LEGAL
Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of, and is incorporated by reference into, the Terms of Service or other written agreement (the "Agreement") between BPI VENTURES GLOBAL – FZCO ("dtcpilot", "we" or "Processor") and the customer that has agreed to the Agreement ("Customer"). It applies automatically whenever dtcpilot processes Customer Personal Data in providing the Service, and no separate signature is required. Customers that need a countersigned copy for their records may request one at [email protected].
This DPA sets out the parties' obligations for the processing of personal data under Data Protection Laws. In the event of a conflict between this DPA and the Agreement in relation to the processing of Customer Personal Data, this DPA prevails, as further described in Section 15.
1. Definitions
Capitalized terms not defined in this DPA have the meanings given in the Agreement. In this DPA:
- "Customer Personal Data" means any personal data contained in Customer Data that dtcpilot processes on behalf of Customer in providing the Service, including personal data about Customer's shoppers, subscribers, leads and staff.
- "Customer Data" means all data, content and information that Customer or its users submit to, or that is collected, synced or generated through, the Service on Customer's behalf, including data received from Third-Party Services that Customer connects.
- "Data Protection Laws" means all laws and regulations relating to the processing of personal data that apply to a party's processing of Customer Personal Data, including, as applicable, the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and its implementing regulations (the "PDPL"); Regulation (EU) 2016/679 (the "GDPR"); the GDPR as it forms part of UK law and the UK Data Protection Act 2018 (the "UK GDPR"); the Swiss Federal Act on Data Protection; and the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020, and its regulations (the "CCPA").
- "Controller", "processor", "data subject", "personal data", "processing" and "supervisory authority" have the meanings given in the applicable Data Protection Laws, and include equivalent terms under those laws, such as "business", "service provider", "consumer" and "personal information" under the CCPA.
- "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data transmitted, stored or otherwise processed by dtcpilot or its Sub-processors.
- "Service" means the dtcpilot platform available at app.dtcpilot.io and the related services provided under the Agreement.
- "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries set out in the Annex to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
- "UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the UK Data Protection Act 2018, as amended from time to time.
- "Sub-processor" means any third party engaged by dtcpilot that processes Customer Personal Data in order to provide the Service.
- "Third-Party Service" means any platform, application or service that Customer chooses to connect to or use with the Service, such as e-commerce platforms, payment providers, advertising platforms, email and messaging tools, shipping and tax services and analytics tools.
2. Roles of the parties
2.1 Customer as controller. For Customer Personal Data, Customer is the controller (or, where Customer processes personal data on behalf of a third party, a processor), and dtcpilot is the processor (or sub-processor, as applicable).
2.2 dtcpilot as independent controller. dtcpilot is an independent controller of personal data it processes for its own business purposes, such as account administration, billing, security and product communications with Customer's users, as described in our Privacy Policy. This DPA does not apply to that processing.
2.3 Customer responsibilities. Customer is responsible for the lawfulness of its collection and use of Customer Personal Data and of its instructions to dtcpilot. Customer represents and warrants that it has provided all notices and obtained all consents, authorizations and other legal bases required under Data Protection Laws for dtcpilot to process Customer Personal Data as contemplated by the Agreement, including for any marketing messages, subscription billing, fraud screening and AI processing that Customer configures through the Service. Customer will ensure that its privacy policy accurately describes its use of service providers such as dtcpilot.
2.4 Third-Party Services. Third-Party Services connected by Customer are Customer's own providers. They are not Sub-processors of dtcpilot, and their processing of personal data is governed by Customer's agreements with them. When Customer instructs the Service to send data to or retrieve data from a Third-Party Service, dtcpilot acts on Customer's instructions and is not responsible for the Third-Party Service's processing.
3. Scope and instructions
3.1 Processing on instructions. dtcpilot will process Customer Personal Data only on Customer's documented instructions, unless required to do otherwise by applicable law, in which case dtcpilot will inform Customer of that legal requirement before processing unless the law prohibits it on important grounds of public interest.
3.2 Documented instructions. Customer instructs dtcpilot to process Customer Personal Data to provide, secure, support and maintain the Service in accordance with the Agreement, this DPA and Customer's configuration and use of the Service, including actions initiated by Customer's users and automations and rules that Customer sets up. The Agreement, this DPA and Customer's use and configuration of the Service constitute Customer's complete instructions. Additional instructions require prior written agreement, including agreement on any additional fees.
