How PayPilot Technologies handles personal data — including the critical distinction between PayPilot as data controller and as data processor.
Effective date: 26 May 2025PayPilot Technologies is committed to compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This policy explains how we handle personal data in connection with the PilotOS platform, and sets out the respective responsibilities of PayPilot and its customers ("Tenants") under UK data protection law.
This policy should be read alongside our Privacy Policy and, where applicable, the Data Processing Agreement ("DPA") forming part of your subscription with us.
The UK GDPR distinguishes between data controllers (who determine the purposes and means of processing) and data processors (who process data on behalf of, and under the instruction of, a controller).
The table below summarises the roles that apply to data processed in connection with PilotOS:
| Category of personal data | Role | Basis |
|---|---|---|
| Tenant account and contact details (name, work email, billing address, phone number of the Tenant's authorised users) | PayPilot is DATA CONTROLLER | We determine how and why this data is collected to manage your subscription and account |
| Merchant data (names, contact details, trading information, bank details) | Tenant is DATA CONTROLLER · PayPilot is DATA PROCESSOR | You instruct us to store and process this data on your behalf |
| Lead, agent, and partner data entered into PilotOS | Tenant is DATA CONTROLLER · PayPilot is DATA PROCESSOR | You instruct us to store and process this data on your behalf |
| Application and underwriting data (including significant persons, financial data) | Tenant is DATA CONTROLLER · PayPilot is DATA PROCESSOR | You instruct us to process this data in connection with MCA and onboarding workflows |
| End-user data in the white-label merchant portal | Tenant is DATA CONTROLLER · PayPilot is DATA PROCESSOR | The merchant portal operates under your brand and under your data relationship with your merchants |
| Website visitor data (paypilot.plus) | PayPilot is DATA CONTROLLER | We collect this data to operate and improve our website |
In summary: once you subscribe to PilotOS and begin using the platform, you become the data controller for all personal data relating to your merchants, leads, agents, and end-users. PayPilot processes that data only on your documented instructions. PayPilot is data controller only for your own Tenant account details.
By using PilotOS, you (the Tenant) take on the role of data controller for all personal data you upload, import, or generate within the platform. As a data controller, you are responsible for:
PayPilot will not be liable for any breach of UK GDPR or other data protection law arising from your use of the platform as data controller.
When acting as your data processor, PayPilot Technologies commits to the following obligations, consistent with Article 28 of UK GDPR:
Where required by UK GDPR, a Data Processing Agreement ("DPA") is available to supplement your subscription terms. The DPA governs the processor-controller relationship for data processed in PilotOS on your behalf and is intended to meet the requirements of Article 28.
For Tenants who require a DPA, please contact legal@paypilot.plus. Where your subscription agreement explicitly incorporates a DPA by reference, that DPA forms part of your binding agreement with us.
PayPilot engages a limited number of trusted third-party sub-processors to assist in the delivery of PilotOS. All sub-processors are required to maintain appropriate data protection standards and are bound by contractual commitments consistent with Article 28 UK GDPR.
Our current sub-processors include providers in the following categories:
We maintain a current list of sub-processors and will notify Tenants of any additions or replacements with reasonable advance notice. To receive sub-processor notifications, please ensure your account contact email is kept current. If you have a contractual right to object to a new sub-processor, such objections must be raised within 14 days of notification.
PayPilot implements the following technical and organisational measures to protect personal data:
Security measures are reviewed and updated regularly. While we take all reasonable precautions, no system is entirely free from risk and we cannot guarantee absolute security.
In the event of a personal data breach affecting data for which PayPilot is data processor, we will:
As data controller, you are responsible for assessing the risk of the breach and, where applicable, notifying the ICO within 72 hours and affected individuals without undue delay.
In the event of a breach affecting data for which PayPilot is data controller (Tenant account details), we will notify affected individuals and the ICO directly in accordance with UK GDPR.
PayPilot retains Tenant-processed data for as long as your subscription is active and for a period of 30 days following termination, to allow for data export. After this period, data will be securely deleted unless a longer retention period is required by law.
Tenant account data (for which we are data controller) is retained for 7 years following the end of the subscription for accounting, tax, and legal purposes.
You may request deletion of your data within the platform at any time, subject to any retention obligations required by applicable law.
PayPilot Technologies and our primary infrastructure are based in the United Kingdom. Where any sub-processor operates outside the UK, we ensure that appropriate transfer mechanisms are in place, including UK International Data Transfer Agreements (IDTAs) or reliance on adequacy regulations.
We will not transfer personal data outside the UK without ensuring that the recipient provides an adequate level of protection.
When PayPilot is the data controller (for Tenant account details), data subjects may exercise their UK GDPR rights directly with us at legal@paypilot.plus.
When PayPilot is the data processor (for merchant, lead, agent, and portal data), data subjects must direct their requests to the relevant Tenant (the data controller). We will assist Tenants in fulfilling such requests to the extent technically feasible within our platform capabilities.
Any individual who believes their data protection rights have not been respected may lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
For all data protection enquiries, please contact us at:
PayPilot Technologies is registered in Scotland. This policy is governed by and construed in accordance with the law of Scotland and applicable UK data protection legislation.