1. Introduction
1.1 This page describes how Otopilote ("Otopilote", "we" or "us") complies with Regulation (EU) 2016/679 (the "GDPR") and the UK General Data Protection Regulation ("UK GDPR") when providing its interactive demo and product onboarding services (the "Services"). It supplements the Privacy Policy and the Terms of Service.
1.2 The commitments set out below form the substance of the Data Processing Agreement ("DPA") that Otopilote enters into with customers who process personal data through the Services. A countersigned copy is available on request from privacy@otopilote.com.
2. Roles of the parties
2.1 Otopilote as controller. With respect to your account information, billing data, support correspondence and information collected through our own marketing website, Otopilote acts as a data controller and processes that data as described in the Privacy Policy.
2.2 Otopilote as processor. With respect to the content you upload and the viewer and engagement data generated by demos and onboarding flows you publish ("Customer Personal Data"), you act as the controller and Otopilote acts as your processor, processing Customer Personal Data only on your documented instructions.
2.3 Otopilote will inform you if, in its opinion, an instruction infringes the GDPR or other applicable data protection law.
3. Details of processing
3.1 Subject matter and duration. Provision of the Services for the term of your subscription and any post-termination period required for deletion or return of data.
3.2 Nature and purpose. Hosting, storage, transcoding, transmission, display, analysis and deletion of Customer Personal Data as necessary to operate the Services and to report demo engagement to you.
3.3 Categories of data subjects. Your authorised users; prospects, customers and employees who view your demos and onboarding flows.
3.4 Types of personal data. Identification and contact data, workspace and role data, engagement and usage data, device and browser data, IP address and approximate location, and any personal data contained in content you choose to upload.
3.5 Special categories. The Services are not intended for special-category data as defined in Article 9 GDPR, and you agree not to submit such data.
4. Legal bases
4.1 Where Otopilote is the controller, it relies on: performance of a contract (providing and billing the Services); legitimate interests (security, abuse prevention, and product improvement using aggregated data); consent (marketing communications and non-essential cookies, withdrawable at any time); and compliance with legal obligations (tax, accounting and lawful requests).
4.2 Where Otopilote is the processor, you are responsible for establishing and documenting a valid legal basis for the processing you instruct, and for providing any notices and obtaining any consents required from data subjects, including before recording individuals or customer environments.
5. Confidentiality and personnel
5.1 Otopilote ensures that persons authorised to process Customer Personal Data are bound by written confidentiality obligations, receive appropriate data protection training, and have access only on a need-to-know basis.
6. Security measures
6.1 Otopilote implements appropriate technical and organisational measures pursuant to Article 32 GDPR, including:
- encryption of data in transit (TLS) and at rest;
- role-based, least-privilege access control with audit logging;
- separation of production, staging and development environments;
- centralised secret management and regular dependency patching;
- encrypted backups with periodic restore testing;
- vulnerability monitoring and incident response procedures;
- security review of vendors prior to onboarding.
7. Subprocessors
7.1 You provide general authorisation for Otopilote to engage subprocessors for cloud hosting, video encoding and delivery, transactional email, error monitoring, product analytics, payment processing and customer support.
7.2 Otopilote imposes data protection terms on each subprocessor that are no less protective than those in the DPA, and remains liable for their performance.
7.3 Otopilote maintains a current list of subprocessors, available on request, and will give you reasonable prior notice before adding a new subprocessor so that you may object on legitimate data protection grounds.
8. International transfers
8.1 Customer Personal Data is stored and processed in the European Union by default.
8.2 Where a transfer outside the EEA or the United Kingdom is necessary, Otopilote relies on an adequacy decision or on the European Commission's Standard Contractual Clauses, incorporating the UK International Data Transfer Addendum where relevant, supported by a transfer impact assessment and supplementary technical and organisational measures.
9. Data minimisation and defaults
9.1 Otopilote collects only the data required to operate the Services. Viewer analytics are pseudonymous unless you deliberately identify a viewer. IP addresses are truncated for analytics purposes, and retention windows are configurable where your plan supports that feature.
10. Personal data breach notification
10.1 Otopilote will notify you without undue delay, and in any event within 72 hours of becoming aware, of any personal data breach affecting Customer Personal Data, and will provide the information reasonably necessary for you to meet your obligations under Articles 33 and 34 GDPR.
11. Assistance with data subject rights
11.1 The Services provide functionality allowing you to access, export, correct and delete Customer Personal Data within your workspace.
11.2 Where you require further assistance in responding to a request concerning access, rectification, erasure, restriction, portability or objection, Otopilote will provide reasonable assistance within the statutory response window on request to privacy@otopilote.com.
11.3 If a data subject contacts Otopilote directly regarding Customer Personal Data, Otopilote will forward the request to you rather than responding substantively, unless legally required to do so.
12. Data protection impact assessments and audits
12.1 Otopilote will provide reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities where required under Articles 35 and 36 GDPR.
12.2 Otopilote will make available information necessary to demonstrate compliance with the DPA and will allow for audits, which may be satisfied by providing documentation of security measures and any available third-party reports, subject to reasonable confidentiality and frequency limits.
13. Deletion and return of data
13.1 On termination or expiry of your subscription, Otopilote will delete or return Customer Personal Data within 90 days, except to the extent applicable law requires continued storage. Backup copies age out in the normal backup cycle.
14. Supervisory authority and contact
14.1 Otopilote's lead supervisory authority is the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP). You may also lodge a complaint with the supervisory authority in your country of residence.
14.2 Data protection enquiries, DPA requests and subprocessor list requests should be sent to privacy@otopilote.com. See also our Privacy Policy and Terms of Service.