3.3 Unlawful instructions. dtcpilot will promptly inform Customer if, in its opinion, an instruction infringes Data Protection Laws. dtcpilot is not required to perform legal research on Customer's behalf and may suspend performance of the instruction until Customer confirms or modifies it.
3.4 Aggregated and de-identified data. dtcpilot may create aggregated or de-identified data derived from Customer Data to operate, secure and improve the Service, provided that such data does not identify Customer, its users or any data subject. dtcpilot will not attempt to re-identify such data. dtcpilot will not use Customer Personal Data to train artificial intelligence models, and will engage AI model providers only under terms that prohibit them from using Customer Personal Data to train their models.
4. Details of processing
The subject matter, duration, nature and purpose of the processing, and the types of personal data and categories of data subjects, are set out in Annex 1.
5. Confidentiality of personnel
dtcpilot will ensure that any person it authorizes to process Customer Personal Data, including employees, contractors and Sub-processor personnel, is subject to an appropriate duty of confidentiality, whether contractual or statutory, has received appropriate training on their data protection responsibilities, and accesses Customer Personal Data only to the extent necessary to provide the Service, provide support or comply with law.
6. Security
6.1 Security measures. Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risks to data subjects, dtcpilot will implement and maintain appropriate technical and organizational measures to protect Customer Personal Data against Personal Data Breaches, including at a minimum the measures described in Annex 2.
6.2 Updates. dtcpilot may update the security measures from time to time, provided that updates do not materially decrease the overall security of the Service.
6.3 Customer responsibilities. Customer is responsible for its own secure use of the Service, including protecting user credentials, configuring roles and permissions appropriately, securing its Third-Party Service accounts, and not uploading data to the Service that is not needed for its use of the Service.
7. Sub-processors
7.1 General authorization. Customer grants dtcpilot a general written authorization to engage Sub-processors to process Customer Personal Data. The Sub-processors engaged at the date of this DPA are listed on our Sub-processors page, which Customer approves.
7.2 Sub-processor obligations. dtcpilot will enter into a written agreement with each Sub-processor that imposes data protection obligations no less protective of Customer Personal Data than those in this DPA, to the extent applicable to the services the Sub-processor provides. dtcpilot remains liable to Customer for the performance of each Sub-processor's obligations, subject to the limitations in Section 14.
7.3 Notice of new Sub-processors. dtcpilot will notify Customer of any intended addition or replacement of a Sub-processor at least 30 days before the new Sub-processor begins processing Customer Personal Data, by email to Customer's account owner and by updating the Sub-processors page. Where an addition is urgently required to maintain the security or continuity of the Service, dtcpilot may give shorter notice and will explain the reason.
7.4 Objection. Customer may object to a new Sub-processor on reasonable grounds relating to data protection by notifying dtcpilot in writing at [email protected] within the notice period. The parties will discuss the objection in good faith. dtcpilot may, at its option, offer a commercially reasonable change to the Service or Customer's configuration that avoids use of the new Sub-processor for Customer Personal Data. If no such change is reasonably available within 30 days of Customer's objection, Customer may terminate the affected part of the Service by written notice, and dtcpilot will refund any prepaid fees covering the terminated part for the period after termination. This is Customer's sole remedy for an objection to a Sub-processor.
8. Data subject requests
8.1 Assistance. Taking into account the nature of the processing, dtcpilot will assist Customer, by appropriate technical and organizational measures and insofar as possible, in fulfilling Customer's obligation to respond to requests from data subjects exercising their rights under Data Protection Laws, including rights of access, rectification, erasure, restriction, portability and objection. The Service provides features that enable Customer to search, export, correct and delete Customer Personal Data, and Customer will use those features first.
8.2 Requests received by dtcpilot. If dtcpilot receives a request directly from a data subject relating to Customer Personal Data, it will, where the data subject identifies Customer, promptly forward the request to Customer and will not respond to it except to direct the data subject to Customer, unless Customer authorizes a response or the law requires it.
8.3 Costs. Where assistance under this Section goes beyond the self-service features of the Service, dtcpilot may charge reasonable fees for that assistance, which it will agree with Customer in advance.
9. Personal Data Breaches
9.1 Notification. dtcpilot will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach. Notice will be sent to Customer's account owner by email.
9.2 Content. To the extent the information is available, dtcpilot's notice will describe the nature of the Personal Data Breach, including the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed to address the breach and mitigate its effects; and a contact point for more information. Where it is not possible to provide all information at the same time, dtcpilot will provide it in phases without undue further delay.
