Legal
Partner DPA
How distributors and resellers must handle personal data.
Purpose and incorporation
This Partner Data Processing Addendum (the "Partner DPA", and in this document "this Addendum") is Axtraction AI's standard for the processing of Personal Data in the channel through which the Approved Products are supplied. It is incorporated by reference into, and forms part of, each of the following (each an "Underlying Agreement", being, in relation to any Counterparty, the agreement under which that Counterparty was authorised to supply, or to manage the supply of, the Approved Products):
- (a) the distribution agreement between Axtraction AI and a Distributor, under which the Distributor is appointed to market and manage an indirect reseller channel for the Approved Products; and
- (b) each reseller agreement between Axtraction AI and a Reseller, under which the Reseller is authorised to market, promote, resell and distribute the Approved Products for onward supply to End-Users.
Every party that executes or accepts an Underlying Agreement (each a "Counterparty") thereby accepts this Addendum in the role module(s) identified in the Cover Sheet below. Capitalised terms used in this Addendum are defined in Section 1; a capitalised term used but not defined in this Addendum has the meaning given to it in the Underlying Agreement under which the Counterparty concerned was authorised, and where a term is defined both in this Addendum and in that agreement, the definition in this Addendum governs for the purposes of this Addendum. In the event of conflict on a data-protection matter, this Addendum prevails over the Underlying Agreement; on all other matters the Underlying Agreement prevails. This Addendum also prevails over any marketing materials, demonstrations, pitch decks, partner or reseller statements, and general product descriptions in respect of data-protection and security matters, and no such material varies this Addendum. This Addendum is published and version-controlled on the Legal Documents Portal as set out in Section 11; the version incorporated into an Underlying Agreement is, at any time, the Current Version published on the Legal Documents Portal, as amended from time to time strictly in accordance with Section 11 (which implements the Change-Control Process). The data-protection precedence stated above (this Addendum prevails on a data-protection matter; the Underlying Agreement prevails on all other matters) is unaffected.
Relationship to the End-User DPA
The two documents. The "End-User DPA" means the Data Processing Addendum published by Axtraction AI at https://axtraction.ai/dpa, as amended from time to time in accordance with its own versioning and change-control provisions. The End-User DPA is the document each End-User accepts through the End-User Licence Terms, and it contains Axtraction AI's obligations as Processor to an End-User Controller (its Section 3, "Module A"), together with the details of processing, the technical and organisational security measures, the approved Sub-processors and the cross-border transfer mechanism (its Annexes 1, 2, 3, 4 and 4A). This Addendum is the document a Distributor and a Reseller accepts. It does not reproduce the End-User DPA and does not vary it.
Numbering is continuous with the standard from which this Addendum is derived. This Addendum retains the clause, section and annex numbering of Axtraction AI's former single channel-wide standard, so that every existing reference to a numbered provision of that standard, and in particular every reference to Annex 5 and to any Part of it, to Section 11 and to Clause 11.5A, and to Module B and Module C, resolves without change. Where a provision of that standard is not reproduced here because it belongs to the End-User DPA, its number is retained as a signpost and is not reused.
How references resolve. In this Addendum, including in Annex 5:
- (i) a reference to Section 3, or to any Clause within it (Clauses 3.1 to 3.14), is a reference to the corresponding provision of the End-User DPA, the numbering of which corresponds; and
- (ii) a reference to Annex 1, Annex 2, Annex 3, Annex 4 or Annex 4A is a reference to that annex of the End-User DPA; and
- (iii) a reference in Annex 5 to "this DPA" is a reference to this Addendum, read together with the End-User DPA on any matter within Section 3 or within Annexes 1 to 4A. Annex 5 is reproduced without amendment so that every existing reference to it, and to any Part of it, resolves unchanged.
Reading the two together. Where both documents apply to the same Processing, they are read together: the End-User DPA governs Axtraction AI's Processing of End-User Personal Data as Processor for the End-User Controller, and this Addendum governs the channel relationship, the restriction on a Counterparty's access to End-User Personal Data, the operational security standard in Annex 5, and the versioning of both as they apply to a Counterparty. Both documents are maintained under the same Change-Control Process, so that a single update propagates consistently (Clause 11.10). Neither document confers on a Counterparty any right of access to End-User Personal Data.
Cover Sheet (complete per Counterparty)
| Field | Entry |
|---|---|
| Counterparty (legal name & company no.) | [Insert] |
| Counterparty type | ☐ Distributor ☐ Reseller |
| Applicable role module(s) | ☐ Module B (Independent Controllers) ☐ Module C (No-Processing Restriction) ☐ Module A (Processor), only where expressly authorised in writing under Clause 5.2 |
| Infrastructure Layer supplied or operated for any End-User? | ☐ No ☐ Yes (if yes, Clause 2.11, Clause 5.4 and Clause 3.7(g) of the End-User DPA apply; record the date of the Clause 2.11(b) written confirmation: [Insert]) |
| Details of Processing (only where Module A is authorised under Clause 5.2) | per Annex 1 of the End-User DPA |
| Effective date | [Insert] |
1. Definitions and roles
1.1 "Data Protection Laws" means the Malaysian Personal Data Protection Act 2010, as amended by the Personal Data Protection (Amendment) Act 2024 and its subsidiary legislation and guidelines (the "PDPA"), and, where applicable to a given processing activity, the EU General Data Protection Regulation (GDPR) and any other applicable data-protection or privacy law.
1.2 "Controller", "Processor", "Personal Data", "Processing", "Data Subject", "Personal Data Breach", and "Sub-processor" have the meanings given under the Data Protection Laws. Under the PDPA, references to a "data controller" and "data processor" are read accordingly.
1.3 "End-User Personal Data" means Personal Data processed within an End-User's deployment of the Approved Products.
"Channel Data" means Personal Data Processed by Axtraction AI, the Distributor, or a Reseller for the purpose of establishing, operating, administering, or enforcing the channel, being:
- (a) business-contact, marketing, onboarding, due-diligence, know-your-customer, beneficial-ownership, deal-registration, pipeline, and channel-administration Personal Data; and
- (b) the contracting, quotation, ordering, invoicing, payment, collection, credit-control, dunning, set-off, dispute, insolvency, tax, accounting, audit, records-retention, and regulatory-compliance Personal Data generated by the buy-sell model, under which Axtraction AI invoices and collects from the Distributor and the Distributor invoices and collects from each Reseller.
Channel Data includes the business contact data of the personnel, officers, directors, and authorised signatories of a Distributor, a Reseller, or an End-User that is held for any of those purposes, and it is the Personal Data in respect of which the Distributor acts as an independent controller responsible for its own compliance in that capacity. Channel Data does not include End-User Personal Data, and nothing in this definition authorises a Distributor or Reseller to access or Process End-User Personal Data, which remains governed by Module C (Section 5).
1.4 Role modules
The following modules allocate roles. A Counterparty may be subject to more than one module.
- Module A: Axtraction AI as Processor: applies to End-User Personal Data, where the End-User (or its own controller) is the Controller and Axtraction AI is the Processor acting on the End-User's documented instructions. Module A is set out in Section 3 of the End-User DPA and is not reproduced in this Addendum. It applies to a Counterparty only where Axtraction AI expressly authorises that Counterparty in writing to Process End-User Personal Data, in which case Clause 5.2 applies it to that Counterparty mutatis mutandis.
- Module B: Independent Controllers (Section 4): applies to Channel Data, where each of Axtraction AI and the Distributor or Reseller acts as an independent Controller.
- Module C: Channel No-Processing Restriction (Section 5): applies to the Distributor and Resellers in respect of End-User Personal Data.
1.5 "Client Data" means all data, records, documents, content, system inputs, uploaded materials, user data, Personal Data, and operational information provided by or on behalf of a Counterparty (or its End-User or the End-User's own controller) to, or Processed within, the Approved Products, including AI input data (prompts, uploaded files, and workflow inputs) and AI output generated from it. Client Data includes End-User Personal Data but is not limited to Personal Data.
1.6 "Sensitive Data" means Personal Data consisting of information as to the physical or mental health or condition of a Data Subject, political opinions, religious beliefs or other beliefs of a similar nature, the commission or alleged commission of any offence, or any other category treated as "sensitive personal data" under the PDPA; and, for the purposes of the pre-approval gate in Clause 2.6, also includes biometric data, financial or payment data, data used for HR or employment decisioning, children's or student data, government or official data, and critical-infrastructure data.
1.7 "Regulated Sector" means any government or statutory body, government-linked company (GLC), Berhad or public listed company, financial institution, insurer, healthcare provider, education institution, legal-sector user, defence or critical-infrastructure operator; or any deployment involving employment or HR decisioning, credit, insurance, healthcare, or public-sector eligibility decisioning; or any other sector or use case requiring enhanced procurement, data-protection, security, or governance review.
1.8 "Security Incident" means a confirmed or reasonably suspected event affecting the confidentiality, integrity, or availability of Client Data or of Axtraction AI systems, whether or not it constitutes a Personal Data Breach. A Personal Data Breach is always a Security Incident; not every Security Incident is a Personal Data Breach.
1.9 "Fully Managed" and "Self-Hosted" are the Deployment Models identified in the Cover Sheet, in the applicable Underlying Agreement, and in the applicable Order. Under a Fully Managed deployment Axtraction AI hosts and operates the Approved Product in a cloud environment it controls, and supplies the Infrastructure Layer itself. Under a Self-Hosted deployment the Approved Product runs in an Infrastructure Layer controlled by the End-User, or by a Reseller supplying or operating that layer for the End-User, and Axtraction AI's responsibility is limited to the components it actually operates or delivers. In either Deployment Model the Axtraction Solution is delivered, configured, orchestrated, and supported exclusively by Axtraction AI; what the End-User or a Reseller controls under a Self-Hosted deployment is the Infrastructure Layer and not the Axtraction Solution. Clause 2.11 allocates responsibility between the two layers.
