Data Processing Agreement
Last updated: February 24, 2026
1. Introduction
This Data Processing Agreement ("DPA") forms part of the Domain Pilot Terms of Service ("Agreement") between Domain Pilot ("Processor," "we," "us," or "our") and the entity or individual agreeing to these terms ("Controller," "Customer," "you," or "your").
This DPA applies to the processing of Personal Data by Domain Pilot on behalf of the Customer in the course of providing the Domain Pilot platform and related services ("Service").
This DPA is designed to ensure compliance with applicable data protection laws, including the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK General Data Protection Regulation ("UK GDPR"), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), and other applicable privacy regulations.
In the event of any conflict between this DPA and the Agreement, this DPA shall prevail with respect to the processing of Personal Data.
2. Definitions
"Applicable Data Protection Laws" means all laws and regulations relating to the processing of Personal Data that apply to the processing described in this DPA, including GDPR, UK GDPR, CCPA/CPRA, and any other applicable privacy regulations.
"Controller" means the entity that determines the purposes and means of the processing of Personal Data. For the purposes of this DPA, the Customer is the Controller.
"Customer Data" means any data, including Personal Data, that the Customer submits to, transfers to, or makes available through the Service, including domain information, registrar credentials, DNS records, and monitoring configurations.
"Data Subject" means an identified or identifiable natural person whose Personal Data is processed.
"Personal Data" means any information relating to an identified or identifiable natural person, as defined in Applicable Data Protection Laws.
"Processing" means any operation or set of operations performed on Personal Data, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, combination, restriction, erasure, or destruction.
"Processor" means the entity that processes Personal Data on behalf of the Controller. For the purposes of this DPA, Domain Pilot is the Processor.
"Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed.
"Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to processors established in third countries, as approved by the European Commission.
"Sub-processor" means any third party engaged by Domain Pilot to process Personal Data on behalf of the Customer.
3. Scope and Roles
3.1 Roles of the Parties
The Customer acts as the Controller and Domain Pilot acts as the Processor with respect to Customer Data processed through the Service.
Where Domain Pilot determines the purposes and means of processing (for example, for billing, account management, or service improvement), Domain Pilot acts as an independent Controller subject to our Privacy Policy.
3.2 Scope of Processing
Domain Pilot processes Personal Data solely for the purpose of providing the Service as described in the Agreement. The details of the processing are described in Annex 1 of this DPA.
3.3 Customer Obligations
The Customer is responsible for:
- Ensuring that its use of the Service complies with Applicable Data Protection Laws
- Having a lawful basis for providing Personal Data to Domain Pilot
- Providing any required notices and obtaining any required consents from Data Subjects
- Ensuring that its instructions to Domain Pilot comply with Applicable Data Protection Laws
4. Data Processing Obligations
4.1 Processing Instructions
Domain Pilot will process Personal Data only on documented instructions from the Customer, including with regard to transfers of Personal Data to a third country. The Agreement and this DPA constitute the Customer's complete instructions at the time of entering into this DPA. Any additional or alternative instructions must be agreed upon separately in writing.
If Domain Pilot believes that an instruction from the Customer infringes Applicable Data Protection Laws, Domain Pilot will promptly inform the Customer.
4.2 Confidentiality
Domain Pilot ensures that all persons authorized to process Personal Data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality. This obligation survives the termination of this DPA.
4.3 Security Measures
Domain Pilot will implement and maintain appropriate technical and organizational measures to protect Personal Data against Security Incidents. These measures include, but are not limited to, the measures described in Annex 2 of this DPA.
