---
title: "Data Processing Agreement"
description: "Data processing terms for Customer Personal Data processed by Autopilot on behalf of customers."
source: "https://legal.aplt.ai/legal/dpa"
updated: "2026-06-30T09:01:23.604658+00:00"
product: Autopilot
content_type: legal
---

# Data Processing Agreement

Data processing terms for Customer Personal Data processed by Autopilot on behalf of customers.

This Data Processing Agreement (**DPA**) forms part of the agreement between **Autopilot Limited** (**Autopilot**, **we**, **our**, or **us**) and the customer that uses the Autopilot platform (**Customer**, **you**, or **your**).

This DPA explains how Autopilot processes Customer Personal Data when providing the Services. It should be read together with Autopilot’s [Terms of Service](/legal/terms), [Privacy Policy](/legal/privacy), [Security & Trust](/legal/security-trust) documentation, [Subprocessors](/legal/subprocessors) documentation, and any applicable order form or written agreement between the parties.

Unless otherwise defined in this DPA, capitalised terms have the meanings given in the Terms of Service.

If this DPA conflicts with the Terms of Service in relation to the processing of Customer Personal Data, this DPA applies to that processing to the extent of the conflict. If a separate written agreement signed by Autopilot and the Customer expressly varies this DPA, that written agreement applies to the extent of the variation.

Autopilot Limited is a New Zealand company. Our privacy contact is **privacy@aplt.ai**.

---

## Definitions

**Agreement** means the Terms of Service, this DPA, any applicable order form, and any other written agreement governing the Customer’s use of the Services.

**Applicable Data Protection Laws** means privacy, data protection, data security, breach notification, and electronic communications laws that apply to the relevant processing of Customer Personal Data, including, where applicable, the New Zealand Privacy Act 2020, the EU GDPR, and the UK GDPR.

**Customer Data** means data, content, records, files, communications, documents, configuration, and other information submitted to, stored in, or processed through the Services by or on behalf of the Customer or its authorised users.

**Customer Personal Data** means Personal Data contained in Customer Data that Autopilot processes on behalf of the Customer in connection with the Services.

**Data Subject** or **Individual** means an identified or identifiable natural person to whom Customer Personal Data relates.

**Personal Data** means personal information, personal data, or equivalent information protected under Applicable Data Protection Laws.

**Security Incident** means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to, Customer Personal Data processed by Autopilot. Security Incident does not include unsuccessful attempts or activities that do not compromise Customer Personal Data, such as unsuccessful login attempts, port scans, denial-of-service attempts, or similar events.

**Services** means the Autopilot platform, applications, websites, APIs, support services, and related products and services provided by Autopilot.

**Subprocessor** means a third party engaged by Autopilot to process Customer Personal Data on behalf of Autopilot in order to provide, support, secure, or operate the Services.

Where Applicable Data Protection Laws use terms such as **controller**, **processor**, **business**, **service provider**, **operator**, or similar concepts, those terms are interpreted consistently with the equivalent roles described in this DPA.

---

## Scope of this DPA

This DPA applies when Autopilot processes Customer Personal Data on behalf of the Customer in connection with the Services.

This DPA does not apply to information that Autopilot processes for its own business purposes as an independent controller or equivalent role, such as account administration, billing, tax and accounting, customer relationship management, support operations, security, diagnostics, legal compliance, fraud prevention, service administration, or business communications. That processing is described in Autopilot’s Privacy Policy.

This DPA also does not apply to information that has been aggregated, anonymised, de-identified, or otherwise processed so that it no longer identifies an individual, provided Autopilot does not use that information to identify the individual.

---

## Roles of the Parties

For Customer Personal Data:

- the Customer is generally the controller, business, or equivalent decision-maker; and
- Autopilot is generally the processor, service provider, or equivalent provider processing Customer Personal Data on the Customer’s behalf.

The Customer decides what Customer Personal Data is submitted to the Services, who is authorised to access it, which features are enabled, which communications are sent, which integrations are connected, and how the Services are configured and used.

