data of, a Regulated Sector (Clause 1.7), Axtraction AI may require, and the End-User shall support, a pre-deployment security and data-protection review covering lawful basis, data categories, the AI use case, human review, security controls, hosting route, audit expectations, and exit obligations. For government, government-linked, listed-entity, or tender-linked engagements, the parties shall also record in the applicable Order the authorised users, official channels, restricted documents, conflict-of-interest declarations, and any public-sector recordkeeping requirement.
2.8 AI-output responsibility
The End-User acknowledges that AI-assisted outputs depend on the quality, completeness, currency, and legality of the Client Data, user prompts, system configuration, and approved workflow design. Axtraction AI is not responsible for inaccurate, incomplete, or inappropriate outputs to the extent caused by defective Client Data, incorrect user input, an unapproved use case, End-User-side configuration changes, or third-party system errors. That allocation does not diminish its own obligations under the Data Protection Laws, or the human-in-the-loop and non-discrimination obligations in the End-User Licence Terms.
2.9 Ownership of Client Data
As between Axtraction AI and the End-User, all Client Data, including all End-User Personal Data and the AI output generated from it, remains the property of the End-User (or of the third parties from whom it is derived). Axtraction AI acquires no right, title, or interest in it beyond the limited, non-exclusive licence to Process it for the purposes and duration of the Underlying Agreement. That ownership is unaffected by the Deployment Model, by hosting location, or by any suspension, dispute, or payment status, and continues after termination, subject only to Clauses 3.7 and 3.14. Nothing here affects Axtraction AI's ownership of the Approved Products and its platform intellectual property, or its use of learnings under Clause 3.12.
2.10 Completion condition (Annex 1)
Production Processing of Personal Data shall not commence for an End-User until Annex 1 has been completed for it, whether directly or by the applicable Order or an equivalent record supplying the Annex 1 particulars, so that the mandatory content required by Article 28(3) of the GDPR (where it applies) and the particulars required by the Data Protection Laws are recorded before Processing starts. Completing Annex 1 is likewise a condition of reliance on Annex 4A, and does not delay the breach duty in Clause 4.1 or the return and deletion of Personal Data under Clause 3.14.
2.11 Layer separation: the Axtraction Solution and the Infrastructure Layer
- (a) Axtraction AI is Processor of the Axtraction Solution layer. Axtraction AI is the Processor of Processing carried out by or within the Approved Products, on the Controller's documented instructions. That role extends to the Infrastructure Layer only where Axtraction AI itself supplies or operates it, as it does in a Fully Managed deployment.
- (b) An Infrastructure Layer supplied by another party is a separate processing relationship. Where a party other than Axtraction AI supplies or operates the Infrastructure Layer, it does so in its own right and as a Processor to the End-User for that layer. It is not a Sub-processor of Axtraction AI for the purposes of Clause 3.4, Annex 3, or Annex 4A. The End-User shall ensure that any such party is engaged, for as long as it supplies or operates that layer, on its own processor terms covering it, including the mandatory content Article 28(3) of the GDPR requires where it applies and an exit return-or-deletion and certification duty no less protective than Clause 3.7(g).
- (c) Responsibility boundary; controllership unchanged. Axtraction AI is not responsible for the security, availability, resilience, configuration, lawfulness, or data-protection compliance of an Infrastructure Layer the End-User or another party supplies or operates, and its own obligations under this DPA, including Annex 2, are limited to the components of the Axtraction Solution it actually operates or delivers. The End-User remains the Controller of End-User Personal Data throughout. This Clause 2.11 allocates processor-side responsibility between two layers; it does not split or dilute controllership, create joint controllership, or relieve any party of its own obligations under the Data Protection Laws.
- (d) No effect on the deployment or on deletion. Nothing in this Clause 2.11 permits the suspension, deactivation, degradation, or interruption of the deployment of an End-User current on its obligations, or conditions, delays, or fee-gates the return or deletion of Personal Data under Clauses 3.7 and 3.14.
