Jump to section
This document is provided in English.
This is the Data Processing Agreement ("DPA") for AI HUB at aimodelhub.ai, incorporated by reference into the Terms of Service. It governs the processing of Personal Data Customer submits to or through the platform in connection with the API routing services.
Purpose and Scope
1.1 This DPA forms an integral part of the Terms of Service between Alchemist Marketing Sdn. Bhd. (Company Registration No. 202101000044 (1400342-A)) ("Data Importer" or "Company") and the entity or individual accessing or using AI HUB ("Data Exporter" or "Customer").
1.2 This DPA governs the processing of Personal Data submitted by Customer to or through the platform in connection with the API routing services ("Services").
1.3 Capitalized terms not defined in this DPA have the meanings set forth in the Terms of Service.
Roles and Responsibilities
2.1 Customer acts as the Data Controller (or Data Processor on behalf of its end-users) with respect to Personal Data contained in API Inputs and Outputs. Company acts strictly as a Data Processor, routing data through its API infrastructure as a passive technical conduit: Company does not monitor, select, classify, refine, or manually modify the contents of Customer's API Inputs or Outputs.
2.2 Under the PDPA, data processors are obligated to comply with applicable data protection principles. Company shall comply with this obligation.
2.3 Customer is solely responsible for obtaining all necessary consents, legal bases, and notices required from data subjects under applicable data protection laws (including the Malaysian PDPA) prior to submitting data to the Service.
Processing Instructions
3.1 Company shall process Personal Data strictly:
- to route API requests to the selected Model Providers;
- to calculate usage deductions and maintain Customer's wallet balance;
- to secure the platform and detect abuse;
- to maintain statutory financial logs.
3.2 Company shall process Personal Data only on documented instructions from Customer. Company shall not use Personal Data for any purpose other than providing the Services, except as required by law.
3.3 Company shall not use Customer's Personal Data to train its own machine learning models.
Sub-Processors
4.1 Customer grants general written authorization to Company to engage third-party Model Providers, inference aggregators, cloud hosting facilities, payment gateways, and other infrastructure providers ("Sub-Processors") necessary to fulfill the Services.
4.2 The Sub-Processors currently engaged by Company are named in Section 4, "Data Sharing and Cross-Border Transfers," of the Privacy Policy.
4.3 Company shall:
- conduct reasonable due diligence on Sub-Processors prior to engagement;
- enter into written agreements with Sub-Processors that impose data protection obligations at least as protective as those set out in this DPA;
- remain responsible for the acts and omissions of its Sub-Processors.
Data Security
5.1 Company shall implement appropriate technical and organisational security measures, including:
- encryption of personal data at rest;
- HTTPS encryption for data in transit;
- API token authentication;
- server firewalls and access controls;
- isolated per-customer containers for Hermes agents;
- restricted access to production data.
5.2 These measures are designed to comply with applicable data protection laws.
Data Breach Notification
6.1 Under the PDPA, data controllers are required to notify the Personal Data Protection Commissioner within seventy-two (72) hours of becoming aware of a personal data breach that causes or is likely to cause significant harm.
6.2 Where Company confirms a personal data breach affecting Customer's Personal Data, Company shall:
- notify Customer without undue delay;
- provide all reasonable assistance to enable Customer to meet its obligations;
- provide such information as is reasonably available regarding the breach.
6.3 Cyberattacks, DDoS disruptions, or upstream Model Provider outages that do not compromise Company's primary databases are governed by the Force Majeure provisions in Terms of Service Section 10.4.
International Transfers
7.1 Customer acknowledges that fulfilling API calls inherently requires routing Inputs across international borders to servers hosting upstream Model Providers located globally.
7.2 Such transfers are conducted in compliance with applicable data protection laws.
Data Retention and Deletion
8.1 Operational API call logs, token metrics, and billing records shall be retained by Company for seven (7) years, in compliance with Section 82 of the Malaysian Income Tax Act 1967 and the Anti-Money Laundering, Anti-Terrorism Financing and Proceeds of Unlawful Activities Act 2001 (AMLA 2001).
8.2 Upon termination of the Services or upon Customer's request, Company shall delete or return all Customer Personal Data in its possession, except where Company is required by law to retain such data.
8.3 Deletion of a Hermes agent destroys its container, memory, uploaded documents, and channel connections irreversibly.
8.4 API request metadata, being the endpoint called, model requested, HTTP status, latency, and token counts, but never the content of any API Input or Output, is retained for ninety (90) days and then deleted. Usage and billing records that support Customer's statements and invoices are a separate record, retained for the period described in Section 8.1, and are the basis for resolving any billing dispute.
Data Subject Rights
9.1 Where Customer is a Data Controller and Company is a Data Processor, Company shall provide reasonable assistance to Customer in responding to data subject rights requests.
9.2 Company shall notify Customer promptly if it receives a data subject request directly, and shall not respond to such request except on Customer's documented instructions or as required by law.
Audit and Compliance
10.1 Company shall maintain records of its processing activities as required under applicable law.
10.2 Customer may, upon reasonable notice and not more than once per calendar year, request information regarding Company's compliance with this DPA. Company shall provide such information as is reasonably available.
Limitation of Liability
11.1 The liability of Company under this DPA shall be governed by the Limitation of Liability provisions set out in Terms of Service Section 10.
11.2 For the avoidance of doubt, the aggregate total liability of Company for any and all claims arising out of or relating to this DPA shall be limited to the greater of: (a) the total amount paid by Customer in the twelve (12) months preceding the claim; or (b) one hundred United States dollars (USD 100.00).
11.3 The limitations in Sections 11.1 and 11.2 shall apply to the fullest extent permitted by applicable law.
Governing Law and Jurisdiction
12.1 This DPA is governed by and shall be construed in accordance with the laws of Malaysia.
12.2 Any dispute arising under or in connection with this DPA shall be finally resolved through binding private arbitration administered by the Asian International Arbitration Centre (AIAC) in Kuala Lumpur, Malaysia, in alignment with the dispute resolution mechanism set out in Terms of Service Section 11.
12.3 Either party may bring proceedings in the Small Claims Court of Malaysia for claims within that court's jurisdictional limit.
Contact Information
Alchemist Marketing Sdn. Bhd. (Company Registration No. 202101000044 (1400342-A))
Block C-38-2 (Second Floor), Zenith Corporate Park,
1, Jalan SS 7/26, SS7, 47301 Petaling Jaya, Selangor, Malaysia.
Email: [email protected]
Need a signed or customized DPA? This document is generic. Tell us what your compliance regime requires and we will work through it with you.
Contact our team