If the Customer is itself acting as a processor or service provider for another controller or business, Autopilot acts as the Customer’s subprocessor or equivalent provider. In that case, the Customer is responsible for ensuring that its instructions to Autopilot are authorised by the relevant controller or business.

---

## Customer Instructions

Autopilot will process Customer Personal Data only on documented instructions from the Customer, unless required to do otherwise by applicable law.

The Customer’s documented instructions include:

- the Agreement;
- the Customer’s use, configuration, and administration of the Services;
- actions taken by authorised users;
- enabled features, workflows, automations, communications, and integrations;
- support, troubleshooting, import, export, billing, or administration requests made by or on behalf of the Customer; and
- any other written instructions agreed by the parties.

The Customer instructs Autopilot to process Customer Personal Data as necessary to provide, operate, maintain, secure, support, troubleshoot, and administer the Services, including to perform Customer-authorised workflows, communications, automations, integrations, imports, exports, reporting, billing, support, and account-administration activities.

Autopilot may refuse, suspend, or delay an instruction where Autopilot reasonably believes the instruction is unlawful, unsafe, technically infeasible, inconsistent with the Services, inconsistent with the Agreement, or likely to create legal, security, operational, deliverability, reputational, or service integrity risk.

Where Autopilot believes an instruction infringes Applicable Data Protection Laws, Autopilot will notify the Customer where reasonably practicable, unless prohibited by law or a regulatory authority.

---

## Customer Responsibilities

The Customer is responsible for:

- complying with Applicable Data Protection Laws in relation to Customer Personal Data;
- having all required rights, notices, permissions, consents, authorisations, and legal bases to collect, use, store, disclose, send, and otherwise process Customer Personal Data through the Services;
- ensuring Customer Personal Data is accurate, lawful, appropriate, and limited to what is reasonably necessary for the Customer’s intended use of the Services;
- determining which users may access the Services and managing user accounts, roles, permissions, and access controls;
- reviewing and configuring available privacy, permission, export, communication, and security settings appropriately;
- responding to Individuals’ requests about Customer Personal Data, except where Autopilot is required by law to respond directly;
- ensuring communications sent through the Services comply with applicable marketing, anti-spam, consumer, telecommunications, privacy, and consent requirements;
- ensuring Customer Personal Data submitted to AI-assisted features is lawful, appropriate, and authorised; and
- promptly notifying Autopilot of suspected unauthorised access, credential compromise, misuse of the Services, or security issues affecting the Customer’s account.

The Services are business-oriented and are not directed at children. The Customer must not intentionally submit children’s information, medical information, biometric information, or other sensitive or special category information to the Services unless the submission is lawful, necessary for the Customer’s use of the Services, and supported by all required notices, rights, consents, and legal bases.

The Customer acknowledges that free-text fields, notes, files, imports, screenshots, messages, and attachments may allow users to enter unexpected sensitive information. The Customer remains responsible for the content submitted by its users.

---

## Autopilot Processing Obligations

Autopilot will:

- process Customer Personal Data only as described in this DPA, the Agreement, the Privacy Policy, or the Customer’s documented instructions;
- implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data;
- ensure that personnel authorised to process Customer Personal Data are subject to confidentiality obligations appropriate to their role;
- limit personnel access to Customer Personal Data to circumstances where access is reasonably needed for support, operations, engineering, security, incident response, legal, compliance, billing, administration, or other legitimate service-related purposes;
- not sell Customer Personal Data;
- not use Customer Personal Data for Autopilot’s own unrelated marketing purposes;
- not use Customer Personal Data submitted through Autopilot as general product-training data or to train public AI models;
- provide reasonable assistance to the Customer as described in this DPA; and
- impose appropriate contractual obligations on Subprocessors that process Customer Personal Data on Autopilot’s behalf.

