Legal
End User DPA
Our standard terms for handling personal information.
What this document is
This End User Data Processing Addendum (the "End User DPA") forms part of the End-User Licence Agreement at https://axtraction.ai/eula and the applicable SOW or End User order (together, the "Underlying Agreement").
It applies where AXTRACTION AI SDN BHD (Company No. 202301042335 (1536252-X)) ("Axtraction AI" or the "Processor") processes Personal Data for the End User identified in the Underlying Agreement (the "Controller").
1. Definitions and scope
1.1 "Applicable Data Protection Law" means the Malaysian Personal Data Protection Act 2010 as amended and any other privacy or data-protection law applicable to the Processing, including the GDPR where applicable.
1.2 "Axtraction AI Managed API" means the AI inference service selected and managed by Axtraction AI using paid enterprise cloud and AI services approved under this End User DPA.
1.3 "Axtraction AI Technology" means Axtraction AI's software, source code, prompts, system instructions, orchestration, models, configuration, documentation and related proprietary technology.
1.4 "Business Day" means a day other than Saturday, Sunday or a public holiday in Kuala Lumpur, Malaysia.
1.5 "Customer Content" means documents, images, data, text, instructions and other content submitted by or for the Controller, together with extracted and generated results linked to it. It includes Personal Data within that content and excludes Axtraction AI Technology.
1.6 "Customer-Provided LLM" means an LLM service procured, licensed, paid for and controlled by the Controller and connected under an approved SOW change.
1.7 "Fully Managed" means deployment in infrastructure provisioned and controlled by Axtraction AI in the Controller's selected Singapore or Frankfurt hosting region.
1.8 "Personal Data", "Personal Data Breach", "Process", "Processing", "Processor", "Controller", "Data Subject" and "Subprocessor" have the meanings given by Applicable Data Protection Law. If a law uses materially equivalent terms, those terms are treated as corresponding to these definitions.
1.9 "Self-Hosted" means deployment in cloud or other infrastructure controlled by the Controller, its authorised reseller or another Controller-appointed operator. "On-Premises" means deployment installed in infrastructure physically located at premises selected or controlled by the Controller.
1.10 "SOW" means the statement of work governing the relevant Controller deployment.
1.11 This End User DPA applies only to Personal Data Processed by Axtraction AI as Processor. Each party remains separately responsible for Personal Data it Processes as an independent Controller, including ordinary business-contact, contracting and billing data.
1.12 If this End User DPA conflicts with the Underlying Agreement on a data-protection matter, this End User DPA prevails for that matter. Mandatory law always prevails.
2. Controller instructions and responsibilities
2.1 Axtraction AI will Process Personal Data only on the Controller's documented instructions, consisting of this End User DPA, the Underlying Agreement, SOW, authorised user activity, configured workflow and other written instructions accepted by Axtraction AI.
2.2 Axtraction AI may also Process Personal Data where required by law. Unless legally prohibited, Axtraction AI will inform the Controller before doing so.
2.3 If Axtraction AI reasonably believes an instruction violates Applicable Data Protection Law, Axtraction AI will notify the Controller and may suspend the affected Processing while the parties resolve it. Axtraction AI need not perform an unlawful instruction.
2.4 The Controller is responsible for:
- determining the purpose and lawful basis of Processing;
- providing required notices and obtaining required consents or other authority;
- ensuring Personal Data and instructions are lawful, relevant and reasonably necessary;
- responding to Data Subjects and regulators as Controller;
- setting appropriate user access and decision processes; and
- identifying any mandatory data-location, provider, retention or security requirement before deployment for inclusion in the SOW.
2.5 The Controller warrants that it has authority to provide the Personal Data and instruct the Processing described in Annex 1.
2.6 Biometric, health or children's data, classified or official-secret material and unusually regulated data may be Processed only where the SOW expressly approves the category and required safeguards.
3. Axtraction AI Processor obligations
3.1 Confidentiality. Axtraction AI ensures that personnel authorised to Process Personal Data are subject to confidentiality obligations and receive access only as necessary for their role.
3.2 Security. Axtraction AI implements and maintains the technical and organisational measures in Annex 2, taking account of the nature, scope, context and purposes of Processing and the risks to individuals.
3.3 Assistance. Taking account of the nature of Processing and information available to Axtraction AI, Axtraction AI will reasonably assist the Controller with security, Personal Data Breach response, data-protection impact assessments, prior consultation, Data Subject rights and compliance enquiries.
3.4 Records. Axtraction AI will maintain records of Processor activities required by Applicable Data Protection Law and provide information reasonably necessary to demonstrate compliance, subject to confidentiality, privilege and security restrictions.