1.10 "Axtraction Solution" means the Approved Products together with the Base Codex, prompts, templates, orchestration and model-selection logic, agent and tool definitions, guardrails, model weights, AI configuration, data-pipeline mapping, and product support, in each case as delivered by Axtraction AI. Delivery of the Axtraction Solution is exclusively Axtraction AI's.
"Infrastructure Layer" means the hardware, servers, compute, storage, network, connectivity, public-cloud subscriptions and accounts, virtualisation and container platform, operating systems, identity provider, and other underlying operating environment on or in which an Approved Product runs, together with their administration, and excludes the Axtraction Solution. The Infrastructure Layer may be supplied or operated by Axtraction AI (as in a Fully Managed deployment), by the End-User, or by a Reseller.
1.11 Channel and product terms
In this Addendum:
"Affiliate" means an entity controlling, controlled by, or under common control with a person, "control" meaning ownership of more than fifty percent (50%) of the voting securities of, or power to direct the management of, that entity.
"Approved Products" means the AI product lines owned by Axtraction AI that Axtraction AI has authorised for supply through the channel, as identified in the applicable Underlying Agreement and Order.
"Base Codex" means Axtraction AI's proprietary software foundation, source code, object code, AI workflow structure, automation engine, model orchestration methodology, prompt architecture, system logic, reusable modules, technical documentation, product methodology, and deployment know-how, together with its model weights, adapters and fine-tunes, embeddings and vector indices, evaluation and benchmark datasets, guardrails and safety filters, tool, function and agent definitions, and the selection, sequencing and configuration of third-party models, in each case whether or not reduced to writing and whether existing now or created later. A reference in this Addendum to "Base Codex material" is a reference to any prompt, template, orchestration sequence, agent or tool definition, guardrail, evaluation dataset, model weight, or other material comprising, embedding, or revealing the Base Codex.
"Distributor" means a person appointed by Axtraction AI under an Underlying Agreement to market and manage an indirect reseller channel for the Approved Products in a defined territory.
"Reseller" means a technology sales partner, value-added reseller, or systems integrator authorised under an Underlying Agreement executed directly with Axtraction AI to market, promote, resell and distribute the Approved Products for onward supply to End-Users.
"End-User" means the ultimate customer entity that licenses and operates an Approved Product for its own internal business purposes.
"End-User Licence Terms" means the standalone licence and acceptance terms published on the Legal Documents Portal that every End-User accepts before deployment.
"Order" means the written order form or equivalent written record for a transaction, issued or countersigned by Axtraction AI, recording the End-User, the Approved Products supplied, the Deployment Model, the licence term, the fees, any acceptance criteria, and any statement of work for Forward Deployed Engineering customisation.
"Distributor Price" means the amount Axtraction AI invoices the Distributor for a transaction under the applicable Underlying Agreement.
"Legal Documents Portal", also referred to in this Addendum as the Portal, means the versioned web location at which Axtraction AI publishes and version-controls its standard channel documents, including the DPA Page (Clause 11.1) and the End-User DPA. The version published there governs.
"Distributor Schedule Pack" means the distributor-specific companion document that populates the variable values and schedule entries of a Distributor's Underlying Agreement.
"Change-Control Process" means the bounded process by which a standard channel document is amended, updated or replaced, being, for this Addendum, the process in Section 11, and, for an Underlying Agreement, the corresponding change-control provision of that agreement.
"Party" and "Parties" mean, in relation to a matter arising under an Underlying Agreement, the parties to that agreement; and in relation to a matter arising under this Addendum, Axtraction AI and the Counterparty concerned.
1.12 Minimum Control Floor
Each Underlying Agreement imposes, as a condition of any Self-Hosted deployment and on every person deploying or operating an Approved Product under a Self-Hosted Deployment Model, a minimum deployment-control standard (the "Minimum Control Floor"). This Addendum does not impose that standard; the Underlying Agreement does. This Clause 1.12 records its content so that it can be understood and applied without reference to any other document, and nothing in this Addendum narrows, waives, qualifies, or creates any exception to it. The Minimum Control Floor is that:
- (a) The standard. No prompt, template, orchestration sequence, agent or tool definition, guardrail, evaluation dataset, or model weight may be deployed, stored, transmitted, backed up, snapshotted, imaged, or held in clear text or in any other form from which its content can be read, reconstructed, or exported by a person having administrative, root, hypervisor, storage, or backup access to the operating environment.
- (b) Permitted form; Sealed Runtime Component. Such material shall be served remotely from an environment Axtraction AI controls, or shall exist in decrypted form only transiently, in volatile memory, within a Sealed Runtime Component and only for so long as an inference request is being served. A "Sealed Runtime Component" is a runtime environment specified in writing by Axtraction AI for the relevant component that, at a minimum, (i) holds decryption keys outside the operating environment or within a hardware-backed key store to which no administrator of that environment has access, (ii) prevents the reading, dumping, copying, snapshotting, imaging, mounting or export of process memory, container images, volumes, snapshots, images and backups containing that material by any person having administrative, root, hypervisor, storage or backup access to the operating environment, and in particular prevents any hypervisor-level or host-level capture of the memory or state of the runtime, any suspend-to-disk, checkpoint, live-migration or virtual-machine snapshot that would expose that material, any storage-layer, volume-level or replica copy of it, and any backup, archive or disaster-recovery copy of it, so that the access described in paragraph (a) is defeated in each case, and (iii) generates tamper-evidence on any attempt to do so. Where Axtraction AI has not specified a Sealed Runtime Component for a component, that component may not be deployed Self-Hosted.
- (c) Transport integrity; no interception or inspection. Where any material within paragraph (a), or any inference request or response carrying or capable of revealing it, or any decryption key or credential for it, passes between an environment Axtraction AI controls and a Sealed Runtime Component or any other component of the deployment: (i) both endpoints authenticate each other by mutual cryptographic authentication to the standard Axtraction AI specifies in writing and, absent a specified standard, by mutually authenticated TLS 1.3 or better, the client credentials and private keys being held as paragraph (b)(i) requires and not being available to any person having administrative, root, hypervisor, storage or backup access to the operating environment; (ii) the traffic is encrypted in transit end to end between those two endpoints, so that neither its content nor any material within paragraph (a) that it carries is available in clear text at any intermediate point, and so that its confidentiality and integrity do not depend on any control operated by a person other than Axtraction AI; and (iii) no person supplying, operating or administering the operating environment, and no person acting for or engaged by such a person, intercepts, terminates, proxies, mirrors, bridges, decrypts, inspects, modifies, logs, records or retains that traffic or its content, whether by a TLS-terminating or TLS-inspecting proxy, gateway, firewall or load balancer, a network tap, span port or packet capture, a service mesh, sidecar or in-cluster interception, an endpoint, agent-based or data-loss-prevention inspection, the installation or use of any certificate authority, trust anchor, root certificate or key on any endpoint for that purpose, or any other means. Connection-level metadata that does not reveal the content of the traffic, and the telemetry and audit logging the Underlying Agreement requires, are not prevented by this paragraph (c).
- (d) Condition precedent to release; certification; no waiver by release. Satisfaction of paragraphs (a) to (c) is a condition precedent to release of the affected component for Self-Hosted deployment and is a continuing condition of its continued deployment. Before release, a written certification signed by a director or equivalent officer confirming that they are satisfied for that deployment is delivered to Axtraction AI, and is re-certified annually and on any material change to the operating environment. A certification later shown to have been materially inaccurate when given is deemed never to have been delivered, and the condition precedent is accordingly treated as never having been satisfied for that deployment. Release, deployment, activation, go-live, or acceptance of payment is not, and shall not be relied on as, evidence of satisfaction of the Minimum Control Floor, an approval under it, or a waiver, variation, or release of it, whether by conduct, election, course of dealing, estoppel, or otherwise.
- (e) Failure after release. The consequences of a failure to satisfy paragraphs (a) to (d) after release are those stated in the Underlying Agreement, including the remediation period it allows for a non-exposing technical control failure, the withdrawal of the affected component, the requirement that the affected functionality be provided only under the Fully Managed Deployment Model, and the characterisation of the breach; and those consequences operate subject at all times to the Paid-Up End-User Protection in Clause 1.14.
1.13 Covered Person
A "Covered Person" is a person whom an Underlying Agreement brings within its anti-extraction, anti-derivation, deployment-control and confidentiality obligations by reason of the access that person holds, being the Distributor, each Reseller, their respective Affiliates, the personnel, contractors, sub-contractors and agents of each of them, and any other person to whom the Distributor or a Reseller gives access to an Approved Product, to any demonstration, sandbox, proof-of-concept or trial environment, or to any part of the Base Codex. An End-User is a Covered Person only where the Distributor or a Reseller gives it access otherwise than under the End-User Licence Terms. Under each Underlying Agreement, the person giving that access must procure that each Covered Person is bound in writing, before the access is given, by obligations no less protective than that agreement's deployment-control, anti-extraction, anti-derivation and confidentiality obligations, and is liable for that Covered Person's acts and omissions as if they were its own. This Clause 1.13 records who is a Covered Person and does not itself confer, enlarge or reduce that status.
1.14 Paid-Up End-User Protection
The "Paid-Up End-User Protection" is the protection conferred by each Underlying Agreement and by the End-User Licence Terms, namely that no person shall suspend, deactivate, degrade, or interrupt, or inject any payment-related notice into, the deployment of an End-User that is current on its own payment and other obligations; that any suspension right against an End-User must be established directly in the End-User Licence Terms and may be exercised only in respect of that End-User's own default; and that the protection prevails over every other provision of the Underlying Agreement, of every schedule to it, and of every document incorporated into it, including any provision on suspension, activation gates, direct-billing step-in, channel-level measures, enforcement support, credit support, key-person remedies, and change control. The Paid-Up End-User Protection prevails over every provision of this Addendum and of Annex 5, and nothing in this Addendum may be read, or exercised, so as to permit what it prohibits. It is not qualified by any payment, dispute, suspension, or termination provision, wherever appearing.