Autopilot may use aggregated, anonymised, de-identified, operational, diagnostic, security, service-usage, and performance information to maintain, support, secure, analyse, and improve the Services, provided that use does not identify an individual and Autopilot does not use that information to re-identify an individual.

Nothing in this DPA gives Autopilot ownership of Customer Data. The Customer retains ownership of Customer Data, subject to the rights granted to Autopilot to provide, operate, support, secure, and administer the Services.

---

## AI-Assisted Features

Autopilot may provide AI-assisted features for assistant, analysis, drafting, summarisation, workflow, operational, support, import-mapping, and related functions.

Where the Customer or an authorised user enables or uses AI-assisted features, the Customer instructs Autopilot to process the prompts, responses, relevant application context, and related Customer Personal Data needed to provide those features.

Autopilot will not intentionally submit broader Customer Personal Data to an AI service provider than is reasonably necessary for the enabled feature, user request, support request, troubleshooting activity, or related operational purpose.

AI-assisted features may use third-party AI service providers identified in Autopilot’s Subprocessors documentation. AI conversation content, prompts, responses, feedback, transcripts, and related context may be stored by Autopilot where reasonably needed to provide, support, secure, monitor, or troubleshoot the relevant feature.

Autopilot does not use Customer Personal Data submitted through Autopilot as general product-training data or to train public AI models. However, Autopilot does not guarantee that all AI processing is no-retention unless that is expressly stated in a separate written agreement or confirmed provider-specific setting.

AI outputs may be incomplete, inaccurate, or unsuitable for a particular purpose. The Customer and its users are responsible for reviewing AI outputs before relying on them, sharing them, making decisions from them, or using them in customer-facing workflows.

---

## Customer Communications

The Services may allow the Customer to send transactional, operational, automated, service-related, and marketing communications.

The Customer controls who it contacts, why it contacts them, what it sends, and whether the communication is lawful and appropriate. Autopilot does not determine whether the Customer has consent or another lawful basis to contact a recipient.

The Customer is responsible for required notices, consents, unsubscribe handling, legal bases, suppression lists, message content, recipient selection, and compliance with applicable communications, marketing, anti-spam, telecommunications, consumer, and privacy laws.

Autopilot may suspend, limit, disable, or restrict communication features if Autopilot reasonably believes they are being misused or may create legal, security, deliverability, reputational, operational, or service integrity risk.

---

## Confidentiality

Autopilot will take reasonable steps to ensure that personnel with access to Customer Personal Data are subject to confidentiality obligations appropriate to their role.

Autopilot will not disclose Customer Personal Data except as described in this DPA, the Agreement, the Privacy Policy, the Subprocessors documentation, the Customer’s documented instructions, or as required by law.

---

## Security Measures

Autopilot will maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, and unauthorised access.

Schedule 2 sets out baseline categories of Autopilot’s technical and organisational measures. Autopilot’s [Security & Trust](/legal/security-trust) documentation provides additional information about current security practices and operational controls. That documentation may be updated as practices evolve and does not make every operational detail an immutable contractual commitment.

Security practices evolve over time. Autopilot may update, replace, or modify its technical and organisational measures, provided the changes do not materially reduce the overall level of protection for Customer Personal Data.

No service can guarantee that security incidents will never occur. This DPA does not create security commitments beyond those stated in this DPA, the Agreement, and Autopilot’s Security & Trust documentation.

---

## Security Incident Notification

Autopilot will investigate suspected Security Incidents affecting Customer Personal Data.

If Autopilot confirms a Security Incident, Autopilot will notify the affected Customer without undue delay and, where feasible, aim to provide initial notice within 72 hours after confirmation. Notification may be delayed where required by law, law enforcement, a regulator, or where immediate notice would increase security risk.

Autopilot’s notice will include available information that is reasonably useful to the Customer, which may include:

- a description of the Security Incident;
- the categories of Customer Personal Data affected, if known;
- the approximate number of affected Individuals or records, if known;
- steps taken or planned by Autopilot to investigate, contain, or remediate the Security Incident;
- recommended steps for the Customer, where applicable; and
- a contact point for follow-up.

