Legal

Data Processing Agreement

Last updated: September 30, 2026

SDR Pilot (sdrpilot.ai) is an AI SDR from $97 a month that runs on your own LinkedIn account. This Data Processing Agreement sets out how SDR Pilot processes your leads and conversations for you, as your processor under Article 28 of the GDPR.

On this page
01

Parties and scope

You are the controller of your lead data, and SDR Pilot is your processor.

This Data Processing Agreement (DPA) is between you, the customer, as controller, and SDR Pilot (KvK 70562431, VAT NL002399377B14, The Hague, the Netherlands) as processor. It forms part of the Terms of Service at /terms/ and applies whenever SDR Pilot processes personal data on your behalf. If this DPA and the Terms conflict on data protection, this DPA wins.

You accept this DPA by accepting the Terms. No separate signature is needed. Email [email protected] for a countersigned copy.

02

What SDR Pilot commits to

The processor duties from Article 28(3) of the GDPR, in plain terms.

  • Instructions: SDR Pilot processes personal data only on your documented instructions, which are the Terms, this DPA and how you configure your workspace. If an instruction appears to break data protection law, we tell you.
  • Confidentiality: everyone who can access the personal data is bound to confidentiality.
  • Security: SDR Pilot applies the technical and organisational measures in Annex II and keeps them up to date.
  • Records: SDR Pilot keeps a record of the processing it carries out for you.
03

Sub-processors

A general authorisation, with 14 days notice and a right to object.

You authorise SDR Pilot to use the sub-processors listed in Annex III. SDR Pilot binds each of them to data protection obligations at least as strict as these, and stays responsible to you for their work. Before a new sub-processor processes customer data, SDR Pilot emails you at least 14 days in advance. You may object by email to [email protected]. If we cannot resolve the objection, you may terminate the affected service without penalty.

04

Assistance to you

Help with data subject requests, DPIAs and audits.

  • Data subject requests: SDR Pilot helps you answer requests for access, rectification, erasure and the other GDPR rights, and forwards any request it receives directly.
  • DPIAs and prior consultation: SDR Pilot gives you the information you reasonably need for a data protection impact assessment.
  • Audits: SDR Pilot makes available, on request, the information needed to show it meets these obligations. Email [email protected].
05

Personal data breaches

SDR Pilot tells you without undue delay.

If SDR Pilot becomes aware of a personal data breach affecting your data, it notifies you without undue delay, with what it knows about the nature of the breach, the data and people affected, the likely consequences and the measures taken. It then helps you meet your own notification duties.

06

At the end of the service

Your data is deleted, or returned first if you ask.

When you delete your account, SDR Pilot deletes the personal data it processes for you within 30 days, unless the law requires it to keep some of it. If you want a copy first, ask before deleting the account and SDR Pilot returns the data to you.

07

Annex I. Details of the processing

ItemDetails
Subject matterProviding SDR Pilot, the AI SDR that runs outreach on the customer's own LinkedIn account
DurationFor the life of the customer's account, then deleted within 30 days of account deletion
Nature and purposeStoring, analysing and scoring lead profiles, writing and sending messages, and managing conversations on LinkedIn on the customer's behalf
Data categoriesLead profile data, conversation content, LinkedIn session data
Data subjectsThe customer's leads and contacts, and the customer's users
08

Annex II. Security measures

  • LinkedIn sessions are encrypted at rest.
  • All data in transit is protected with TLS.
  • Access control with least privilege: only the people and systems that need access have it.
  • Hosting in the EU, in Germany.
  • Backups are encrypted.
  • Each sender uses one dedicated IP address, never shared with another customer.
09

Annex III. Sub-processors

The current list lives on its own page and is kept up to date.

The authorised sub-processors, with their country, purpose and the data they handle, are listed at /subprocessors/. That list is Annex III of this DPA.