PilotApps PilotApps
  • Privacy Policy
  • Terms & Conditions
  • Data Processing Agreement
  • Log in

Data Processing Agreement

This Data Processing Agreement (the “DPA”) is entered into as of the date You accept the Terms by and between PilotApps.ai (Amaravel Technologies) (“PilotApps”) and You (“You/Your”).

You and PilotApps shall be individually referred to as “Party” and collectively as “Parties”.

The Parties acknowledge and understand that this DPA forms an integral part of the terms of service available at /sauth/legal/terms.html between You and PilotApps describing and governing Your access to and use of the Services (the “Terms”) and is applicable where PilotApps is the Processor of Your Personal Data. In the event of a conflict between this DPA and the Terms, this DPA shall prevail.

1. Definitions

Terms not specifically defined herein shall have the meaning ascribed thereto in the Terms.

“Controller” shall mean the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.

“Data Protection Laws” shall mean the data protection laws of the country in which You are established and any data protection laws applicable to You in connection with the Terms, including but not limited to GDPR, UK GDPR and the UK Data Protection Act, the Swiss DPA, CCPA/CPRA and other US state privacy laws as applicable, PIPEDA, and India’s Digital Personal Data Protection Act (“DPDPA”), in each case as may be amended, superseded or replaced.

“Data Subject” shall mean any identified or identifiable natural person to whom the Personal Data relates.

“GDPR” shall mean Regulation (EU) 2016/679.

“Personal Data” means information relating to an identified or identifiable natural person forming a part of Customer Data.

“Personal Data Breach” shall mean a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.

“Processing” shall mean any operation or set of operations which is performed on personal data, whether or not by automated means.

“Processor” shall mean a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.

“Restricted Transfer” means a transfer of Personal Data from the EEA, UK or Switzerland to a country which is not subject to an adequacy determination under applicable Data Protection Laws.

“Sensitive Personal Information” means special-category and similarly sensitive data as defined under applicable Data Protection Laws.

“Standard Contractual Clauses” or “SCCs” means (i) where the GDPR applies, the EU Commission Implementing Decision (EU) 2021/914 clauses (“EU SCCs”); (ii) where the UK GDPR applies, the UK International Data Transfer Addendum (“UK SCCs”); and (iii) where the Swiss DPA applies, the applicable Swiss standard data protection clauses (in each case as updated, amended or superseded from time to time).

2. Scope and Responsibilities

2.1 This DPA applies to Processing of Personal Data forming a part of the Customer Data.

2.2 PilotApps shall Process Personal Data only on Your behalf, as a Processor and at all times only in accordance with this DPA. For the avoidance of doubt, PilotApps shall be the Processor where You are the Controller of the Personal Data and where You are the Processor, PilotApps shall be the sub-processor of Personal Data.

2.3 Within the scope of the Terms, each party shall be responsible for complying with its respective obligations as Controller and Processor under Data Protection Laws and You shall issue Processing instruction only in compliance with applicable Data Protection Laws.

3. Term and Termination

3.1 This DPA becomes effective upon You subscribing to the Services by agreeing to the Terms. It shall continue to be in full force and effect as long as PilotApps is Processing Personal Data pursuant to the Terms and shall terminate automatically thereafter.

3.2 Where amendments are required to ensure compliance of this DPA with Data Protection Laws, the Parties shall make reasonable efforts to agree on such amendments upon Your request. Where the Parties are unable to agree upon such amendments, either party may terminate the Terms in accordance with the termination procedure contained therein.

4. Processing Instructions

4.1 PilotApps will Process Personal Data in accordance with Your instructions. This DPA contains Your initial instructions to PilotApps. The Parties agree that You may communicate any change in your initial instructions to PilotApps by way of amendment to this DPA.

4.2 Any instructions that would lead to Processing outside the scope of this DPA (e.g. because a new Processing purpose is introduced) will require a prior agreement between the Parties.

4.3 PilotApps shall without undue delay inform You in writing if, in PilotApps's opinion, an instruction infringes Data Protection Laws and provide a detailed explanation of the reasons for its opinion in writing.

5. Processor Personnel

5.1 PilotApps will restrict its personnel from Processing Personal Data without authorization. PilotApps will impose appropriate contractual obligations upon its personnel, including relevant obligations regarding confidentiality, data protection and data security, as required under the applicable Data Protection Laws.