3.5 No general-model training or cross-customer reuse. Axtraction AI will not use Customer Content to train a general model or reuse it for another customer. Axtraction AI may improve its own prompt templates, orchestration, extraction accuracy and service through abstract learning, performance analysis and non-identifying know-how that does not disclose or reproduce Customer Content.
3.6 Enterprise AI services. Axtraction AI uses paid enterprise cloud and AI services. Axtraction AI contractually configures and uses them so that customer inputs and outputs are not used to train a provider's general models without permission. This is not a promise of provider-side zero data retention: limited caching, safety, abuse-monitoring, security and service-operation Processing may occur under the provider's enterprise terms.
3.7 No sale or unrelated advertising. Axtraction AI will not sell Personal Data or use Customer Content for unrelated advertising.
4. Hosting, inference and deployment allocation
4.1 For Fully Managed deployment, the Controller chooses Singapore or Frankfurt. Axtraction AI hosts the application infrastructure, network, storage, database and application copy of Customer Content retained by Axtraction AI in that selected region.
4.2 AI inference may use global endpoints and may be Processed outside the selected hosting region. The selected hosting region is not a representation that every inference operation remains there.
4.3 Axtraction AI chooses and may change the paid enterprise model and provider used for the agreed use case. If the Controller has a mandatory AI-processing-location, provider or security restriction, it must be recorded in the SOW before deployment. Axtraction AI will select a route that satisfies an accepted restriction or will notify the Controller that it cannot support the affected use case.
4.4 If Axtraction AI cannot satisfy an accepted restriction using its managed providers, the Controller may request a Customer-Provided LLM through written SOW change control, or Axtraction AI may decline the affected use case.
4.5 A Customer-Provided LLM is selected and controlled by the Controller and is not an Axtraction AI Subprocessor. The Controller is responsible for its provider agreement, DPA, transfer mechanism, security, region, retention, credentials and compliance. Axtraction AI sends data to it only on the Controller's documented instruction and remains responsible for the integration Axtraction AI agrees to perform.
4.6 For Self-Hosted or On-Premises deployment, the Controller or its operator controls the primary application database, infrastructure access, backups and disaster recovery and acts in its own data-protection role for that infrastructure. Axtraction AI remains responsible for Personal Data it accesses or receives in providing the Axtraction AI application, support or Axtraction AI Managed API.
4.7 If a Self-Hosted or On-Premises deployment uses the Axtraction AI Managed API, the Personal Data sent to Axtraction AI is Processed by Axtraction AI and its applicable Subprocessors under this End User DPA. If it uses a Customer-Provided LLM, Axtraction AI does not retain a separate managed-inference content copy, but may retain limited integration, support, billing and security metadata.
5. Subprocessors
5.1 The Controller gives Axtraction AI general authorisation to use the Subprocessors listed in Annex 3 for the described services.
5.2 Axtraction AI will impose written data-protection obligations on each Subprocessor that are no less protective in substance than the obligations applicable to that Subprocessor's Processing under this End User DPA. Axtraction AI remains responsible for its Subprocessors to the extent required by Applicable Data Protection Law.
5.3 Axtraction AI will give the Controller and its registered Partner at least 30 days' advance notice before adding a completely new Subprocessor that will Process Customer Content, except where urgent use is required to address law or a critical security issue, in which case Axtraction AI will notify as soon as practicable.
5.4 The Controller may object within 15 days after notice on a specific, documented and reasonable data-protection or mandatory-compliance ground. A preference for a particular model or provider is not by itself a valid objection.
5.5 The parties will work in good faith to resolve a valid objection through a compliant alternative provider or route. If Axtraction AI cannot reasonably resolve it, the Controller may use an approved Customer-Provided LLM, discontinue the affected optional function, or, if the issue makes the agreed core use case legally impossible, terminate the affected Processing and service under the Underlying Agreement. No solution requires Axtraction AI to let the Controller select a model managed by Axtraction AI merely by preference.
5.6 Infrastructure providers selected and controlled solely by the Controller for Self-Hosted or On-Premises deployment, and the Controller's Customer-Provided LLM, are not Axtraction AI Subprocessors.
6. Personal Data Breach
6.1 Axtraction AI will notify the Controller without undue delay and provide a preliminary notice within 24 hours after becoming aware of a confirmed Personal Data Breach affecting Personal Data under Axtraction AI's control.
6.2 The initial notice may be incomplete. Axtraction AI will provide available information on the nature of the breach, likely consequences, affected data and individuals, containment and remediation, and a contact point, with rolling updates as investigation progresses.
