Legal

Data Processing Agreement

Version 1.0 · Last updated: 7 May 2026

This Data Processing Agreement (“DPA”) is entered into between:

  • ARPD Ltd trading as Coach Pilot (“Processor”, “we”, “us”); and
  • the customer organisation that creates or is provisioned a workspace on the Coach Pilot platform (“Controller”, “you”).

This DPA forms part of, and is governed by, the Coach Pilot terms of service accepted by the Controller. If there is any conflict between this DPA and those terms in relation to the processing of personal data, this DPA prevails.

1. Roles

The Controller determines the purposes and means of the processing of personal data in connection with its use of the Coach Pilot platform. The Processor processes personal data only on the Controller’s documented instructions and only to the extent necessary to provide the service.

2. Subject matter and purpose

The Processor provides AI-assisted leadership and recruitment coaching software. The Processor will process personal data only as necessary to provide, secure, support and administer the service for the Controller during the subscription term, and in accordance with the Controller’s documented instructions.

3. Categories of data subjects and personal data

Data subjects may include the Controller’s authorised users, such as managers, owners and administrators, and third parties referenced by those users in coaching content, such as direct reports, candidates or colleagues.

Personal data may include account details, user roles, tenant membership details, coaching session content, summaries, follow-up notes, uploaded content, audit-log metadata, billing identifiers, and technical data such as IP addresses and user-agent strings used for security and service administration.

4. Controller instructions

The Processor will process personal data only on the Controller’s documented instructions, which consist of:

  • this DPA;
  • the Controller’s configuration and use of the platform, including settings for retention, sensitive data handling and integrations; and
  • any further written instructions agreed by the parties.

If the Processor considers that an instruction infringes applicable data protection law, the Processor will inform the Controller without undue delay.

5. Confidentiality

The Processor will ensure that persons authorised to process personal data are subject to confidentiality obligations and receive appropriate data protection and security training.

6. Security

The Processor will implement appropriate technical and organisational measures to protect personal data, taking into account the nature of the processing and the risks to data subjects. These measures include:

  • TLS 1.2 or higher for data in transit.
  • Encryption at rest for relevant content and notes.
  • Password hashing using bcrypt or equivalent.
  • Tenant isolation measures, including row-level security and application-level access controls.
  • Role-based access control and secure session management.
  • CSRF protection, security headers and rate limiting.
  • Signed and verified webhooks where applicable.
  • Audit logging of sensitive administrative actions.
  • Limits on document size and parsing complexity to reduce security and reliability risks.

7. Sub-processors

The Controller authorises the Processor to engage sub-processors to provide the service, including:

  • Replit for hosting, compute and managed database services.
  • Anthropic for model inference.
  • Stripe for payment processing and billing.
  • Resend for transactional email delivery.
  • Slack Technologies for Slack integration, where enabled by the Controller.

The Processor will ensure that each sub-processor is bound by written terms imposing data protection obligations equivalent to those in this DPA. The Processor remains responsible to the Controller for the performance of each sub-processor’s obligations. The Processor will give the Controller prior notice of any intended addition or replacement of a sub-processor and will allow the Controller to object on reasonable data protection grounds.

8. International transfers

Where personal data is transferred outside the UK or EEA, the Processor will use an appropriate lawful transfer mechanism, such as the UK IDTA, the UK Addendum to the EU Standard Contractual Clauses, or another legally recognised transfer safeguard, together with supplementary measures where appropriate.

9. Assistance

Taking into account the nature of the processing, the Processor will assist the Controller, by appropriate technical and organisational measures, in responding to data subject requests and in complying with its obligations under data protection law relating to security, breach notification, DPIAs and prior consultation.

10. Breach notification

The Processor will notify the Controller without undue delay, and in any event within 72 hours of becoming aware, of a personal data breach affecting Controller personal data. The notice will include, where known, the nature of the breach, the affected data and data subjects, likely consequences and the measures taken or proposed to address it.

11. Audit and information

The Processor will make available to the Controller, on reasonable written request and no more than once in any 12-month period unless required sooner by law or a supervisory authority, the information necessary to demonstrate compliance with this DPA. This may include this DPA, security documentation, audit summaries and relevant compliance evidence. The Processor will allow for and contribute to audits and inspections to the extent required by Article 28.

12. Retention, return and deletion

Personal data will be retained only for as long as necessary for the provision of the service, the Controller’s configured retention settings, legal obligations and legitimate security needs.

On termination of the subscription, the Processor will delete or return personal data in accordance with the Controller’s instructions, subject to any legal retention requirement. Any backup or residual copies will be deleted in accordance with the Processor’s standard deletion cycle and will be held beyond use until then.

13. Liability and termination

Each party’s liability under this DPA is governed by the limitation of liability provisions in the terms of service, except to the extent that such limitation cannot lawfully apply to liability arising under applicable data protection law. This DPA terminates automatically when the underlying terms of service terminate.

14. Acceptance

Acceptance of this DPA is recorded per workspace by the workspace owner using the relevant acceptance control. The acceptance will be timestamped, version-stamped and recorded in the workspace audit log, and can be produced on request as evidence of acceptance.

15. Contact

For questions about this DPA, including sub-processor changes, transfers or data subject requests, contact support@arpd.co.uk.