9.3 Response. dtcpilot will promptly take reasonable steps to contain, investigate and remediate the Personal Data Breach and will provide reasonable cooperation to help Customer meet any obligation to notify supervisory authorities or data subjects. Customer is responsible for deciding whether to make such notifications, unless the law requires dtcpilot to notify directly.
9.4 No admission. dtcpilot's notification of or response to a Personal Data Breach is not an acknowledgement of fault or liability. Unsuccessful attempts or activities that do not compromise the security of Customer Personal Data, such as pings, port scans, blocked login attempts or denial-of-service attacks, are not Personal Data Breaches.
10. Data protection impact assessments and consultation
Taking into account the nature of the processing and the information available to it, dtcpilot will provide reasonable assistance to Customer with any data protection impact assessment and any prior consultation with a supervisory authority that Customer is required to carry out under Data Protection Laws in relation to its use of the Service. dtcpilot will first do so by providing documentation about the Service, including this DPA, the Sub-processor list and its security documentation. Additional assistance may be subject to reasonable fees.
11. International transfers
11.1 Locations. Customer acknowledges that dtcpilot is established in the United Arab Emirates and that dtcpilot and its Sub-processors may process Customer Personal Data in the United States and other countries, as described on the Sub-processors page. dtcpilot will ensure that every transfer of Customer Personal Data is made in accordance with Data Protection Laws.
11.2 EU Standard Contractual Clauses. To the extent that Customer Personal Data subject to the GDPR is transferred to dtcpilot in a country that has not been recognized as providing adequate protection, the SCCs are incorporated into this DPA by reference and apply as follows:
- Module Two (controller to processor) applies where Customer is a controller, and Module Three (processor to processor) applies where Customer is a processor;
- Customer is the "data exporter" and dtcpilot is the "data importer";
- in Clause 7, the optional docking clause applies;
- in Clause 9, Option 2 (general written authorization) applies, with the time period for prior notice of Sub-processor changes set out in Section 7.3 of this DPA;
- in Clause 11, the optional language does not apply;
- in Clause 17, Option 1 applies, and the SCCs are governed by the law of Ireland;
- in Clause 18(b), disputes will be resolved before the courts of Ireland;
- Annex I of the SCCs is completed with the information in Annex 1 of this DPA, and the competent supervisory authority is the one determined in accordance with Clause 13; and
- Annex II of the SCCs is completed with the information in Annex 2 of this DPA.
11.3 UK transfers. To the extent that Customer Personal Data subject to the UK GDPR is transferred to a country that has not been recognized as adequate, the SCCs as applied under Section 11.2 are amended by the UK Addendum, which is incorporated by reference. Tables 1 to 3 of the UK Addendum are completed with the information in Section 11.2 and Annexes 1 and 2 of this DPA, and in Table 4 either party may end the UK Addendum as set out in its Section 19.
11.4 Swiss transfers. To the extent that Customer Personal Data subject to the Swiss Federal Act on Data Protection is transferred, the SCCs apply as set out in Section 11.2 with the modifications required by Swiss law, including that references to the GDPR are read as references to the Swiss Federal Act on Data Protection and that the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority.
11.5 UAE PDPL. Where the PDPL applies, dtcpilot will transfer Customer Personal Data outside the UAE only in accordance with the cross-border transfer provisions of the PDPL and its implementing regulations, including to countries with adequate levels of protection or on the basis of contractual obligations that ensure an adequate level of protection for the data.
11.6 Onward transfers. dtcpilot will ensure that transfers of Customer Personal Data to Sub-processors are protected by Standard Contractual Clauses or equivalent contractual safeguards, or by another lawful transfer mechanism.
11.7 Conflict. If there is a conflict between this DPA and the SCCs or the UK Addendum, the SCCs or the UK Addendum prevail to the extent of the conflict.
12. Audits
12.1 Information. dtcpilot will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA. dtcpilot will first satisfy this obligation by providing, on written request and subject to confidentiality obligations, copies of relevant security documentation, summaries of available third-party audit reports or certifications of dtcpilot or its Sub-processors, and written responses to reasonable security and privacy questionnaires, no more than once in any 12-month period unless there has been a Personal Data Breach.