Key security measures include:
Zero-Knowledge Encryption for Credentials:
- All registrar API keys are encrypted using AES-256-GCM encryption
- Credentials are encrypted client-side before transmission to our servers
- The Customer's account password serves as the encryption key
- Domain Pilot personnel cannot access, view, or retrieve API credentials in plain text
- Credentials are decrypted only temporarily in isolated environments during authorized API operations
- Decrypted credentials are immediately purged from memory after use
Data Encryption:
- All data in transit is encrypted using TLS 1.2 or higher
- All sensitive data at rest is encrypted using AES-256 encryption
- Encryption keys are stored separately from encrypted data
Access Controls:
- Role-based access control for internal systems
- Principle of least privilege for all personnel
- Multi-factor authentication for administrative access
- All access to production systems is logged and audited
Infrastructure Security:
- Secure cloud hosting with industry-leading providers
- Network firewalls and intrusion detection systems
- DDoS protection and rate limiting
- Regular vulnerability scanning and patching
- Continuous monitoring and automated threat detection
4.4 Assistance to the Controller
Domain Pilot will assist the Customer in:
- Responding to requests from Data Subjects exercising their rights under Applicable Data Protection Laws
- Ensuring compliance with security, breach notification, data protection impact assessments, and prior consultation obligations under Applicable Data Protection Laws
Such assistance will be provided taking into account the nature of the processing and the information available to Domain Pilot.
5. Sub-processors
5.1 Authorization
The Customer provides general authorization for Domain Pilot to engage Sub-processors to process Personal Data on behalf of the Customer, subject to the requirements of this Section 5.
5.2 Current Sub-processors
A list of current Sub-processors is available at domainpilot.io/legal/sub-processors or upon request at privacy@domainpilot.io. The list includes the Sub-processor's name, location, and description of processing.
5.3 New Sub-processors
Domain Pilot will notify the Customer before engaging any new Sub-processor by updating the Sub-processor list and providing at least 14 days' notice before the new Sub-processor begins processing Personal Data.
5.4 Objection to Sub-processors
If the Customer has a reasonable, legitimate objection to a new Sub-processor, the Customer must notify Domain Pilot in writing within 14 days of receiving notice. The parties will work together in good faith to find a mutually acceptable resolution. If no resolution is reached, the Customer may terminate the affected portion of the Service without penalty.
5.5 Sub-processor Obligations
Domain Pilot will ensure that each Sub-processor is bound by data protection obligations no less protective than those set out in this DPA. Domain Pilot remains fully liable for the acts and omissions of its Sub-processors.
6. Security Incidents
6.1 Notification
Domain Pilot will notify the Customer of any confirmed Security Incident without undue delay and in any event within 72 hours of becoming aware of the Security Incident. Notification will be sent to the email address associated with the Customer's account or to such other address as the Customer designates.
6.2 Content of Notification
The notification will include, to the extent reasonably available:
- A description of the nature of the Security Incident, including the categories and approximate number of Data Subjects and Personal Data records affected
- The name and contact details of the Domain Pilot contact from whom more information can be obtained
- A description of the likely consequences of the Security Incident
- A description of the measures taken or proposed to address the Security Incident, including measures to mitigate its possible adverse effects
6.3 Cooperation
Domain Pilot will cooperate with the Customer and take reasonable steps to assist in the investigation, mitigation, and remediation of the Security Incident. Domain Pilot will take reasonable steps to contain and minimize the impact of the Security Incident.
6.4 Limitations
Domain Pilot's notification of or response to a Security Incident will not be construed as an acknowledgment of any fault or liability with respect to the Security Incident.
7. International Data Transfers
7.1 Transfer Mechanisms
Where Personal Data is transferred outside the European Economic Area ("EEA"), the United Kingdom, or Switzerland to a country not recognized as providing an adequate level of data protection, Domain Pilot will ensure that appropriate safeguards are in place, including:
- Standard Contractual Clauses as approved by the European Commission
- UK International Data Transfer Agreement or UK Addendum to the EU SCCs, as applicable
- Any other transfer mechanism approved under Applicable Data Protection Laws
7.2 Standard Contractual Clauses
Where applicable, the Standard Contractual Clauses are incorporated into this DPA by reference. For the purposes of the SCCs:
- Module Two (Controller to Processor) applies to the processing described in this DPA
- The Customer is the "data exporter" and Domain Pilot is the "data importer"
- The competent supervisory authority is the supervisory authority of the EEA member state in which the Customer is established
- The governing law is the law of the EEA member state in which the Customer is established
7.3 Additional Safeguards
Domain Pilot implements supplementary measures to protect Personal Data during international transfers, including encryption of data in transit and at rest, access controls, and regular security assessments.