6.3 Axtraction AI will take reasonable steps to contain, investigate and remediate the breach and preserve relevant records. Axtraction AI will reasonably assist with legally required notifications.
6.4 The Controller decides whether and how to notify a regulator or Data Subject unless law independently requires Axtraction AI to notify. Axtraction AI will not make a notification naming the Controller without prior consultation unless legally required.
6.5 A security event not involving the Controller's Personal Data is not a Personal Data Breach under this End User DPA, but may be handled under Axtraction AI's security and incident processes.
7. Data Subject requests and regulatory assistance
7.1 The Controller is responsible for verifying and responding to Data Subject requests.
7.2 If Axtraction AI directly receives a request concerning the Controller's Personal Data, Axtraction AI will forward it to the Controller within two Business Days and will not respond substantively unless instructed or legally required.
7.3 Axtraction AI will provide reasonably available technical and data assistance within five Business Days after a supported request, or sooner where reasonably required for the Controller's legal deadline.
7.4 Standard self-service search, export and deletion functions are included. Substantial custom retrieval, transformation or engineering assistance may be charged if agreed in advance and permitted by law.
7.5 For Self-Hosted or On-Premises deployment, the Controller or its operator handles requests against the primary database. Axtraction AI assists only for Personal Data under Axtraction AI control or within the Axtraction AI application functionality it supports.
8. Retention, return, deletion and legal holds
8.1 Default active-service retention. Axtraction AI's standard application-content retention is a rolling 12 months. For a service managed by Axtraction AI, Axtraction AI may retain the actual uploaded document or content, submitted input, composed inference request as applicable, extracted output and generated response for that period to provide customer-visible history, support, billing verification, reliability, accuracy improvement and prompt optimisation for the Controller's service.
8.2 Axtraction AI may retain customer-visible workflow and audit information for 12 months, including timestamps, user and system actions, source references, corrections, approvals, rejections, overrides and recorded outcomes.
8.3 Axtraction AI may retain operational and security metadata for up to 12 months, including page counts, input and output token counts, request identifiers, provider and model version, prompt-template version identifier, errors and security events. Relevant records may be kept longer for an active incident, dispute, legal claim or legal obligation.
8.4 Prompts and system instructions defined by Axtraction AI remain Axtraction AI Technology and are not disclosed to the Controller. Retention of an internal composed inference request does not give the Controller a right to inspect Axtraction AI prompt text.
8.5 For Self-Hosted or On-Premises deployment, the primary database and customer-visible history remain in the Controller environment under its retention rules. Clause 8.1 applies to content sent to the Axtraction AI Managed API. Where a Customer-Provided LLM is used, Clause 4.7 applies.
8.6 Early deletion on request. The Controller may request deletion of identified Personal Data before the standard period. Axtraction AI will comply where reasonably capable and legally permitted after confirming scope and explaining any resulting loss of history, support, reprocessing, accuracy investigation or auditability. Early deletion is not the default.
8.7 End of service. At SOW expiry or termination, Axtraction AI provides a 30-day read-only and self-service export period. After that period, Axtraction AI locks application access and begins deletion or irreversible anonymisation of active Customer Content under its standard process, ordinarily completing active-system deletion within 30 further days.
8.8 Encrypted backup copies are overwritten through the ordinary backup cycle and may remain for up to 90 days after active deletion. They remain protected, are not restored except for disaster recovery or legal need, and are deleted on the applicable cycle.
8.9 In Self-Hosted or On-Premises deployment, the Controller retains or deletes its own primary data. It must delete Axtraction AI application packages, containers and expired licence files as required by the End-User Licence Agreement; those items are not Controller Personal Data.
8.10 Axtraction AI is not the Controller's default evidence repository or legal archive. A legal hold changes the standard cycle only after Axtraction AI accepts a written request identifying the records, scope, duration, authorised contact and agreed security or fees. The Controller remains responsible for timely export and preservation.
8.11 Axtraction AI may retain a copy required by law, court order or an active legal claim. It will isolate and use that copy only for the retention purpose and delete it when the purpose ends.
9. Government and law-enforcement requests
9.1 Unless prohibited by law, Axtraction AI will notify the Controller before disclosing Personal Data in response to a government or law-enforcement demand.
9.2 Axtraction AI will reasonably verify the demand, seek clarification or challenge it where legally available and appropriate, disclose only the minimum legally required information, and record the legal basis and recipient.
9.3 If notice is temporarily prohibited, Axtraction AI will provide delayed notice when the prohibition ends, unless law continues to prohibit it.
9.4 Axtraction AI will require Subprocessors to pass through legally permitted notices of demands affecting Customer Content.
