Last updated: 9 October 2026
This Data Processing Agreement (“DPA”) forms part of the Terms and Conditions between 77Labs (Tomasz Gorski, trading as 77Labs, “we”) and the business that subscribes to Autopilot (“you”). It applies whenever we process personal data on your behalf, and it is designed to meet Article 28 of the UK GDPR.
1. Roles
For personal data about your customers, leads, contacts and staff that you put into or collect through Autopilot (“Customer Personal Data”), you are the controller and we are your processor.
2. Details of the processing
- Subject matter and purpose: providing the Autopilot software and any setup, support or Ads Management services you buy.
- Duration: the length of your subscription plus the deletion period in section 9.
- Types of data: names, addresses, phone numbers, email addresses, property and job details, photos, quotes, booking details, messages, call recordings and transcripts, reviews and any other information you choose to store.
- Data subjects: your customers, prospective customers, contacts and your staff users.
- Nature of processing: storing, organising, sending messages and emails, answering calls and chats, scheduling, generating quotes and reports.
3. Our obligations
We will:
- process Customer Personal Data only on your documented instructions, which are these terms and the way you configure and use Autopilot, unless the law requires otherwise (in which case we will tell you, unless the law forbids it);
- make sure anyone we authorise to process the data is bound by confidentiality;
- take appropriate technical and organisational security measures, as described in section 6;
- help you, taking into account the nature of the processing, to respond to requests from individuals exercising their rights, and with security, breach notification, data protection impact assessments and consultation with the ICO;
- make available the information you reasonably need to show compliance with Article 28 and allow for reasonable audits, on at least 30 days’ written notice, at your cost and no more than once a year unless required by the ICO.
4. Sub-processors
You give us general authorisation to use sub-processors. Our current sub-processors are:
| Sub-processor | Purpose | Location |
|---|---|---|
| HighLevel Inc. (LeadConnector) | Platform hosting, CRM, messaging, phone, AI features | USA |
| Carriers and AI providers engaged by HighLevel | Delivery of calls, SMS, and AI responses | USA / various |
| Mailgun Technologies | Email delivery | USA / EU |
| Stripe | Payments you take from your own customers through Autopilot (if enabled) | USA / EU |
We will give you at least 30 days’ notice by email before adding or replacing a sub-processor. If you object on reasonable data protection grounds and we cannot resolve it, you may cancel without penalty. We impose data protection obligations on each sub-processor that are no less protective than this DPA, and remain responsible for them.
5. International transfers
Customer Personal Data may be transferred to the USA and other countries where our sub-processors operate. Where this happens we rely on adequacy regulations (including the UK Extension to the EU-US Data Privacy Framework) or the UK International Data Transfer Addendum to the European Commission’s Standard Contractual Clauses.
6. Security
- Data is hosted on HighLevel’s infrastructure, encrypted in transit and at rest.
- Access is by individual user logins with role-based permissions; we recommend you enable two-factor authentication.
- Our own access to your account is limited to what is needed for setup and support.
7. Personal data breaches
We will notify you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data, and give you the information you reasonably need to meet your own obligation to report to the ICO within 72 hours.
8. Your obligations
You are responsible for having a lawful basis for the data you put into Autopilot and for the messages you send, for giving your customers the privacy information they need (including that calls may be recorded or answered by an AI assistant), and for complying with PECR when sending marketing.
9. Deletion and return
When your subscription ends you can export your data for 30 days. After that we will delete Customer Personal Data, unless the law requires us to keep it. Backups held by our sub-processors are deleted on their normal cycle.
10. General
If this DPA conflicts with the Terms and Conditions on a data protection matter, this DPA wins. It is governed by the law of England and Wales.