Data Processing Addendum

How Pilotlab processes personal data on your behalf, including transfer mechanisms and sub-processing.

Last updated: June 2026 · Effective June 2026 · v0.1 (draft)

This Data Processing Addendum ("DPA") forms part of the agreement between you (the controller) and Pilotlab (the processor) and applies where we process personal data on your behalf.

1.1. You are the controller and we are the processor in respect of Customer Personal Data, as those terms are defined in applicable Data Protection Law.

2.1. We process Customer Personal Data only on your documented instructions, which are given by your use of the Services and by the agreement.

Subject matterDurationNature and purposeCategories of data subject
Provision of the Pilotlab ServicesFor the term of the agreement plus the retention periodHosting, storage and processing of Customer Data to deliver the ServicesYour personnel, your customers and contacts you record
Annex 1 — Details of processing

3.1. We ensure that personnel authorised to process Customer Personal Data are bound by appropriate confidentiality obligations.

4.1. We implement and maintain the technical and organisational measures described in Annex 2, including encryption in transit and at rest, access control and logging.

5.1. You provide general authorisation for us to engage sub-processors listed in our Sub-processors page.

5.2. We will give at least thirty (30) days notice before adding or replacing a sub-processor, and you may object on reasonable data-protection grounds.

6.1. We will provide reasonable assistance to enable you to respond to requests from data subjects exercising their rights.

7.1. We will notify you without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a personal data breach affecting Customer Personal Data.

8.1. Where Customer Personal Data is transferred outside the UK or EEA, the transfer is made under the UK International Data Transfer Addendum or the EU Standard Contractual Clauses as applicable.

9.1. We will make available information necessary to demonstrate compliance and will allow for audits on reasonable notice, no more than once per year unless required by a supervisory authority.

10.1. On termination we will delete or return Customer Personal Data at your election, subject to any retention required by law.

Encryption of data in transit (TLS 1.2+) and at rest; role-based access control with least privilege; centralised audit logging; documented incident response; annual penetration testing; supplier security review before onboarding.

To request a countersigned copy of this DPA, contact our privacy team.

privacy@pilotlab.app
Data Processing Addendum | Pilotlab Legal