Acuerdo de Tratamiento de Datos (DPA)
Última actualización: 2026-06-12
Effective date: 2026-06-12. Version: dpa_v2_2. Replaces: dpa_v2_1. Parties: the "Customer" (gym owner, identified in the executed signature block) as data controller; Digital Technologies OÜ, an Estonian private limited company, registration code 16576446, VAT EE102558489, with registered seat at Harju maakond, Tallinn, Kesklinna linnaosa, Estonia and place of central administration at Calle Conde de Altea 46, 46005 Valencia, Spain, corporate representative for service of process in Estonia: Magrat OÜ (reg. 11730730) ("Pilotium") as data processor.
C.1.1 Purpose and scope
This Data Processing Agreement ("DPA") governs the processing of personal data by Pilotium on behalf of the Customer in connection with the Pilotium service, as required by Article 28(3) GDPR.
C.1.2 Definitions
Terms used and not defined have the meanings in the GDPR.
- "Standard Contractual Clauses" or "SCCs" means the clauses in the Annex to Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
- "Sub-processor List" means the list at pilotium.cc/legal/subprocessors, as updated.
- "TOMs" means the Technical and Organisational Measures described in Annex H.
- "DPF" means the EU-U.S. Data Privacy Framework as adopted by Commission Implementing Decision (EU) 2023/1795.
C.1.3 Subject-matter, duration, nature and purpose, categories of data, categories of data subjects
| Element | Description |
|---|---|
| Subject-matter | Provision of the Pilotium SaaS to the Customer |
| Duration | The duration of the Customer's contract with Pilotium + the retention periods set out in the Retention Policy (retention_v2) for residual data |
| Nature and purpose | Multi-channel messaging (WhatsApp / SMS / email / chat), AI conversational assistant, lead management, advertising-campaign management, creative generation, analytics and reporting |
| Categories of personal data | Identifiers (name, phone, email, social handles); conversation content; lead-source data; behavioural data on the Customer's surfaces; AI-derived qualification state and persona tags |
| Categories of data subjects | The Customer's leads, prospects, members, employees and contractors |
C.1.4 Customer instructions
Pilotium processes personal data on the documented instructions of the Customer, set out in (i) this DPA, (ii) the Terms of Service, (iii) the configurations the Customer makes in the Service. Pilotium will not process personal data for any other purpose, except where required by Union or Member-State law to which Pilotium is subject (in which case Pilotium will inform the Customer of that legal requirement before processing, unless that law prohibits such information).
If Pilotium considers that an instruction infringes GDPR or other Union/Member-State data-protection law, Pilotium will notify the Customer in writing without undue delay, and may refuse to act on the instruction. The right to refuse to act survives the Customer's reiteration of the instruction.
C.1.4a Independent-controller processing carve-out
For a narrow set of processing operations where Pilotium must set the means or purpose itself (in particular: AI-safety filters across all tenants, cross-tenant abuse detection, fraud-prevention models, infrastructure-level intrusion detection), Pilotium acts as independent controller on the basis of Article 6(1)(f) GDPR (Pilotium's legitimate interest in service security), under a documented LIA. These operations are out of the scope of this DPA. The Customer acknowledges this limited scope.
C.1.5 Confidentiality
Pilotium ensures that persons authorised to process personal data are bound by confidentiality obligations or are under an appropriate statutory obligation of confidentiality (Article 28(3)(b) GDPR). These confidentiality obligations survive the individual's relationship with Pilotium.
C.1.6 Security (Article 32 GDPR)
Pilotium implements appropriate technical and organisational measures as described in Annex H (TOMs). Pilotium reviews and updates the TOMs at least annually.
C.1.7 Sub-processors
Pilotium engages the sub-processors listed in the Sub-processor List. The Customer hereby grants general authorisation under Article 28(2) GDPR for the engagement of those sub-processors.
Pilotium will give the Customer at least 30 calendar days' prior notice of any addition, removal or substitution of a sub-processor, by email and by publication on the Sub-processor List page. The Customer's right to object under Article 28(2) GDPR is not extinguished by the 14-day courtesy reply window; objections lodged after that window remain valid but may be addressed after the change has taken effect, with Pilotium offering reasonable mitigation including, where the objection is substantiated, termination of the affected portion of the Service without penalty and a pro-rated refund.
Each sub-processor is bound by a written contract that imposes data-protection obligations materially equivalent to those imposed on Pilotium under this DPA. Pilotium remains fully liable to the Customer for the performance of those obligations by each sub-processor (Article 28(4) GDPR).
C.1.8 Breach notification
Pilotium will notify the Customer of any personal-data breach affecting Customer data without undue delay, and in any event within 48 hours of becoming aware of the breach. The notification will include:
- The nature of the breach and, where possible, the categories and approximate number of data subjects and data records affected.
- The date and time of Pilotium becoming aware of the breach, and the basis for that determination.
- The name and contact details of the data-protection contact.
- The likely consequences of the breach.
- The measures taken or proposed to address the breach, including mitigating measures.