6. Disclosure to Third Parties; Data Subjects Rights

6.1 PilotApps will not disclose Personal Data to any government agency, court, or law enforcement except with Your written consent or as necessary to comply with applicable mandatory laws. If PilotApps is obliged to disclose Personal Data to a law enforcement agency, then PilotApps agrees to give You reasonable notice of the access request prior to granting such access, to allow You to seek a protective order or other appropriate remedy, unless legally prohibited.

6.2 In case You receive any request or communication from Data Subjects which relate to the Processing of Personal Data ("Request"), PilotApps shall reasonably provide You with reasonable cooperation, information and assistance in relation to any such Request where instructed by You.

6.3 Where PilotApps receives a Request, PilotApps shall (i) not directly respond to such Request, unless required to do so under applicable Data Protection Laws (ii) forward the Request to You within five (5) business days of identifying the Request as being related to You and (iii) provide Assistance according to further instructions from You.

7. Technical and Organizational Measures

7.1 PilotApps shall implement and maintain appropriate technical and organizational security measures to ensure that Personal Data is Processed according to this DPA and applicable Data Protection Laws, and to protect Personal Data against a Personal Data Breach, as described in Appendix II.

8. Assistance with Data Protection Impact Assessment

8.1 Where a Data Protection Impact Assessment ("DPIA") is required under applicable Data Protection Laws for the Processing of Personal Data, PilotApps shall provide upon request to You any information and assistance reasonably required for the DPIA including assistance for any communication with data protection authorities, where required, unless the requested information or assistance is not pertaining to PilotApps's obligations under this DPA.

9. Information Rights and Audit

9.1 Upon Your written request at reasonable intervals, PilotApps shall make available to You relevant information regarding its Processing of Personal Data, which may include summaries of third-party audits or certifications to the extent PilotApps maintains them, to demonstrate compliance with this DPA.

9.2 PilotApps will without undue delay refer to You any requests received from national data protection authorities that relate to its Processing of Personal Data.

9.3 To the extent required by applicable Data Protection Laws PilotApps undertakes to reasonably cooperate with You in its dealings with national data protection authorities.

10. Personal Data Breach Notification

In respect of any Personal Data Breach (actual or reasonably suspected), to the extent required and as prescribed by applicable Data Protection Laws PilotApps shall:

10.1 notify You of a Personal Data Breach involving PilotApps or a sub-processor without undue delay;

10.2 if mandated under applicable laws, notify the concerned national authorities and/or the affected Data Subjects;

10.3 provide reasonable information, cooperation and assistance to You in relation to any action to be taken in response to a Personal Data Breach, including regarding any communication of the Personal Data Breach to Data Subjects and national data protection authorities.

11. Subcontracting

11.1 PilotApps shall have Your general authorization for the engagement of third-party sub-processors. Where required under applicable Data Protection Laws, PilotApps will notify You of any intended changes to that list through the appointment or replacement of any sub-processor at least fifteen (15) days in advance. You may object to PilotApps’s appointment or replacement of a sub-processor prior to its appointment or replacement, provided such objection is based on reasonable grounds relating to data protection. In such an event, PilotApps will either not appoint or replace the sub-processor or, if this is not possible, PilotApps may suspend or terminate the Services (without prejudice to any fees accrued prior to such suspension or termination).

11.2 Where PilotApps, with Your consent, subcontracts its obligations and rights under this DPA it shall do so only by way of a binding written contract with the sub-processor which imposes essentially the same obligations as the ones imposed on PilotApps under this DPA.

11.3 Where the sub-processor fails to fulfil its data protection obligations under the subcontracting agreement, PilotApps shall remain fully liable to You for the fulfilment of its obligations under this DPA and for the performance of the sub-processor's obligations.

12. International Data Transfers

12.1 The Parties agree that when there is a transfer of Personal Data from the country where You are established to another country, PilotApps shall provide an adequate level of protection and security that is in accordance with the requirements of the applicable Data Protection Laws.

12.2 The Parties agree that when the transfer of Personal Data from You to PilotApps is a Restricted Transfer and applicable Data Protection Laws require that appropriate safeguards are put in place, such transfer shall be subject to the appropriate Standard Contractual Clauses, which shall be deemed incorporated into and form part of this DPA as set forth in Exhibit A.

13. Deletion or Return of Personal Data

Upon termination of Your Account, PilotApps may delete all Customer Data, including Personal Data in accordance with the procedure set forth in the Terms. This requirement shall not apply to the extent that PilotApps is permitted by applicable law to retain some or all of the Personal Data, in which event PilotApps shall isolate and protect the Personal Data from any further processing except to the extent as required by such law.

