Legal
Data Processing Agreement
Last updated: May 16, 2026 · GDPR Article 28 compliant
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between RePilot Technologies Pvt. Ltd. (“Processor”) and the customer (“Controller”). It governs how RePilot processes personal data on behalf of its customers in accordance with the EU General Data Protection Regulation (GDPR) and applicable data protection laws.
1. Definitions
"Personal Data" means any information relating to an identified or identifiable natural person as defined in GDPR Article 4.
"Controller" means the RePilot customer who determines the purposes and means of processing personal data.
"Processor" means RePilot Technologies Pvt. Ltd., which processes personal data on behalf of the Controller.
"Sub-processor" means any third party engaged by the Processor to process personal data.
2. Subject Matter and Duration
RePilot processes personal data solely to provide the automation platform services described in the Terms of Service. Processing occurs for the duration of the customer's active subscription and for up to 30 days post-termination, after which all personal data is permanently deleted.
3. Nature and Purpose of Processing
RePilot processes personal data for the following purposes on behalf of the Controller:
- Storing and managing Instagram Business account credentials (encrypted)
- Receiving webhook events from Meta (Instagram comment and message data)
- Creating and managing lead records from social media interactions
- Sending automated direct messages via the Instagram Messaging API
- Providing analytics and reporting on automation performance
4. Categories of Personal Data
Data processed on behalf of Controllers may include:
- Instagram user IDs and usernames of people who interact with the Controller's posts
- Contact information (phone numbers, email) where voluntarily shared by end users
- Message content of automated conversations
- Interaction timestamps and engagement metadata
5. Processor Obligations
RePilot shall:
a) Process personal data only on documented instructions from the Controller (as set out in the Terms of Service and any automation rules configured by the Controller)
b) Ensure that authorised personnel are bound by appropriate confidentiality obligations
c) Implement appropriate technical and organisational security measures (AES-256 encryption at rest, TLS 1.3 in transit, access controls, audit logging)
d) Not engage Sub-processors without prior written consent of the Controller, except as listed in Section 7
e) Assist the Controller in responding to data subject requests (access, rectification, erasure, portability) within 72 hours of the Controller's request
f) Delete or return all personal data to the Controller upon termination of the agreement
g) Make available to the Controller all information necessary to demonstrate compliance with this DPA
6. Controller Obligations
The Controller confirms that:
a) It has a lawful basis for processing the personal data it collects and shares with RePilot
b) It has obtained any necessary consents from data subjects
c) It complies with applicable data protection laws in its use of the RePilot platform
d) It will notify RePilot promptly of any changes to its data protection obligations
7. Sub-processors
RePilot uses the following sub-processors to deliver its services:
• Google Cloud Platform (GCP) — Infrastructure hosting (servers, database, storage) — EU/US regions
• Upstash / Google Cloud Memorystore — Redis queue infrastructure
• Meta Platforms Inc. — Instagram Graph API (data originates from Meta's platform)
RePilot will notify Controllers of any intended changes to sub-processors with reasonable advance notice. Controllers may object to new sub-processors within 14 days of notification.
8. International Data Transfers
Where personal data is transferred outside the European Economic Area (EEA), RePilot ensures appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) as approved by the European Commission.
Our primary infrastructure is hosted on Google Cloud Platform (us-central1). Google maintains SCCs for international transfers.
9. Security Measures
RePilot implements the following technical and organisational measures:
- AES-256 encryption for all API tokens and credentials stored at rest
- TLS 1.3 for all data in transit
- Role-based access control limiting data access to authorised personnel only
- Regular security reviews and dependency audits
- Automated monitoring and alerting for anomalous access patterns
- Secure secret management via Google Cloud Secret Manager
10. Data Breach Notification
In the event of a personal data breach, RePilot will notify the Controller without undue delay and, where feasible, within 72 hours of becoming aware of the breach.
Notification will include: the nature of the breach, categories of data affected, approximate number of data subjects affected, likely consequences, and measures taken or proposed to address the breach.
To report a security incident: security@repilot.in
11. Governing Law
This DPA is governed by the laws of India, without prejudice to the data protection rights of EU data subjects under the GDPR. Any disputes shall be subject to the jurisdiction of courts in India.
12. Contact
For DPA-related enquiries or to request a signed copy of this agreement:
privacy@repilot.in
RePilot Technologies Pvt. Ltd., India