1. Scope and roles
This addendum applies whenever a provider is given access to a business customer's data to deliver a service through SupportPilots. In this arrangement the business customer is the data controller: they decide what data exists and why it is processed. SupportPilots facilitates and secures the access on the customer's behalf and acts as their processor. The provider processes personal data only on the customer's documented instructions and never for its own purposes. If a provider is ever asked to act outside those instructions, it must decline and tell SupportPilots.
2. Permission-based access
Access is never automatic. A customer chooses one of four levels for each engagement: none (the provider works from a written brief with no data access at all); selected knowledge base (read access to specific FAQ or help-centre articles the customer picks); redacted conversations (conversation text with personal identifiers removed); or full project (working access to the customer's project workspace). Every grant is made only by the customer, is scoped to the specific order, is time-boxed to the work, and can be revoked at any moment. When a grant is revoked or expires, access ends immediately.
3. Nature and purpose of processing
A provider accesses customer data for one reason only: to perform the agreed service. Typical work includes writing or improving FAQ articles, fixing or refining AI answers, and translating support content. The provider must not use the data for anything beyond the agreed task. There is no secondary use, no analytics on the side, and no repurposing of one customer's data to serve another.
4. Categories of data
The data a provider may touch is limited to what the customer chooses to expose: support knowledge base content, redacted conversation text, and only the personal data the customer deliberately makes available for the task. Providers must not seek out, combine, or enrich additional personal data, and must not attempt to re-identify individuals in redacted material. Special-category data should not be shared with a provider unless the customer has a lawful basis and has instructed it explicitly.
5. Provider obligations
Every provider is bound by confidentiality and processes data only on the customer's instructions. Providers must not bulk download, export, or retain customer data beyond what a task requires. They must apply appropriate technical and organisational security to anything they handle. They must assist the customer in responding to data-subject requests, and they must delete or return the data when the order ends. These duties survive the end of the individual engagement.
6. Security measures
Access happens over authenticated sessions on the SupportPilots platform, never through shared credentials or raw database dumps. Permissions follow least-privilege: a provider sees only the level the customer granted, nothing more. Every grant and every access event is logged for audit. Data is encrypted with TLS in transit and stored on EU-resident infrastructure. These measures reflect the requirements of GDPR Article 32 on security of processing.
7. Sub-processing
SupportPilots relies on a small set of vetted infrastructure and AI inference sub-processors to run the platform, for example Supabase for hosting and database and kie.ai and Anthropic for AI inference. These sub-processors are engaged under written terms and appropriate safeguards. Providers are not sub-processors of the platform; they are authorised persons acting for a specific customer under that customer's own instructions and grant.
8. Data-subject rights
Because the business customer is the controller, they own the relationship with the individuals whose data is processed. SupportPilots and any provider with access will assist the controller in responding to requests for access, deletion, correction, or restriction. Where a request reaches SupportPilots or a provider directly, it is routed to the controller rather than actioned independently.
9. Breach notification
A provider who discovers or suspects a data breach, unauthorised access, or misuse must report it to SupportPilots without undue delay. SupportPilots investigates, contains the issue, and notifies the affected customer promptly so the controller can meet its own notification duties to the ICO and to data subjects where required. Silence or delay in reporting a suspected breach is itself a breach of these terms.
10. Retention and deletion
Provider access ends when the order closes or the grant is revoked, whichever comes first. Providers must not keep copies of customer data once access ends, whether locally, in personal notes, or in any other store. SupportPilots retains audit logs of grants and access events for security and accountability, but these logs record who accessed what and when, not the substance of the customer's confidential content.
11. International transfers
Customer data is stored within the European Union. SupportPilots does not move personal data outside the EEA in the ordinary course of providing the service. Where any transfer outside the EEA becomes necessary, it takes place only under an approved safeguard, such as an adequacy decision or standard contractual clauses, so the protection travelling with the data is not weakened.
12. Supervisory authority and contact
The Information Commissioner's Office (ICO) is the UK supervisory authority for data protection matters relating to this service. Questions about data processing, access grants, or this addendum should go to privacy@supportpilots.com. The controlling legal entity is Telvara Holdings Limited, company number 17175891, registered at 27 Crofton Road, No. 6, 1st Floor, Liverpool, L13 5UJ, United Kingdom.