12.2 On-site audits. If the information provided under Section 12.1 is not sufficient to demonstrate compliance, or where a supervisory authority requires it, Customer may, at its own cost, conduct an audit of dtcpilot's relevant processing, either itself or through an independent auditor bound by confidentiality and not a competitor of dtcpilot, subject to the following: Customer gives at least 30 days' prior written notice; the audit takes place no more than once in any 12-month period, during normal business hours and in a manner that minimizes disruption to dtcpilot's business; the scope, timing and duration are agreed in advance; the audit does not extend to data of other customers, to Sub-processors' facilities, or to information subject to confidentiality obligations to third parties; and Customer provides dtcpilot with a copy of any audit report free of charge. Customer will reimburse dtcpilot's reasonable costs of supporting an on-site audit.
12.3 SCC audits. The parties agree that audits under Clause 8.9 of the SCCs will be carried out in accordance with this Section 12.
13. Return and deletion
13.1 During the term. Customer can export and delete Customer Personal Data through the Service at any time during the term of the Agreement.
13.2 On termination. On termination or expiry of the Agreement, Customer will have 30 days to export its Customer Data using the Service's export features. After that period, dtcpilot will delete Customer Personal Data from its production systems within 90 days of the end of the subscription. Deleted data will be removed from backups in the ordinary course of the backup cycle, within 35 days of its deletion from production systems. On request, dtcpilot will confirm deletion in writing.
13.3 Retention required by law. dtcpilot may retain Customer Personal Data to the extent and for as long as required by applicable law, in which case it will continue to protect that data in accordance with this DPA, isolate it from further processing and process it only for the purposes for which retention is required.
14. Liability
Each party's liability arising out of or relating to this DPA, including under the SCCs and the UK Addendum to the extent permitted by them, is subject to the exclusions and limitations of liability in the Agreement, and any reference in the Agreement to the liability of a party means the aggregate liability of that party under the Agreement and this DPA together. Nothing in this Section limits either party's liability to data subjects under the SCCs or any liability that cannot be limited under applicable law.
15. Order of precedence
In the event of any conflict or inconsistency, the following order of precedence applies: first, the SCCs and the UK Addendum, where they apply; second, this DPA; and third, the Agreement. Except as expressly modified by this DPA, the terms of the Agreement remain in full force and effect.
16. CCPA service provider terms
To the extent that dtcpilot processes Customer Personal Data that is "personal information" subject to the CCPA, dtcpilot acts as Customer's "service provider" and agrees that it will:
- not sell or share (as those terms are defined in the CCPA) Customer Personal Data;
- not retain, use or disclose Customer Personal Data for any purpose, including any commercial purpose, other than the business purposes specified in the Agreement and this DPA, or as otherwise permitted by the CCPA;
- not retain, use or disclose Customer Personal Data outside the direct business relationship between dtcpilot and Customer;
- not combine Customer Personal Data with personal information it receives from or on behalf of another person, or collects from its own interactions with consumers, except as permitted by the CCPA;
- comply with the obligations that apply to it under the CCPA and provide the same level of privacy protection as the CCPA requires;
- notify Customer if it determines that it can no longer meet its obligations under the CCPA; and
- permit Customer, on reasonable notice, to take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Data, and to ensure that dtcpilot uses it in a manner consistent with Customer's obligations under the CCPA, through the measures described in Sections 8 and 12.
Customer discloses Customer Personal Data to dtcpilot only for the limited and specified business purposes of providing, securing, supporting and improving the Service as set out in the Agreement. dtcpilot certifies that it understands and will comply with the restrictions in this Section.