2.12 Security telemetry: Axtraction AI as controller
Separately from the Processing it carries out as Processor under Clause 3, Axtraction AI generates and retains security telemetry recording export, bulk-retrieval, and related events in deployments it operates, in order to detect and investigate a suspected breach of the use restrictions in the End-User Licence Terms. In respect of any Personal Data contained in that telemetry, Axtraction AI acts as a controller and not as a Processor, because it determines the purpose of that Processing for its own account, and it relies on its legitimate interests in protecting its intellectual property and the integrity of the Approved Products. Axtraction AI shall Process that Personal Data only for that purpose, shall retain it for no longer than twelve (12) months unless it is required for an investigation that is under way or for the establishment, exercise, or defence of a legal claim, and shall protect it in accordance with Annex 2. The End-User shall inform the personnel concerned that the telemetry is collected. Nothing in this Clause 2.12 authorises the use of End-User Personal Data Processed within the Approved Products for that or for any other purpose: Clause 3.10 continues to govern that data, and this Clause 2.12 neither widens it nor creates an exception to it.
3. Our obligations as Processor
Where Axtraction AI processes End-User Personal Data as Processor for an End-User Controller:
3.1 Instructions
Axtraction AI shall process End-User Personal Data only on the End-User's documented instructions, which are the End-User Licence Terms, the applicable Order, this DPA, and any further written instructions, unless required to process by law (in which case it shall, where lawful, inform the Controller first).
3.1A Instructions that infringe (immediate notification)
Axtraction AI shall immediately inform the Controller if, in its opinion, an instruction given by or on behalf of the Controller infringes the GDPR, the PDPA, or any other applicable Data Protection Law, identifying the instruction and the provision it considers infringed. Where carrying out the instruction would cause it to act unlawfully, it may decline that instruction alone until the Controller confirms, withdraws, or amends it, and shall continue all other Processing on the Controller's documented instructions. This discharges the duty in the final paragraph of Article 28(3) of the GDPR and the equivalent duty under the PDPA; it imposes no general review of the Controller's instructions or compliance.
3.2 Confidentiality
Axtraction AI shall ensure that persons authorised to process the Personal Data are bound by appropriate confidentiality obligations.
3.3 Security
Axtraction AI shall implement and maintain the technical and organisational measures set out in Annex 2, appropriate to the risk.
3.4 Sub-processors
The End-User grants a general authorisation for Axtraction AI to engage the Sub-processors listed in Annex 3. Axtraction AI shall (a) give notice of intended additions or replacements and allow the Controller a reasonable period to object on reasonable data-protection grounds, and (b) impose data-protection obligations on each Sub-processor no less protective than this Clause 3, and remains liable for its Sub-processors' acts and omissions.
3.5 Assistance: Data Subject rights
Taking into account the nature of the Processing, Axtraction AI shall reasonably assist the Controller in responding to Data Subject requests (access, correction, erasure, portability, objection, and withdrawal of consent) under the Data Protection Laws.
3.6 Assistance: security, breach, DPIA
Axtraction AI shall reasonably assist the Controller with security, Personal Data Breach notification, data-protection impact assessments, and prior consultation with the regulator, to the extent the Controller does not otherwise have the relevant information.
3.7 Deletion or return
On expiry or termination of the Underlying Agreement, or of the Processing under it, Axtraction AI shall, at the Controller's choice, return the End-User Personal Data or delete it, and shall in either case delete all existing copies within its possession or control, being the Axtraction Solution layer and, where it supplies or operates it, the Infrastructure Layer (Clause 2.11(a)). Copies at an Infrastructure Layer it does not control are dealt with by paragraph (g). The periods below are those required by Article 28(3)(g) of the GDPR and the equivalent PDPA obligation:
- (a) Election. The Controller may elect in writing, up to the thirtieth (30th) day after expiry or termination, whether the End-User Personal Data is returned or deleted and, where return is elected, the reasonable format and delivery route. Axtraction AI shall give effect to that election and complete the return or deletion, and the deletion of all existing copies, within thirty (30) days of receiving it.
- (b) Absent an election. Absent a written election within thirty (30) days after expiry or termination, Axtraction AI shall delete the End-User Personal Data and all existing copies within a further thirty (30) days, so deletion is complete no later than sixty (60) days after expiry or termination.
