Penguin Pilot — GDPR and UK GDPR Terms
Data Processing Addendum — The Network Software Limited trading as Penguin Pilot
Version 1.0 · Effective 01 October 2026
Read this first
These terms only apply if EU or UK data protection law applies to what you do in the platform. We are a New Zealand company and most of our customers are in New Zealand. For them, clause 10 of the Platform Terms and the Privacy Act 2020 do the work instead, and none of this is relevant.
The short version. You decide why personal data goes into your workspace and what happens to it, so you are the controller. We hold and process it on your instructions, so we are the processor. Article 28 of the GDPR requires a written contract between those two roles, and this is it. Nothing needs signing — these terms apply automatically when they are relevant to you.
We have kept this short on purpose. Where the GDPR already sets out a rule, a deadline or a right, we have not copied it out here. It applies to each of us directly, in whatever form it takes at the time, and restating it would only create a second version to go out of date. This document covers the things Article 28 requires a contract to say, the clauses that make our cross-border transfers lawful, and a small number of commercial points between you and us.
1. When these terms apply
1.1 Scope. These terms apply to our processing of personal data on your behalf where that processing is subject to the EU General Data Protection Regulation or the UK GDPR. We call both of them the GDPR in these terms.
1.2 They form part of our agreement. These terms form part of the Penguin Pilot Terms of Service (the Platform Terms). On the subjects they cover they prevail over the Platform Terms and the Privacy Policy. They apply automatically from the moment the GDPR applies to your processing, without either of us signing anything.
1.3 Words. Words defined in the GDPR — controller, processor, personal data, processing, data subject, personal data breach, special category data, supervisory authority — carry the meanings the GDPR gives them. Customer Personal Data means personal data within Customer Data, as Customer Data is defined in the Platform Terms. Account Data means the personal data we collect directly to run your subscription: names, work email addresses, login records, billing details and support conversations.
1.4 The Privacy Act still applies. Nothing here displaces the Privacy Act 2020, which continues to apply to us as a New Zealand company.
1.5 If you bought through a Partner. Where your workspace was provisioned by a white label Partner, the Partner is your processor and we are a sub-processor. These terms then apply between us and the Partner, and clause 8.6 of the White Label Partner Terms explains the chain.
2. Who is who
In short: you are the controller of what goes into your workspace. We are the processor of it, and the controller of the data we hold to run your account.
2.1 You are the controller of Customer Personal Data. You decide why it is collected, what is done with it and how long it is kept.
2.2 We are the processor of Customer Personal Data. We process it only on your behalf.
2.3 Account Data is different. We are the controller of Account Data and we process it for our own purposes as a business. Part A of our Privacy Policy explains what we do with it. These terms do not apply to it.
2.4 We are not joint controllers with you, and nothing in our arrangement makes us one.
3. What we do as your processor
In short: this clause is the Article 28 list. It is the part the regulation requires to be written down.
3.1 Description of the processing. The subject matter, duration, nature and purpose of the processing, the type of personal data and the categories of data subject are set out in Annex A.
3.2 Our obligations. We will:
(a) process Customer Personal Data only on your documented instructions, including in relation to transfers, unless EU or UK law requires otherwise — and where it does, we will tell you before processing unless that law prohibits us from telling you. Your instructions are the Platform Terms, these terms, and your configuration and use of the platform;
(b) ensure that every person we authorise to process Customer Personal Data is under a binding obligation of confidentiality;
(c) take the security measures required by Article 32, which are described in Annex B;
(d) engage sub-processors only on the basis set out in clause 4;
(e) assist you, by appropriate technical and organisational measures and insofar as this is possible, in responding to requests from data subjects exercising their rights under Chapter III;
(f) assist you in meeting your obligations under Articles 32 to 36 — security, breach notification to the supervisory authority and to data subjects, data protection impact assessments and prior consultation — taking into account the nature of the processing and the information available to us;
(g) at your choice, delete or return Customer Personal Data at the end of the services and delete existing copies, as set out in clause 6; and
(h) make available the information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits, as set out in clause 7.
3.3 If an instruction looks unlawful. If we consider that an instruction from you infringes the GDPR, we will tell you immediately. We may pause the processing concerned while we resolve it with you.
3.4 Breaches and requests, in practice. Where clause 3.2(e) or 3.2(f) is engaged, we will act without undue delay and in time for you to meet the deadlines the GDPR sets for you. We have deliberately not restated those deadlines here; they bind you directly and they are the ones that count.
4. Sub-processors
In short: we use sub-processors, you have agreed to that in general terms, we tell you before the list changes, and you can object.
4.1 General authorisation. You give us general authorisation to engage sub-processors. The current list is at penguinpilot.ai/legal/third-party-services.
4.2 Notice of changes. We will give the notice shown in Annex C before adding or replacing a sub-processor, by updating that page and notifying you by email or in the platform.
4.3 Objecting. You may object within the notice period on reasonable data protection grounds. We will work with you in good faith to find a solution. If we cannot, you may terminate the affected part of your subscription without penalty and we will refund any prepaid fees for the unused period.
