Data Processing Addendum
Effective July 29, 2026 · last updated July 29, 2026
This Addendum governs our processing of personal data on a customer's behalf. It follows the order of Article 28(3) of the GDPR and closes with the three annexes a reviewer expects (processing particulars, technical measures, and the subprocessor list) so that it can be assessed without a follow-up email. It is not yet an executed instrument; see the note above.
Scope and roles
This Addendum forms part of the Terms of Service between Digital Envision LLC (“DMC Pilot”, “Processor”) and the customer organization (“Customer”, “Controller”). It applies to all processing of personal data contained in Customer Data.
The Customer is the controller of personal data about its corporate clients, event attendees and delegates, vendor contacts and its own staff. DMC Pilot is the processor of that data. Where DMC Pilot processes personal data for its own purposes (account administration, billing, security and product improvement that does not use Customer Data) it acts as a controller and its Privacy Policy governs.
Where the Customer is itself a processor for a corporate client, the Customer's obligations here apply as if it were the controller, and it confirms it has the authority to instruct us on that data.
“Data Protection Law” means the EU GDPR, the UK GDPR and the UK Data Protection Act 2018, the Swiss FADP, the CCPA as amended by the CPRA, and any other privacy law applicable to the processing. For the CCPA, DMC Pilot is a service provider: it does not sell or share personal information, does not retain or use it outside the direct business purpose of providing the platform, and does not combine it with data from other sources except as permitted for a service provider.
Processing on instructions
We will process personal data only on the Customer's documented instructions, which consist of the Terms, this Addendum, the Customer's configuration of the platform, and any further written instruction the parties agree. We will not process it for any other purpose, and in particular will not use it to train artificial intelligence models, to build profiles, or for our own marketing.
We will inform the Customer if, in our opinion, an instruction infringes Data Protection Law, and may suspend the affected processing until the instruction is amended or confirmed.
If we are legally compelled to disclose personal data, we will notify the Customer before disclosing where we are lawfully permitted to do so, disclose only what is legally required, and challenge a request that appears overbroad or unlawful.
Confidentiality and personnel
Access to personal data is limited to personnel who need it to deliver or support the platform, is granted on a least-privilege basis, and is withdrawn when no longer needed or on the person leaving. Personnel are bound by written confidentiality obligations that survive their engagement, and receive guidance appropriate to the sensitivity of the data they can reach.
Where a member of our staff accesses a customer organization's data for support purposes, that access is recorded in an administrative audit log that cannot be removed by deleting the account that performed it.
Security measures
We implement and maintain the technical and organizational measures set out in Annex II, having regard to the state of the art, the cost of implementation, and the nature, scope and purposes of the processing, as well as the risk to the people concerned. We will not materially reduce the security of the platform during the term.
Annex II states what is in place and, where a control is not yet in place, says so. A security annex that lists aspirations alongside facts is not usable by a reviewer, so the two are separated.
Subprocessors
The Customer gives general written authorization for the engagement of subprocessors. Those engaged at the date of this Addendum are listed in Annex III and maintained at /subprocessors.
We will impose on each subprocessor data protection obligations no less protective than those in this Addendum, and remain fully liable to the Customer for a subprocessor's performance.
Before adding or replacing a subprocessor we will give the Customer at least 30 days' notice, by email to the administrative contact and by updating the published register. The Customer may object on reasonable data protection grounds within that period. If we cannot accommodate the objection, the Customer may terminate the affected subscription without penalty and receive a pro-rata refund of prepaid fees. We may replace a subprocessor on shorter notice where necessary to preserve security or continuity, and will tell the Customer as soon as practicable.
Data subject requests
The platform lets the Customer answer most requests itself, without contacting us: access, export, correction and erasure are available in the product, and export produces a complete machine-readable copy.
