Pilotran
TemplatesPricingHow-toBlog
Legal

Data Processing Agreement

Last updated: September 2026

Read this
This is the standard DPA between Pilotran and a Customer whose use triggers the GDPR, UK GDPR, or a similar data-protection regime. Business and Enterprise buyers can execute it in one of two ways: (a) accept it inline by clicking “I agree to the DPA” on the billing page, or (b) request a countersigned copy by emailing hello@pilotran.com. Either method binds both parties equally.

1. Definitions

Terms used here match the meanings given in the GDPR (Regulation (EU) 2016/679) and the UK GDPR. Specifically:

  • Customer — the natural or legal person subscribed to a Pilotran paid plan.
  • Pilotran — Pilotran, the data processor providing the workflow automation platform.
  • Customer Data — any Personal Data that Pilotran Processes on behalf of Customer through the platform.
  • Sub-processor — any third party engaged by Pilotran to Process Customer Data.
  • SCCs — the European Commission's Standard Contractual Clauses (2021/914) for the transfer of Personal Data to third countries.

2. Subject matter and duration

Pilotran Processes Customer Data solely to provide the workflow automation service described at pilotran.com/features. Processing lasts for the duration of Customer's subscription plus a 30-day return/deletion window on termination.

3. Nature and purpose of processing

Pilotran runs Customer-authored workflows that read from and write to Customer-connected apps (Gmail, Slack, Notion, HubSpot, etc.) and may invoke Large Language Models for AI steps. Pilotran does not Process Customer Data for any purpose other than delivering the platform, ensuring its reliability, and complying with law.

4. Types of Personal Data and Data Subjects

The types of Personal Data Processed are determined by the workflows Customer chooses to run and the apps Customer chooses to connect. Typical categories include:

  • Names, email addresses, job titles, phone numbers.
  • Email and Slack message contents where Customer has authorised Pilotran to read them.
  • CRM records (contacts, deals, notes) where Customer has connected HubSpot or a similar system.
  • Content of files stored in connected document systems.
  • Metadata generated by the platform: workflow definitions, run logs, timestamps.

Data Subjects are typically Customer's employees, customers, prospects, and correspondents.

5. Obligations of Pilotran

Pilotran will:

  • Process Customer Data only on documented instructions from Customer. The subscription and the workflows Customer configures constitute those instructions.
  • Ensure personnel with access to Customer Data are bound by confidentiality obligations.
  • Implement appropriate technical and organisational security measures (see Section 6).
  • Assist Customer with responding to Data Subject requests, DPIA obligations, and data-protection authority enquiries — to the extent reasonably possible given the nature of the Processing.
  • Not engage a new Sub-processor without giving Customer prior notice and an opportunity to object (see Section 8).
  • On termination, return or delete all Customer Data within 30 days, unless retention is required by law.

6. Security measures

Pilotran maintains technical and organisational measures proportionate to the risk, including:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256) for all Customer Data.
  • Least-privilege access controls — engineering access to production is limited, logged, and reviewed quarterly.
  • OAuth tokens for connected apps are encrypted at rest with per-workspace keys and never exposed to Customer's workflow AI prompts.
  • Structured logging with automated PII scrubbing on error paths.
  • Regular dependency vulnerability scanning and automated patching via CI.
  • Documented incident response process with a target notification time of 72 hours (see Section 9).

7. International transfers

Where Pilotran or a Sub-processor Processes Customer Data outside the EEA or UK, Pilotran relies on the SCCs (Module 2 or Module 3 as applicable) or an equivalent legally recognised transfer mechanism. The SCCs are incorporated into this DPA by reference and take precedence over any conflicting clause.

8. Sub-processors

Customer authorises Pilotran to engage the Sub-processors listed below. Pilotran will notify Customer of any intended change to this list at least 30 days in advance (via a notice on this page and an email to the workspace owner). Customer may object to a new Sub-processor by emailing hello@pilotran.com within that 30-day window; if the objection cannot be resolved, Customer may terminate the affected subscription and receive a pro-rated refund.

Sub-processorPurposeLocationSafeguards
Anthropic PBCLLM inference for AI steps (Claude models)United StatesSCCs · zero-retention API
OpenAI, L.L.C.LLM inference for AI steps when GPT models are selectedUnited StatesSCCs · zero-retention API
Amazon Web Services (Railway hosting)Application hosting, database, background workersUnited States · SingaporeSCCs · encryption at rest
Stripe, Inc.Billing, subscription management, payment method storageUnited States · IrelandSCCs · PCI-DSS Level 1
Resend (or configured SMTP)Transactional email delivery (invites, digests, failure alerts)United StatesSCCs · TLS in transit
SentryError monitoring and diagnostic logsUnited StatesSCCs · PII scrubbing enabled

9. Personal Data Breach notification

If Pilotran becomes aware of a Personal Data Breach affecting Customer Data, Pilotran will notify Customer without undue delay and in any event within 72 hours of becoming aware. The notification will include the nature of the breach, the approximate number of Data Subjects and records concerned, the likely consequences, and the measures Pilotran has taken or proposes to take.

10. Cooperation with authorities

Pilotran will cooperate reasonably with supervisory authorities in the performance of their tasks. Pilotran will inform Customer before disclosing Customer Data in response to a legally binding request unless prohibited from doing so by law.

11. Return or deletion of Customer Data

On expiry or termination of Customer's subscription, Pilotran will return or delete all Customer Data within 30 days, at Customer's election. Backup copies containing Customer Data are purged within 90 days of the primary deletion. Pilotran may retain limited data required to comply with legal obligations (e.g. tax records).

12. Liability and precedence

Each party's liability under this DPA is subject to the limitations set out in the Terms of Service. In the event of a conflict between this DPA and the Terms of Service on the subject of Personal Data Processing, this DPA controls. In the event of a conflict between this DPA and the SCCs, the SCCs control.

13. How to accept

This DPA takes effect between Customer and Pilotran on the earliest of: (a) Customer clicking “I agree to the DPA” on the billing page; (b) Customer emailing hello@pilotran.com to confirm acceptance; or (c) Customer's continued use of a paid plan after being notified of a material update to this DPA. A countersigned PDF is available on request for procurement or vendor-onboarding processes.

14. Contact

Data protection queries and general enquiries both go to hello@pilotran.com.

Pilotran

AI workflow automation on autopilot. Pick a template, connect your apps, let Claude do the rest.

Product

  • Features
  • Templates
  • Pricing

Learn

  • How-to guides
  • Blog

Compare

  • vs Zapier
  • vs n8n
  • vs Make
  • vs Relay
  • vs Gumloop

Company

  • About
  • Contact
  • Privacy
  • Terms
  • DPA
© 2026 Pilotran