Legal
Note: This is a standard template provided for convenience. It is not legal advice. Have it reviewed by qualified counsel before you rely on it in a specific engagement, and complete the bracketed items in the signature block if a countersigned copy is required.
Capitalized terms not defined here have the meaning given in the Agreement. "Personal Data," "Controller," "Processor," "Sub-processor," "Data Subject," "Processing," and "Personal-Data Breach" have the meanings given under applicable data-protection law, including the EU/UK GDPR, the California Consumer Privacy Act as amended (CCPA/CPRA), Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and Quebec's Law 25 (together, "Data-Protection Laws"). "Customer Personal Data" means Personal Data that we Process on your behalf under the Agreement.
For Customer Personal Data — the contact details and messages that your website visitors and prospective customers submit through lead and booking forms — you are the Controller and we are the Processor. You determine the purposes and means of Processing; we Process only to provide the service.
For Personal Data relating to your own account (your name, email, and billing information), we act as an independent Controller, as described in our Privacy Policy; that Processing is outside the scope of this DPA.
This DPA applies to the extent we Process Customer Personal Data subject to Data-Protection Laws.
The details required by Article 28(3) GDPR (and equivalents) are set out in Annex A. In summary: we Process Customer Personal Data to host your generated website, receive and deliver leads and bookings to you, send the confirmation and review-request emails you enable, and provide related support. Processing continues for the term of the Agreement and the limited period afterward described in Section 11.
We will Process Customer Personal Data only on your documented instructions, including as set out in the Agreement and this DPA and as necessary to provide and secure the service, unless required to do otherwise by law (in which case we will inform you first, unless the law prohibits it). Your use and configuration of the service constitute your instructions. We will inform you if, in our opinion, an instruction infringes Data-Protection Laws.
We will not sell Customer Personal Data, nor retain, use, or disclose it for any purpose other than providing the service, nor for our own commercial purposes, and we make the same commitments a "service provider" makes under the CCPA/CPRA.
You provide general authorization for us to engage the Sub-processors listed in Annex C to Process Customer Personal Data. We impose data-protection obligations on each Sub-processor that are no less protective than those in this DPA, and we remain responsible for their performance.
We will give you reasonable prior notice (by email or by updating Annex C) before adding or replacing a Sub-processor. If you have a reasonable, data-protection-based objection, you may raise it within ten (10) days; if we cannot reasonably address it, you may terminate the affected service as your exclusive remedy.
We maintain the technical and organizational measures set out in Annex B, designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, and unauthorized disclosure or access. We may update these measures over time provided the level of protection is not materially reduced.
Taking into account the nature of the Processing, we provide tools that let you access, correct, export, and delete Customer Personal Data yourself (through your dashboard and the account-deletion feature). Where a Data Subject contacts us directly regarding data we Process on your behalf, we will refer them to you and assist you in responding, as reasonably required and at your expense where the law permits.
We will notify you without undue delay, and where feasible within seventy-two (72) hours, after becoming aware of a Personal-Data Breach affecting Customer Personal Data. The notice will describe, to the extent known, the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed. We will reasonably cooperate with you in investigating and mitigating the breach.
Our primary database and file storage are hosted in Canada (via Supabase). Certain Sub-processors (see Annex C) Process Customer Personal Data in the United States or other countries. To the extent a transfer of Customer Personal Data is subject to cross-border transfer requirements under Data-Protection Laws, the parties agree to rely on an appropriate transfer mechanism — including, where applicable, the European Commission's Standard Contractual Clauses (and the UK Addendum), which are incorporated by reference and completed using the information in the Annexes — or another lawful mechanism.
You may delete Customer Personal Data at any time using the service (deleting a site removes its leads and bookings; deleting your account cascades to all associated sites, leads, and bookings). On termination or expiry of the Agreement, we will delete Customer Personal Data within thirty (30) days, except to the extent retention is required by law, in which case we continue to protect it and Process it only as required for that purpose.
We will make available information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior written notice and no more than once per year (unless required by a supervisory authority or following a Personal-Data Breach), allow for and contribute to audits conducted by you or an independent auditor bound by confidentiality. Audits must be conducted during business hours, without unreasonably disrupting our operations, and at your expense.
Each party's liability arising out of or related to this DPA is subject to the exclusions and limitations of liability set out in the Agreement, and any reference in the Agreement to a party's liability means the aggregate liability of that party under the Agreement and this DPA combined.
This DPA is governed by the same law as the Agreement — the laws of the State of Delaware, USA — except where Data-Protection Laws require otherwise. This DPA takes effect when you accept the Agreement and remains in effect for as long as we Process Customer Personal Data on your behalf.
Ossotan Consulting — LocalPilot AI
Data-protection contact: ossotan.consulting@gmail.com
Website: localpilot.pro
| Subject matter | Provision of the LocalPilot AI website, lead, and booking service. |
|---|---|
| Duration | The term of the Agreement plus the deletion period in Section 11. |
| Nature & purpose | Hosting the Customer's generated website; receiving, storing, and delivering leads and bookings; sending Customer-enabled confirmation and review-request emails; providing support. |
| Categories of Data Subjects | The Customer's prospective and actual customers (the visitors who submit forms on the Customer's generated site). |
| Categories of Personal Data | Name, phone number, email address, service requested, appointment details, and any message content the Data Subject submits; technical data such as IP address associated with the submission. |
| Special categories | None requested or required. The Customer must not submit special-category data through the service. |
| Sub-processor | Function | Processes end-customer data? | Location |
|---|---|---|---|
| Supabase | Database & file storage | Yes (stores leads & bookings) | Canada |
| Netlify | Hosting, functions, CDN | Yes (serves forms; processes IP/log data) | United States |
| Resend | Email delivery | Yes (sends confirmation/review emails) | United States |
| Anthropic | AI content generation | No (business info only, not end-customer contacts) | United States |
| Stripe | Payment processing | No (Customer billing only) | United States |
| Google (Places API) | Review-link lookup | No | United States |
| Pexels | Stock photos | No | United States |
This list may be updated per Section 6. The current version is always available at localpilot.pro/dpa.html.
Acceptance of the Agreement constitutes acceptance of this DPA; a signature is not required. Where a countersigned copy is needed, complete the block below.
Customer (Controller)
Ossotan Consulting (Processor)