Where a request cannot be satisfied through the product, we will assist the Customer at no charge, within a timeframe that allows the Customer to meet its own statutory deadline. If a data subject contacts us directly about Customer Data, we will not respond to the substance. We will tell them to contact the Customer, and notify the Customer promptly.
Personal data breach
We will notify the Customer without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting Customer Data, so that the Customer can meet its own 72-hour obligation with time to spare.
The notification will include, so far as known at the time:
- the nature of the breach, including the categories and approximate number of data subjects and records affected;
- the likely consequences;
- the measures taken or proposed to address it and to mitigate its effects; and
- a contact point for further information.
We will provide further information as the investigation develops rather than withholding an initial notification until everything is known, will cooperate with the Customer's own notification obligations, and will not notify a supervisory authority or data subject about the Customer's data without first consulting the Customer, except where we are independently required to.
Impact assessments and prior consultation
We will provide reasonable assistance with a data protection impact assessment or prior consultation with a supervisory authority relating to the platform, including information about our processing, our security measures and our subprocessors.
In practice this is already written rather than promised. We hold a completed impact assessment covering the platform's special-category and staff-location processing, scored before and after each control, and it closes with a template the Customer's own data protection officer completes for their deployment, the half of the assessment only they can write. We also hold a transfer impact assessment covering every subprocessor against US surveillance law. Both are available to a Customer or a prospective Customer under a confidentiality agreement, because they name residual risks and our own weak points with more candor than is wise to publish to the open web.
Two areas commonly require a DPIA and the Customer should expect to conduct one: dietary requirements and allergies, which are special category data processed at scale; and staff time tracking, which records location at check-in and is monitoring of workers. Both are features the Customer chooses to enable, and the assessment is the Customer's to make as controller.
Return and deletion
On termination we retain Customer Data for 60 days so that the Customer can export it, and will provide a complete copy on request during that window at no charge. After that period we delete it from live systems.
Backups are immutable for their retention period, so a copy may persist in a backup after deletion from live systems, and expires with that backup. Backups are used only to restore the service and are never queried to answer a request about a person. We will certify deletion in writing on request, and will retain data for longer where the Customer instructs us in writing or the law requires it.
Within the term, retention is enforced by the platform according to the schedule in Annex I, which the Customer configures.
Audits and information
We will make available the information necessary to demonstrate compliance with this Addendum, and will respond to a reasonable security questionnaire once in any twelve-month period at no charge.
We hold no third-party audit report today (no SOC 2, no ISO 27001 certificate) and our Trust page states that position plainly rather than deferring it to diligence. Until such a report exists, the Customer may audit our compliance itself, or through an independent auditor bound by confidentiality, on 30 days' notice, no more than once a year unless a breach or a regulator requires otherwise, during business hours and in a manner that does not compromise the security of other customers' data. Where we later obtain an audit report, providing it satisfies this obligation.
International transfers
The platform operates in the United States and its subprocessors are predominantly US-based, so personal data of people in the EEA, the UK and Switzerland is transferred out of those territories. Annex III states each subprocessor's location.
Where such a transfer requires an Article 46 safeguard, the parties intend to rely on the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor), with the UK International Data Transfer Addendum for UK transfers and the Swiss addendum where the FADP applies, and with this Addendum's annexes serving as the Clauses' Annexes I, II and III. Docking is permitted.
Stated plainly: those Clauses are not yet executed. The transfer impact assessment supporting them is complete. It assesses each subprocessor against FISA 702, EO 12333 and the CLOUD Act, and concludes that transfers may proceed on Module Two with the measures in Annex II, with no residual risk assessed as high. The technical measures are in place; the annexes are published above; what remains is signature at onboarding.
Two findings from that assessment we would rather state here than have a Customer discover later. Dietary and allergy data is materially protected against compelled disclosure at the storage layer, because it is encrypted under a key the database and file storage providers do not hold, and because model requests that could carry it are confined to zero-retention endpoints. The broader attendee dataset is not: names, contacts and travel details are plaintext to a compelled infrastructure provider, and no supplementary measure available to us reduces that further without breaking the product. Residual risk there is assessed as medium. A Customer for whom that is unacceptable, or who is under a regulator's instruction requiring EU residency, cannot be accommodated today.