2. General obligations (all modules)
2.1 Each party shall comply with the Data Protection Laws applicable to it in respect of all Processing under the Underlying Agreement.
2.2 Each party is responsible for establishing its own lawful basis for the Processing it carries out as a Controller, and for issuing its own privacy notices to its Data Subjects.
2.3 Where required by the PDPA, each party shall appoint and maintain one or more Data Protection Officers and register/notify as required by law, and shall make the relevant contact point available to the other party.
2.4 Client Data readiness warranty
Each Counterparty that provides, uploads, or instructs the Processing of Client Data represents and warrants that it has the lawful basis, authority, consent, notice, internal approval, and rights required to provide that Client Data to Axtraction AI and to permit its Processing for the purposes of the Approved Products and the Underlying Agreement. That Counterparty is responsible for the accuracy, relevance, and lawful minimisation of the Client Data and for ensuring that, before deployment, each individual whose Personal Data is included has been given any notice, and (where required) has given any consent, required by the Data Protection Laws. A readiness checklist supporting this warranty is at Annex 5 (Part L). The corresponding warranty of an End-User in respect of its own deployment is given under the End-User DPA.
2.5 Prohibited data upload; acceptable use
No Counterparty shall upload or transmit to, or cause Axtraction AI to Process within, the Approved Products any data that is unlawful, stolen, or misappropriated; that it has no legal right or authority to provide or Process; that infringes a third party's intellectual-property or other rights; that has been improperly scraped or collected; that contains malware or malicious code; or that is export-controlled, state-secret, official-secret, or highly classified, unless in each case Axtraction AI has expressly approved the upload in writing and the relevant details are recorded in Annex 1. This Clause 2.5 supplements the acceptable-use provisions of the End-User Licence Terms, which apply the same bar downstream to End-Users.
2.6 Sensitive Data pre-approval gate
A Counterparty shall not upload, or instruct Axtraction AI to Process, any Sensitive Data unless the data category, purpose, hosting route, security controls, retention position, and approval status are first recorded in Annex 1 or a written data-processing schedule and Axtraction AI has approved the Processing in writing. The following per-type requirements apply:
| Sensitive Data type | Pre-approval requirement |
|---|---|
| Health / medical data | Enhanced security review and Counterparty confirmation of lawful basis. |
| Biometric data | Specific written approval and legal/security review. |
| Financial / payment data | Regulated Sector review (Clause 2.7) and security confirmation. |
| HR / employment-decision data | AI-output limitation and human-review controls (Clause 2.8 and the End-User Licence Terms). |
| Children's / student data | Education-sector and consent/notice review. |
| Government / official data | Government / GLC / Berhad handling protocol (Annex 5 Part K) and access restrictions. |
| Critical-infrastructure data | Security and business-continuity review. |
The "Special/sensitive categories" field in Annex 1 records the outcome of this gate.
2.7 Regulated Sector pre-deployment review
Before any Approved Product is deployed for use in, or to Process data of, a Regulated Sector (Clause 1.7), Axtraction AI may require, and the relevant Counterparty shall support, a pre-deployment security and data-protection review. The review may cover lawful basis, data categories, the AI use case, human review, security controls, hosting route, audit expectations, procurement requirements, and exit obligations. This Clause 2.7 operates together with the Regulated Sector security-review trigger and enhanced-handling protocol in Annex 5 (Parts I and K) and any pre-clearance obligation in the Underlying Agreement.
2.8 AI-output responsibility
Each Counterparty acknowledges that AI-assisted outputs of the Approved Products depend on the quality, completeness, format, currency, and legality of the Client Data, user prompts, system configuration, and approved workflow design. Axtraction AI is not responsible for inaccurate, incomplete, or inappropriate outputs to the extent caused by defective Client Data, incorrect user input, an unauthorised or unapproved use case, Counterparty-side configuration changes, or third-party system errors. This allocation is without prejudice to the human-in-the-loop, non-determinative-use, and non-discrimination obligations in the End-User Licence Terms (in which this responsibility allocation is mirrored) and does not diminish Axtraction AI's own obligations under the Data Protection Laws.
2.9 Ownership of Client Data
As between Axtraction AI and a Counterparty (or its End-User), all Client Data, including all End-User Personal Data, inputs, uploaded materials, configurations, and the AI output generated from them, is and remains the property of that Counterparty or End-User (or of the third parties from whom it is derived). Axtraction AI acquires no right, title, or interest in the Client Data other than the limited, non-exclusive licence to Process it for the purposes of, and for the duration of, the Underlying Agreement, as recorded in the End-User DPA and the End-User Licence Terms (Sections 3.2 and 3.3 of the End-User Licence Terms). This ownership is not affected by the Deployment Model, by where the Client Data is hosted, or by any suspension, dispute, or payment status, and it continues after termination, subject only to the return-and-deletion provisions in Clause 3.14 and Annex 5 (Part J). Neither this Clause 2.9 nor anything else in this Addendum gives a Counterparty any right, title, or interest in Client Data of an End-User, or any right to access or Process it, which remains governed by Module C (Section 5). Nothing in this Clause 2.9 affects Axtraction AI's ownership of the Base Codex, the Approved Products, and its platform intellectual property, including all improvements, enhancements and generally-applicable developments to them, which are and remain the sole and exclusive property of Axtraction AI, or its use of aggregated, anonymised, and de-identified learnings under Clause 3.12.
2.10 [Not reproduced. The completion condition for Annex 1 (Details of Processing), which conditions the commencement of production Processing under Module A, is Clause 2.10 of the End-User DPA. Where Axtraction AI authorises a Counterparty to Process End-User Personal Data under Clause 5.2, that condition applies to that Counterparty through Clause 5.2.]
2.11 Layer separation: the Axtraction Solution and the Infrastructure Layer
- (a) Axtraction AI is Processor of the Axtraction Solution layer. Axtraction AI is the Processor under Module A in respect of Processing carried out by or within the Approved Products, being the Processing of End-User Personal Data by the Axtraction Solution on the Controller's documented instructions. Module A does not extend to Processing carried out by, within, or by means of the Infrastructure Layer, except to the extent Axtraction AI itself supplies or operates that layer, as it does in a Fully Managed deployment, in which case Module A applies to that layer as well.
- (b) A Reseller-supplied Infrastructure Layer is a separate processing relationship. Where a Reseller supplies or operates the Infrastructure Layer on or in which an Approved Product runs, it does so in its own right and as a Processor to the End-User in respect of that layer, on the End-User's instructions and under its own contract with the End-User or with the party procuring on the End-User's behalf. Such a Reseller is not a Sub-processor of Axtraction AI for the purposes of Clause 3.4, Annex 3, or Annex 4A, Axtraction AI neither appoints nor authorises it in that capacity, and Axtraction AI's responsibility and liability for its Sub-processors under Clause 3.4 do not extend to it. Processor terms in place first: a condition of release. No Approved Product, and no part of the Axtraction Solution, shall be released, installed, deployed, activated, or otherwise made available into an Infrastructure Layer supplied or operated by a Reseller until that Reseller has (i) put in place with the End-User (or with the party procuring on the End-User's behalf) the processor terms the Data Protection Laws require for that layer, including the mandatory content required by Article 28(3) of the GDPR where it applies and an exit return-or-deletion obligation and certification duty no less protective than Clause 3.7(g); and (ii) confirmed in writing to Axtraction AI that it has done so, identifying the End-User, the environment concerned, the contract under which those terms are in place, and the date they took effect. Sub-paragraphs (i) and (ii) are a condition of release and not merely an allocation of responsibility, and that Reseller shall maintain those terms for as long as it supplies or operates that layer and shall notify Axtraction AI in writing if they cease to be in place. This condition is in addition to, and is neither satisfied nor displaced by, the condition precedent to release and the certification and annual re-certification requirements in the Minimum Control Floor (Clause 1.12, and in particular paragraph (d) of it). Axtraction AI may act on that written confirmation without further inquiry, and neither the confirmation nor this paragraph (b) makes Axtraction AI responsible for the content, adequacy, or performance of those terms or for that layer (paragraph (c)). This condition operates before first release into the layer concerned; it does not permit, and shall not be exercised so as to effect, the suspension, deactivation, degradation, or interruption of, or the injection of any payment, suspension, or termination notice into, an existing deployment of an End-User that is current on its own payment and other obligations (the Paid-Up End-User Protection in Clause 1.14, which prevails, and paragraph (e)). Nothing in this paragraph (b) permits that Reseller to access or Process End-User Personal Data within the Approved Products, which remains governed by Module C (Section 5, and in particular Clause 5.4).
- (c) Responsibility boundary; controllership unchanged. Axtraction AI is not responsible for the security, availability, resilience, configuration, lawfulness, or data-protection compliance of an Infrastructure Layer that the End-User or a Reseller supplies or operates, and Axtraction AI's own obligations under the End-User DPA, including its Annex 2, and under Annex 5, are limited to the components of the Axtraction Solution it actually operates or delivers. The End-User remains the Controller of End-User Personal Data throughout, whichever party supplies or operates the Infrastructure Layer. This Clause 2.11 allocates processor-side responsibility between two layers; it does not transfer, share, split, or dilute controllership, does not create joint controllership between Axtraction AI and any Reseller, and does not relieve any party of its own obligations under the Data Protection Laws.