- (c) Retention required by law. Paragraphs (a) and (b) do not apply to the extent, and for so long as, applicable law requires Axtraction AI to retain the End-User Personal Data or any copy. Where it relies on this paragraph it shall, before the applicable period expires, notify the Controller in writing, state the law relied on and the categories and volume retained, retain no more and no longer than that law requires, keep protecting what is retained under Annex 2, Process it only for the purpose that justifies the retention, and delete it as soon as that requirement ends.
- (d) Backups. Copies in backup or business-continuity media are deleted through the normal backup-expiry cycle rather than by targeted extraction. Until deleted they remain subject to Annex 2 and paragraph (c), and none may be accessed, restored, or Processed except for the purpose that justifies its retention or a restoration for the Controller's own benefit.
- (e) Certification. Axtraction AI shall confirm completion of the return or deletion in writing on the Controller's request, identifying anything retained under paragraph (c) or (d).
- (f) No charge, no gate. Return and deletion under this Clause 3.7 is provided on the terms of Clause 3.14, and prevails over any inconsistent period in an Underlying Agreement or Order.
- (g) Infrastructure Layer Axtraction AI does not control. Where the End-User, or another party it engages, supplies or operates the Infrastructure Layer (Clause 1.11), copies of End-User Personal Data may exist at that layer in storage, snapshots, images, replicas, caches, logs, and backups. Axtraction AI has no possession of, access to, or control over those copies, and paragraphs (a) to (f) do not extend to them. Instead:
- (i) Where another party controls the layer. The End-User shall ensure that party, as a Processor to it in its own right under Clause 2.11(b), is obliged on the same trigger and within the same periods as paragraphs (a) and (b) to return or delete, at the Controller's choice, all End-User Personal Data held at or written to that layer and to delete all existing copies, on terms no less protective than paragraphs (a) to (e), with paragraphs (c) and (d) applying mutatis mutandis, and to certify completion to the Controller in writing within ten (10) business days, identifying what was covered and anything retained.
- (ii) Where the End-User controls the layer. Copies at that layer are within the Controller's own possession or control and it is for the Controller to deal with them.
- (iii) Axtraction AI's role. At the Controller's request and so far as it is able, Axtraction AI shall identify the categories and locations of End-User Personal Data the Approved Products wrote to that layer, so the Controller and that party can give effect to sub-paragraph (i). That layer being outside its responsibility under Clause 2.11(c), Axtraction AI is not responsible for that party's performance, and nothing here delays paragraphs (a) to (f).
3.8 Records and audit
Axtraction AI shall maintain records of its Processing, make available the information reasonably necessary to demonstrate compliance with this Clause 3, and allow for and contribute to audits, subject to reasonable prior written notice of not less than ten (10) business days, confidentiality, no more than one audit in any twelve (12) month period (save after a Personal Data Breach affecting the Controller or where a regulator so directs), and the audit boundary in Clause 3.13.
3.9 Cross-border transfers
Any transfer of End-User Personal Data across borders shall comply with Clause 5 and Annex 4.
3.10 Data-use limitation
In its capacity as Processor, Axtraction AI shall use End-User Personal Data, and other Client Data Processed on the Controller's instructions, only to deliver, operate, configure, support, secure, troubleshoot, bill for, audit, and maintain the Approved Products and agreed services, and for any other purpose the Controller expressly authorises in writing. It shall not sell that data, disclose it for unrelated commercial purposes, or use it to build or enrich a profile of, or a product competing with, the Controller. No purpose here, and no reference to maintaining or improving the Approved Products, authorises model training or development, which Clause 3.11 governs exclusively.
3.11 First-party no-training default
Axtraction AI shall not itself use End-User Personal Data or other Client Data to train, fine-tune, embed, or develop any artificial-intelligence or machine-learning model, including any model of Axtraction AI's own and any public or third-party model, unless the Controller has expressly authorised that use in writing (in the applicable Order, Annex 1, or a written data-use instruction) specifying the model, purpose, and scope. The Sub-processor no-training positions and the retention rule in Annexes 3 and 4 are in addition to this default, not a substitute for it. Clause 3.12 permits aggregated, anonymised, or de-identified operational learnings to be used for the purposes stated there and for nothing else; it is not an exception to this default.