Special category data
The platform stores dietary requirements and allergies, which are data concerning health under Article 9. The Customer, as controller, is responsible for identifying a condition under Article 9(2), in practice usually explicit consent obtained from the attendee at registration, and for giving the corresponding notice.
Our commitments for this category, beyond the general measures:
- encrypted at rest under a dedicated application key, on every write path;
- the shortest default retention of any class, 60 days after a program ends, capped at one year;
- excluded from the context routinely supplied to AI features, and reachable only through a purpose-scoped attendee lookup;
- each such access recorded in the activity log;
- where a model request could carry it, routed only to zero-data-retention endpoints, failing rather than falling back to an endpoint that retains.
Liability
Each party's liability under this Addendum is subject to the limitations and exclusions in the Terms of Service. Nothing in this Addendum limits a data subject's rights under Data Protection Law, or either party's liability to a supervisory authority.
Term
This Addendum takes effect with the Terms and continues until we have ceased all processing of Customer Data. Provisions that by their nature should survive, do.
Annex I, Processing details
Parties. Controller: the Customer organization named on the Order. Processor: Digital Envision LLC, 16192 Coastal Highway, Lewes, DE 19958, United States of America. Contact for data protection matters: privacy@dmcpilot.com.
Subject matter and duration. Provision of the DMC Pilot platform for the duration of the subscription, plus the 60-day post-termination export window.
Nature and purpose. Hosting, storage, transmission, backup, indexing, display and processing of Customer Data so that the Customer can plan and operate events: sales and proposals, program operations, flight and ground transport, vendor management, staffing, client and guest portals, and AI-assisted analysis and drafting.
Categories of data subject. The Customer's employees and contractors; its corporate client contacts; event attendees and delegates; vendor and supplier contacts; drivers, photographers and other on-site service providers; and guests receiving advisories.
Categories of personal data. Identification and contact details; employer, role and permissions; travel details including flight information and passport-adjacent data; dietary requirements and allergies; signed waivers and consent records; e-signature evidence including IP address and device; staff check-in location, address, IP and user agent; message and document content; authentication and audit records.
Special categories. Data concerning health, in the form of dietary requirements and allergies. Restrictions as set out in §12.
Frequency. Continuous, for the duration of the subscription.
Retention. As configured by the Customer within the bounds the platform enforces:
| Class | Default | Permitted range |
|---|---|---|
| Dietary requirements and allergies | 60 days after the program ends | 7 days to 1 year |
| Attendee records | 1 year after the program ends | 30 days to 3 years |
| Staff check-in location and device data | 90 days | 7 days to 1 year |
| Notifications | 90 days | 7 days to 1 year |
| Assistant conversations and memories | 180 days | 30 days to 2 years |
| Soft-deleted records | 30 days | 7 days to 1 year |
| Activity and audit logs | 1 year | 90 days to 7 years |
Enforcement is enabled per organization. Until the Customer enables it, the schedule runs in reporting mode: it identifies what is due for deletion without deleting it.
Annex II, Technical and organizational measures
In place.
- Tenancy isolation. Enforced by row-level security in Postgres, so every record is scoped to one organization at the database layer and the boundary cannot be bypassed by application code.
- Authorization. Every server action performs its own permission check and is treated as a public endpoint; interface-level gating is explicitly not the security boundary. Permissions span fourteen product areas with view, create, edit and delete rights, plus scoped powers for billing, cross-program access and external sharing. Program access is membership-scoped, and a non-member receives a not-found response rather than a denial.
