You
You own the relationship with your customers and you decide what data is collected and why.
checkmAIt builds and runs AI systems that handle real customer information: enquiries, phone calls, messages and records. This page sets out how we meet the UK GDPR and the EU GDPR, how responsibility is divided between you, us and the platforms underneath, and the standard a provider has to meet before it becomes part of the stack.
Under the GDPR, the business that decides why personal data is used is the controller. Anyone handling that data on its instructions is a processor. Anyone the processor brings in is a sub-processor. Each layer is accountable for its own part, and mixing them up is how accountability gets lost.
checkmAIt is a brand owned and operated by JMT Media Limited, a company registered in England and Wales and established in the United Kingdom, so we are subject to the UK GDPR directly. Where the systems we build handle the personal data of people in the EEA, the EU GDPR applies to that processing and we comply with it.
You own the relationship with your customers and you decide what data is collected and why.
We design, build and run the system to your brief. We only touch data to deliver the service, and we choose vetted platforms to run it on.
Hosting, AI models, telephony, messaging and CRM providers. Each signs GDPR terms, publishes its audits, and lists its own suppliers.
For our own website, marketing and client relationships, we are the controller instead, and our privacy policy covers that in full.
We do not add a platform to the stack because it is cheap or because it is what everyone else uses. Before any provider handles personal data on a client build, we check it against a fixed standard, and we keep checking.
We review the stack periodically against each provider's live documentation rather than assuming last year's position still holds. If a provider drops a certification, changes its transfer basis, or stops publishing its sub-processors, we replace it.
We keep a full register of every platform in the stack: what it does, the DPA that covers it, its transfer basis, its audits and where the data physically sits, with links to each provider's own source documents so you can check any of it yourself or hand it to your advisers. Clients and prospective clients can request that register at any time. Email privacy@thecheckmait.com and we will send it.
The GDPR is easier to meet when the system is designed for it rather than retrofitted. Every build starts from these:
Our systems draft replies, answer calls, classify enquiries and schedule appointments automatically. None of them make decisions with legal or similarly significant effects on a person, such as credit, employment or eligibility decisions.
Anyone dealing with one of our systems can ask to speak to a person, and a person can take over any conversation at any point. Where an automated system has made a decision about you, you can ask for a human to review it. Requests go to privacy@thecheckmait.com or to the business you were dealing with.
If you are an individual whose data sits in a system we run, the business you dealt with is the controller and it decides on your request. Contact them first. If you cannot identify or reach them, email privacy@thecheckmait.com and we will identify the controller and pass your request on.
If you are a checkmAIt client, send requests to the same address and we will support you in answering them within your statutory deadline.
The full list of rights, our response times and how to complain to a supervisory authority are set out in the privacy policy.
checkmAIt is a brand owned and operated by JMT Media Limited, a company registered in England and Wales with company number 16015121, at 38 Pinfold Close, Repton, Derby, DE65 6FR, United Kingdom. Contracts, invoices and telecoms records are in the name of JMT Media Limited. It is the legal entity accountable for everything on this page.
We are not required to appoint a Data Protection Officer, so data protection questions come to the address above and are answered by a person rather than routed into a queue.
The privacy policy covers what we collect, why, how long we keep it, and how phone calls and text messages are handled specifically.
Want the platform register, a signed DPA, or answers on data residency for your own setup? Email privacy@thecheckmait.com. We will send the documents rather than a summary of them.