8. Data Subject Rights
8.1 Assistance
Domain Pilot will assist the Customer in responding to requests from Data Subjects to exercise their rights under Applicable Data Protection Laws. These rights may include:
- Right of access
- Right to rectification
- Right to erasure
- Right to restriction of processing
- Right to data portability
- Right to object to processing
8.2 Redirecting Requests
If Domain Pilot receives a request directly from a Data Subject regarding the Customer's data, Domain Pilot will promptly redirect the Data Subject to the Customer, unless otherwise instructed by the Customer or required by law.
9. Data Retention and Deletion
9.1 Duration of Processing
Domain Pilot will process Personal Data for the duration of the Agreement, unless otherwise agreed in writing.
9.2 Return or Deletion
Upon termination of the Agreement, Domain Pilot will, at the Customer's choice:
- Return all Customer Data in a commonly used, machine-readable format, or
- Delete all Customer Data from its systems
This will be completed within 30 days of termination, unless Applicable Data Protection Laws require further storage. The Customer must request data export before account termination.
9.3 Residual Data
After deletion, Domain Pilot may retain anonymized or aggregated data that cannot be used to identify any individual. Backup copies may be retained for a limited period in accordance with our backup retention schedule, after which they will be securely deleted.
10. Audits and Compliance
10.1 Information and Audit Rights
Domain Pilot will make available to the Customer all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by the Customer or a third-party auditor mandated by the Customer.
10.2 Audit Process
The Customer must provide at least 30 days' written notice of an audit request. Audits will be conducted during normal business hours and in a manner that minimizes disruption to Domain Pilot's operations. The Customer bears the cost of any audit unless the audit reveals material non-compliance by Domain Pilot.
10.3 Confidentiality
Audit results are confidential and may only be shared with the Customer's advisors who have a need to know and are bound by confidentiality obligations.
10.4 Compliance Certifications
Where available, Domain Pilot may satisfy audit requests by providing relevant compliance certifications, audit reports, or other documentation demonstrating compliance with this DPA.
11. CCPA/CPRA Specific Provisions
To the extent the CCPA/CPRA applies to the processing of Personal Data under this DPA:
11.1 Roles
Domain Pilot acts as a "Service Provider" as defined under the CCPA/CPRA. The Customer acts as a "Business."
11.2 Restrictions
Domain Pilot will not:
- Sell or share Personal Data received from the Customer
- Retain, use, or disclose Personal Data for any purpose other than performing the Service as specified in the Agreement
- Retain, use, or disclose Personal Data outside the direct business relationship with the Customer
- Combine Personal Data received from the Customer with Personal Data received from other sources, except as permitted by the CCPA/CPRA
11.3 Compliance Certification
Domain Pilot certifies that it understands and will comply with the restrictions set forth in this Section 11.
12. Liability
Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set forth in the Agreement.
13. General Provisions
13.1 Governing Law
This DPA is governed by and construed in accordance with the governing law provisions of the Agreement, unless otherwise required by Applicable Data Protection Laws.
13.2 Severability
If any provision of this DPA is found to be invalid or unenforceable, the remaining provisions will remain in full force and effect.
13.3 Amendments
This DPA may be amended by Domain Pilot to reflect changes in Applicable Data Protection Laws or our processing practices. Material changes will be communicated to the Customer with reasonable advance notice.
13.4 Entire Agreement
This DPA, together with the Agreement and its annexes, constitutes the entire agreement between the parties regarding the processing of Personal Data and supersedes all prior agreements on this subject.