- Encryption. TLS in transit. Encryption at rest at the platform layer. Additional AES-256-GCM field-level encryption, under a separate application-managed key, for sensitive personal data including dietary requirements, allergies and passport-adjacent details. Key rotation is supported with retired keys retained for decryption.
- Authentication. Invitation-only account creation with single-use hashed invitation tokens. Time-based one-time-password two-factor authentication available to every user. SAML single sign-on with optional organization-wide enforcement on the Enterprise plan.
- External access without credentials. Vendors, clients, drivers and guests reach scoped, revocable token links rather than accounts, so no standing credentials exist for them.
- Logging. Activity logs across every product area recording actor, action and time, with AI-originated changes labeled. Administrative access to a customer organization is separately logged. The audit trail survives account erasure: the actor is replaced with an irreversible keyed pseudonym rather than the record being deleted. Access to health data is logged as a distinct event.
- Rate limiting on authentication and public endpoints, backed by a distributed store.
- Backups. Automated daily backups of the database with seven days' retention, taken and restorable by the database platform. Verified as completing.
- Monitoring. Application errors alert the engineering team directly. Payloads are scrubbed before leaving the application: identity fields, credentials, cookies, authorization headers, query strings and sensitive keys including dietary and allergy fields are redacted.
- Secure development. All changes are version-controlled and reviewed, environments are separated, dependencies are scanned and patched, and infrastructure is fully managed. There are no self-administered servers and no inbound network surface to maintain.
- Data minimization by design. Client-facing surfaces exclude cost and margin structurally rather than by permission, and guest advisories carry no internal detail.
Not yet in place. Stated so that a reviewer is not left to infer it.
- An independent off-site backup held outside the database provider's own account. The mechanism is written and configured for 35-day immutable object-lock storage, but it is not yet operating, so today the only backups are those the database platform holds.
- Point-in-time recovery. Restores are to a daily snapshot.
- An independent penetration test.
- A third-party audit report or certification. See Trust.
- A published uptime service level agreement.
- Formal, evidenced policy set of the kind SOC 2 or ISO 27001 requires.
Annex III, Subprocessors
Compiled from the source code rather than from recollection. The current version is maintained at /subprocessors, which is where changes are announced under §5.
Infrastructure
| Subprocessor | Processing | Location | Health data |
|---|---|---|---|
| Supabase | Primary database, authentication and object storage | United States (us-east-2) | Yes |
| Vercel | Application hosting, serverless execution and scheduled jobs | United States, with a global edge network | Only if present |
| Cloudflare R2 | File and document storage, photo albums, database backup target | Automatic region selection | Yes |
| Upstash | Distributed rate limiting | United States | No |
| Sentry | Application error monitoring and session replay | United States | Only if present |
Communications and payments
| Subprocessor | Processing | Location | Health data |
|---|---|---|---|
| Resend | Transactional email, invitations, proposals, digests, alerts | United States | No |
| Expo (EAS Push) | Mobile push notification relay for the DMC Pilot iOS and Android app | United States | No |
| Stripe | Subscription billing, add-ons and usage charges | United States | No |
| Cal.com | Demonstration booking on the public website only | United States | No |
Artificial intelligence
| Subprocessor | Processing | Location | Health data |
|---|---|---|---|
| OpenRouter | Model gateway, the single route by which any model is called | United States | Yes |
| Google (Gemini), via OpenRouter | Assistant answers, document and manifest analysis, safety guards | United States | Only if present |
| OpenAI, via OpenRouter | Fallback for assistant answers and guards | United States | Only if present |
| Perplexity, via OpenRouter | Client and destination research requiring web search | United States | No |
Operational data sources
| Subprocessor | Processing | Location | Health data |
|---|---|---|---|
| AviationStack / FlightAware | Flight status tracking | United States | No |
| Mapbox | Geocoding, maps and place search | United States | No |
Questions about this document: legal@dmcpilot.com. Privacy requests: privacy@dmcpilot.com. Security reports: security@dmcpilot.com.