4.4 Flow-down and liability. We impose data protection obligations on every sub-processor that are no less protective than these terms, and we remain fully liable to you for their performance.
5. What you do as controller
In short: the lawfulness of what goes into your workspace is yours. We cannot see whether you have a lawful basis, and we do not assume one.
5.1 Lawfulness. You are responsible for having a lawful basis for the personal data you put into the platform and for everything you instruct us to do with it, for giving data subjects the information the GDPR requires, and for ensuring your instructions to us are lawful. You warrant that they are.
5.2 Special category data. The platform is general business software. It is not designed or marketed for processing Article 9 data — health, biometrics, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sex life or sexual orientation — at scale. If you intend to put that kind of data into your workspace, tell us first at support@penguinpilot.ai so we can confirm whether we can support it. Where you use voice cloning, the voice sample is likely to be biometric data, and clause 10.4 of the Platform Terms requires documented consent for it.
5.3 Your own configuration. You are responsible for the roles, permissions and access you set up, for your users’ credentials, and for the third-party services you connect.
6. At the end
In short: you get an export window, then we delete. The Platform Terms already set the timings and we have not duplicated them.
6.1 Export and deletion. Annex C sets out the export window and the deletion that follows it, and clauses 21.8 and 21.9 of the Platform Terms say the same. You may choose return instead of deletion during the export window. Data ages out of backups on our normal cycle. Annex C sets out that period, and every other period these terms use, in one place. A backup is not restored to live systems except as part of a disaster recovery event.
6.2 What we keep. We may keep Customer Personal Data where EU, UK or New Zealand law requires us to, for as long as that law requires and for no other purpose.
6.3 Certification. If you ask in writing during the export window, we will confirm in writing once deletion is complete.
7. Showing you we are doing it
In short: ask us and we will answer. A full audit is available if the answers genuinely do not settle it, on terms that are fair to both of us.
7.1 Information. We will make available to you the information reasonably necessary to demonstrate compliance with Article 28.
7.2 Questionnaire. Once in any twelve-month period, and additionally after a personal data breach affecting your Customer Personal Data, you may send us a reasonable security and data protection questionnaire. We will respond within the period shown in Annex C. A completed industry-standard questionnaire we already hold, or a current third-party audit report, satisfies this where it covers your questions.
7.3 Audits. Where clauses 7.1 and 7.2 genuinely do not answer your questions, you or an independent auditor you appoint may audit us. Audits are on the notice shown in Annex C, during business hours, no more often than Annex C allows, except where a supervisory authority requires otherwise or following a personal data breach affecting your Customer Personal Data, subject to confidentiality, must not disrupt our operations or give access to any other customer’s data or to our commercially sensitive information, and are at your cost unless the audit reveals a material failure by us.
7.4 Regulators. Nothing in clause 7.3 limits the rights of a supervisory authority.
8. Sending data outside the EEA and the UK
In short: your data sits in Australia. New Zealand has adequacy and Australia does not, so the standard contractual clauses below are what make the transfer lawful — not our New Zealand address.
8.1 Where the data is. We are a New Zealand company. We store Customer Data on servers in Australia, and we and our sub-processors may access and process it from New Zealand, Australia and the other countries shown on the sub-processor page. Clause 9.7 of the Platform Terms says the same.
8.2 Why the clauses do the work. New Zealand is approved for transfers from the EU by a European Commission adequacy decision, and for transfers from the UK by regulations made under the UK GDPR. Australia is approved by neither. Because your data is stored there, we do not rely on New Zealand adequacy for these transfers. We rely on the clauses below.
8.3 EU standard contractual clauses. To the extent a transfer under these terms is subject to Chapter V of the EU GDPR, the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914 (the EU SCCs) are incorporated into these terms and take effect between you as data exporter and us as data importer, as follows:
Module Two (controller to processor) applies.
In Clause 9, Option 2 (general written authorisation) applies, with the notice period in clause 4.2 of these terms.
In Clause 11, the optional independent dispute resolution wording is not included.
In Clause 17, the governing law is the law of Ireland. In Clause 18(b), the forum is the courts of Ireland.
Annex A and Annex B to these terms complete Annexes I and II to the EU SCCs. The competent supervisory authority for Annex I.C is the one determined under Clause 13(a).
8.4 UK Addendum. To the extent the transfer is subject to the UK GDPR, the International Data Transfer Addendum to the EU SCCs issued by the Information Commissioner, version B1.0 (the UK Addendum), is incorporated and applies to the EU SCCs as set out in clause 8.3. For Table 4, the party that may end the Addendum when the Approved Addendum changes is the data exporter. Tables 1 to 3 are completed by Annex A and Annex B.
8.5 Switzerland. Where Swiss data protection law applies, the EU SCCs apply with the amendments the Swiss Federal Data Protection and Information Commissioner requires.
8.6 The UK data protection test. UK law requires the exporter to assess whether protection in the destination country is materially lower than under UK law — what the Information Commissioner still calls a transfer risk assessment. That assessment is yours to make as exporter. We will give you the information reasonably available to us that you need in order to make it.