3.12 Aggregated and anonymised learning boundary
Axtraction AI may use aggregated, anonymised, or de-identified learnings from the operation of the Approved Products to maintain and improve system performance, security, usability, workflow design, error handling, and platform functionality, provided they are rendered non-identifiable to the de-identification standard under the Data Protection Laws, so that they are no longer Personal Data and cannot be used to re-identify any Controller, End-User, or Data Subject, and disclose no Client Data, confidential information, or Regulated Sector data. Neither those learnings nor any other de-identified data derived from End-User Personal Data or other Client Data may be used to train, fine-tune, embed, or develop any artificial-intelligence or machine-learning model, including any model of Axtraction AI's own, unless the Controller has expressly authorised that use in writing under Clause 3.11.
3.13 Audit boundary
The Controller's audit and information rights under Clause 3.8 are exercised through a controlled audit process and do not require Axtraction AI to disclose its source code or platform architecture, security-sensitive information whose disclosure would compromise the platform, confidential vendor or commercial arrangements, or any other customer's data. Where information necessary to demonstrate compliance is withheld on that basis, Axtraction AI shall provide a reasonable alternative means of verification: a summary, a certification, or an independent audit report.
3.14 Retention, deletion, and exit; no fee-gating of statutory rights
The return and deletion of Personal Data required by Clause 3.7 and the Data Protection Laws is provided without charge and is not conditioned on payment status, whatever any fee, retention, or payment-status provision elsewhere in this DPA, an Underlying Agreement, or an Order may say. On expiry or termination the End-User may also request export of its Client Data in a commercially reasonable format. Only services beyond that return and deletion, such as custom export formatting, migration support, data cleansing, or extended retention, are chargeable, and only where agreed in writing.
4. Personal Data Breach
4.1 A party that becomes aware of a Personal Data Breach affecting Personal Data processed under an Underlying Agreement shall notify the other party, and Axtraction AI shall notify the Controller, without undue delay and in any event within 72 hours of becoming aware.
4.2 The notification shall describe, so far as known, the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed. The parties shall cooperate in good faith on investigation, remediation, and any notification to a regulator or Data Subjects the Data Protection Laws require, including the PDPA's mandatory breach notification.
4.3 Security Incidents: notice and cooperation
Axtraction AI shall notify the End-User without undue delay of any Security Incident that is not a Personal Data Breach but materially affects the End-User's Client Data or its use of the Approved Products. An End-User affected by a Security Incident shall cooperate in good faith to investigate, contain, and remediate it, including by preserving relevant logs, promptly suspending compromised accounts and revoking exposed credentials within its control, and keeping non-public information about the incident confidential during active investigation. That confidentiality covers only Axtraction AI's security-sensitive information: it never restricts the End-User's own right or duty as Controller to notify a regulator or affected Data Subjects, or any disclosure required by law.
5. Cross-border transfers
5.1 A party shall not transfer Personal Data outside Malaysia (or, where the GDPR applies, outside the jurisdiction concerned) unless a lawful transfer basis is in place: for the PDPA, appropriate safeguards, a substantially-similar-law basis, or another permitted ground; and for the GDPR, an adequacy decision, Standard Contractual Clauses, or another Chapter V mechanism. The basis for each destination is recorded in Annex 4 and, for GDPR restricted transfers, Clause 5.3 and Annex 4A.
5.2 Where Standard Contractual Clauses apply, they are incorporated by reference and completed per Annex 4 and, for Clause 5.3 transfers, Annex 4A.
5.3 GDPR restricted transfers (Controller to Axtraction AI)
Where the GDPR applies and the Controller (or the establishment from which the Personal Data is transferred) is in the EU or EEA, each transfer of Personal Data from that Controller to Axtraction AI in Malaysia, including remote access from Malaysia for support, troubleshooting, configuration, or Forward Deployed Engineering, is a restricted transfer under Chapter V. The Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914 (the "EU SCCs") are incorporated for each such transfer between the End-User and Axtraction AI, using Module Two (controller to processor) or, where the End-User is itself a processor, Module Three, completed as set out in Annex 4A. On a conflict the EU SCCs prevail to the extent the GDPR requires. Axtraction AI maintains, and provides on request, a transfer impact assessment covering the Malaysia leg and the supplementary measures applied.