Autopilot may provide information in phases as it becomes available. Autopilot’s notification of a Security Incident is not an admission of fault or liability.

The Customer remains responsible for determining whether it must notify Individuals, regulators, customers, or other parties, unless Applicable Data Protection Laws require Autopilot to notify directly. Autopilot will provide reasonable assistance to support the Customer’s legally required notifications, taking into account the nature of the processing and the information available to Autopilot.

The Customer must promptly notify Autopilot if it suspects unauthorised access to the Services, compromised credentials, misuse of accounts, or any issue that may affect the security of Customer Personal Data.

---

## Subprocessors and Operational Providers

The Customer gives Autopilot general authorisation to engage Subprocessors to process Customer Personal Data where reasonably necessary to provide, support, secure, and operate the Services. Autopilot may also use operational providers for internal business, security, support, collaboration, administration, development, troubleshooting, and service-operation purposes. Where those providers process Customer Personal Data on Autopilot’s behalf, Autopilot will treat them as Subprocessors for the purposes of this DPA.

Autopilot’s current Subprocessors documentation is incorporated by reference into this DPA and is the source of truth for the current list of Subprocessors and Operational Providers. Schedule 4 confirms that incorporation relationship and does not maintain a separate provider list. The Subprocessors documentation may be updated in accordance with this section. A provider may not process Customer Personal Data for every Customer or every feature.

Autopilot will impose appropriate contractual obligations on Subprocessors that process Customer Personal Data on Autopilot’s behalf. Where a Subprocessor fails to meet its data protection obligations in relation to Customer Personal Data, Autopilot remains responsible to the Customer for the performance of Autopilot’s obligations under this DPA, subject to the limitations of liability in the Agreement.

Autopilot may update its Subprocessors from time to time. Where Autopilot intends to add or replace a material Subprocessor, Autopilot will update its Subprocessors documentation and, where reasonably practicable, provide at least 30 days’ notice before the new Subprocessor processes Customer Personal Data. Autopilot may use a shorter notice period where needed for security, continuity, availability, legal compliance, urgent operational reasons, or to avoid material harm to the Services or customers.

The Customer may object to a new material Subprocessor by notifying Autopilot within 15 days after notice, explaining the reasonable data protection basis for the objection. The parties will work in good faith to resolve the objection. If the objection cannot reasonably be resolved, Autopilot may make available a workaround, permit the Customer to stop using the affected feature, or allow the Customer to terminate the affected Services in accordance with the Agreement.

---

## International Processing and Transfers

This section applies to international processing and transfer obligations only to the extent those obligations apply under Applicable Data Protection Laws.

Customer Personal Data may be processed and stored in New Zealand, Australia, the United States, and other jurisdictions where Autopilot or its providers operate.

Autopilot does not provide strict data residency unless expressly agreed in a separate written agreement.

Where Customer Personal Data is transferred internationally, Autopilot will take reasonable steps designed to support the protection of Customer Personal Data, including by using reputable providers and relevant contractual, organisational, or technical safeguards where required or appropriate.

For Customer Personal Data subject to the New Zealand Privacy Act, where Autopilot discloses Customer Personal Data to an overseas recipient and Information Privacy Principle 12 applies, Autopilot will take reasonable steps designed to support comparable safeguards or rely on another available lawful basis or exception.

For Customer Personal Data subject to EU GDPR or UK GDPR transfer restrictions, the parties will rely on applicable adequacy decisions, standard contractual clauses, the UK International Data Transfer Addendum or International Data Transfer Agreement, or another lawful transfer mechanism where required by those laws. Further details may be set out in Schedule 5, an order form, or a separate transfer addendum.

---

## Assistance with Individual Rights

The Customer is generally responsible for responding to requests from Individuals relating to Customer Personal Data.

