Sign in
Legal

GDPR & Data Policy

How PayPilot Technologies handles personal data — including the critical distinction between PayPilot as data controller and as data processor.

Effective date: 26 May 2025
1. Overview

PayPilot Technologies is committed to compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This policy explains how we handle personal data in connection with the PilotOS platform, and sets out the respective responsibilities of PayPilot and its customers ("Tenants") under UK data protection law.

This policy should be read alongside our Privacy Policy and, where applicable, the Data Processing Agreement ("DPA") forming part of your subscription with us.

2. Controller and Processor Roles — The Critical Distinction

The UK GDPR distinguishes between data controllers (who determine the purposes and means of processing) and data processors (who process data on behalf of, and under the instruction of, a controller).

The table below summarises the roles that apply to data processed in connection with PilotOS:

Category of personal dataRoleBasis
Tenant account and contact details (name, work email, billing address, phone number of the Tenant's authorised users)PayPilot is DATA CONTROLLERWe determine how and why this data is collected to manage your subscription and account
Merchant data (names, contact details, trading information, bank details)Tenant is DATA CONTROLLER · PayPilot is DATA PROCESSORYou instruct us to store and process this data on your behalf
Lead, agent, and partner data entered into PilotOSTenant is DATA CONTROLLER · PayPilot is DATA PROCESSORYou instruct us to store and process this data on your behalf
Application and underwriting data (including significant persons, financial data)Tenant is DATA CONTROLLER · PayPilot is DATA PROCESSORYou instruct us to process this data in connection with MCA and onboarding workflows
End-user data in the white-label merchant portalTenant is DATA CONTROLLER · PayPilot is DATA PROCESSORThe merchant portal operates under your brand and under your data relationship with your merchants
Website visitor data (paypilot.plus)PayPilot is DATA CONTROLLERWe collect this data to operate and improve our website

In summary: once you subscribe to PilotOS and begin using the platform, you become the data controller for all personal data relating to your merchants, leads, agents, and end-users. PayPilot processes that data only on your documented instructions. PayPilot is data controller only for your own Tenant account details.

3. Tenant's Responsibilities as Data Controller

By using PilotOS, you (the Tenant) take on the role of data controller for all personal data you upload, import, or generate within the platform. As a data controller, you are responsible for:

  • Ensuring you have a lawful basis under UK GDPR for processing each category of personal data you hold in PilotOS
  • Providing appropriate privacy notices to the individuals whose data you process (your merchants, leads, agents, and portal users)
  • Responding to data subject rights requests from individuals whose data you hold
  • Ensuring that any data shared with third parties through PilotOS integrations or webhooks is permitted under your legal basis and privacy notices
  • Maintaining a Record of Processing Activities (ROPA) as required under Article 30 UK GDPR
  • Complying with any sector-specific regulations applicable to your business (e.g. FCA rules, PCI DSS)
  • Not uploading special category data (e.g. health data, biometric data) without ensuring appropriate safeguards are in place

PayPilot will not be liable for any breach of UK GDPR or other data protection law arising from your use of the platform as data controller.

4. PayPilot's Responsibilities as Data Processor

When acting as your data processor, PayPilot Technologies commits to the following obligations, consistent with Article 28 of UK GDPR:

  • Process personal data only on your documented instructions and not for any other purpose
  • Ensure that all personnel with access to personal data are subject to appropriate confidentiality obligations
  • Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk
  • Not engage sub-processors without informing you and providing you the opportunity to object
  • Assist you in responding to data subject rights requests, to the extent technically feasible
  • Assist you in meeting your obligations under Articles 32–36 of UK GDPR (security, breach notification, DPIAs)
  • Delete or return all personal data on termination of the subscription, at your election
  • Make available all information necessary to demonstrate compliance with Article 28 obligations
5. Data Processing Agreement

Where required by UK GDPR, a Data Processing Agreement ("DPA") is available to supplement your subscription terms. The DPA governs the processor-controller relationship for data processed in PilotOS on your behalf and is intended to meet the requirements of Article 28.

