Legal
Data Processing Agreement
Last updated: 8 July 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Ayok IT Solutions Limited (trading as PilotVantage) ("PilotVantage", "Processor") and the customer organisation ("Customer", "Controller") using the PilotVantage platform. It sets out how we process personal data on your behalf under Article 28 of the UK GDPR.
1. Roles & scope
For personal data contained in Customer Data, the Customer is the controller and PilotVantage is the processor. This DPA applies to our processing of such personal data to provide the service. Where the Customer is itself a processor for a third party, PilotVantage acts as a sub-processor.
2. Details of processing
| Subject matter | Provision of the PilotVantage GRC platform |
|---|---|
| Duration | For the term of the subscription, plus the retention period in section 8 |
| Nature & purpose | Hosting, storage, and processing of Customer Data to deliver GRC functionality (risk, controls, incidents, policies, audits, vendors, evidence, training, reporting) |
| Types of personal data | Names, work contact details, job roles, user account and authentication data, and any personal data the Customer chooses to enter into records |
| Categories of data subjects | The Customer's staff, contractors, administrators, and any individuals referenced in the Customer's records |
3. Our obligations as processor
We will:
- process personal data only on the Customer's documented instructions (including as set out in the Terms and this DPA), unless required by law;
- ensure persons authorised to process the data are under confidentiality obligations;
- implement appropriate technical and organisational security measures (see section 5 and our Security page);
- respect the conditions in sections 6–7 for engaging sub-processors;
- assist the Customer, taking into account the nature of processing, with data-subject rights requests and with security, breach notification, and data protection impact assessments;
- at the Customer's choice, delete or return personal data at the end of the service (see section 8);
- make available information necessary to demonstrate compliance and allow for audits as described in section 9.
4. Customer obligations
The Customer warrants that it has a lawful basis and any necessary consents/notices to provide Customer Data to us, and that its instructions comply with applicable law. The Customer is responsible for configuring roles and access appropriately within the platform.
5. Security measures
We maintain measures appropriate to the risk, including: encryption of data in transit (TLS); logical tenant isolation between customers; role-based access control; enforced two-factor authentication for administrators; audit logging; access on a least-privilege basis; regular patching; and backup and recovery procedures. Full detail is on our Security page.
6. Sub-processors
The Customer authorises PilotVantage to engage the sub-processors listed below to process Customer Data. Each is bound by data protection terms no less protective than this DPA.
| Sub-processor | Purpose | Location |
|---|---|---|
| DigitalOcean, LLC | Cloud hosting & infrastructure (application, database, backups) | United Kingdom (London, LON1) |
| Stripe Payments Europe, Ltd. | Subscription billing & payment processing | EU / UK (card data handled by Stripe; not stored by PilotVantage) |
7. Changes to sub-processors
We will give the Customer reasonable prior notice (via this page and/or email to administrators) of any intended addition or replacement of a sub-processor, giving the Customer the opportunity to object on reasonable data-protection grounds.
8. International transfers & retention
Customer Data is hosted in the United Kingdom. Any transfer outside the UK is protected by an appropriate safeguard (UK adequacy, the IDTA, or SCCs plus the UK Addendum). On termination, we will delete or return Customer Data within 90 days of the end of the service, unless retention is required by law; backups are purged on a rolling cycle.
9. Personal data breaches
We will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, and provide the information reasonably needed for the Customer to meet its own notification obligations.
10. Audits
On reasonable written request (no more than once a year, unless required by a supervisory authority or following a breach), we will provide information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality.
11. Contact
Data protection contact: Micheal Opayemi — privacy@pilotvantage.com
Ayok IT Solutions Limited (trading as PilotVantage), 124 City Road, London, England, EC1V 2NX