This Data Processing Agreement (“DPA”) forms part of the Terms of Service and applies where AIM Intelligence Co., Ltd. processes personal data on a customer’s behalf in providing Stinger. The customer is the controller; AIM Intelligence is the processor. Where they conflict, this DPA prevails over the Terms on data-protection matters.
We process personal data only to provide the Service and only on the customer’s documented instructions, including in respect of cross-border transfers, and will inform the customer if an instruction appears to infringe applicable law.
The subject matter is the operation of adversarial assessments. Processing covers assessment configurations, attack prompts, target AI responses, and scoring traces. Because traces capture whatever the customer’s target system emits, they may contain incidental personal data; the customer is the controller of that emitted content and is responsible for its lawful basis.
Personnel with access are bound by confidentiality. We maintain appropriate technical and organizational measures under Article 32 GDPR, including encryption, access control, tenant isolation, and secure handling and short retention of uploaded credentials.
The customer provides general authorization for sub-processors (including AWS for hosting in Seoul / ap-northeast-2 and any model providers). We impose equivalent data-protection obligations on each, give notice of changes with an opportunity to object, and remain liable for their performance.
We will not use personal data or assessment traces to train or improve any model without the customer’s consent, and we bind any model sub-processor to the same commitment.
We assist the customer with data-subject requests and with security, breach-notification, and impact-assessment obligations. We notify the customer of a personal-data breach without undue delay. We make available the information needed to demonstrate compliance, satisfied first through our security certifications and reports, with on-site audit as a conditioned fallback.
On termination, we delete or return personal data at the customer’s choice, subject to any legal retention requirement. Assessment traces and uploaded credentials are deleted on a short, defined window.
Where transfers require it, the EU Standard Contractual Clauses (Module Two, Controller-to-Processor) apply, with the UK Addendum and Swiss amendments as applicable, and the relevant Korean PIPA cross-border transfer terms.
To request the countersigned DPA: success@aim-intelligence.com.