6. Security
6.1 Each party shall implement appropriate technical and organisational measures to protect Personal Data against unauthorised or unlawful Processing and accidental loss, destruction, or damage, consistent with Annex 2 and the security provisions of the End-User Licence Terms.
6.2 For Self-Hosted deployments, the party that controls the Infrastructure Layer is responsible for the security measures within it, and Axtraction AI's security responsibility follows the layer allocation in Clause 2.11(c).
6.3 Penetration testing
The End-User shall not conduct or permit penetration testing, vulnerability scanning, load or stress testing, red-team activity, exploit testing, traffic flooding, scraping, or other intrusive security testing against Axtraction AI systems or the environments it operates without its prior written approval. Approved testing must follow the scope, timing, environment, notification, rate limits, and remediation agreed with Axtraction AI. For Self-Hosted deployments the restriction applies to Axtraction AI-operated components only; the End-User may test its own environment, provided it does not test, degrade, or affect components Axtraction AI operates.
6.4 Third-party AI model provider risk
Certain Approved Products use third-party AI models, APIs, or cloud AI services, including those listed in Annex 3, which are subject to their providers' terms, availability, model behaviour, usage limits, safety filters, and possible interruptions. Axtraction AI remains responsible for its own obligations under this DPA, including its Clause 3.4 responsibility for Sub-processors and the transfer safeguards in Annex 4. Subject to those obligations and to the Data Protection Laws, it is not liable for changes or interruptions in a third-party model's behaviour or availability except as expressly agreed, and liability under this clause is subject to Clause 7.
6.5 Disaster recovery and backup scope
Backup and disaster-recovery commitments apply only as expressly stated in the applicable Order, Annex 2, or a project schedule. Standard backups are not by themselves disaster recovery, high availability, failover, zero data loss, or a guaranteed recovery-time or recovery-point objective.
6.6 Business-continuity boundary
Business-continuity obligations apply only where expressly stated in the applicable Order, an SLA, or a project schedule. Axtraction AI is not responsible for the End-User's own business continuity, staff availability, internal approvals, network, devices, identity provider, or client-side vendors.
7. Liability
7.1 Liability routing
Each party's liability under or in connection with this DPA is subject to the exclusions and limitations of liability in the applicable Underlying Agreement, except where the Data Protection Laws do not permit that limitation. This Clause 7.1 routes liability to those provisions; it does not create, enlarge, reduce, or displace anything in that agreement.
- (a) End-User. Liability under this DPA is subject to the liability provisions of the End-User Licence Terms, read with the carve-outs stated in them; nothing here subjects to a cap a liability those terms place outside it. Where this DPA and the Underlying Agreement are inconsistent as to the routing or limitation of a liability, the Underlying Agreement prevails.
- (b) Statutory floor. Nothing in this Clause 7.1 or in any Underlying Agreement limits or excludes a liability that cannot be limited or excluded under the Data Protection Laws, including the direct liability of a processor to a Data Subject under Article 82 of the GDPR, any liability arising from a regulator's exercise of its enforcement powers, and any liability under the PDPA that cannot be contracted out of.
8. Term, survival, and precedence
8.1 This DPA takes effect on the effective date recorded in the applicable Order and continues while any Personal Data is processed under the Underlying Agreement.
8.2 Obligations that by their nature should survive (including confidentiality, deletion and return, and breach cooperation for incidents arising during the term) survive termination.
8.3 This DPA is governed by the laws of Malaysia, and disputes are subject to the exclusive jurisdiction of the High Court of Malaya (Kuala Lumpur), consistent with the Underlying Agreement.
9. Versioning and change control
9.1 Publication and versioning
This DPA is published on its legal page at https://axtraction.ai/dpa (the "DPA Page") and is version-controlled. Each version carries a version number, a version date, and a stated effective date; the current version (the "Current Version") stays accessible there, and Axtraction AI keeps an archive of superseded versions, each with a change-log against the one before it, and provides a copy on request (a signed, dated copy under Clause 9.8).
9.2 Live incorporation and advance agreement
Each Underlying Agreement incorporates this DPA as amended from time to time under this Clause 9. The version that applies at any time is the Current Version then published, and each updated version takes effect automatically on its stated effective date without re-executing the Underlying Agreement, subject to Clauses 9.3 to 9.7. By executing or accepting an Underlying Agreement, the End-User agrees in advance to be bound by it as so amended.