Where not possible to provide all information within 48 hours, Pilotium will provide available information at that time and the remaining information in updates without undue delay. Pilotium provides reasonable cooperation to the Customer for the purposes of the Customer's notifications under Articles 33 and 34 GDPR.
C.1.9 Data Subject Rights
Pilotium will assist the Customer in fulfilling its obligation to respond to data-subject requests under Articles 12–22 GDPR. Where a data subject contacts Pilotium directly with a request relating to the Customer's processing, Pilotium will forward the request to the Customer within 72 hours of receipt by Pilotium and inform the data subject that the Customer is the controller responsible. The Customer's response clock under Article 12(3) GDPR runs from the initial receipt of the request (whether received first by Pilotium or by the Customer); the Customer remains responsible for responding within one month under Article 12(3), with the possibility of a two-month extension for complex requests.
C.1.10 Audit rights
The Customer has the right to audit Pilotium's compliance with this DPA:
- Annually, on at least 30 calendar days' prior written notice, by the Customer or by an independent auditor (subject to confidentiality and not being a competitor of Pilotium), during normal business hours and in a manner that does not unreasonably disrupt Pilotium's operations.
- On reasonable cause (e.g. a breach, a regulatory inquiry, or a credible third-party report of non-compliance), by the Customer or its auditor, with reasonable notice proportionate to the urgency.
Notwithstanding the foregoing, nothing in this clause restricts the right of a competent supervisory authority to conduct inspections under Article 58(1)(f) GDPR. Pilotium will cooperate without the auditor-confidentiality and non-competitor gates set out above when the auditor is a supervisory authority.
The Customer is responsible for the costs of audits requested by it, unless the audit reveals material non-compliance, in which case Pilotium bears its own costs and the Customer's reasonable external auditor costs.
Pilotium provides on request: its current SOC 2 Type II report (where issued), the Sub-processor List, the TOMs Annex, a summary of the Records of Processing on behalf of the Customer (Article 30(2)), and a summary of recent penetration-test results. Pilotium makes available to the Customer all information necessary to demonstrate compliance with Article 28 GDPR (Article 28(3)(h)).
C.1.11 International transfers
The transfer of personal data outside the EEA is governed by (a) Article 45 adequacy where applicable (including the DPF for self-certified US importers); (b) Standard Contractual Clauses 2021/914 with the module elections set out below; (c) both, as belt-and-braces.
SCC module elections (this is a contractual term; the Sub-processor List provides the update mechanism but does not override this election).
| Sub-processor (importer) | SCC Module elected | Role of Pilotium | Role of importer |
|---|---|---|---|
| WhatsApp LLC (US) | Module 3 | Data exporter (processor) | Data importer (processor) |
| Meta Platforms, Inc. (US) | Module 3 | Data exporter (processor) | Data importer (processor) |
| Anthropic, PBC (US) | Module 3 | Data exporter (processor) | Data importer (processor) |
| Google LLC (US) | Module 3 | Data exporter (processor) | Data importer (processor) |
| TikTok Inc. (US/Singapore) | Module 3 | Data exporter (processor) | Data importer (processor) |
| Cloudflare, Inc. (US) | Module 3 | Data exporter (processor) | Data importer (processor) |
| Stripe, Inc. (US ancillary) | Module 3 | Data exporter (processor) | Data importer (processor) |
| Resend, Inc. (US) | Module 3 | Data exporter (processor) | Data importer (processor) |
Clause 7 (docking). The parties incorporate Clause 7 of the SCCs. The Customer may at any time accede further entities to the SCCs as additional data exporters by written notice; Pilotium will reasonably cooperate to complete the Annex.
Clause 8.7 (onward transfers). Sub-processors are contractually restricted from making onward transfers other than to entities bound by SCCs/BCRs/adequacy decision, or where Article 49 GDPR derogations apply with the data subject explicitly informed. Pilotium reviews each sub-processor's published sub-sub-processor list at least annually.
Clause 14(e) (TIA refresh). Pilotium re-performs the Transfer Impact Assessment on any material change to importer-country law or practice, and at least every 24 months, in accordance with EDPB Recommendations 01/2020, version 2.0 of 18 June 2021. A redacted copy of each TIA is available to the Customer under NDA on written request.
Clause 15 (government access). Each sub-processor outside the EEA is contractually required, to the maximum extent permitted by law, to (i) notify Pilotium of any legally binding government-access request within 24 hours of receipt, or as soon as legally permissible; (ii) challenge such requests where lawful grounds exist (Clause 15(2)); (iii) provide the minimum information legally required (Clause 15(1)(c)); and (iv) document all such requests for the annual transparency report. Pilotium will notify the affected Customer without undue delay and at the latest within 72 hours, where lawful. Internal escalation: DPO → CEO → external counsel within 4 hours of notification by the sub-processor.
Schrems-III contingency. If Implementing Decision (EU) 2023/1795 is invalidated or suspended, Pilotium will (a) suspend new DPF-based transfers within 30 days of the operative judgment and (b) complete transition to SCC 2021/914 within 90 days, with status updates to the Customer at days 30, 60 and 90.
