Skip to content
SimpliPilot logo

Data Processing Agreement

Effective date: 7 August 2026 · Last updated: 7 August 2026

Provided by SimpliPilot LLC, a limited liability company.

This document is pending final legal review. It reflects how SimpliPilot LLC intends to operate and should be reviewed and approved by a licensed attorney before public launch.

This agreement applies where SimpliPilot LLC, a limited liability company (“Processor”) processes personal data on behalf of a customer (“Controller”) through the SimpliPilot platform. It forms part of the Terms of Service. A countersigned copy is available on request from support@simplipilot.com.

1. Roles and scope

The Controller determines the purposes and means of processing the personal data it puts into its workspace — for example customer contacts, invoices, scheduling and uploaded media. The Processor processes that data only to provide, secure and support the service. The Processor is an independent controller for its own account, billing and telemetry data, as described in the Privacy Policy.

2. Subject matter and categories

  • Subject matter: provision of the SimpliPilot business management platform.
  • Duration: the term of the subscription, plus the deletion window below.
  • Data subjects: the Controller's team members, customers, leads and contacts.
  • Data categories: identity and contact details, business transaction records, scheduling data, communications, and uploaded files or media.

3. Processor obligations

  • Process personal data only on the Controller's documented instructions, including for international transfers, unless required by law.
  • Ensure personnel with access are bound by confidentiality.
  • Implement appropriate technical and organisational measures (see the Security Overview).
  • Assist the Controller, taking account of the nature of processing, with data-subject requests, security, breach notification and impact assessments.
  • Make available information reasonably necessary to demonstrate compliance, and allow audits limited to once per year on reasonable notice, or where required by a supervisory authority.

4. Subprocessors

The Controller gives general authorisation for the Processor to engage subprocessors listed on the Subprocessors page. The Processor imposes data-protection obligations no less protective than this agreement, remains liable for their performance, and will give reasonable prior notice of additions so the Controller can object on legitimate grounds.

5. International transfers

Where processing involves transferring personal data of individuals in the UK or EEA outside those areas, the parties rely on Standard Contractual Clauses or an applicable adequacy decision, with any required addenda incorporated by reference. Transfer mechanisms are subject to final attorney review before public launch.

6. Personal data breach

The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s data, with the information reasonably available, and will cooperate on investigation and remediation.

7. Return and deletion

On termination, the Controller may export its data during a window of normally 30 days. After that window the Processor deletes or anonymises the data, except where retention is required by law (for example billing and tax records).

8. Contact

Data protection enquiries: support@simplipilot.com.