Last updated June 23, 2026
This is a template, not a signed agreement. It describes the terms on which VOpilot will process personal data on your behalf. It becomes binding only when executed by both parties. If your organization requires a countersigned DPA, email support@vopilot.co. Please have your own counsel review it before relying on it.
This Data Processing Addendum (“DPA”) supplements the VOpilot Terms of Service(the “Agreement”) between the customer (“Customer,” the data controller) and VOpilot (the data processor), and applies to VOpilot's processing of personal data on Customer's behalf.
Customer is the controller of the personal data it submits to VOpilot; VOpilot is the processor and processes that data only to provide the service and on Customer's documented instructions (including as set out in the Agreement and this DPA), unless required by law.
Subject matter & duration: processing for the term of the Agreement plus any retention period described below.
Nature & purpose: hosting, organizing, parsing, and presenting the records Customer creates or forwards (jobs, auditions, invoices, contacts, expenses, residuals, payments), and sending email Customer initiates.
Categories of data subjects: Customer and its clients, agents, end clients, and contacts.
Types of personal data: names, email addresses, phone numbers, postal/billing addresses, business and payment-status details, and the contents of emails Customer forwards.
VOpilot will: (a) process personal data only on Customer's documented instructions; (b) ensure persons authorized to process the data are bound by confidentiality; (c) implement appropriate technical and organizational security measures (see Section 5); (d) assist Customer, taking into account the nature of processing, with data-subject requests and with its own security and breach obligations; and (e) make available information reasonably necessary to demonstrate compliance with this DPA.
Customer authorizes VOpilot to engage the sub-processors listed on our Security page (currently Supabase, Vercel, Cloudflare, Anthropic, Stripe, PayPal, Resend, and Sentry). VOpilot imposes data-protection obligations on each sub-processor substantially similar to those in this DPA and remains responsible for their performance. We will give notice of new sub-processors and a reasonable opportunity to object on legitimate grounds.
VOpilot maintains technical and organizational measures appropriate to the risk, including tenant isolation via database row-level security, encryption in transit and at rest, field-level encryption of particularly sensitive values, restricted and multi-factor-protected production access, and logging of operator access to user data (surfaced to Customer in-app). A current description is published on our Security page.
VOpilot will notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer's data, and will provide information reasonably available to help Customer meet its own notification obligations.
Taking into account the nature of the processing, VOpilot will assist Customer with appropriate measures to respond to requests from data subjects to exercise their rights. Customer can fulfill most such requests directly through the application.
Where personal data is transferred across borders, the parties will rely on a lawful transfer mechanism (such as the applicable Standard Contractual Clauses), which are incorporated by reference where required.
On termination of the Agreement, VOpilot will, at Customer's choice, delete or return Customer's personal data within a reasonable period, except to the extent retention is required by law.
This DPA forms part of the Agreement. In the event of a conflict regarding the processing of personal data, this DPA controls. The liability terms of the Agreement apply to this DPA.
To put this DPA in place for your organization, contact support@vopilot.co. Both parties' authorized signatures are required for it to take effect.