- (d) Covered Person status; the Minimum Control Floor applies with full force. A Reseller that supplies or operates an Infrastructure Layer on or in which any Approved Product, or any prompt, template, orchestration sequence, agent or tool definition, guardrail, evaluation dataset, model weight, or other Base Codex material, runs, is stored, is transmitted, or is backed up, thereby holds administrative, root, hypervisor, storage, or backup access to an environment in which Axtraction AI material runs. That Reseller is accordingly a Covered Person (Clause 1.13), and remains subject in full to the deployment controls that its Underlying Agreement imposes for Self-Hosted deployments, including the Minimum Control Floor (Clause 1.12: the standard in paragraph (a), permitted form and Sealed Runtime Component in paragraph (b), transport integrity and no interception in paragraph (c), condition precedent to release, director-signed certification and annual re-certification and no waiver by release or acceptance of payment in paragraph (d), and the consequences of failure in paragraph (e)). The separation of layers in this Clause 2.11 narrows Axtraction AI's data-protection responsibility for the Infrastructure Layer; it does not narrow, waive, qualify, or create any exception to those controls, which apply to a Reseller-supplied or Reseller-operated Infrastructure Layer precisely because that access exists, and this Clause 2.11 shall not be construed as reducing them.
- (e) Paid-up End-Users; no effect on deletion. Nothing in this Clause 2.11 permits the suspension, deactivation, degradation, or interruption of, or the injection of any payment, suspension, or termination notice into, the deployment of an End-User that is current on its own payment and other obligations (the Paid-Up End-User Protection in Clause 1.14, which prevails), and nothing in it conditions, delays, or fee-gates the return or deletion of Personal Data under Clause 3.7 and Clause 3.14.
3. Module A: Processor obligations
Not reproduced in this Addendum. Module A, being Axtraction AI's obligations as Processor to an End-User Controller (instructions, confidentiality, security, Sub-processors, assistance, deletion or return, records and audit, cross-border transfers, the data-use limitation, the first-party no-training default, the aggregated and anonymised learning boundary, the audit boundary, and retention, deletion and exit), is set out in Section 3 of the End-User Data Processing Addendum published at https://axtraction.ai/dpa, Clauses 3.1 to 3.14, and is accepted by each End-User through the End-User Licence Terms. The numbering of that Section corresponds to the numbering used in this Addendum, so that a reference in this Addendum, including in Annex 5, to Section 3 or to any Clause within it is a reference to the corresponding provision of that document. Where Axtraction AI expressly authorises a Counterparty in writing to Process End-User Personal Data, Clause 5.2 applies Module A to that Counterparty mutatis mutandis in respect of that Processing. This Section 3 imposes no obligation on a Counterparty and confers on a Counterparty no right of access to End-User Personal Data.
4. Module B: Independent Controllers (Channel Data)
4.1 In respect of Channel Data, each of Axtraction AI and the Distributor or Reseller acts as an independent Controller and not as joint controllers. Nothing in this Addendum creates a joint-controllership arrangement in respect of Channel Data. This allocation matches the position under each Underlying Agreement, under which the Distributor processes contracting, invoicing, collection, and channel-administration data, including the business contact data of Reseller and End-User personnel, as an independent controller responsible for its own compliance in that capacity. It extends, without limitation, to the Personal Data that Axtraction AI, the Distributor, or a Reseller holds for ordering, invoicing, payment, collection, credit control, dispute handling, and enforcement under the buy-sell model described in Clause 1.3(b), responsibility for each such Processing sitting with the party carrying it out.
4.2 Each party shall: (a) process Channel Data only for legitimate channel, contractual, onboarding, due-diligence, relationship-management, order-processing, invoicing, payment, collection, credit-control, dispute-handling, enforcement, tax, accounting, billing and compliance, records-retention, audit, and lawful marketing purposes; (b) provide its own privacy notice to the relevant Data Subjects; (c) maintain appropriate security; and (d) notify the other party without undue delay of any Personal Data Breach affecting Channel Data shared by that other party.
4.3 Neither party shall disclose Channel Data received from the other except as permitted by the Underlying Agreement and the Data Protection Laws.
4.4 Buy-sell Channel Data
The categories described in Clause 1.3(b) are Channel Data and are Processed by each party as an independent Controller under this Module B. Each party is responsible for its own lawful basis, transparency and notices, accuracy, retention period, security, cross-border transfer basis, and response to Data Subject requests in respect of the Channel Data it Processes, and for any use of Channel Data for direct marketing, which is subject to the applicable Data Protection Laws and to the objection and opt-out rights they confer. None of that Personal Data is End-User Personal Data, and Processing it does not bring a Distributor or Reseller within Module A or engage the restriction in Module C. For the avoidance of doubt, nothing in this Module B, and no data-protection ground, makes the Distributor's obligation to pay the Distributor Price conditional on, or contingent upon, any downstream collection or any downstream party's default. That obligation is absolute, unconditional, and completely independent of whether the Distributor has received or collected payment from any Reseller or End-User, and of any failure, delay, non-payment, insolvency, cancellation, or default by a Reseller or End-User, as the applicable Underlying Agreement provides; and nothing in this Addendum creates, conditions, qualifies, postpones, or reduces it.
5. Module C: channel no-processing restriction
5.1 The Distributor and each Reseller shall not access or process End-User Personal Data within the Approved Products, except as expressly authorised in writing by Axtraction AI.
5.2 Where Axtraction AI expressly authorises a Distributor or Reseller to process End-User Personal Data, that party shall act as a Processor (or Sub-processor of the End-User) and the obligations in Module A (Section 3 of the End-User DPA) apply to it mutatis mutandis in respect of that Processing.
5.3 The Distributor and each Reseller shall not attempt to re-identify individuals from, or otherwise repurpose, any de-identified or aggregated outputs of the Approved Products.
5.4 Infrastructure Layer: what Clause 5.1 does and does not restrict
Clause 5.1 restricts access to and Processing of End-User Personal Data within the Approved Products. It does not prevent a Reseller from supplying or operating the Infrastructure Layer (Clause 1.10) on or in which an Approved Product runs, which the Reseller may do. Where a Reseller does so:
- (a) Clause 2.11 applies: the Reseller acts as a Processor to the End-User in its own right in respect of that layer, it is not a Sub-processor of Axtraction AI, the End-User remains Controller, and Axtraction AI is not responsible for the security or compliance of that layer;
- (b) the Reseller is a Covered Person (Clause 1.13) and remains subject in full to the deployment controls that its Underlying Agreement imposes for Self-Hosted deployments, including the Minimum Control Floor (Clause 1.12, and Clause 2.11(d)), and to the security-conduct requirements in Annex 5;
- (c) the access needed to run the layer is permitted; the use of that access is restricted. Supplying or operating that layer is not an authorisation under Clause 5.1 and confers no right to access or Process End-User Personal Data within an Approved Product. Subject to the rest of this paragraph (c) and to paragraph (d), the Reseller may hold and use the administrative, root, hypervisor, storage, network, identity, and backup access to the Infrastructure Layer that operating that layer legitimately requires, including provisioning, configuration, patching, monitoring, capacity, availability and performance management, storage and volume management, replication, snapshotting, and backup and restoration of the environment; and the technical Processing that necessarily results from operating that layer, being the storing, hosting, transmitting, replicating, snapshotting, and backing up of data at rest and in transit without inspecting, reading, interpreting, or analysing its content, is Processing of that layer under Clause 2.11(b) and is not a breach of Clause 5.1. What the Reseller shall not do is use that access to read, open, inspect, extract, copy, export, decrypt, index, search, mine, disclose, or otherwise Process the content of End-User Personal Data within an Approved Product, or to reconstruct that content from any snapshot, image, replica, backup, cache, log, or memory, except as Axtraction AI expressly authorises in writing under Clause 5.1, in which case Clause 5.2 applies to that Processing. Where restoring, migrating, or troubleshooting the environment requires the Reseller to handle an Approved Product's data or storage, it shall act on the End-User's documented instruction under its own processor terms (Clause 2.11(b)), limit the handling to the minimum required for that task and to the personnel who need it, keep a record of it available to the Controller and, on request, to Axtraction AI, and retain no copy beyond what the task requires; and
- (d) the Reseller shall not in any circumstances use that access to read, reconstruct, dump, image, export, or disclose any prompt, template, orchestration sequence, agent or tool definition, guardrail, evaluation dataset, model weight, or other Base Codex material, and shall not circumvent, disable, or tamper with any control required by the Minimum Control Floor (Clause 1.12). Nothing in paragraph (c) permits any act within this paragraph (d). Where a routine operational function permitted by paragraph (c), such as backing up, replicating, or snapshotting an environment as a whole, necessarily captures Base Codex material in packaged, sealed, or encrypted form, that capture is not of itself an act within this paragraph (d), provided the Reseller does not open, unpack, decrypt, mount for inspection, analyse, extract from, or disclose the captured material, keeps the resulting media subject to the controls required by the Minimum Control Floor, and deletes them in accordance with the applicable retention cycle.
5.5 Exit at a Reseller-operated Infrastructure Layer
Where a Reseller supplies or operates the Infrastructure Layer, the return or deletion of End-User Personal Data held at that layer on expiry or termination, and the signed certification of it, are allocated to that Reseller by Clause 3.7(g) of the End-User DPA on the same trigger and within the same periods as apply to Axtraction AI, and that allocation is owed to Axtraction AI under this Addendum as incorporated into that Reseller's Underlying Agreement, as well as to the End-User under the processor terms required by Clause 2.11(b). Nothing in this Clause 5.5 conditions, delays, or fee-gates that return or deletion, permits any act prohibited by the Paid-Up End-User Protection in Clause 1.14, or limits or discharges that Reseller's separate obligation on expiry or termination to return or destroy Base Codex material and to certify that destruction, which arises under the deployment controls and Base Codex protections in its Underlying Agreement.
6. Personal Data Breach (all modules)
6.1 A party that becomes aware of a Personal Data Breach affecting Personal Data processed under an Underlying Agreement shall notify the other affected party (and, for Module A, the Controller) without undue delay and in any event within 72 hours of becoming aware. This 72-hour obligation is mandatory and prevails over any severity-based response cadence, including the overlay in Annex 5 (Part D); any Personal Data Breach is notified in accordance with this Clause 6.1 within 72 hours regardless of the severity tier assigned to it.