17. General
This DPA remains in effect for as long as dtcpilot processes Customer Personal Data, and the obligations in Sections 9, 13 and 14 survive termination. dtcpilot may update this DPA from time to time to reflect changes in Data Protection Laws or in the Service, provided that updates do not materially reduce the protection of Customer Personal Data; material updates will be notified to account owners in advance. This DPA is governed by the law that governs the Agreement, except where the SCCs or Data Protection Laws require otherwise. Questions about this DPA can be sent to:
BPI VENTURES GLOBAL – FZCOIFZA Business Park, Building A1, Dubai Digital Park,
Dubai Silicon Oasis, Dubai, United Arab Emirates
Email: [email protected]
Annex 1: Details of processing
| Item | Description |
|---|---|
| Data exporter | Customer, as identified in its dtcpilot account and the Agreement. Activities relevant to the transfer: use of the Service to operate Customer's direct-to-consumer business. Role: controller (or processor, where Customer acts for a third party). |
| Data importer | BPI VENTURES GLOBAL – FZCO, IFZA Business Park, Building A1, Dubai Digital Park, Dubai Silicon Oasis, Dubai, United Arab Emirates; contact [email protected]. Activities relevant to the transfer: provision of the Service. Role: processor. |
| Subject matter | Provision of the dtcpilot platform and related support to Customer under the Agreement. |
| Duration | The term of the Agreement, plus the export and deletion periods set out in Section 13 of this DPA. |
| Nature and purpose of processing | Collection, receipt from connected Third-Party Services, recording, organization, structuring, storage, retrieval, analysis, enrichment, transmission to Third-Party Services on Customer's instructions, and deletion of Customer Personal Data, for the purposes of: AI creative generation and analysis; launching and managing advertising; operating funnels and checkout; managing subscriptions, a customer portal and failed-payment recovery; operating orders, refunds and fulfilment; fraud and reseller detection; profit analytics and reporting; sending transactional and retention communications configured by Customer; and providing support, security and maintenance of the Service. |
| Categories of data subjects | Customer's shoppers and end customers; Customer's subscribers; Customer's leads and prospects; and Customer's staff, contractors and agents who use the Service or whose details appear in Customer Data. |
| Categories of personal data | Identification and contact data (names, email addresses, postal and shipping addresses, phone numbers); order and transaction data (order history, products purchased, amounts, refunds, fulfilment and tracking details); payment data (payment tokens and payment metadata such as card brand, last four digits, expiry and transaction status; dtcpilot does not store full card numbers); subscription data (plan, status, billing dates, payment recovery status); device, network and fraud signals (IP address, device and browser attributes, risk scores and fraud indicators); marketing and engagement data (consent status, list membership, message and campaign engagement); support messages and correspondence; and, for Customer's staff, user account and activity data. |
| Sensitive data | The Service is not intended for processing special categories of personal data or other sensitive data, and Customer will not submit such data to the Service except where incidental to its use and permitted by Data Protection Laws. Where incidental sensitive data is processed, the measures in Annex 2 apply. |
| Frequency of transfer | Continuous, for the duration of the Agreement. |
| Retention | As set out in Section 13 of this DPA and as configured by Customer through the Service. |
| Sub-processor transfers | As set out on the Sub-processors page, for the purposes, and for the duration, described there. |
Annex 2: Technical and organizational security measures
- Encryption in transit: all connections to the Service, its APIs and between its components over public networks are encrypted using TLS.
- Encryption at rest: databases, backups and object storage are encrypted at rest. Third-party access tokens, API keys and other credentials are additionally encrypted at the application level.
- Tenant isolation: Customer Data is logically segregated per company, and access controls enforce that each company's data is accessible only to that company's authorized users and to platform processes acting for that company.
- Access control: role-based access control within the Service; unique user accounts; hashed passwords; session management with expiry; and administrative access for dtcpilot personnel restricted to those who need it, on the principle of least privilege, protected by strong authentication and reviewed periodically.
- Payment data minimization: full card numbers are handled by PCI DSS compliant payment processors and are never stored by dtcpilot; the Service stores only tokens and limited payment metadata.
- Logging and monitoring: audit logging of sign-ins and significant user and administrative actions; infrastructure and application monitoring and alerting; and retention of security logs for investigation.
- Network and infrastructure security: hosting on reputable cloud infrastructure providers; web application firewall, DDoS mitigation and bot protection at the network edge; and restricted network access to databases and internal services.
- Secure development: code review before deployment; separation of development, testing and production environments; use of non-production data for testing wherever practical; and dependency and vulnerability management.
- Availability and resilience: automated database backups with point-in-time recovery; backup retention of up to 35 days; and procedures to restore availability and access to data in a timely manner.
- Data minimization in AI processing: AI features send AI model providers only the data necessary for the requested task, through business APIs under terms that prohibit use of the data for model training.
- Personnel: confidentiality obligations for all personnel with access to Customer Personal Data; security and privacy awareness training; and prompt revocation of access on role change or departure.
- Vendor management: security and privacy due diligence on Sub-processors before engagement and periodically thereafter, and written data protection terms with each Sub-processor.
- Incident response: a documented incident response process covering detection, triage, containment, investigation, remediation, customer notification and post-incident review.
- Data subject rights and deletion: Service features that allow Customer to search, export, correct and delete Customer Personal Data, and processes for secure deletion at the end of the Agreement.
- Testing and evaluation: regular review and testing of the effectiveness of these measures, and updates as threats and the Service evolve.
Related documents: Terms of Service, Privacy Policy, Sub-processors, Cookie Policy, Acceptable Use Policy and Refund & Cancellation Policy.