Data Processing Agreement
Last updated: April 24, 2026
1. Introduction
This Data Processing Agreement ("DPA") forms part of the Terms of Service between CompliPilot("Processor", "we", "us") and you ("Controller", "Customer") and governs the processing of personal data by CompliPiloton behalf of the Customer in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR").
2. Definitions
- Personal Data: Any information relating to an identified or identifiable natural person (Article 4(1) GDPR).
- Processing: Any operation performed on personal data, including collection, storage, retrieval, use, disclosure, or deletion.
- Sub-processor: A third party engaged by CompliPilot to process personal data on behalf of the Customer.
3. Scope and Purpose of Processing
CompliPilot processes personal data solely to provide EU AI Act compliance scanning and related services as described in the Terms of Service. Types of personal data processed may include:
- URLs and websites submitted for AI compliance analysis
- Customer account information (email address)
- Organizational data voluntarily provided for compliance assessment
- Usage metadata (timestamps, request IDs, scan counts)
Scan results are stored only to allow the Customer to access their own compliance reports. CompliPilot does not use Customer data for model training, advertising, or any purpose unrelated to the service.
4. Obligations of the Processor
- Process personal data only on documented instructions from the Controller, unless required by EU or Member State law.
- Ensure persons authorized to process personal data have committed themselves to confidentiality.
- Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk (see Section 6).
- Assist the Controller in responding to data subject requests exercising their rights under GDPR Articles 15–22.
- Delete or return all personal data to the Controller after the end of the service provision, at the Controller's choice.
- Make available all information necessary to demonstrate compliance and allow for audits.
5. Sub-processors
CompliPilot uses the following sub-processors to deliver the Service. The Customer authorizes the use of these sub-processors:
- Vercel Inc.— Application hosting and edge delivery (United States, EU data region available).
- Stripe Inc.— Payment processing and subscription management (United States, SCCs in place).
- Upstash Inc.— Redis database for rate limiting, session management, and compliance data storage (EU, Frankfurt).
- Sentry (Functional Software Inc.)— Error monitoring and observability (EU region, no PII sent by policy).
We will notify the Customer of any intended changes to sub-processors, giving the Customer the opportunity to object within 30 days.
6. Security Measures
CompliPilot implements the following technical and organizational measures to protect personal data:
- Encryption in transit: All data is transmitted over TLS 1.3.
- Encryption at rest: Stored data (account information, API keys) is encrypted using AES-256.
- Access controls: API keys are hashed with SHA-256. Access to production systems is restricted and logged.
- Rate limiting: All public endpoints are rate-limited by IP to prevent abuse.
- Data minimization: We store only data strictly necessary to provide the service.
- Regular security reviews: Periodic security assessments, dependency scanning, and CodeQL code analysis.
7. Data Breach Notification
In the event of a personal data breach, CompliPilot will notify the Controller without undue delay and in any event within 72 hours of becoming aware of the breach. The notification will include:
- A description of the nature of the breach
- The categories and approximate number of data subjects affected
- The likely consequences of the breach
- The measures taken or proposed to address the breach
8. International Data Transfers
Where personal data is transferred outside the EEA, CompliPilotensures that appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission, or reliance on adequacy decisions where applicable.
9. Data Subject Rights
CompliPilotassists the Controller in fulfilling obligations to respond to data subject requests under GDPR Articles 15–22, including the right of access, rectification, erasure, restriction, portability, and objection. Customers and end users may exercise their rights directly via /api/user/export and /api/user/delete endpoints.
10. Duration and Termination
This DPA remains in effect for the duration of the Customer's use of CompliPilot services. Upon termination, CompliPilot will delete all personal data processed on behalf of the Controller within 30 days, unless retention is required by applicable law.
11. Contact
For questions about this DPA or to request a signed copy, please contact us at privacy@complipilot.dev.