Data Processing Agreement
Last updated: October 9, 2026
This Data Processing Agreement sets out how PilotLab LLC processes personal data on behalf of its customers when they use PilotLab products and services.
1. Application and Order of Precedence
This Data Processing Agreement ("DPA") forms part of the agreement between PilotLab LLC ("PilotLab") and the customer ("Customer") for PilotLab products and services, including our Terms & Conditions (the "Agreement"). It applies when PilotLab processes Customer Personal Data on Customer's behalf.
It applies automatically when Customer accepts the Agreement. Customers who need a countersigned copy can request one from support@pilotlab.net. If this DPA conflicts with the Agreement on the processing of personal data, this DPA controls. If it conflicts with the Standard Contractual Clauses, the Standard Contractual Clauses control.
2. Definitions
- Customer Personal Data: personal data in Customer Data that PilotLab processes on Customer's behalf to provide the Services.
- Data Protection Laws: all data protection and privacy laws that apply to the processing, including the EU GDPR, the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended (CCPA) and other US state privacy laws.
- Security Incident: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
- Subprocessor: a third party that PilotLab engages to process Customer Personal Data.
- Standard Contractual Clauses (SCCs): the clauses approved by the European Commission in Decision 2021/914, and the UK International Data Transfer Addendum where applicable.
Terms such as controller, processor, data subject and processing have the meanings given in the GDPR. "Business," "service provider" and "sell" have the meanings given in the CCPA.
3. Roles of the Parties
Customer is the controller (or a processor acting for its own controller) of Customer Personal Data, and PilotLab is a processor (or subprocessor). Under the CCPA, PilotLab is Customer's service provider. Each party will comply with the Data Protection Laws that apply to it. Customer is responsible for having a lawful basis, and any notices and consents required, for the processing, including consent for emails, calls, texts and call recordings made through the Services.
4. Processing Instructions
PilotLab will process Customer Personal Data only on Customer's documented instructions, which are the Agreement, this DPA and Customer's use and configuration of the Services, unless the law requires otherwise (in which case PilotLab will tell Customer first unless the law prohibits it). PilotLab will tell Customer if it believes an instruction breaks Data Protection Laws.
PilotLab will not sell or share Customer Personal Data, retain, use or disclose it outside the direct business relationship with Customer or for any purpose other than providing the Services, or combine it with personal data from other sources except as permitted by the CCPA.
5. Confidentiality of Personnel
PilotLab will ensure that people authorized to process Customer Personal Data are bound by confidentiality obligations and have access only as needed to provide the Services.
6. Security Measures
PilotLab will implement appropriate technical and organizational measures to protect Customer Personal Data, taking into account the nature of the processing and the risks involved. These include the measures in Annex 2. PilotLab may update its measures as long as the overall level of protection is not reduced.
7. Subprocessors
Customer gives general authorization for PilotLab to use Subprocessors. Our current Subprocessors are listed on our Subprocessors page. PilotLab will impose data protection terms on each Subprocessor that are at least as protective as this DPA, and remains responsible for their performance.
PilotLab will give at least 30 days' notice before adding or replacing a Subprocessor, by updating the Subprocessors page and notifying customers who have subscribed to updates. Customer may object on reasonable data protection grounds within that period. The parties will discuss the objection in good faith; if it cannot be resolved, Customer may terminate the affected Service and receive a refund of prepaid fees for the remaining term.
8. Data Subject Requests
Taking into account the nature of the processing, PilotLab will help Customer respond to requests from individuals exercising their rights under Data Protection Laws. If PilotLab receives a request directly, it will refer the individual to Customer and will not respond itself unless Customer authorizes it or the law requires it.
9. Security Incidents
PilotLab will notify Customer without undue delay, and in any case within 72 hours, after becoming aware of a Security Incident affecting Customer Personal Data. The notice will include the information reasonably available about the nature of the incident, the data and individuals affected, likely consequences and the measures taken. PilotLab will take reasonable steps to contain and investigate the incident. Notification is not an admission of fault.
10. Impact Assessments and Consultations
PilotLab will provide reasonable information to help Customer carry out data protection impact assessments and consult supervisory authorities where Data Protection Laws require it.
11. International Transfers
PilotLab processes data in the United States. To the extent Customer Personal Data subject to the GDPR, UK GDPR or Swiss law is transferred to a country without an adequacy decision, the parties agree to the SCCs, which are incorporated by reference: Module 2 (controller to processor) or Module 3 (processor to processor) as applicable, with the optional docking clause, the general authorization option in Clause 9 with the notice period above, and the governing law and courts of Ireland. For UK transfers, the UK International Data Transfer Addendum applies. For Swiss transfers, references to the GDPR are read as references to Swiss law. Annexes 1 and 2 of this DPA complete the SCC annexes.
12. Audits
On written request, PilotLab will provide information reasonably needed to demonstrate compliance with this DPA, such as answers to security questionnaires and summaries of relevant policies. If that is not enough to meet Customer's obligations, Customer may conduct an audit, at its own cost, no more than once a year (unless required by a regulator or following a Security Incident), with at least 30 days' notice, during business hours and subject to confidentiality.
13. Return and Deletion
After the Agreement ends, PilotLab will make Customer Personal Data available for export for 30 days and will then delete it within a further 60 days, unless the law requires PilotLab to keep it. Backups are deleted on their normal rotation schedule and remain protected under this DPA until then.
14. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, except where Data Protection Laws do not allow this.
15. Annex 1: Details of Processing
- Subject matter and duration: providing the Services for the term of the Agreement plus the deletion period above.
- Nature and purpose: hosting, storing, transmitting, analyzing and otherwise processing Customer Personal Data to provide, secure and support the Services, as instructed by Customer.
- Categories of data subjects: Customer's users, and Customer's contacts, leads, customers, subscribers, callers, email recipients and website users whose data Customer submits to the Services.
- Categories of personal data: depending on the product, names, email addresses, phone numbers, carrier and line type data, IP addresses, message content, call audio and transcripts, website content, account and usage data, and financial or bookkeeping records.
- Special categories: none intended. Customer must not submit special category data or protected health information unless agreed in writing.
- Frequency: continuous, for as long as Customer uses the Services.
16. Annex 2: Security Measures
- Encryption: data is encrypted in transit using TLS, and stored on infrastructure providers that encrypt data at rest.
- Access control: least-privilege access, unique accounts, multi-factor authentication for administrative access, and prompt removal of access when no longer needed.
- Logical separation: customer data is logically separated so one customer cannot access another's data.
- Logging and monitoring: logging of administrative access and monitoring of systems for availability and security events.
- Secure development: code review, dependency updates and testing before production releases.
- Resilience: backups and recovery procedures for production data.
- Vendor management: review of Subprocessors' security before engagement.
- Incident response: a documented process for investigating, containing and notifying Security Incidents.