10. Audit and information rights
10.1 Axtraction AI will make available information reasonably necessary to demonstrate compliance, including appropriate security summaries, the ISO/IEC 27001:2022 certificate, relevant independent assurance information and reasonable questionnaire responses.
10.2 Detailed backup, restoration and security information is available on reasonable written request under confidentiality and security restrictions. Axtraction AI need not disclose source code, prompt text, raw penetration-test material, credentials, information that would weaken security, another customer's information or privileged material.
10.3 The Controller may exercise a remote documentary audit once in 12 months, except after a Personal Data Breach, regulator request or reasonable evidence of material non-compliance.
10.4 An on-site or independent audit is available only where documentary information is reasonably insufficient to satisfy a legal requirement. It requires at least 15 Business Days' notice, occurs during business hours, avoids disruption, uses an auditor that is not an Axtraction AI competitor and is bound by confidentiality, and is limited to relevant systems and records.
10.5 The Controller bears its audit cost. Axtraction AI bears its own ordinary response cost, but substantial custom assistance may be charged if agreed in advance. Axtraction AI will promptly remediate a material non-compliance identified by a valid audit.
11. International transfers
11.1 Axtraction AI and the Controller will ensure that a cross-border transfer has a lawful basis and safeguards required by Applicable Data Protection Law.
11.2 For Personal Data subject to Malaysian law, Axtraction AI will apply the requirements governing transfer outside Malaysia, including reasonable due diligence on destination protection and contractual, technical and organisational safeguards appropriate to the transfer.
11.3 Where the GDPR applies and Personal Data is transferred from the EEA to Axtraction AI in a country not covered by an applicable adequacy decision, the parties will use the European Commission's then-applicable Standard Contractual Clauses for controller-to-processor transfers (Module Two), completed consistently with Annex 4, unless another lawful transfer mechanism applies.
11.4 Where a Subprocessor transfer requires processor-to-processor clauses, Axtraction AI will implement the applicable Module Three or another lawful transfer mechanism.
11.5 The parties will reasonably cooperate on transfer-impact assessment and supplementary safeguards. Nothing requires disclosure of information prohibited by law or that would materially compromise security.
12. Liability and relationship to the Underlying Agreement
12.1 Liability arising under this End User DPA is subject to the exclusions and single liability cap in the End-User Licence Agreement, applied in aggregate with all other claims under the Underlying Agreement.
12.2 Ordinary Personal Data, confidentiality and security claims remain within that cap. Fraud, wilful misconduct, deliberate theft or unauthorised disclosure of trade secrets, and liability that law does not permit the parties to limit remain subject to the carve-outs in the End-User Licence Agreement.
12.3 This End User DPA creates no insurance, escrow, source-code access, fixed penalty or guaranteed compensation. Mandatory Data Subject rights and regulatory powers are unaffected.
13. Privacy contact
13.1 Axtraction AI's privacy and data-protection contact is privacy@axtraction.ai. Axtraction AI will provide current contact particulars for its responsible privacy officer on request.
13.2 The absence of a statutory requirement for Axtraction AI to register a Data Protection Officer does not reduce Axtraction AI's obligations under this End User DPA. Axtraction AI will reassess registration requirements if its Processing changes.
14. Publication and change control
14.1 This End User DPA is published at https://axtraction.ai/end-user-dpa. The then-current version applies through the End-User Licence Agreement, and Axtraction AI retains an archive and evidence of the version and acceptance date relevant to the Controller.
14.2 Axtraction AI may update this End User DPA for legal, regulatory, security, operational, clarification or Subprocessor reasons. Axtraction AI will give the Partner and registered Controller at least 30 days' advance email notice of a material change. Clause 5 separately governs a new Subprocessor.
14.3 A minor correction may take effect on publication. An urgent legal or critical-security change may take effect sooner with notice as soon as practicable.
14.4 An update may not during a current SOW automatically add a Processing purpose or Personal Data category, change the selected hosting region, extend the agreed 12-month application-content retention, permit training on Customer Content, or materially reduce security. Such a change requires written SOW change or renewal.
14.5 Continued use after a properly notified effective date constitutes acceptance to the extent permitted by law. If Applicable Data Protection Law requires affirmative acceptance of a material processor-contract change, that change takes effect for the Controller only when validly accepted.
14.6 Axtraction AI will maintain a private archive and a reasonable change summary and will provide a prior version on reasonable request.
Annex 1: Details of Processing
A. Subject matter and duration
Provision, operation, support, security and improvement of the Axtraction AI Product and FDE Professional Service for the term of the Underlying Agreement, the 30-day export period and the retention and deletion periods in Clause 8.