6.2 The notification shall describe, to the extent known, the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed. The parties shall cooperate in good faith on investigation, remediation, and any notification to a regulator or Data Subjects required under the Data Protection Laws (including the PDPA's mandatory breach-notification obligations).
6.3 Counterparty cooperation
A Counterparty affected by a Security Incident shall cooperate with Axtraction AI in good faith to investigate, contain, and remediate it, including by preserving relevant logs and system information, promptly suspending compromised user accounts and revoking exposed credentials within its control, providing timely instructions where required, and maintaining the confidentiality of non-public information about the incident during active investigation. Nothing in this Clause 6.3 restricts, delays, or otherwise fetters a Counterparty's own right or duty as Controller to notify a regulator or affected Data Subjects, or to make any disclosure required by law; the confidentiality expectation applies only to Axtraction AI's confidential and security-sensitive information and never to a party's lawful notification obligations.
7. Cross-border transfers
7.1 A party shall not transfer Personal Data outside Malaysia (or, where the GDPR applies, outside the jurisdiction concerned) unless a lawful transfer basis is in place under the applicable Data Protection Laws: for the PDPA, appropriate safeguards, a substantially-similar-law basis, or another permitted ground under the PDPA as amended; and for the GDPR, an adequacy decision, Standard Contractual Clauses, or another Chapter V mechanism. Each party is responsible for the transfer basis for the Channel Data it Processes as an independent Controller under Module B (Clause 4.4). The basis relied on by Axtraction AI for each destination to which End-User Personal Data is transferred is recorded in Annex 4 (and, for GDPR restricted transfers from an End-User Controller to Axtraction AI, in the GDPR restricted-transfer clause and Annex 4A of the End-User DPA).
7.2 The transfer mechanism(s) relied on by Axtraction AI are recorded in Annex 4. Where Standard Contractual Clauses apply, they are incorporated by reference and completed per Annex 4 and, for GDPR restricted transfers, per Annex 4A.
8. Security
8.1 Each party shall implement appropriate technical and organisational measures to protect Personal Data against unauthorised or unlawful Processing and against accidental loss, destruction, or damage, consistent with Annex 2 and §5 of the End-User Licence Terms.
8.2 For Self-Hosted deployments, the parties acknowledge that the Infrastructure Layer (Clause 1.10) is controlled by the End-User, or by a Reseller supplying or operating it for the End-User, and that the party controlling it is responsible for the security measures within it. Axtraction AI's security responsibility is limited to the components of the Axtraction Solution it actually operates or delivers, in accordance with Clause 2.11(c); it does not extend to the security or compliance of an Infrastructure Layer that the End-User or a Reseller supplies or operates. A Reseller controlling an Infrastructure Layer is a Covered Person (Clause 1.13) and remains subject in full to the deployment controls and to the Minimum Control Floor (Clause 1.12), as recorded in Clause 2.11(d), and neither this Clause 8.2 nor the responsibility boundary it states reduces those obligations or excuses any failure to meet them.
8.3 Penetration testing
A Counterparty shall not conduct or permit any penetration testing, vulnerability scanning, load or stress testing, red-team activity, exploit testing, traffic flooding, scraping, or other intrusive security testing against Axtraction AI systems or shared infrastructure without Axtraction AI's prior written approval. Approved testing must follow the scope, timing, environment, notification, rate limits, testing rules, and remediation procedures agreed with Axtraction AI. For Self-Hosted deployments, this restriction applies to Axtraction AI-operated or shared components only; a Counterparty may test its own operating environment and infrastructure, provided it does not test, degrade, or affect components Axtraction AI operates or any shared multi-tenant system.
8.4 Third-party AI model provider risk
Certain Approved Products use third-party AI models, APIs, or cloud AI services (including those listed in Annex 3). Such services are subject to their providers' terms, availability, regional support, model behaviour, usage and rate limits, safety filters, policy and pricing changes, and possible service interruptions. Axtraction AI remains responsible for its own obligations under the End-User DPA, including its Clause 3.4 responsibility for Sub-processors and the transfer safeguards in Annex 4, but, subject to those obligations and to the Data Protection Laws, Axtraction AI is not liable for limitations, changes, or interruptions in a third-party model's behaviour or availability except to the extent expressly agreed in the Underlying Agreement. Liability under this Clause 8.4 is subject to Section 9, and is routed to the applicable Underlying Agreement in the manner, and subject to the uncapped heads, carve-outs, and Super-Caps, stated in Clause 9.1.
8.5 Disaster recovery and backup scope
Backup and disaster-recovery commitments apply only to the extent expressly stated in the applicable Order, Annex 2, Annex 5, or an enterprise project schedule. Standard backups do not by themselves constitute disaster recovery, high availability, active-active failover, zero data loss, or a guaranteed recovery-time or recovery-point objective, unless expressly agreed.
8.6 Business-continuity boundary
Business-continuity obligations apply only where expressly stated in the applicable Order, an SLA, or a business-continuity or project-governance schedule. Axtraction AI is not responsible for a Counterparty's or End-User's own business continuity, staff availability, internal approvals, local network, devices, identity provider, or client-side third-party vendors, except to the extent expressly contracted.
8.7 Security Annex
The operational security controls, responsibility-allocation (RACI) and classification tables, Security Incident severity classification and non-notifiable-incident response cadence overlay, credential and API-key management, vulnerability and patch responsibility, multi-tenant segregation baseline, security-controls checklist by deployment model, data-retention/deletion and exit provisions, and operational templates applicable to Processing under this Addendum and under the End-User DPA are set out in Annex 5 (Security Annex), which forms part of this Addendum. The response-cadence overlay in Annex 5 (Part D) is subject to Section 6.1, which prevails for any Personal Data Breach.
9. Liability
9.1 Liability routing
Each party's liability under or in connection with this Addendum is subject to the exclusions and limitations of liability in the applicable Underlying Agreement, as identified and qualified in this Clause 9.1, except to the extent such limitation is not permitted by the Data Protection Laws. This Clause 9.1 routes liability to the correct provisions of the applicable Underlying Agreement. It does not create, enlarge, reduce, displace, or substitute for any liability, exclusion, cap, super-cap, aggregate, carve-out, or uncapped head in that agreement, and it is to be read so as to give each of them full effect.
- (a) Distributor. For the Distributor, liability arising out of or in connection with this Addendum is subject to the exclusion of indirect loss and the general liability cap in its Underlying Agreement, read with, and subject to, each of the following provisions of that agreement, each of which continues to apply according to its own terms:
- (i) the uncapped heads stated in that agreement, which by their own terms disapply its exclusions, its general cap and both of its Super-Caps, operate as a term of that agreement, and prevail over its carve-out provision, its Confidentiality Super-Cap and its Indemnity Super-Cap to the extent of any inconsistency;
- (ii) the carve-outs from the exclusion of indirect loss and from the general cap, and in particular the carve-out that routes the Distributor's indemnities, and with them its indemnity for breach of confidentiality, data-protection, or data-security obligations by the Distributor or its Resellers, to the Indemnity Super-Cap and not to the general cap; together with the other carve-outs stated in that provision, being those for the Distributor's payment obligations, breach of confidentiality, infringement or misappropriation of Axtraction AI's intellectual property, fraud or wilful misconduct, liability that cannot be excluded or limited under applicable law, any liability within the uncapped heads, the remediation debt payable on an exposure of Base Codex material (a reimbursement of incurred cost and not compensation for breach), and third-party intellectual-property claims;
- (iii) the Confidentiality Super-Cap, with the uncapped exceptions stated in it;
- (iv) the Indemnity Super-Cap, with the uncapped exceptions stated in it; and
- (v) the single shared aggregate, under which the Confidentiality Super-Cap and the Indemnity Super-Cap are not cumulative as they apply to the Distributor, one amount is recoverable under both taken together, and any amount paid or payable under one reduces the amount available under the other; and which does not apply to and does not cap any liability within the uncapped heads, the remediation debt payable on an exposure of Base Codex material, the Distributor's payment obligations, or any liability that cannot be limited under applicable law.
Accordingly, and for the avoidance of doubt, the general liability cap in the Distributor's Underlying Agreement does not apply to any liability that agreement carves out of it. It does not apply to the Distributor's indemnity liability for breach of confidentiality, data-protection, or data-security obligations by the Distributor or its Resellers, which is subject instead to the Indemnity Super-Cap and to the single shared aggregate; and it does not apply to any liability within the uncapped heads, which is uncapped. No provision of this Addendum, and no characterisation of a claim as a data-protection claim, subjects such a liability to the general cap.
- (b) Reseller. For a Reseller, liability arising out of or in connection with this Addendum is subject to the exclusion of indirect loss and the liability cap in its Underlying Agreement, read with the carve-outs from them stated in that agreement, and in particular the carve-outs for:
- (i) breach of confidentiality;
- (ii) the Reseller's infringement or misappropriation of Axtraction AI intellectual property;
- (iii) the Reseller's indemnity obligations, which include its indemnity for breach of confidentiality, data-protection, or data-security obligations by the Reseller;
- (iv) fraud or wilful misconduct;
- (v) any liability that cannot be excluded or limited under applicable law; and
- (vi) the Reseller's breach of the Self-Hosted deployment controls in that agreement (including the Minimum Control Floor in Clause 1.12, the Sealed Runtime Component standard, the transport-integrity and no-interception controls, and the certification and telemetry obligations) or of the Base Codex protections in that agreement, liability for which is uncapped where the breach caused or enabled Base Codex material to be read, reconstructed, exported, disclosed or otherwise made accessible to a person not authorised to receive it, and is in any event outside the cap.