8.7 If a mechanism falls away. If a transfer mechanism we rely on is invalidated or withdrawn, we will work with you in good faith to put a lawful alternative in place without undue delay.
9. Liability, changes and law
9.1 Liability. Our liability under these terms is subject to the limitations and exclusions in clause 19 of the Platform Terms. Nothing here limits either party’s liability to a data subject.
9.2 Changes. We may change these terms in the same way and on the same basis as clause 23 of the Platform Terms. Changes to the sub-processor list are governed by clause 4, not by this clause.
9.3 Governing law. These terms are governed by the law of New Zealand and the New Zealand courts have exclusive jurisdiction — except that the EU SCCs and the UK Addendum keep their own governing law and forum, which prevail for anything arising under them.
10. Contact
10.1 Us. Data protection questions, requests under these terms and anything about a personal data breach: support@penguinpilot.ai. That address is monitored on business days and is the fastest route to a person.
10.2 You. Tell us at support@penguinpilot.ai who we should contact about data protection matters. If you do not, we will use the administrator contact on your account.
Annex A — Description of the processing
This Annex completes Annex I to the EU SCCs and Tables 1 to 3 of the UK Addendum.
Data exporter. You, the customer, as identified in your account and your order. Role: controller. Contact: the person notified under clause 10.2, or the administrator contact on your account. Activities relevant to the transfer: using the Penguin Pilot platform to run your business.
Data importer. The Network Software Limited (New Zealand company number 9429048076104) trading as Penguin Pilot, of 3 Waiata Avenue. Remuera. Role: processor. Contact: support@penguinpilot.ai. Activities relevant to the transfer: providing, hosting, securing and supporting the platform.
Categories of data subject. Determined by you. Typically your contacts, leads and prospects; your customers and clients; vendors, buyers, tenants and landlords; form respondents, booking guests and open home attendees; recipients of messages you send; people who sign documents you send; and your own staff, contractors and users.
Categories of personal data. Determined by you. Typically name, contact details and address; job title and employer; correspondence and communication history; notes and records you create; activity and engagement data; documents and files you upload; signature images and signing audit trails; calendar and meeting data; and, where you use the relevant modules, financial and transaction records, payroll and remuneration data and financial account references.
Special category data. Not expected. Clause 5.2 requires you to tell us before you put Article 9 data into your workspace. Where you use voice cloning, the voice sample is likely to be biometric data.
Frequency. Continuous, for the duration of your subscription.
Nature of the processing. Collection, recording, organisation, structuring, storage, retrieval, consultation, use, transmission, alignment, combination, restriction, erasure and destruction, as necessary to provide the platform and as directed by your configuration and use of it.
Purpose. Providing, hosting, securing, maintaining and supporting the platform for you; sending communications you instruct us to send; transmitting data to third-party services you have connected; and complying with the law.
Duration. The term of your subscription, plus the export and deletion periods in clause 6.
Sub-processors. As listed at penguinpilot.ai/legal/third-party-services, each processing for the purpose and duration described against it there.
Annex B — Technical and organisational measures
This Annex completes Annex II to the EU SCCs. It describes the measures in place at the effective date. We may change them, provided the level of security is not reduced.
Encryption. Data encrypted in transit using TLS, and at rest on our hosting provider’s encrypted storage.
Access control. Role-based access within the platform, controlled by you. Internal access to production on a least-privilege basis, limited to named personnel who need it, with multi-factor authentication required.
Separation. Each customer’s workspace is logically separated, and access is scoped to the workspace.
Confidentiality. Everyone we authorise to process Customer Personal Data is bound by written confidentiality obligations that survive the end of their engagement.
Resilience. Managed hosting with redundancy, regular automated backups, and restoration testing.
Logging. Audit trails for signing and for key workspace events, retained so that you can demonstrate what happened and when.
Vulnerability management. Dependency and platform patching on a regular cycle, with security updates prioritised.
Incident response. A documented process for identifying, escalating and responding to security incidents, including notifying you under clause 3.2(f).
Sub-processor measures. Obligations no less protective than these imposed on every sub-processor under clause 4.4, with an appropriate transfer mechanism where the sub-processor is outside an adequate jurisdiction.
AI providers. We contract with our AI providers so that data we send on your behalf is not used to train their models and is retained only under the zero-retention or limited-retention terms we have agreed. Those terms are published on the sub-processor page.
These terms are provided by The Network Software Limited trading as Penguin Pilot. Questions: support@penguinpilot.ai.
Annex C — Standard Periods
Every period these terms use is collected here, so there is one place to find them and one place to change them. Where a clause refers to a period, this is the period it means. Deadlines set by the GDPR itself are not listed, because they bind each of us directly and we do not restate them.
| Period | How long |
|---|---|
| Export window after your subscription ends | 30 days |
| Deletion from our production systems, after the export window | 30 days |
| Data ageing out of our backups, after deletion | 30 days |
| Notice before we add or replace a sub-processor | 30 days |
| Our response to a security questionnaire | 30 days |
| Notice before an audit | 30 days |
| How often you may audit us | Once in any 12 months |
| Notice before we change these terms | 30 days |