B. Nature and purpose
Receiving, transmitting, hosting, organising, securing, retrieving, displaying, extracting, classifying, analysing and generating results from Customer Content; providing customer history, workflow, auditability, support and incident response; measuring pages and tokens for billing and operations; improving reliability, extraction accuracy and Axtraction AI prompt templates without cross-customer content reuse or general-model training; and deleting or returning data.
C. Categories of Data Subjects
Controller users and personnel; employees and applicants; customers and their personnel; suppliers, vendors and business contacts; invoice, account and payment contacts; investigation subjects, complainants, witnesses and other persons appearing in lawfully held case material; and other persons whose data the Controller lawfully submits for the approved use case.
D. Types of Personal Data
Identity and contact data; account and user data; employment and organisational data; invoice, supplier, customer, bank and payment information; documents and images; case, allegation, offence and evidence information; user instructions and workflow actions; extracted and generated results; audit and security logs; usage, page and token metadata; and special categories expressly approved in the SOW.
E. Processing frequency
Continuous or intermittent as initiated by authorised users, configured workflow, support and ordinary service operation.
F. Controller instructions
The Underlying Agreement, SOW, authorised configuration and user activity, and written instructions accepted by Axtraction AI.
Annex 2: Technical and organisational measures
Axtraction AI maintains measures appropriate to its role and risk, including:
- an information-security management system aligned to Axtraction AI's ISO/IEC 27001:2022 certification scope;
- encryption of Personal Data in transit and at rest in production systems controlled by Axtraction AI using industry-standard protocols and managed keys;
- role-based least-privilege access, multifactor authentication for privileged access, joiner-mover-leaver controls and access review;
- logical tenant segregation and separate customer environments for unrelated Fully Managed customers, with approved group sharing only where the SOW permits;
- logging and monitoring of administrative, security and material application events;
- secure development, code review, change control, dependency management, vulnerability management and security testing;
- incident detection, response, escalation, evidence preservation and post-incident review;
- encrypted backups in the selected Fully Managed hosting region and periodic restoration testing, without an unstated RPO, RTO or cross-region failover guarantee;
- personnel confidentiality, security awareness and role-appropriate access controls;
- risk-based vendor assessment and written Subprocessor security and data-protection terms;
- data-retention, deletion and secure-disposal procedures; and
- business-continuity measures appropriate to the service architecture.
For Self-Hosted and On-Premises deployment, Axtraction AI applies these measures to the application components, support access and data under its control. The Controller or its operator is responsible for its infrastructure, operating system, database, network, VPN, IAM, backups, disaster recovery and physical security unless the SOW expressly reallocates a task.
Annex 3: Approved Subprocessors
The following paid enterprise services may Process Customer Content where applicable to the selected deployment and AI route managed by Axtraction AI:
| Provider or service | Purpose | Location characteristics |
|---|---|---|
| Google Cloud Platform, including Vertex AI and Gemini enterprise services | Fully Managed infrastructure and AI inference | Application hosting in the selected Singapore or Frankfurt region; Gemini inference may use global endpoints |
| Amazon Web Services, including Amazon Bedrock | Cloud and enterprise AI inference where selected by Axtraction AI | Region or cross-region processing according to the Axtraction AI configuration and applicable enterprise service |
| Microsoft Azure, including Azure OpenAI and Microsoft Foundry | Cloud and enterprise AI inference where selected by Axtraction AI | Region or global processing according to the Axtraction AI configuration and applicable enterprise service |
Axtraction AI selects the provider and model for the use case. Not every provider is used for every Controller. Infrastructure and LLM providers selected and controlled by the Controller for Self-Hosted, On-Premises or Customer-Provided LLM use are not Axtraction AI Subprocessors.
Annex 4: GDPR transfer completion
Where Clause 11.3 applies:
- the Controller is the data exporter and Axtraction AI is the data importer;
- Module Two of the European Commission Standard Contractual Clauses adopted by Decision (EU) 2021/914 applies;
- the description of transfer is Annex 1 of this End User DPA;
- the technical and organisational measures are Annex 2;
- the authorised Subprocessors are Annex 3;
- docking is permitted;
- optional general written authorisation for Subprocessors applies, with the notice period in Clause 5;
- the competent supervisory authority and governing EU Member State are those determined under the SCCs by reference to the exporter's establishment and the GDPR; and
- the parties' electronic acceptance of this End User DPA records their binding agreement to the completed SCCs to the extent permitted by applicable law, and they will execute a separate completion page if reasonably required.
This is the current version published on this page under Clause 14.1. Axtraction AI keeps a private archive of each version with a change summary, records the version and acceptance date that applies to each customer, and provides a prior version on reasonable request.
Write to legal@axtraction.ai.