9.3 Updates and notice
Axtraction AI may amend this DPA only to reflect a change in Data Protection Laws or regulator guidance, a change of Sub-processor, security measure, or operational practice, a change to the Approved Products, or a reasonable operational ground. For any change that materially and adversely affects the End-User's rights or obligations (a "Material Change"), it shall give at least thirty (30) days' prior written notice before the change takes effect, under the notices provision of the Underlying Agreement and by publication on the DPA Page. Where the Underlying Agreement was accepted by click-through or acceptance of an Order, notice is given by publication together with notice to the contact captured at acceptance. A Material Change takes effect only if both published and notified.
9.4 Prospective effect only
An updated version applies prospectively only, from its stated effective date, and not to Processing already carried out or to any right or liability accrued before that date. The version current when specific Processing was carried out continues to govern it.
9.5 Objection and exit (Material Adverse Change)
If a Material Change has a significant adverse effect on the End-User, it may object in writing within the notice period. On a valid objection: (a) the parties shall discuss the change in good faith; (b) the version that applied immediately before it continues to apply pending resolution; and (c) if the matter is unresolved after thirty (30) days, the End-User may continue under that prior version until the then-current term of its Underlying Agreement expires, or terminate that agreement without penalty on thirty (30) days' written notice, without prejudice to accrued rights. Paragraph (c) does not affect the Controller's standing veto under Clause 9.11. This DPA may not be severed from, or terminated separately while, an Underlying Agreement under which any Processing continues.
9.6 Non-material changes
Non-material changes, including Sub-processor additions or replacements under Clause 3.4 and clarifications, take effect on posting to the DPA Page.
9.7 No degradation
No update may materially reduce the security measures (Annex 2) or the overall level of protection for Personal Data under the version in effect immediately before it.
9.8 Signed copy
Axtraction AI shall, on request, provide a signed and dated copy of the applicable version to an End-User that requires a signed exhibit.
9.9 Good faith
Axtraction AI shall exercise its rights under this Clause 9 in good faith, for the grounds stated in Clause 9.3, and not arbitrarily or unreasonably.
9.10 Data-protection certainty
Nothing in this Clause 9 reduces the certainty of processing terms the Data Protection Laws require: at any time a single, complete, identifiable Current Version constitutes the binding processing terms; the archive preserves the terms that governed past Processing; and a signed, dated copy of any version is available under Clause 9.8.
9.11 GDPR Article 28 material changes (affirmative acceptance)
Where this DPA governs Processing subject to the GDPR, a Material Change to the mandatory content required by Article 28(3), namely the security measures (Annex 2), the nature, purpose, or categories of the Processing, or the return-or-deletion terms, takes effect against the Controller only on its affirmative acceptance (opt-in), not on notice alone. If it does not accept, the version that applied immediately before remains in force as to that Controller under Clause 9.5, without the Controller having to terminate: the objection right there is a standing veto to that extent. A change of Sub-processor remains governed by Clause 3.4, and the no-degradation floor in Clause 9.7 continues to apply.
Annex 1: Details of Processing
Completed per End-User. The fields are:
| Field | Entry |
|---|---|
| Subject matter of Processing | [e.g. providing the Approved Products to the End-User] |
| Nature and purpose | [Completed per End-User] |
| Duration | [Coterminous with the licence term] |
| Categories of Data Subjects | [e.g. End-User's staff, customers, case subjects] |
| Categories of Personal Data | [Completed per End-User] |
| Special/sensitive categories (if any) | [Completed per End-User / None]: any Sensitive Data is subject to the pre-approval gate in Clause 2.6 |
| Approved AI use case | [Completed per End-User] |
| Hosting region | [Completed per End-User]: where the Approved Products and End-User Personal Data are hosted |
| AI-inference region | [Completed per End-User]: where AI/LLM inference runs for this deployment |
| Training / model-development authorisation (if any) | [None unless expressly stated here]. See Clause 3.11. |
| Prohibited-data confirmation | End-User confirms compliance with Clause 2.5 |
| Controller | [End-User] |
| Processor (Axtraction Solution layer) | Axtraction AI Sdn Bhd |
| Infrastructure Layer (Clause 1.11): supplied / operated by | [Axtraction AI (Fully Managed) / End-User / another party the End-User engages: insert name]. Where it is not Axtraction AI, Clause 2.11 allocates responsibility and Clause 3.7(g) exit return or deletion. |
Annex 2: Technical and organisational security measures
Axtraction AI maintains an ISO/IEC 27001:2022-certified Information Security Management System (ISMS). Within it, the following measures are implemented and maintained, appropriate to the risk:
- Access control: role-based access, least-privilege, unique credentials, and multi-factor authentication for administrative access.
