Data Processing Addendum
Last updated 29 September 2026 · Devtech, LLC d/b/a Agency Pilot
This Data Processing Addendum ("DPA") forms part of the Terms of Service between Devtech, LLC, an Ohio limited liability company doing business as Agency Pilot ("Agency Pilot") and the customer ("Customer"). It applies when Agency Pilot processes personal data on the Customer's behalf. It is accepted automatically with the Terms; if your organisation needs a countersigned copy, email [email protected].
1. Scope and roles
For Customer Data containing personal data, the Customer is the controller (or a processor acting for its own clients) and Agency Pilot is the processor (or sub-processor) and, under US state laws, a service provider or contractor. Details of the processing are in Annex 1. Agency Pilot is a controller only for the account, billing and usage data described in its Privacy Policy, and for de-identified fraud signals as described in the Terms.
2. Instructions
Agency Pilot processes Customer personal data only on the Customer's documented instructions — which are the Terms, this DPA and the Customer's configuration and use of the Service — unless required by law, in which case it will inform the Customer where legally permitted. Agency Pilot will tell the Customer if it believes an instruction infringes applicable data protection law. The Customer is responsible for the lawfulness of its instructions, including notices and consents for its clients' website visitors.
3. Confidentiality
Everyone Agency Pilot authorises to process Customer personal data is bound by confidentiality obligations.
4. Security
Agency Pilot implements appropriate technical and organisational measures to protect Customer personal data, including those in Annex 2, and may update them as long as the overall level of protection is not reduced.
5. Subprocessors
The Customer gives general authorisation for Agency Pilot to use subprocessors in the categories listed on the subprocessors page. For security reasons that page does not name providers. The Customer may obtain the current list of named subprocessors on request, under confidentiality. Agency Pilot:
- will impose data protection obligations on each subprocessor that are no less protective than this DPA, and remains responsible for their performance;
- will give at least 30 days' notice of a new subprocessor to account owners who have asked to be told.
The Customer may object to a new subprocessor on reasonable data protection grounds. If the parties can't resolve the objection, the Customer may terminate the affected service and receive a pro-rata refund of prepaid fees for it.
6. Assistance and requests
Taking into account the nature of the processing, Agency Pilot will help the Customer respond to data subject requests (largely through the Service's own features for finding, exporting and deleting data), and with data protection impact assessments and consultations with authorities where required. If Agency Pilot receives a request directly from a data subject about Customer Data, it will refer them to the Customer.
7. Personal data breaches
Agency Pilot will notify the Customer without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting Customer personal data, with the information reasonably available to help the Customer meet its own obligations, and will take reasonable steps to contain and remedy it.
8. International transfers
Customer personal data is processed in the United States. Where the GDPR, UK GDPR or Swiss law requires a transfer mechanism, the parties agree that the EU Standard Contractual Clauses (Module 2 or 3 as applicable) and the UK Addendum are incorporated by reference, with Agency Pilot as data importer, the governing law and forum of Ireland for the Clauses, and the Annexes to this DPA completing their appendices.
9. Deletion and return
The Customer can export its data from the Service while its account is active. After the account ends, Agency Pilot deletes Customer personal data within 90 days (session recordings 7 days after the paid period ends), except where law requires it to be kept, in which case it stays protected by this DPA.
10. Information and audits
On request, Agency Pilot will provide information reasonably necessary to demonstrate compliance with this DPA, including answers to security questionnaires. If that is not sufficient, the Customer may carry out an audit once a year, on 30 days' notice, during business hours, under confidentiality, and at its own cost, in a way that doesn't compromise other customers' data or Agency Pilot's security.
11. US state law terms
Agency Pilot will not sell or share Customer personal information, retain, use or disclose it outside the direct business relationship or for any purpose other than the business purposes in the Terms, or combine it with other personal information except as those laws permit. Agency Pilot certifies it understands these restrictions and will notify the Customer if it can no longer meet them.
12. General
The Terms' limitation of liability applies to this DPA. If this DPA conflicts with the Terms, this DPA controls for the processing of personal data; the Standard Contractual Clauses, where they apply, control over both.
Annex 1: Processing details
| Subject matter and duration | Provision of the Service for the term of the Customer's subscription, plus the deletion period. |
|---|---|
| Nature and purpose | Hosting, storage, retrieval, analysis and display of Customer Data; client onboarding and access grants; reporting from connected accounts; lead capture and attribution; fraud detection; heatmaps, session recording and uptime monitoring; messaging; conversion uploads the Customer enables; support. |
| Data subjects | The Customer's team members; its clients' owners and staff and portal users; leads and customers of its clients; visitors to websites where the tracking script is installed; people who communicate with the Customer through the Service. |
| Categories of data | Contact details; account identifiers; lead and sale details; messages, call recordings and documents; connected-account performance data; online identifiers, IP addresses, device and browser information, approximate location, website interaction data and, if enabled, session recordings. |
| Special categories | None intended. The Service masks sensitive form fields by default; the Customer must not enable collection of special category data without a lawful basis. |
| Frequency | Continuous. |
Annex 2: Security measures
- Encryption in transit with TLS; connection tokens and third-party credentials encrypted at rest with AES-256-GCM.
- Logical separation of each customer's data with database row-level security, enforced server-side on every request.
- Role-based access with owner, admin, member and viewer roles, per-member permissions, and client users limited to their own business.
- Authenticator-app two-factor authentication for agency users; passwords handled by the authentication provider and stored only as hashes.
- Least-privilege requests to third-party platforms; owner-level access never requested.
- Masking of password, payment and (by default) all typed fields in session recordings; pages with passwords or card fields not recorded.
- Verification of inbound webhooks by signature; rate limits on public endpoints.
- Managed infrastructure providers with their own security programmes; backups managed by the database provider.
- Error monitoring, logging of onboarding-link events, and an incident response process.
- Retention limits and scheduled deletion as described in the Privacy Policy.