If Autopilot receives a request directly from an Individual relating to Customer Personal Data, Autopilot may redirect the Individual to the Customer or notify the Customer, unless legally prohibited or required to respond directly.

Taking into account the nature of the processing and the information available to Autopilot, Autopilot will provide reasonable assistance to help the Customer respond to legally required requests for access, correction, deletion, restriction, objection, portability, or similar rights under Applicable Data Protection Laws.

Autopilot may need to verify the requester’s identity, understand the requester’s relationship to the relevant Customer or dealership, and coordinate with the Customer before taking action.

---

## Assistance with Compliance, Assessments, and Regulatory Requests

To the extent required by Applicable Data Protection Laws, and taking into account the nature of the processing and the information available to Autopilot, Autopilot will provide legally required, reasonable assistance connected to Customer Personal Data where reasonably required for:

- security and breach response obligations;
- data protection impact assessments or privacy impact assessments relating to the Customer’s use of the Services;
- prior consultation or engagement with a regulator where required by Applicable Data Protection Laws;
- reasonable information requests needed to demonstrate Autopilot’s compliance with this DPA; and
- other legally required Customer obligations relating to Customer Personal Data.

Autopilot may satisfy assistance requests by providing existing documentation, written responses, product functionality, support guidance, Security & Trust documentation, Subprocessors documentation, or other reasonable information.

Autopilot is not required to provide bespoke legal advice, prepare custom compliance reports, complete unlimited or repetitive questionnaire responses, disclose security-sensitive information, provide information unrelated to Customer Personal Data, or perform assistance that is not required by Applicable Data Protection Laws or this DPA.

Assistance that requires significant additional work, bespoke responses, engineering work, legal analysis, technical export work, or support outside ordinary service support may be subject to reasonable administrative or professional services charges.

---

## Return and Deletion of Customer Personal Data

During the term of the Services, the Customer may access, export, correct, or delete certain Customer Data using available product functionality, subject to the Customer’s permissions, plan, and enabled features.

Upon termination or expiry of the Services, the Customer may request reasonable export or return assistance within 30 days, where available, appropriate, and permitted by law and the Agreement.

At the Customer’s written choice, made before termination or within 30 days after termination, Autopilot will either:

- make Customer Personal Data reasonably available for export or return, where available and technically feasible; or
- delete or de-identify Customer Personal Data from active production systems within 90 days after a verified deletion request.

If the Customer does not make a return or deletion choice within that period, the Customer instructs Autopilot to handle Customer Personal Data in accordance with the Agreement, Privacy Policy, and Autopilot’s operational retention practices.

Autopilot may retain Customer Personal Data where required or reasonably necessary for legal, tax, accounting, regulatory, audit, security, backup, disaster recovery, dispute, enforcement, fraud prevention, compliance, legitimate business, or operational purposes.

Customer Personal Data retained in backups, logs, archives, provider systems, or disaster recovery systems may not be immediately deleted, but will be protected from active processing and deleted, overwritten, or de-identified in accordance with applicable retention practices, unless retained for one of the purposes described above.

---

## Audit and Information Rights

Autopilot will make available reasonable information necessary to demonstrate compliance with this DPA, where required by Applicable Data Protection Laws or reasonably necessary for the Customer’s compliance obligations relating to Customer Personal Data.

Audit and information rights are documentation-first. The Customer agrees to first use Autopilot’s available legal documentation, Security & Trust documentation, Subprocessors documentation, written responses, product information, and other existing materials to assess Autopilot’s processing of Customer Personal Data.

Where Applicable Data Protection Laws require additional audit rights, or where an additional audit is reasonably necessary for the Customer’s compliance obligations relating to Customer Personal Data, the Customer may request an audit no more than once in any 12-month period, unless a Security Incident or regulator request reasonably requires a further audit.