For Tenants who require a DPA, please contact legal@paypilot.plus. Where your subscription agreement explicitly incorporates a DPA by reference, that DPA forms part of your binding agreement with us.

6. Sub-processors

PayPilot engages a limited number of trusted third-party sub-processors to assist in the delivery of PilotOS. All sub-processors are required to maintain appropriate data protection standards and are bound by contractual commitments consistent with Article 28 UK GDPR.

Our current sub-processors include providers in the following categories:

  • Cloud infrastructure and database hosting
  • Email delivery and transactional notifications
  • Authentication and identity services
  • Payment processing (for platform subscription billing only)
  • Error monitoring and application performance
  • Customer support tooling

We maintain a current list of sub-processors and will notify Tenants of any additions or replacements with reasonable advance notice. To receive sub-processor notifications, please ensure your account contact email is kept current. If you have a contractual right to object to a new sub-processor, such objections must be raised within 14 days of notification.

7. Security Measures

PayPilot implements the following technical and organisational measures to protect personal data:

  • Encryption of data in transit using TLS 1.2 or higher
  • Encryption of data at rest
  • Role-based access control with principle of least privilege
  • Multi-factor authentication for administrative access
  • Comprehensive audit logging of data access and changes
  • Regular vulnerability assessments and penetration testing
  • Incident response procedures with documented escalation paths
  • Business continuity and disaster recovery procedures
  • Staff training on data protection and security awareness

Security measures are reviewed and updated regularly. While we take all reasonable precautions, no system is entirely free from risk and we cannot guarantee absolute security.

8. Personal Data Breaches

In the event of a personal data breach affecting data for which PayPilot is data processor, we will:

  • Notify the affected Tenant without undue delay upon becoming aware of the breach
  • Provide information sufficient to allow the Tenant to fulfil any notification obligations to the ICO and/or affected individuals
  • Cooperate with the Tenant's incident response activities
  • Take appropriate steps to contain and remediate the breach

As data controller, you are responsible for assessing the risk of the breach and, where applicable, notifying the ICO within 72 hours and affected individuals without undue delay.

In the event of a breach affecting data for which PayPilot is data controller (Tenant account details), we will notify affected individuals and the ICO directly in accordance with UK GDPR.

9. Data Retention and Deletion

PayPilot retains Tenant-processed data for as long as your subscription is active and for a period of 30 days following termination, to allow for data export. After this period, data will be securely deleted unless a longer retention period is required by law.

Tenant account data (for which we are data controller) is retained for 7 years following the end of the subscription for accounting, tax, and legal purposes.

You may request deletion of your data within the platform at any time, subject to any retention obligations required by applicable law.

10. International Transfers

PayPilot Technologies and our primary infrastructure are based in the United Kingdom. Where any sub-processor operates outside the UK, we ensure that appropriate transfer mechanisms are in place, including UK International Data Transfer Agreements (IDTAs) or reliance on adequacy regulations.

We will not transfer personal data outside the UK without ensuring that the recipient provides an adequate level of protection.

11. Data Subject Rights

When PayPilot is the data controller (for Tenant account details), data subjects may exercise their UK GDPR rights directly with us at legal@paypilot.plus.

When PayPilot is the data processor (for merchant, lead, agent, and portal data), data subjects must direct their requests to the relevant Tenant (the data controller). We will assist Tenants in fulfilling such requests to the extent technically feasible within our platform capabilities.

Any individual who believes their data protection rights have not been respected may lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

12. Contact and DPO

For all data protection enquiries, please contact us at:

  • Email: legal@paypilot.plus
  • Subject: Data Protection Enquiry

PayPilot Technologies is registered in Scotland. This policy is governed by and construed in accordance with the law of Scotland and applicable UK data protection legislation.

PayPilot Technologies · Registered in ScotlandQuestions? Contact us at legal@paypilot.plus