Legal

Data Processing Agreement

Effective 2026-06-16
This page summarizes our Data Processing Agreement. A countersigned DPA is available to enterprise customers on request: success@aim-intelligence.com.

This Data Processing Agreement (“DPA”) forms part of the Terms of Service and applies where AIM Intelligence Co., Ltd. processes personal data on a customer’s behalf in providing Stinger. The customer is the controller; AIM Intelligence is the processor. Where they conflict, this DPA prevails over the Terms on data-protection matters.

1. Scope and roles

We process personal data only to provide the Service and only on the customer’s documented instructions, including in respect of cross-border transfers, and will inform the customer if an instruction appears to infringe applicable law.

2. Nature of processing

The subject matter is the operation of adversarial assessments. Processing covers assessment configurations, attack prompts, target AI responses, and scoring traces. Because traces capture whatever the customer’s target system emits, they may contain incidental personal data; the customer is the controller of that emitted content and is responsible for its lawful basis.

3. Confidentiality and security

Personnel with access are bound by confidentiality. We maintain appropriate technical and organizational measures under Article 32 GDPR, including encryption, access control, tenant isolation, and secure handling and short retention of uploaded credentials.

4. Sub-processors

The customer provides general authorization for sub-processors (including AWS for hosting in Seoul / ap-northeast-2 and any model providers). We impose equivalent data-protection obligations on each, give notice of changes with an opportunity to object, and remain liable for their performance.

5. No training on customer data

We will not use personal data or assessment traces to train or improve any model without the customer’s consent, and we bind any model sub-processor to the same commitment.

6. Assistance, breach, and audits

We assist the customer with data-subject requests and with security, breach-notification, and impact-assessment obligations. We notify the customer of a personal-data breach without undue delay. We make available the information needed to demonstrate compliance, satisfied first through our security certifications and reports, with on-site audit as a conditioned fallback.

7. Deletion or return

On termination, we delete or return personal data at the customer’s choice, subject to any legal retention requirement. Assessment traces and uploaded credentials are deleted on a short, defined window.

8. International transfers

Where transfers require it, the EU Standard Contractual Clauses (Module Two, Controller-to-Processor) apply, with the UK Addendum and Swiss amendments as applicable, and the relevant Korean PIPA cross-border transfer terms.

9. Annexes (in the signed DPA)

  • Annex I — parties, and the categories of data subjects and personal data, nature and purpose, and retention.
  • Annex II — technical and organizational security measures.
  • Annex III — the list of sub-processors.

To request the countersigned DPA: success@aim-intelligence.com.