- Encryption: Personal Data encrypted in transit (TLS) and at rest for Fully Managed environments.
- Network & environment: a dedicated, isolated single-tenant environment per customer as standard for Fully Managed deployments; network segmentation; hardened baseline configurations. Self-Hosted deployments are single-tenant within the environment the End-User controls.
- Logging & monitoring: audit logging of access to Personal Data and security-relevant events, retained per policy.
- Vulnerability & patch management: regular patching, periodic vulnerability scanning, and secure-development practices.
- Personnel: confidentiality undertakings, background screening as permitted by law, and security-awareness training.
- Resilience: backup, disaster recovery, and periodic restoration testing appropriate to the deployment.
- Incident response: a documented Personal Data Breach response process aligned with Clause 4.
- Governance & audit: ISMS internal audits, management review, and independent surveillance audits under the ISO/IEC 27001:2022 certification.
- Sub-processor governance: security due diligence and contractual flow-down of these measures to Sub-processors (Annex 3).
Annex 3: Approved Sub-processors
| Sub-processor | Service provided | Processing location(s) | Cross-border safeguard |
|---|---|---|---|
| Google Cloud Platform (Google LLC / Google Cloud EMEA Ltd) | Primary cloud hosting, compute, and storage of the Approved Products (Fully Managed deployments) | As recorded in Annex 1 (hosting region) | Google Cloud DPA incorporating EU Standard Contractual Clauses; regional data residency (see Annex 4) |
| Amazon Web Services (Amazon Web Services, Inc. / Amazon Web Services EMEA SARL) | AI/LLM inference services (e.g. Amazon Bedrock), where the deployment uses that service, as recorded in Annex 1 | As recorded in Annex 1 (AI-inference region) | AWS Data Processing Addendum incorporating SCCs; Amazon Bedrock does not use customer inputs or outputs to train its foundation models (per AWS's published terms). Axtraction-side retention is governed by Annex 4 |
| Microsoft Azure (Microsoft Corporation / Microsoft Ireland Operations Ltd) | AI/LLM inference services (e.g. Azure OpenAI Service), where the deployment uses that service, as recorded in Annex 1 | As recorded in Annex 1 (AI-inference region) | Microsoft Products and Services DPA incorporating SCCs; the Azure OpenAI Service does not use customer prompts or completions to train Microsoft's or OpenAI's foundation models (per Microsoft's published terms). Axtraction-side retention is governed by Annex 4 |
Axtraction AI keeps this list current and gives notice of additions or replacements under Clause 3.4. The no-training statements above describe the Sub-processors' position; Axtraction AI's own obligation is in Clause 3.11.
Annex 3 change log
Each entry records a change to this Annex and the date it took effect, so an End-User can see what the list held at any past time. A change applies prospectively only, and the version of this Annex current when specific Processing was carried out continues to govern that Processing (Clause 9.4). Additions and replacements are notified under Clause 3.4 and take effect under Clause 9.6.
| Effective | DPA version | Change |
|---|---|---|
| 4 August 2026 | 1.0 | Baseline on first publication of this Annex: Google Cloud Platform (hosting), Amazon Web Services and Microsoft Azure (AI/LLM inference). |
Annex 4: Cross-border transfer mechanism
Data residency. End-User Personal Data is hosted in the hosting region recorded in Annex 1, agreed before deployment so a customer with an in-country residency requirement can meet it. AI/LLM inference runs in the AI-inference region recorded in Annex 1, which is the hosting region wherever the AI service supports it. A change of either region is a change to the Details of Processing, made only on the Controller's written instruction.