The cap in a Reseller's Underlying Agreement does not apply to any liability that agreement carves out of it, including a data-protection or data-security liability within its indemnity and a liability within paragraph (vi).
- (c) End-User. An End-User is not a party to this Addendum. The liability of an End-User in connection with the Processing of Personal Data is governed by the End-User DPA and by the End-User Licence Terms, and nothing in this Addendum applies to it, varies it, or is to be read as routing it.
- (d) No narrowing. Nothing in this Addendum narrows, limits, qualifies, or displaces any provision described in paragraphs (a) to (c). In particular, nothing in this Addendum subjects to the general liability cap in the Distributor's Underlying Agreement any liability that agreement's uncapped heads, carve-outs, Confidentiality Super-Cap, Indemnity Super-Cap, or single shared aggregate place outside that cap; or subjects to the cap in a Reseller's Underlying Agreement any liability that agreement's carve-outs place outside it. Where this Addendum and an Underlying Agreement are inconsistent as to the routing, cap, or aggregation of a liability, the provision of the Underlying Agreement described in this Clause 9.1 prevails and this Clause 9.1 is read to give effect to it; the general data-protection precedence of this Addendum does not operate to displace it.
- (e) Statutory floor. Nothing in this Clause 9.1 or in any Underlying Agreement limits or excludes a liability that cannot be limited or excluded under the Data Protection Laws, including the direct liability of a processor to a Data Subject under Article 82 of the GDPR, any liability arising from a regulator's exercise of its enforcement powers, and any liability under the PDPA that cannot be contracted out of.
10. Term, survival, and precedence
10.1 This Addendum takes effect on the effective date in the Cover Sheet and continues for as long as any Personal Data is processed under the Underlying Agreement.
10.2 Obligations that by their nature should survive (including confidentiality, deletion/return, and breach cooperation for incidents arising during the term) survive termination.
10.3 This Addendum is governed by, and construed in accordance with, the laws of Malaysia, and disputes are subject to the exclusive jurisdiction of the High Court of Malaya (Kuala Lumpur), consistent with the Underlying Agreement.
11. Versioning and change control
11.1 Portal and versioning
This Addendum is published by Axtraction AI on its partner data-protection page at https://axtraction.ai/partner-dpa, which forms part of Axtraction AI's Legal Documents Portal (the "DPA Page"), and is version-controlled. Each version carries a version number, a version date, and a stated effective date; the current version (the "Current Version") remains accessible on the DPA Page, and Axtraction AI retains an archive of all superseded versions, each with a change-log against the preceding version, and shall provide a copy of any superseded version to any Counterparty on request (a signed, dated copy being available under Clause 11.8).
11.2 Live incorporation and advance agreement
Each Underlying Agreement incorporates this Addendum as amended from time to time in accordance with this Section 11. The version that applies to a Counterparty at any time is the Current Version then published on the DPA Page, and each updated version takes effect automatically on its stated effective date without any need to re-execute the Underlying Agreement, subject to Clauses 11.3 to 11.7. By executing or accepting an Underlying Agreement, each Counterparty gives its advance agreement to be bound by the Current Version as so amended.
11.3 Updates and notice
Axtraction AI may amend this Addendum only to reflect a change in Data Protection Laws or regulator guidance, a change of Sub-processor, security measure, or operational practice, a change to the Approved Products, or a reasonable operational ground. For any change that materially and adversely affects a Counterparty's rights or obligations (a "Material Change"), Axtraction AI shall give that Counterparty at least thirty (30) days' prior written notice, given under the notices provision of the Underlying Agreement and by publication on the DPA Page, before the change takes effect. For a Counterparty that accepts an Underlying Agreement by click-through or order acceptance, notice of a Material Change is given by publication on the DPA Page together with notice to the email contact captured at acceptance, and that combined notice satisfies the notice condition in this Clause 11.3. A Material Change does not take effect unless it is both published on the DPA Page and so notified.
11.4 Prospective effect only
An updated version applies prospectively only, from its stated effective date, and does not apply retroactively to Processing already carried out, or to any right or liability accrued, before that date. The version that was current when specific Processing was carried out continues to govern that Processing.
11.5 Objection and exit (Material Adverse Change)
If a Material Change has a significant adverse effect on a Counterparty, the Counterparty may object in writing within the notice period. On a valid objection: (a) the Parties shall discuss the change in good faith; (b) pending resolution, the version that applied immediately before the change continues to apply to that Counterparty; and (c) if the matter is not resolved within thirty (30) days, the expedited expert-determination track in Clause 11.5A applies and must be exhausted or waived before the Counterparty may make any election under this paragraph (c); and, only after that track has been exhausted or waived, and then only to the extent the expert's determination permits (or, where no Party refers the matter within the period allowed by Clause 11.5A, to the extent the absence of a reference leaves the matter unresolved), the Counterparty may either continue under that prior version until the expiry of the then-current term of its Underlying Agreement, or terminate the affected Underlying Agreement without penalty on thirty (30) days' written notice, in each case without prejudice to accrued rights and to the protection of paid-up End-Users. Nothing in this paragraph (c) affects the continued application, pending resolution, of the prior version under paragraph (b), or the affirmative-acceptance standing veto of a Controller under Clause 11.11 (which continues to apply of its own force, without that Controller being required to refer any matter under Clause 11.5A, to arbitrate, or to terminate); and no reference, step, or determination under Clause 11.5A may permit the suspension, deactivation, degradation, or interruption of, or the injection of any payment, suspension, or termination notice into, the deployment of any paid-up End-User, or the bare severance of this Addendum while any Processing continues. This Addendum may not be severed from, or terminated separately while, an Underlying Agreement under which any Processing continues. Where a Material Adverse Change to this Addendum is not resolved, the remedy is reversion to the version that applied immediately before the change until orderly wind-down of the affected Processing, or termination of the affected Underlying Agreement, and never the bare severance of this Addendum alone while any Processing continues.
11.5A Expedited expert determination (Material Adverse Change to this Addendum)
This Clause provides an expedited, merits-based track that is seated ahead of the reversion-or-terminate fork in Clause 11.5(c), so that an unresolved Material Adverse Change to this Addendum is decided on its merits without escalation to termination of the Underlying Agreement. The change-control provision of each Underlying Agreement hooks into this track: it requires this track to be exhausted or waived before any objection-and-exit election is available under that agreement in respect of a change to this Addendum, and it bars the termination or severance of this Addendum as incorporated while any Processing of Personal Data continues, the remedy being reversion to the prior version until orderly wind-down, or termination of that agreement, and never bare severance of this Addendum alone. This Clause 11.5A forms part of the single Change-Control Process (Clause 11.10).
- (a) Reference. If the good-faith discussion under Clause 11.5(a) has not resolved the matter within the thirty (30) day period referred to in Clause 11.5(c), either Party may, within a further ten (10) business days, refer the matter to an independent expert (the "Expert") by written notice to the other Party.
- (b) Appointment. The Expert shall be a suitably qualified, independent data-protection or information-security practitioner agreed by the Parties or, failing agreement within five (5) business days of the referral notice, appointed on the application of either Party by the Director (or Chairman for the time being) of the Asian International Arbitration Centre (AIAC), Kuala Lumpur, or, if that body declines, by the President for the time being of the Malaysian Bar. The Expert must be free of any material conflict of interest and shall disclose any interest before accepting appointment.
- (c) Scope. The Expert shall determine: (i) whether the change is a Material Change and has a significant adverse effect on the objecting Counterparty (a Material Adverse Change) under Clause 11.5; (ii) whether the change is justified on one or more of the grounds in Clause 11.3 and complies with the no-degradation floor in Clause 11.7; and (iii) the appropriate resolution, being one of: (A) the change stands and applies to the Counterparty from a date the Expert fixes; (B) the change applies subject to modifications, safeguards, or a transition period the Expert specifies; or (C) the version that applied immediately before the change continues to apply to that Counterparty under Clause 11.5(b) until the expiry of the then-current term of its Underlying Agreement.
- (d) Process and timing. The Expert shall act as an expert and not as an arbitrator, shall determine the procedure (giving each Party a reasonable opportunity to make written submissions), and shall use reasonable endeavours to issue a written, reasoned determination within twenty (20) business days of accepting appointment. The determination is final and binding on the Parties in the absence of fraud or manifest error, is not itself a Material Change, and is without prejudice to Section 10.3 (governing law and forum).
- (e) Costs. Each Party bears its own costs of the reference; the Expert's fees are shared equally unless the Expert, having regard to the outcome and the Parties' conduct, directs otherwise.
- (f) Status quo pending determination. Pending the Expert's determination, the version that applied immediately before the change continues to apply to the objecting Counterparty under Clause 11.5(b), save that any change (or part of a change) required by applicable Data Protection Laws or by a direction of a competent regulator takes effect on its stated effective date notwithstanding the pendency of the reference.
- (g) Guardrails preserved. Nothing in this Clause 11.5A: (i) severs this Addendum from, or terminates it separately while, an Underlying Agreement under which any Processing continues, the bar in Clause 11.5 continuing to apply so that this Addendum is never severed alone; (ii) defers, dilutes, or fee-gates the mandatory 72-hour Personal Data Breach notification duty in Section 6.1, which prevails regardless of any reference under this Clause; (iii) defers or fee-gates the return or deletion of Personal Data required on expiry or termination (Clause 3.14 and Annex 5 Part J), which is never conditioned on payment; (iv) overrides the Controller's affirmative-acceptance veto for Article 28 core changes in Clause 11.11, which continues to operate as a standing veto for a Module A Controller, so that for such a Controller the Expert may not impose an unaccepted Article 28 core change and resolution (C) in paragraph (c)(iii) applies unless the Controller accepts; or (v) reduces the protection of paid-up End-Users.
11.6 Non-material changes
Non-material changes, including Sub-processor additions or replacements handled under Clause 3.4, and clarifications, take effect on posting to the DPA Page.