TikTok / PAFACA contingency. If TikTok Inc. ceases US operations by reason of US legislation (including Pub.L. 118-50 PAFACA), Pilotium will terminate transfers to TikTok Inc. within 5 business days and notify the Customer accordingly.
Refuse-instruction clause (EDPB Opinion 28/2024). Pilotium will refuse, suspend, or escalate any Customer instruction whose implementation would require Pilotium to make a transfer outside the EEA for which no Article 45 adequacy, no Article 46(2)(c) SCC, and no Article 49 derogation is in place. The refusal/escalation is logged in the audit log.
Re-transfers controller-to-controller (gym network). Where the Customer instructs Pilotium to share lead data with a Customer-controlled CRM, PMS or analytics endpoint established outside the EEA, the Customer is the data exporter for that transfer and is responsible for executing SCC Module 1 (controller-to-controller) directly with the recipient. Pilotium will make available a Module 1 template on written request. Pilotium will not effect the transfer until the Customer confirms in writing that Module 1 (or an Article 45 adequacy decision) is in place.
Use Case mapping (EDPB Recommendations 01/2020 v2.0 Annex 2). Each transfer is mapped to a Use Case in the TIA. Most processor-to-processor transfers fall under Use Case 6 ("transfer to processor for limited purposes"); Cloudflare's transit-only role is treated under Use Case 2 with EU-PoP routing as the operative supplementary technical measure.
C.1.12 Deletion and return of data
On termination of the Customer's contract, and except where Union or Member-State law (in particular Estonian Raamatupidamise seadus § 12, Maksukorralduse seadus § 58, Käibemaksuseadus § 36 lg 1 p 3; Spanish Código de Comercio art. 30, Ley 58/2003 arts. 66 and 66 bis, Ley 37/1992 art. 165) requires storage — in which case the data is blocked within the meaning of Recital 39 GDPR, Article 32 LOPDGDD, and § 6 of the Estonian Personal Data Protection Act, and is processed solely to fulfil the relevant obligation:
- Pilotium will, at the Customer's choice expressed in writing within 30 days of termination, return the personal data in a structured, commonly-used and machine-readable format (CSV / JSON) or delete the personal data.
- Pilotium will issue a written certificate of destruction (or, as the case may be, of return) within 60 days of the request (Article 28(3)(g) GDPR; SCC 2021/914 Clause 8.5).
- Backups containing personal data continue to exist until natural expiry under the Retention Policy (currently 90 days for backups).
C.1.13 AI Act — Customer as deployer flow-down
Where the Customer operates an AI system within the meaning of Regulation (EU) 2024/1689, the Customer:
- provides affected natural persons with the information required under Articles 50 and 26 to the extent applicable;
- does not modify, shorten or suppress the first-message AI-disclosure preamble configured by Pilotium (regulatory floor under Article 50(1));
- does not remove or alter machine-readable provenance marks on creatives generated through the Service (Article 50(2));
- applies a visible adjacent label on destination platforms without native AI-disclosure flag only where the creative constitutes a deep fake within the meaning of Article 3(60) AI Act AND does not fall within the artistic-creative carve-out of Article 50(4) second subparagraph; where the carve-out applies, the appropriate-manner disclosure is satisfied by Pilotium's Privacy Policy §A.10.1;
- maintains a sufficient level of AI literacy among personnel operating the Service (Article 4);
- notifies Pilotium of any serious incident under Article 3(49) within 48 hours of awareness to enable Pilotium's Article 73 reporting;
- cooperates with Pilotium on any Fundamental Rights Impact Assessment (FRIA) under Article 27 if Pilotium ever scopes a system into Annex III high-risk territory;
- confirms that the Service is not used as, or within, an Annex III high-risk AI system (use for such purposes constitutes material breach).
C.1.13a GPAI provider chain transparency
Anthropic and Google are upstream GPAI providers under Article 51 AI Act. Pilotium relies on their Article 53 documentation and passes through summary information on written request as part of the audit-rights chain in §C.1.10. Kuaishou Technology is excluded from this clause unless and until Kling is adopted in production, at which point the DPA, Annex G and Sub-processor List must be updated before use.
C.1.14 Liability
The limitation of liability in the Terms of Service applies to this DPA. Nothing in this clause limits either party's liability to data subjects under Article 82 GDPR or to supervisory authorities under Articles 83 and 84 GDPR. Liability for personal-data breaches caused by gross negligence or wilful misconduct is not limited.
C.1.15 Governing law and forum
This DPA is governed by Spanish law (Código Civil, Código de Comercio, Ley 7/1998 LCGC) and submitted to the courts of Valencia, Spain, in line with Terms of Service §B.1.16. Brussels I bis Regulation 1215/2012 articles 17–19 (consumer carve-outs) and article 25 (choice-of-court agreements) apply.
C.1.16 Entry into force; precedence
This DPA enters into force on signature or on the Customer's acceptance of the Terms of Service, whichever is earlier, and supersedes any prior DPA. In the event of conflict between this DPA and the Terms of Service, this DPA prevails for matters of personal-data processing.