This Data Processing Addendum ("DPA") forms part of the agreement between you (the controller) and Pilotlab (the processor) and applies where we process personal data on your behalf.
1. Roles of the parties
1.1. You are the controller and we are the processor in respect of Customer Personal Data, as those terms are defined in applicable Data Protection Law.
2. Scope and purpose of processing
2.1. We process Customer Personal Data only on your documented instructions, which are given by your use of the Services and by the agreement.
| Subject matter | Duration | Nature and purpose | Categories of data subject |
|---|---|---|---|
| Provision of the Pilotlab Services | For the term of the agreement plus the retention period | Hosting, storage and processing of Customer Data to deliver the Services | Your personnel, your customers and contacts you record |
3. Confidentiality
3.1. We ensure that personnel authorised to process Customer Personal Data are bound by appropriate confidentiality obligations.
4. Security measures
4.1. We implement and maintain the technical and organisational measures described in Annex 2, including encryption in transit and at rest, access control and logging.
5. Sub-processing
5.1. You provide general authorisation for us to engage sub-processors listed in our Sub-processors page.
5.2. We will give at least thirty (30) days notice before adding or replacing a sub-processor, and you may object on reasonable data-protection grounds.
6. Data subject rights
6.1. We will provide reasonable assistance to enable you to respond to requests from data subjects exercising their rights.
7. Personal data breaches
7.1. We will notify you without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a personal data breach affecting Customer Personal Data.
8. International transfers
8.1. Where Customer Personal Data is transferred outside the UK or EEA, the transfer is made under the UK International Data Transfer Addendum or the EU Standard Contractual Clauses as applicable.
9. Audits
9.1. We will make available information necessary to demonstrate compliance and will allow for audits on reasonable notice, no more than once per year unless required by a supervisory authority.
10. Deletion and return
10.1. On termination we will delete or return Customer Personal Data at your election, subject to any retention required by law.
Annex 2 — Technical and organisational measures
Encryption of data in transit (TLS 1.2+) and at rest; role-based access control with least privilege; centralised audit logging; documented incident response; annual penetration testing; supplier security review before onboarding.
To request a countersigned copy of this DPA, contact our privacy team.
privacy@pilotlab.app