11.7 No degradation
No update to this Addendum may materially reduce the technical and organisational security measures (Annex 2), the operational security standard in Annex 5, or the overall level of protection for Personal Data provided under the version in effect immediately before the update.
11.8 Signed copy
Axtraction AI shall, on request, provide a signed and dated copy of the applicable version of this Addendum to any Counterparty that requires a signed exhibit.
11.9 Good faith
Axtraction AI shall exercise its rights under this Section 11 in good faith, for the grounds stated in Clause 11.3, and not arbitrarily, capriciously, or unreasonably.
11.10 Data-protection certainty; single mechanism
Nothing in this Section 11 reduces the certainty of processing terms required by the Data Protection Laws: at any time there is a single, complete, and identifiable Current Version constituting the binding processing terms; the archive preserves the terms that governed past Processing; and a signed, dated copy of any version is available under Clause 11.8. This Section 11 operates as the same Change-Control Process as that in each Underlying Agreement, in the End-User DPA, and in the End-User Licence Terms, so that a single update propagates across every Underlying Agreement, this Addendum, the End-User DPA, and the End-User Licence Terms.
11.11 GDPR Article 28 material changes (affirmative acceptance)
Where this Addendum governs Processing subject to the GDPR and a Counterparty acts as Controller with Axtraction AI as Processor, a Material Change to the mandatory content required by Article 28(3) of the GDPR, namely the technical and organisational security measures (Annex 2), the nature, purpose, or categories of the Processing, or the return-or-deletion terms, takes effect against that Controller only on the Controller's affirmative acceptance (opt-in), and not on notice alone. If that Controller does not accept such a change, the version that applied immediately before the change remains in force as to that Controller under Clause 11.5, without the change taking effect and without the Controller being required to terminate; the objection right in Clause 11.5 operates as a standing veto to that extent. A change of Sub-processor remains governed by the general authorisation and object-on-reasonable-grounds procedure in Clause 3.4 rather than this Clause 11.11. The no-degradation floor in Clause 11.7 continues to apply. This Clause 11.11 preserves the Controller's governance of documented instructions required by the GDPR while leaving the live model in Clauses 11.2 to 11.6 intact for Processing governed by the PDPA and for non-core changes.
Annexes 1 to 4A: where they are
Annex 1 (Details of Processing), Annex 2 (Technical and Organisational Security Measures), Annex 3 (Approved Sub-processors), Annex 4 (Cross-Border Transfer Mechanism) and Annex 4A (EU SCC Completion) are the annexes of the End-User DPA published at https://axtraction.ai/dpa, and a reference to any of them in this Addendum, including in Annex 5, is a reference to that annex as published there. They are not reproduced here, they are maintained under the same Change-Control Process, and the no-degradation floor in Clause 11.7 applies to them. Annex 5 below is an annex of this Addendum and keeps its number and its Part lettering.
Annex 5: Security Annex
This Annex 5 forms part of this DPA and sets out operational security controls, responsibility-allocation (RACI) and classification tables, incident and cadence rules, data-lifecycle controls, and operational templates. Its tables are keyed to Axtraction AI's two Deployment Models, and not to any product-tier taxonomy: Fully Managed (Axtraction AI hosts and operates the Approved Product in a cloud environment it controls, and supplies the Infrastructure Layer itself) and Self-Hosted (the Approved Product runs in an Infrastructure Layer (Clause 1.10) controlled by the End-User, or by a Reseller supplying or operating that layer for the End-User). In either Deployment Model, the Axtraction Solution is delivered, configured, orchestrated and supported exclusively by Axtraction AI. Where a control differs by Deployment Model, the applicable column governs.
Responsibility as between the two layers is allocated by Clause 2.11: Axtraction AI is Processor for Processing carried out by the Approved Products; a Reseller supplying or operating the Infrastructure Layer is a Processor to the End-User in its own right for that layer and is not an Axtraction AI Sub-processor; Axtraction AI is not responsible for the security or compliance of an Infrastructure Layer it does not supply or operate; and the End-User remains Controller throughout. Accordingly, in the Self-Hosted columns and rows of this Annex, "Counterparty" means the party that controls the Infrastructure Layer for the deployment concerned, being the End-User or, where a Reseller supplies or operates it, that Reseller. Such a Reseller is a Covered Person (Clause 1.13) and remains subject in full to the deployment controls that its Underlying Agreement imposes for Self-Hosted deployments, including the Minimum Control Floor (Clause 1.12, and Clause 2.11(d)); nothing in this Annex reduces those controls.
Nothing in this Annex reduces the obligations in the body of this DPA or the mandatory 72-hour Personal Data Breach duty in Section 6.1.
Part A: Data Role Classification
| Role | When it applies | Control position |
|---|---|---|
| Processor (Module A) | Axtraction AI Processes End-User Personal Data solely to deliver the Approved Products on the End-User Controller's documented instructions. | Default position for End-User deployments; Section 3 applies. |
| Independent Controller (Module B) | Axtraction AI and a Distributor or Reseller each determine their own purposes for Channel Data as defined in Clause 1.3, including the contracting, ordering, invoicing, payment, collection, credit-control, dispute, tax, audit, and regulatory-compliance Personal Data generated by the buy-sell model (Clause 1.3(b)), which is the Personal Data the Distributor holds as independent controller. | Limited to the purposes listed in Clause 4.2(a), being legitimate channel, contractual, onboarding, due-diligence, relationship-management, order-processing, invoicing, payment, collection, credit-control, dispute-handling, enforcement, tax, accounting, billing and compliance, records-retention, audit, and lawful marketing purposes; Section 4 applies, including Clause 4.4. |
| No-Processing (Module C) | A Distributor or Reseller does not access or Process End-User Personal Data. | Default for the Distributor/Reseller; Section 5 applies unless Axtraction AI expressly authorises Processing in writing. |
| Infrastructure Layer processor (own right) | A Reseller supplies or operates the Infrastructure Layer (Clause 1.10) on or in which an Approved Product runs. | Processor to the End-User in its own right for that layer; not an Axtraction AI Sub-processor; Clause 2.11 and Clause 5.4 apply. Covered Person (Clause 1.13), subject in full to the deployment controls and the Minimum Control Floor (Clause 1.12). |
Part B: Data Category Taxonomy
| Data category | Examples | Default control |
|---|---|---|
| Business data | Company records, policies, operational documents. | Allowed if covered by the Order and confidentiality. |
| Personal Data | Employee / customer / user information. | DPA mandatory (Module A). |
| Sensitive Data | Health, biometric, financial, HR-decision, children/student, government, or Regulated Sector records. | Pre-approval gate (Clause 2.6) + enhanced security review. |
| AI input data | Prompts, uploaded files, workflow inputs, user instructions. | Used only for approved service delivery and support. |
| AI output | Reports, summaries, recommendations, extracted insights, generated content. | Human review / validation required (Clause 2.8; End-User Licence Terms). |
| Metadata / logs | Access logs, telemetry, usage analytics, audit records. | Security, billing, support, and platform operations. |
| System telemetry | Performance data, error logs, availability data. | Platform reliability and improvement (subject to Clause 3.12). |
| Regulated Sector data | Financial, insurance, healthcare, public-sector, HR, education, legal, or critical-infrastructure data. | Pre-deployment review (Clause 2.7). |
Part C: Security Incident severity classification
| Severity | Description | Example |
|---|---|---|
| Critical | Confirmed unauthorised access, exfiltration, or material compromise of Client Data or a production environment. | Malicious access to production data; ransomware affecting the service. |
| High | Material security issue with potential data exposure or serious service impact. | Compromised administrative credential; vulnerability under active exploitation. |
| Medium | Limited incident with contained impact, or a suspected compromise requiring investigation. | Misdirected document; suspicious login attempt. |
| Low | Minor issue with no material data exposure or service impact. | Non-sensitive logging error; low-risk configuration issue. |
Part D: response cadence overlay (non-notifiable Security Incidents only)
This overlay is a voluntary operating target for Security Incidents that are not Personal Data Breaches. It does not apply to, and never displaces, the mandatory 72-hour Personal Data Breach notification in Section 6.1.
| Severity | Initial notice to affected Counterparty | Update cadence | Closure |
|---|---|---|---|
| Critical | Without undue delay after confirmation; target within 24 hours. | Daily or as agreed until containment. | After investigation and remediation plan. |
| High | Target within 48 hours after confirmation. | Every 2–3 business days or as agreed. | After root-cause and corrective actions. |
| Medium | Target within 5 business days where Counterparty impact is likely. | As material updates arise. | If requested or required. |
| Low | Logged and reported in periodic security review. | Not applicable unless escalated. | Not usually required. |
Express carve-outs (mandatory):
- Personal Data Breach overrides. Any Security Incident that is or becomes a Personal Data Breach is notified under Section 6.1 without undue delay and in any event within 72 hours of becoming aware, regardless of the severity tier assigned under Part C. The Medium (5 business days) and Low (logged-only) cadences never apply to a Personal Data Breach.
- Voluntary tightening. For a Personal Data Breach classified as Critical, Axtraction AI additionally targets initial notice within 24 hours, a voluntary tightening within, and never a relaxation of, the mandatory 72-hour duty.
- Regulatory duties preserved. Nothing in this overlay limits either party's mandatory notification duties under the Data Protection Laws (including the PDPA's breach-notification obligations).