Any audit must be:

- requested on at least 30 days' written notice;
- limited to the processing of the Customer’s own Customer Personal Data;
- conducted during normal business hours;
- conducted remotely where reasonably possible;
- conducted in a way that does not compromise Autopilot’s systems, security, confidentiality, availability, intellectual property, or other customers’ information; and
- subject to reasonable confidentiality, security, timing, and scope requirements.

Any external auditor must be independent, reputable, suitably qualified, bound by confidentiality obligations, not a competitor of Autopilot, and reasonably acceptable to Autopilot.

Audits do not include source-code review, production system access, penetration testing, vulnerability scanning, access to other customers’ data, or on-site inspection unless Autopilot expressly agrees in writing.

The Customer is responsible for its audit costs and Autopilot’s reasonable costs where the audit requires substantial time, support, engineering, legal, or administrative work.

---

## Legal Requests

If Autopilot receives a subpoena, warrant, court order, regulator request, law enforcement request, or other legal request for Customer Personal Data, Autopilot will, where legally permitted and reasonably practicable, notify the Customer before disclosing Customer Personal Data.

Autopilot may disclose Customer Personal Data where required by law or where Autopilot reasonably believes disclosure is necessary to comply with legal obligations, protect rights or safety, prevent fraud or abuse, enforce the Agreement, or protect the Services.

Where legally permitted, Autopilot will take reasonable steps to limit disclosure to the Customer Personal Data reasonably required by the legal request.

---

## Changes to this DPA

Autopilot may update this DPA from time to time to reflect changes in law, regulatory guidance, Services, security practices, subprocessors, operational practices, or business requirements.

The latest version will be made available through Autopilot’s legal documentation.

If Autopilot makes a material change that materially reduces protections for Customer Personal Data, Autopilot will provide reasonable notice where required by the Agreement or Applicable Data Protection Laws.

Changes to Subprocessors are handled under the Subprocessors and Operational Providers section.

---

## Term and Survival

This DPA remains in effect for as long as Autopilot processes Customer Personal Data on behalf of the Customer.

Sections that by their nature should survive termination will continue to apply for as long as Autopilot retains Customer Personal Data, including confidentiality, security, return and deletion, legal requests, audit limitations, liability, and governing law.

---

## Liability and Order of Precedence

Each party’s liability under this DPA is subject to the exclusions and limitations of liability in the Agreement, unless prohibited by Applicable Data Protection Laws.

If there is a conflict between this DPA and the Agreement regarding the processing of Customer Personal Data, this DPA applies to the extent of the conflict.

If applicable standard contractual clauses, the UK International Data Transfer Addendum, the UK International Data Transfer Agreement, or other mandatory transfer terms apply and conflict with this DPA, those transfer terms apply to the extent of the conflict for the relevant transfer.

---

## Governing Law

This DPA is governed by the laws of New Zealand unless otherwise agreed in writing between the parties.

Mandatory data protection rights, obligations, remedies, or transfer terms that apply under Applicable Data Protection Laws are not limited by this governing law clause.

---

# Schedule 1 — Processing Details

## Subject Matter

The provision of Autopilot dealership SaaS services, including workflow, CRM and customer management, vehicle sales and deal operations, reporting, communications, automation, finance and administration workflows, AI-assisted features, support, billing, security, and related operations.

## Duration

For the term of the Customer’s use of the Services, plus any retention period required or permitted for support, audit, backup, legal, tax, accounting, dispute, security, compliance, or operational purposes.

## Nature of Processing

Collection, hosting, storage, organisation, retrieval, display, transmission, import, export, analysis, reporting, communication sending, automation, AI-assisted processing where enabled, support access, troubleshooting, security monitoring, incident investigation, billing administration, deletion, archival, and related processing.

## Purpose of Processing

To provide, operate, maintain, secure, support, troubleshoot, and administer the Services, and to perform Customer-authorised workflows, communications, automations, reporting, integrations, AI-assisted features, imports, exports, billing, and support activities. Autopilot may use aggregated, anonymised, de-identified, operational, diagnostic, security, service-usage, and performance information to analyse and improve the Services as described in the Autopilot Processing Obligations section.