LLM processing. Certain Approved Products transmit input data, which may include Personal Data unless the End-User minimises or de-identifies it, to AI/LLM services (Amazon Bedrock and/or Azure OpenAI), contracted as data processors that do not use customer inputs or outputs to train their foundation models (per their published service terms). For Axtraction-side retention of inference data, the End-User may elect zero retention, in which case nothing is kept beyond the transient period needed to return the output; otherwise Axtraction AI keeps it for no longer than twelve (12) months, subject only to retention required by law. Axtraction AI's own use of that data for model training or development is governed by Clause 3.11 and Clause 3.12.
| Transfer | Exporter | Importer | Destination | Mechanism relied on |
|---|---|---|---|---|
| Hosting, PDPA-covered | Axtraction AI (Malaysia) | Google Cloud | The hosting region recorded in Annex 1 | Where that region is in Malaysia, no cross-border transfer arises. Otherwise PDPA s 129 (as amended 2024): a jurisdiction with substantially similar law or comparable protection, per Axtraction AI's recorded transfer assessment, plus the Google Cloud DPA incorporating SCCs |
| Hosting and remote access, GDPR-covered | The Controller (EU/EEA) | Axtraction AI / Google Cloud | The hosting region recorded in Annex 1 | Where that region is in the EU/EEA, no third-country hosting transfer arises. The Controller-to-Axtraction AI (Malaysia) leg, including remote access, is covered by the EU SCCs incorporated under Clause 5.3 and completed per Annex 4A, with a transfer impact assessment |
| LLM inference | Axtraction AI | AWS (Bedrock) / Microsoft Azure (Azure OpenAI) | The AI-inference region recorded in Annex 1 | Sub-processor DPA incorporating SCCs; no-training configuration at the Sub-processor; elective zero retention or twelve-month maximum on the Axtraction side. The basis is the recorded s 129 basis for PDPA-covered data, and Clause 5.3 with Annex 4A for GDPR-covered data |
Where an AI service is unavailable in the region recorded in Annex 1, Personal Data goes only to the nearest approved region under a mechanism in this table, and the End-User is informed first.
Annex 4A: EU SCC completion (Clause 5.3)
The EU SCCs incorporated under Clause 5.3 are completed as follows:
- Modules: Module Two (controller → processor); Module Three (processor → processor) where the exporting End-User is itself a processor.
- EU SCC Clause 7 (docking): included.
- EU SCC Clause 9 (sub-processors): Option 2 (general written authorisation); the authorised list is Annex 3; the notice period is that in Clause 3.4 of this DPA.
- EU SCC Clause 11(a) (independent dispute-resolution body): not selected.
- EU SCC Clause 13 / Annex I.C (supervisory authority): the supervisory authority of the exporter's establishment; otherwise as determined under that clause.
- EU SCC Clauses 17 and 18 (governing law and forum): the law and courts of the EU member state of the exporter's establishment; absent one, of Ireland.
- Annex I.A (parties): exporter: the End-User identified in the applicable Order; importer: Axtraction AI Sdn Bhd (Malaysia), as processor.
- Annex I.B (description of transfer): as recorded in Annex 1 as completed for that End-User; the transfer includes remote access from Malaysia to Personal Data hosted in the region recorded in Annex 1, for support, troubleshooting, configuration, and Forward Deployed Engineering, on a least-privilege basis.
- Annex II (technical and organisational measures): Annex 2 of this DPA, supplemented by hosting in the region recorded in Annex 1 and, where that region is outside the EU/EEA, the supplementary measures recorded in the transfer impact assessment referred to in Clause 5.3; encryption in transit and at rest; role-based least-privilege access for remote support; and logging of administrative access.
- Annex III (sub-processors): Annex 3 of this DPA.
Completing Annex 1 is a condition of reliance on this Annex 4A.
Acceptance
Each End-User accepts this DPA by executing or accepting its Underlying Agreement. Acceptance is recorded with its Annex 1 particulars rather than on this page. A signed and dated copy is available under Clause 9.8.
Write to privacy@axtraction.ai. That address also reaches our data protection officer; requests for a signed or superseded copy go there.
For anything else, info@axtraction.ai.