Annex 1: Details of Processing
Categories of Data Subjects
- Customer's employees, contractors, and team members who access the Service
- Customer's clients whose domain information may be managed through the Service
Categories of Personal Data
- Account information: name, email address, password (hashed)
- Registrar API credentials (encrypted using zero-knowledge architecture)
- Domain registration data: domain names, registration dates, expiration dates, registrant information
- DNS records and configurations
- SSL certificate data
- Uptime monitoring data: URLs, response times, status codes
- Usage data: login timestamps, feature usage, IP addresses
- Billing information: payment method details (processed by third-party payment provider)
- Communication data: support tickets, notification preferences
Sensitive Data
No special categories of personal data (as defined by GDPR Article 9) are intentionally processed. Registrar API credentials are treated with the highest level of security through zero-knowledge encryption.
Nature and Purpose of Processing
- Providing the Domain Pilot platform and related services
- Connecting to and syncing data from Customer's registrar accounts
- Monitoring domain expiration, uptime, and SSL certificates
- Sending alerts and notifications as configured by the Customer
- Managing DNS records on Customer's behalf
- Providing analytics and reporting on domain status
- Customer support and communication
Duration of Processing
Processing continues for the duration of the Agreement. Upon termination, data is handled in accordance with Section 9 of this DPA.
Frequency of Processing
- Registrar sync: automated, every 24 hours or as configured
- Uptime monitoring: automated, every 1 to 60 minutes as configured
- SSL monitoring: automated, daily
- Alerts: event-driven, as conditions are met
- DNS management: on-demand, initiated by Customer
Annex 2: Technical and Organizational Security Measures
1. Encryption
| Measure | Implementation |
|---|---|
| Data in transit | TLS 1.2 or higher for all communications |
| Data at rest | AES-256 encryption for all sensitive stored data |
| API credentials | AES-256-GCM zero-knowledge encryption, client-side encryption with password-derived keys |
| Backup encryption | All backups encrypted at rest |
2. Access Control
| Measure | Implementation |
|---|---|
| Authentication | Multi-factor authentication for all administrative access |
| Authorization | Role-based access control with principle of least privilege |
| Password policy | Strong password requirements enforced |
| Session management | Automatic session timeout, secure session handling |
| Access logging | All access to production systems logged and audited |
3. Infrastructure Security
| Measure | Implementation |
|---|---|
| Hosting | Secure cloud hosting with industry-leading providers |
| Network | Firewalls, intrusion detection, network segmentation |
| DDoS protection | Automated DDoS mitigation |
| Vulnerability management | Regular scanning, timely patching |
| Monitoring | Continuous monitoring and automated threat detection |
4. Operational Security
| Measure | Implementation |
|---|---|
| Incident response | Documented incident response plan with regular drills |
| Security testing | Regular penetration testing and security assessments |
| Development | Secure software development lifecycle (SDLC) |
| Personnel | Confidentiality obligations for all personnel with data access |
| Training | Security awareness training for all team members |
5. Data Protection
| Measure | Implementation |
|---|---|
| Data minimization | Only necessary data collected and processed |
| Retention | Data retained only as long as necessary for the stated purpose |
| Deletion | Secure deletion procedures for data no longer needed |
| Portability | Data export available in common formats |
| Separation | Customer data logically separated |
Annex 3: List of Sub-processors
The current list of Sub-processors is maintained at domainpilot.io/legal/sub-processors and includes:
| Sub-processor | Location | Purpose |
|---|---|---|
| Fly.io | United States, European Union | Infrastructure hosting and data storage |
| Stripe | United States | Payment processing and subscription management |
| Resend | United States | Transactional email delivery |
| PostHog, Sentry | United States, European Union | Product analytics and usage tracking |
This list will be updated as Sub-processors change. Customers will receive 14 days' notice before any new Sub-processor begins processing Personal Data.
Contact
For questions about this DPA or data processing practices:
Privacy inquiries: privacy@domainpilot.io
Security issues: security@domainpilot.io
Mail:
Domain Pilot
Attention: Privacy Team
[Company Address]
By using Domain Pilot, you acknowledge that you have read and agree to this Data Processing Agreement.