Part E: access control and privileged-access RACI
| Control area | Axtraction AI: Fully Managed | Axtraction AI: Self-Hosted | Counterparty (both models) |
|---|---|---|---|
| User provisioning | Provide system capability and admin roles; operate the hosting environment. | Provide system capability; Counterparty operates the environment. | Assign authorised users; remove leavers promptly. |
| MFA / strong authentication | Enable and enforce for administrative access where supported. | Provide capability; Counterparty configures and enforces. | Ensure users comply with the access policy. |
| Privileged accounts | Restrict and log Axtraction-side admin access. | Restrict and log Axtraction support access; Counterparty restricts environment admin access. | Limit internal admin users. |
| Access review | Provide technical reports where available; review Axtraction-side access. | Support with reports; Counterparty reviews environment access. | Review user lists and permissions periodically. |
| Offboarding | Revoke Axtraction-side access. | Revoke Axtraction support access; Counterparty revokes environment access. | Notify Axtraction AI of relevant user changes where required. |
Part F: credential and API-key management
Credentials, API keys, access tokens, secrets, sandbox and production credentials, cloud keys, and integration keys must be securely managed. The parties shall not share credentials through unsecured channels, and compromised credentials must be revoked promptly. In Fully Managed deployments, Axtraction AI manages platform and infrastructure secrets, while the Counterparty manages its own user credentials and any client-provided integration keys. In Self-Hosted deployments, the Counterparty manages environment, infrastructure, and user secrets, while Axtraction AI manages only the credentials for support access it is granted. Client-provided credentials remain the Counterparty's responsibility unless the Order expressly transfers a management function to Axtraction AI.
Part G: vulnerability and patch responsibility
| Component | Fully Managed | Self-Hosted |
|---|---|---|
| Axtraction AI platform / application | Axtraction AI (subject to release cycle and severity). | Axtraction AI provides updates; Counterparty applies them to its environment within agreed timelines. |
| Cloud / infrastructure | Axtraction AI (via its cloud Sub-processors, Annex 3). | Counterparty (its own infrastructure and cloud). |
| Operating environment, network, devices, identity provider | Axtraction AI for the hosted environment. | Counterparty. |
| Third-party integrations | As agreed; dependency/API changes may affect timelines. | Counterparty, with Axtraction AI support as agreed. |
| Open-source dependencies | Axtraction AI for included platform dependencies; unapproved client- or partner-introduced dependencies are excluded. | Axtraction AI for included platform dependencies; the Counterparty must not introduce unapproved dependencies that create IP, security, or licence-contamination risk. |
Part H: multi-tenant segregation baseline
Where the Approved Products use multi-tenant or shared cloud architecture (typically Fully Managed), Client Data is logically segregated per tenant in accordance with the applicable architecture and security controls. Dedicated tenancy, a private cloud instance, an isolated or single-tenant environment, on-premise deployment, or enhanced segregation must be expressly stated in the Order and may involve additional fees. Self-Hosted deployments are single-tenant by nature within the Counterparty-operated environment.
Part I: security-controls checklist by Deployment Model
| Control | Fully Managed | Self-Hosted |
|---|---|---|
| Access control | Operated by Axtraction AI; role-based, least-privilege. | Provided by Axtraction AI; configured and operated by the Counterparty. |
| MFA | Enabled and enforced for administrative access. | Capability provided; enforced by the Counterparty. |
| Encryption | In transit (TLS) and at rest, per Annex 2. | In transit (TLS); at-rest and environment encryption is the Counterparty's responsibility, with Axtraction AI guidance. |
| Logging | Platform and access logs operated by Axtraction AI (Annex 2). | Application logging provided; environment/infrastructure logging is the Counterparty's responsibility. |
| Backups / DR | Per Annex 2 and the Order (Clause 8.5). | Counterparty responsibility unless expressly contracted. |
| Security review | Per Annex 2; enhanced where Personal/Sensitive Data or a Regulated Sector is involved (Clauses 2.6–2.7). | Same triggers, scoped to the components Axtraction AI operates or delivers. |
| Penetration testing | By approval and protocol only (Clause 8.3). | Counterparty may test its own environment; Axtraction-operated/shared components by approval only (Clause 8.3). |
| Incident response | Severity classification and cadence overlay (Parts C–D), subject to Section 6.1. | Same, coordinated with the Counterparty-operated environment. |
Part J: data retention, deletion, and exit
Retention and deletion are defined by data type, Deployment Model, the applicable Order, legal retention obligations, backup cycles, and technical feasibility. The table below is the default position. The return and deletion of Personal Data required by Clause 3.7 and the Data Protection Laws is provided without charge and is not conditioned on payment status (Clause 3.14). The periods for return and deletion of End-User Personal Data are those stated in Clause 3.7 of this DPA, and no other document supplies them.
| Data type | Default retention | Deletion / return |
|---|---|---|
| End-User Personal Data / Client Data | Retained during the active service term unless the Order states otherwise. | On expiry or termination, returned or deleted at the Controller's choice under Clause 3.7, without charge and not subject to payment status: the Controller may elect in writing up to thirty (30) days after expiry or termination, and Axtraction AI completes the return or deletion, and deletes all existing copies, within thirty (30) days of that written election (Clause 3.7(a)); absent an election within that thirty (30) day window, Axtraction AI deletes within a further thirty (30) days, so that deletion is complete no later than sixty (60) days after expiry or termination (Clause 3.7(b)). Retention required by law is permitted only on the terms of Clause 3.7(c): the law relied on is stated in writing, the retention is limited to what that law requires, the data stays protected under Annex 2, and it is Processed only for the purpose that justifies the retention. Backup copies are handled under Clause 3.7(d). Axtraction AI's obligation covers End-User Personal Data and copies within its possession or control; where a Reseller supplies or operates the Infrastructure Layer, copies held at that layer are returned or deleted by that Reseller on the same trigger and within the same periods, with signed certification, under Clause 3.7(g). |
| Personal Data (specific instruction) | Retained only as needed for service delivery and lawful obligations. | Deleted on valid instruction, subject to technical and legal constraints. |
| Logs / telemetry | Retained for security, audit, support, and billing periods. | Anonymised or retained where needed for security records. |
| Backups | Retained per backup rotation. | Deleted through the normal backup-expiry cycle rather than by targeted extraction (Clause 3.7(d)), unless separately agreed. Until deleted, backup copies stay protected under Annex 2 and may not be accessed, restored, or Processed for any purpose other than one that justifies their retention or a restoration for the Controller's benefit. |
| AI / LLM inference data (prompts, inputs, and outputs sent to Amazon Bedrock / Azure OpenAI) | Zero retention where the End-User or Client so elects; otherwise retained by Axtraction AI for a maximum of twelve (12) months, then deleted. The AI Sub-processors do not use this data to train their foundation models (Annexes 3–4), and Axtraction AI does not itself use it to train, fine-tune, embed, or develop any model, including its own, absent express written authorisation (Clause 3.11). | Deleted at the end of the elected retention period (or transiently, where zero retention is elected), subject only to retention required by law. |
| AI outputs (stored within the Approved Product as End-User content) | As stated in the Order or product configuration. | Exported or deleted as agreed. |
Exit support. On expiry or termination, the Counterparty may request export of Client Data in a commercially reasonable format. The base return and deletion of Personal Data is free (Clause 3.14). Only value-added services: custom export formatting, migration support, data cleansing, transition assistance, or extended retention beyond the standard return/deletion, are chargeable, and only where agreed in writing. No fee, and no payment-status condition, may be applied to the statutory return or deletion of Personal Data.
Part K: Regulated Sector and government / GLC / Berhad enhanced handling
Before deployment in a Regulated Sector (Clause 1.7), the pre-deployment review in Clause 2.7 applies. For government, GLC, Berhad/listed-entity, or tender-linked engagements, Client Data and procurement documents are handled with enhanced confidentiality: the parties should record authorised users, official communication channels, restricted documents, tender data, conflict-of-interest declarations, audit sensitivity, approved disclosures, and any public-sector recordkeeping requirement in the applicable Order or a procurement annex. Any distributor-specific enhanced data-handling protocol (for example, a distributor's Government/GLC/Berhad protocol) is set out in the applicable Distributor Schedule Pack and applies in addition to this Part K.
Part L: operational templates
Incident Log Template
| Incident ID | Date / time | Severity | Deployment Model | Description | Initial action | Counterparty notified | Personal Data Breach? | Status |
|---|---|---|---|---|---|---|---|---|
| INC-[ ] | [ ] | Critical / High / Medium / Low | Fully Managed / Self-Hosted | [ ] | [ ] | Yes / No / N/A | Yes / No | Open / Contained / Closed |
Client Data Readiness Checklist (backs Clause 2.4)
| Readiness item | Confirmation | Remarks |
|---|---|---|
| Lawful basis / authority to provide data | Yes / No / N/A | |
| Consent / notice completed where required | Yes / No / N/A | |
| Data accuracy checked | Yes / No / N/A | |
| Data minimised to the agreed use case | Yes / No / N/A | |
| Sensitive Data disclosed and pre-approved (Clause 2.6) | Yes / No / N/A | |
| Prohibited-data confirmation (Clause 2.5) | Yes / No / N/A | |
| Data owner identified | Yes / No / N/A | |
| Technical owner identified | Yes / No / N/A | |
| Security-review path confirmed (Clauses 2.6–2.7) | Yes / No / N/A |
Security Exception Register
| Exception item | Reason | Risk rating | Mitigation | Approved by | Review date |
|---|---|---|---|---|---|
| [e.g. no MFA for specific users] | [ ] | Low / Medium / High | [ ] | [ ] | [ ] |
| [e.g. special integration access] | [ ] | Low / Medium / High | [ ] | [ ] | [ ] |
Acceptance
Accepted and agreed by the Counterparty identified in the Cover Sheet, in the role module(s) identified there.
| Counterparty | Axtraction AI Sdn Bhd |
|---|---|
| Signature: ______________________ | Signature: ______________________ |
| Name: ______________________ | Name: ______________________ |
| Designation: ______________________ | Designation: ______________________ |
| Date: ______________________ | Date: ______________________ |
Write to privacy@axtraction.ai. That address also reaches our data protection officer; requests for a signed or superseded copy go there.
For anything else, info@axtraction.ai.