## Processing Frequency

Ongoing while the Customer account is active and as authorised users interact with the Services. Certain limited processing may continue after termination where permitted under this DPA, the Agreement, or applicable law.

## Data Sources

The Customer, authorised users, dealership administrators, imports, connected systems or integrations authorised by the Customer, support interactions, billing processes, communications, and automatic technical or service operations.

## Processing Locations

Autopilot is based in New Zealand and uses selected managed service providers. Customer Personal Data may be processed in New Zealand, Australia, the United States, and other jurisdictions where Autopilot or its providers operate. Autopilot does not provide strict data residency unless expressly agreed in writing.

---

# Schedule 2 — Technical and Organisational Measures

Autopilot maintains technical and organisational measures designed to protect Customer Personal Data. This Schedule summarises baseline categories of measures. Autopilot’s [Security & Trust](/legal/security-trust) documentation provides additional information about current security practices and operational controls. Security practices may evolve, provided Autopilot does not materially reduce the overall level of protection for Customer Personal Data.

## Baseline Measures

Autopilot’s measures may include, where applicable:

- managed cloud infrastructure and server-side handling of privileged credentials;
- TLS for connections between users and Autopilot;
- authentication, session management, invite-based account access, password controls, and optional account-protection features such as authenticator-app MFA or passkeys where enabled;
- organisation, dealership, role, permission, and field-level access controls for supported workflows;
- database Row Level Security for client-side access and server-side scope checks for trusted backend operations;
- route-specific authentication, permission, signature, or shared-secret checks for protected pages, APIs, server actions, cron routes, and webhooks;
- validation, allowlists, and managed database APIs in supported forms, actions, imports, and workflows;
- permission-aware export controls for supported export workflows;
- selected file-size, MIME-type, bucket-access, and storage controls for supported upload areas;
- operational logging, monitoring, and selected audit or event records for security, support, billing, email, webhook, cron, performance, administration, and deal-change workflows;
- incident response processes that may include investigation, containment, session revocation, password resets, access restriction, feature disabling, secret rotation, remediation, and customer communication where appropriate;
- selected soft-delete, deactivation, deletion, backup, archive, and disaster-recovery practices; and
- provider-level contractual, security, privacy, and operational controls for managed infrastructure, database, storage, deployment, email, payment, AI, support, and operational services.

These measures may vary by feature, customer configuration, provider, and operational context. Public asset storage, customer-configured integrations, free-text fields, user uploads, and customer-controlled communications may require additional Customer-side configuration and review.

Unless separately stated in current Autopilot documentation or a written agreement, Autopilot does not claim SOC 2, ISO 27001, PCI, GDPR certification, external penetration testing, or external audit certification.

---

# Schedule 3 — Categories of Data Subjects and Personal Data

## Categories of Data Subjects

Customer Personal Data may relate to:

- dealership customers, prospects, leads, and contacts;
- dealership staff and authorised users;
- dealership administrators and organisation owners;
- finance, transport, supplier, and operational contacts entered by Customers;
- recipients of communications sent by or on behalf of Customers;
- support requesters and people appearing in support context, screenshots, logs, message excerpts, files, or attachments; and
- billing contacts and Customer account administrators.

## Categories of Personal Data

Depending on Customer configuration, enabled features, integrations, and user activity, Customer Personal Data may include:

- account and user information, including names, email addresses, job titles, dealership or business information, account credentials, authentication information, role, permission, access-control, onboarding, administration, and support details;
- customer and contact information, including names, contact names, company names, email addresses, mobile and phone numbers, addresses, postal addresses, customer numbers, lead sources, notes, and related profile data;
- identity and registration-adjacent information, including date of birth, driver licence number, licence version or 5b, LTSA or company references, GST or company numbers where entered;
- vehicle and deal records, including vehicle make, model, variant, year, colour, VIN or chassis, registration, stock number, order or SIDO numbers, sale price, deposit, trade-in details, finance details, lender or finance company, deal status, delivery or status dates, sales channel, salesperson, finance manager, gross profit or reporting data, and operational notes;
- communications, including transactional, operational, automated, service-related, and marketing message content and metadata, delivery events, unsubscribe preferences, templates, and recipient information;
- attachments and files, including documents, records, screenshots, images, board attachments, dealership branding assets, avatars, backgrounds, import files, exports, and other uploaded or generated materials;
- support and operational data, including support tickets, issue reports, internal notes, diagnostic context, logs, screenshots, webhook payloads, ticket metadata, and customer correspondence;
- technical and usage information, including IP addresses, browser, device, operating-system information, session and device metadata, routes, pages, features and actions used, diagnostic information, application logs, approximate location derived from technical information, and performance data; and
- billing and subscription information, including billing contacts, account details, invoices, subscription plan and status, payment identifiers, tax or billing address information, transaction metadata, and payment-related records.

Payment card information is generally processed by Stripe or another payment provider and is not stored directly by Autopilot.

## Sensitive or Special Category Data

Autopilot is not designed for medical, biometric, children’s, or other special category information. However, Customers control free-text fields, notes, files, imports, communications, and attachments, so unexpected sensitive information may be entered by Customers or users.

The Customer must not submit sensitive or special category information unless it is lawful, necessary, appropriate for the Customer’s use of the Services, and supported by all required notices, rights, consents, authorisations, and legal bases.

---

# Schedule 4 — Subprocessors and Operational Providers

Autopilot’s [Subprocessors](/legal/subprocessors) documentation is incorporated by reference into this DPA and is the source of truth for the current list of Subprocessors and Operational Providers.

The Subprocessors documentation identifies provider names, purposes, categories of Customer Personal Data or customer information that may be processed, and related provider information where available. It also distinguishes service subprocessors from internal operations and support providers.

Autopilot may update the Subprocessors documentation in accordance with the Subprocessors and Operational Providers section of this DPA. A provider may not process Customer Personal Data for every Customer or every feature. The Customer’s use of a feature, configuration, support request, or other instruction may determine whether a provider is involved.

This Schedule does not maintain a separate duplicate provider list. If this DPA and the current Subprocessors documentation describe provider details differently, the current Subprocessors documentation controls for the current provider list, subject to Autopilot’s obligations in this DPA and the Agreement.

---

# Schedule 5 — EU, UK, and Other Transfer Terms Where Applicable

This Schedule applies only where Customer Personal Data is subject to the EU GDPR, UK GDPR, or other laws requiring specific transfer safeguards. It does not mean every Customer Data set is subject to EU GDPR, UK GDPR, the European Commission Standard Contractual Clauses, the UK International Data Transfer Addendum, or the UK International Data Transfer Agreement.

Where Customer Personal Data is transferred from the European Economic Area, the United Kingdom, or Switzerland to New Zealand, an applicable adequacy decision or equivalent lawful transfer mechanism may apply. Where Customer Personal Data is transferred onward to a jurisdiction or provider that requires additional safeguards, Autopilot will use an appropriate transfer mechanism where required.

Where required, the parties will enter into, incorporate, or rely on the applicable version of:

- the European Commission Standard Contractual Clauses;
- the UK International Data Transfer Addendum;
- the UK International Data Transfer Agreement;
- an applicable adequacy decision;
- a recognised certification, binding scheme, or approved safeguard; or
- another lawful transfer mechanism available under Applicable Data Protection Laws.

For EU GDPR controller-to-processor transfers between the Customer and Autopilot, the applicable module will ordinarily be Module Two unless the parties agree or the facts require otherwise. For processor-to-processor or onward subprocessor transfers, the applicable module or transfer mechanism will be determined by the relevant processing chain.

If transfer terms are required and not already included in the Agreement, the parties agree to work in good faith to complete the required transfer terms promptly.
