checkmAIt
Home How It Works Privacy Terms GDPR
GDPR Statement

We vet every platform before it holds your data

checkmAIt builds and runs AI systems that handle real customer information: enquiries, phone calls, messages and records. This page sets out how we meet the UK GDPR and the EU GDPR, how responsibility is divided between you, us and the platforms underneath, and the standard a provider has to meet before it becomes part of the stack.

Last updated: 7 September 2026 Version 1.0 UK GDPR · EU GDPR
Section 01

Three parties, three roles

Under the GDPR, the business that decides why personal data is used is the controller. Anyone handling that data on its instructions is a processor. Anyone the processor brings in is a sub-processor. Each layer is accountable for its own part, and mixing them up is how accountability gets lost.

checkmAIt is a brand owned and operated by JMT Media Limited, a company registered in England and Wales and established in the United Kingdom, so we are subject to the UK GDPR directly. Where the systems we build handle the personal data of people in the EEA, the EU GDPR applies to that processing and we comply with it.

Controller

You

You own the relationship with your customers and you decide what data is collected and why.

Processor

checkmAIt

We design, build and run the system to your brief. We only touch data to deliver the service, and we choose vetted platforms to run it on.

Sub-processors

The platforms

Hosting, AI models, telephony, messaging and CRM providers. Each signs GDPR terms, publishes its audits, and lists its own suppliers.

For our own website, marketing and client relationships, we are the controller instead, and our privacy policy covers that in full.

Section 02

How we vet providers and sub-processors

We do not add a platform to the stack because it is cheap or because it is what everyone else uses. Before any provider handles personal data on a client build, we check it against a fixed standard, and we keep checking.

  • A written data processing agreement. Either built into the provider's standard terms or executed by us through their portal. No DPA, no data.
  • Independent security certification. We look for SOC 2 Type II, ISO 27001, or equivalent audited evidence rather than a marketing page that says "enterprise grade".
  • A lawful transfer basis. Standard Contractual Clauses with the UK Addendum or IDTA, EU-US Data Privacy Framework certification, or an adequacy decision. We check which one applies before data crosses a border, not after.
  • A published sub-processor list. If a provider will not say who it passes data to, the chain goes dark one layer down and we cannot stand behind it. This is a hard requirement.
  • No training on your data. Our AI providers are contractually barred from training their models on anything sent through their business interfaces. That is a term in the contract, not a toggle in a settings page.
  • Meaningful data controls. Where a provider offers redaction of personal data, configurable retention or automatic deletion, we switch them on rather than leaving the defaults.
  • Data residency where it is needed. Where a client requires data to stay inside the UK or EU, we select providers and regions that can do it, including running the same AI models through EU-hosted infrastructure.

We review the stack periodically against each provider's live documentation rather than assuming last year's position still holds. If a provider drops a certification, changes its transfer basis, or stops publishing its sub-processors, we replace it.

We keep a full register of every platform in the stack: what it does, the DPA that covers it, its transfer basis, its audits and where the data physically sits, with links to each provider's own source documents so you can check any of it yourself or hand it to your advisers. Clients and prospective clients can request that register at any time. Email privacy@thecheckmait.com and we will send it.

Section 03

What we commit to as your processor

  • We act only on your documented instructions. We do not use your data for our own purposes, and we never sell it.
  • We collect the minimum the system needs. If a field is not needed to do the job, we do not capture it.
  • We tell you before we add a sub-processor that will handle your data, so you have the chance to object.
  • We help you answer data subject requests. Access, correction, deletion, portability and objection. The decision is yours as controller; the work of finding and extracting the data is ours.
  • We notify you of a breach without undue delay, and we support your own 72-hour notification to the regulator with whatever detail you need.
  • We delete or return your data when the contract ends, on your instruction, and we confirm when it is done.
  • We sign a DPA with you. We will sign ours or work from yours, whichever your legal team prefers.
Section 04

The principles we build to

The GDPR is easier to meet when the system is designed for it rather than retrofitted. Every build starts from these:

  • Lawfulness and transparency. People are told who they are dealing with. Our AI voice agents identify the business at the start of every call, and announce recording where recording is on.
  • Purpose limitation. Data captured to answer an enquiry is used to answer that enquiry.
  • Data minimisation. Redaction and short retention windows are on by default, not an upgrade.
  • Accuracy. Records are correctable, and corrections propagate rather than sitting in one system.
  • Storage limitation. Recordings and transcripts delete on a schedule instead of accumulating forever.
  • Integrity and confidentiality. Encryption in transit and at rest, per-person credentials in a password manager, access limited to the people on the build and removed when they leave it.
  • Accountability. We can show you the register, the agreements and the settings. That is the whole point of publishing this page.
Section 05

AI, automation and human review

Our systems draft replies, answer calls, classify enquiries and schedule appointments automatically. None of them make decisions with legal or similarly significant effects on a person, such as credit, employment or eligibility decisions.

Anyone dealing with one of our systems can ask to speak to a person, and a person can take over any conversation at any point. Where an automated system has made a decision about you, you can ask for a human to review it. Requests go to privacy@thecheckmait.com or to the business you were dealing with.

Section 06

Exercising your rights

If you are an individual whose data sits in a system we run, the business you dealt with is the controller and it decides on your request. Contact them first. If you cannot identify or reach them, email privacy@thecheckmait.com and we will identify the controller and pass your request on.

If you are a checkmAIt client, send requests to the same address and we will support you in answering them within your statutory deadline.

The full list of rights, our response times and how to complain to a supervisory authority are set out in the privacy policy.

Section 07

Who to contact

checkmAIt is a brand owned and operated by JMT Media Limited, a company registered in England and Wales with company number 16015121, at 38 Pinfold Close, Repton, Derby, DE65 6FR, United Kingdom. Contracts, invoices and telecoms records are in the name of JMT Media Limited. It is the legal entity accountable for everything on this page.

Data protection contactprivacy@thecheckmait.com
Platform registerOn request
DPAAvailable to sign

We are not required to appoint a Data Protection Officer, so data protection questions come to the address above and are answered by a person rather than routed into a queue.

Related

The full picture

The privacy policy covers what we collect, why, how long we keep it, and how phone calls and text messages are handled specifically.

Want the platform register, a signed DPA, or answers on data residency for your own setup? Email privacy@thecheckmait.com. We will send the documents rather than a summary of them.

checkmAIt
Home How It Works Privacy Policy Terms GDPR Contact

© 2026 checkmAIt. All rights reserved.