1. Scope
This Data Processing Agreement (“DPA”) forms part of the GrowthPilot Terms of Service between THYNKR SYSTEMS LTD, company number 15306717, registered office Office 2, 1st Floor, 73 Station Passage, London E18 1JL (“Processor”, “THYNKR”), and the customer (“Controller”, “Customer”). It applies where THYNKR processes personal data in Customer Data on the Customer’s behalf.
It applies to processing subject to the UK GDPR and the Data Protection Act 2018 and, where applicable, the EU GDPR (“Data Protection Law”). It takes effect when the Customer accepts the Terms, without a separate signature.
2. Roles
The Customer is the controller of personal data in its workspace. THYNKR is its processor and processes that data only to provide GrowthPilot.
THYNKR is a separate controller for account, security, billing and support data, as described in the Privacy Policy.
3. Details of processing
| Item | Details |
|---|---|
| Subject matter | Provision of GrowthPilot: hosting, analysis, AI features, content workflows, governed execution, client reporting and agency invoicing |
| Duration | The term of the Customer’s use of GrowthPilot and the retention period afterwards described in “Deletion and return” |
| Nature and purpose | Storage, retrieval, organisation, analysis, AI processing, transmission (including transactional email), display, backup and deletion, as needed to provide the features the Customer uses |
| Data subjects | The Customer’s clients and their contacts; invoice recipients; people named in brand profiles, content, notes or competitor research; and individuals whose details appear in connected marketing data |
| Personal data | Names, business contact details, invoice and payment-record details, invoice-email delivery and engagement events, text the Customer enters, and personal data that may appear in connected data such as search queries |
| Special-category data | Not expected. The Customer must not upload special-category or criminal-offence data |
4. Instructions
THYNKR processes Customer personal data only on the Customer’s documented instructions, which consist of the Terms, this DPA and the Customer’s use and configuration of GrowthPilot, unless law requires otherwise. In that case THYNKR will inform the Customer first unless the law prohibits it. THYNKR will tell the Customer if it believes an instruction infringes Data Protection Law.
5. Confidentiality
THYNKR ensures that people authorised to process Customer personal data are bound by confidentiality.
6. Security
THYNKR maintains appropriate technical and organisational measures under Article 32, including:
- encryption in transit (HTTPS) for all GrowthPilot domains;
- two-step sign-in for every account, with optional authenticator apps and single-use backup codes;
- role-based access and organisation, client and project isolation checked on every request;
- encryption of connected-account access and refresh tokens at rest (AES-256-GCM);
- human approval of the exact version before governed execution, with signed handoffs, bounded retries, receipts and audit records;
- audit logging of security and administrative events;
- nightly encrypted (age) database backups stored off-site in private Cloudflare R2 storage in the EU jurisdiction, with a deletion lock and tested restores;
- separation of the application, AI and execution services, each with its own credentials; and
- rate limiting and abuse protection on public endpoints.
THYNKR does not currently hold a formal certification such as SOC 2 or ISO 27001. Measures may evolve, but THYNKR will not materially reduce the overall level of protection.
7. Subprocessors
The Customer authorises THYNKR to engage the subprocessors below. THYNKR imposes data-protection obligations on each subprocessor consistent with Article 28 and remains responsible for their performance.
| Provider | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| IONOS SE | Hosting of the GrowthPilot application, API, database, background workers and public website | Germany (EU) | UK adequacy regulation for the EEA |
| Fasthosts Internet Limited | Hosting of the GrowthPilot AI service and the governed-execution gateway (n8n) | United Kingdom | Not a restricted transfer |
| Cloudflare, Inc. | Network delivery, DNS and security for GrowthPilot domains; storage of encrypted database backups (R2, EU jurisdiction) | Global network; backups stored in the EU | Provider data processing terms with the UK International Data Transfer Addendum and standard contractual clauses |
| OpenAI, L.L.C. | AI model processing for analysis, research and content features | United States | Provider data processing terms with the UK International Data Transfer Addendum and standard contractual clauses |
| Mailgun Technologies, Inc. | Transactional email (sign-in codes, invitations, account security, invoice emails, team notifications) and delivery and engagement events | United States | Provider data processing terms with the UK International Data Transfer Addendum and standard contractual clauses |
| Stripe Payments Europe, Ltd. and Stripe, Inc. | GrowthPilot subscription billing | Ireland and United States | Provider data processing terms with the UK International Data Transfer Addendum and standard contractual clauses |
| Google LLC (Google Workspace) | Mailbox for info@thynkrsystems.com, which receives support email and requests to join | United States and other countries | Provider data processing terms with the UK International Data Transfer Addendum and standard contractual clauses |
THYNKR will give at least 14 days’ notice of a new subprocessor by email or in the Service. The Customer may object on reasonable data-protection grounds within that period. If the parties cannot resolve the objection, the Customer may cancel the affected subscription and receive a refund of prepaid fees for the unused period.
8. Data subject requests
THYNKR will give reasonable assistance to help the Customer respond to data subject requests. If THYNKR receives a request about Customer personal data, it will refer the person to the Customer unless the law requires otherwise.
9. Assistance with compliance
Taking into account the nature of the processing, THYNKR will give reasonable assistance with security, breach notification, data-protection impact assessments and prior consultation under Articles 32 to 36.
10. Personal data breaches
THYNKR will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer personal data. The notice will describe, as far as known, the nature of the breach, the data and people affected, likely consequences, and measures taken or proposed, and will name a contact point. Information may be provided in phases. Notice is not an admission of fault.
11. Deletion and return
During use, the Customer can delete records in GrowthPilot and can ask THYNKR to export its workspace data. On termination, or earlier on request, THYNKR will delete Customer personal data from the live system within 30 days of a verified request, unless the law requires retention. Copies in encrypted backups expire on the backup schedule: daily backups after 35 days and monthly backups after 400 days. Until then they stay encrypted and protected and are not used except to restore the Service.
12. Audits and information
THYNKR will make available information reasonably necessary to demonstrate compliance with Article 28, normally by written answers and security documentation. Where an audit is required by law or reasonably needed after a breach, it must be on at least 30 days’ notice (unless a regulator requires less), during business hours, by an independent auditor bound by confidentiality, at most once a year, and at the Customer’s cost unless it finds a material breach by THYNKR.
13. International transfers
THYNKR will make restricted transfers of Customer personal data only under a lawful transfer mechanism. The current subprocessors and the safeguard used for each are listed above. Where required, the UK International Data Transfer Addendum and standard contractual clauses are incorporated by reference.
14. Government requests
Unless prohibited by law, THYNKR will direct a government request for Customer personal data to the Customer and, where it must respond directly, disclose only what is legally required.
15. Customer obligations
The Customer confirms that it has a lawful basis for the personal data it puts into or connects to GrowthPilot; that it gives required privacy information, including to its clients and to invoice recipients whose email delivery and engagement events GrowthPilot records; that it is authorised to connect each third-party account; and that its instructions comply with Data Protection Law.
16. Liability and priority
Liability under this DPA is subject to the Terms, except where Data Protection Law prohibits limitation. If this DPA conflicts with the Terms on processing of Customer personal data, this DPA prevails.
17. Contact
THYNKR SYSTEMS LTD, Office 2, 1st Floor, 73 Station Passage, London E18 1JL, United Kingdom. Email: info@thynkrsystems.com.