14. Obligations under Privacy Laws in the US

14.1 Where CA Privacy Laws apply, You are the Business and PilotApps is the Service Provider with respect to Personal Information of Consumers disclosed by You to PilotApps forming part of Customer Data. PilotApps will not Sell or Share such Personal Information; will not retain, use, or disclose it except to provide the Services or as otherwise permitted by CA Privacy Laws; will not combine it with Personal Information from other sources except as permitted; and will delete it at Your direction in response to a Consumer deletion request. PilotApps shall notify You if it determines that it can no longer comply with CCPA. You disclose Personal Information to PilotApps solely for a valid Business Purpose and to enable PilotApps to Process it for providing Services.

14.2 In addition, in case of Processing of Personal Data of residents of other US states with applicable privacy laws, PilotApps shall provide reasonable assistance to You in meeting Your obligations under those laws in relation to the security of Processing.

15. Miscellaneous

15.1 In case of any conflict, the provisions of this DPA shall take precedence over the Terms. In case of any conflict between the DPA and the SCCs, the SCCs shall take precedence.

15.2 This DPA shall not apply to the Processing of Personal Data where PilotApps is deemed to be the Controller under applicable Data Protection Laws.

15.3 No party shall receive any remuneration for performing its obligations under this DPA except as explicitly set out herein or in another agreement.

15.4 Where this DPA requires a “written notice” or “written request” such notice can also be communicated per email to the other party at support@pilotapps.ai.

15.5 Any supplementary agreements or amendments to this DPA must be made in writing and signed by both Parties.

15.6 Should individual provisions of this DPA become void, invalid or non-viable, this shall not affect the validity of the remaining conditions of this DPA.

Exhibit A — Standard Contractual Clauses

I. In relation to transfers of Personal Data originating from the EEA and subject to the EU GDPR, the SCCs shall apply, completed as follows: Module 2 (Controller to Processor) where You are a Controller and PilotApps is a Processor; Module 3 (Processor to Processor) where You are a Processor and PilotApps is a sub-processor; Clause 7 optional docking applies; Clause 9(a) Option 2 applies; Clause 11 optional language does not apply; Clause 17 Option 1, Irish law; Clause 18(b) courts of Ireland.

II. In relation to transfers originating from the UK or Switzerland, the EU SCCs as implemented above apply with the usual UK GDPR / Swiss DPA modifications (references to EU law replaced by UK or Swiss law; competent authority the ICO or Swiss FDPIC; governing law England and Wales or Switzerland as applicable).

III. For descriptions in the SCCs, You are the “data exporter” and PilotApps.ai (Amaravel Technologies) is the “data importer”.

IV. If the SCCs are replaced, amended or no longer recognized as valid, the Parties will promptly put an alternative transfer mechanism in place or cease the transfer.

Appendix I — Parties and description of transfer

Data exporter: The entity that has entered into the Terms with PilotApps; contact details as provided while entering into the Terms. Role: Controller (or Processor, as applicable).

Data importer: PilotApps.ai (Amaravel Technologies). Contact: support@pilotapps.ai. Role: Processor.

Categories of data subjects: employees, contractors, business partners or other individuals having Personal Data stored, transmitted to, made available to, accessed or otherwise processed by the data importer.

Categories of personal data: as determined by the Customer; typically name, phone numbers, e-mail address, address, company name, plus any application-specific data transferred by authorised personnel.

Sensitive data: No Sensitive Personal Information is to be transferred. The data exporter shall not disclose (and shall not permit any individual to disclose) any Sensitive Personal Data to the data importer for processing.

Frequency: continuous, for the duration of the Services.

Sub-processors: as notified to You by PilotApps.ai (Amaravel Technologies). For the current list, contact support@pilotapps.ai.

Appendix II — Technical and organisational measures

PilotApps implements and maintains a security program appropriate to the nature of the Services, including access controls, encryption in transit, credential hashing, network protections, logging, and personnel confidentiality obligations. For a current description of security measures, contact support@pilotapps.ai.

Appendix III — List of sub-processors

Our current list of sub-processors is available upon request at support@pilotapps.ai.

Effective Date: 18 August 2026
Last Updated: 18 August 2026

© 2026 PilotApps.ai (Amaravel Technologies). All rights reserved.