Terms of Service
Last updated: January 2025
1. Introduction
These Terms of Service ("Terms") govern your use of the DSPilot platform ("Service") provided by DSPilot ("we", "us", or "our"). By registering for or using our Service, you agree to be bound by these Terms. If you are entering into this agreement on behalf of a company or other legal entity, you represent that you have the authority to bind such entity to these Terms.
2. Service Description
DSPilot provides a software-as-a-service (SaaS) platform for Amazon Delivery Service Partners (DSPs) that includes:
- Schedule management
- Driver availability collection
- Fleet and van assignments management
- Performance metrics tracking and analytics
- Driver mobile dashboard
- Leaderboards and rankings
- Netradyne safety tracking
3. Account Registration
To use DSPilot, you must register for an account. You agree to:
- Provide accurate and complete registration information
- Maintain the security of your account credentials
- Notify us immediately of any unauthorised access
- Accept responsibility for all activities under your account
4. Acceptable Use
You agree not to:
- Use the Service for any unlawful purpose
- Upload false, misleading, or fraudulent data
- Attempt to gain unauthorised access to any part of the Service
- Interfere with or disrupt the Service or servers
- Reverse engineer, decompile, or disassemble the Service
- Use the Service to store or transmit malicious code
- Resell or redistribute the Service without authorisation
5. Data Ownership and Responsibilities
Your Data: You retain all rights to the data you upload to DSPilot ("Your Data"). You grant us a limited licence to use Your Data solely to provide the Service.
Data Controller Responsibilities: As the data controller for driver personal data, you are responsible for:
- Ensuring you have lawful authority to process driver data
- Providing appropriate privacy notices to drivers
- Responding to data subject access requests
- Complying with all applicable data protection laws
5A. Third-Party Platform Data
Data Ingestion: DSPilot processes performance data that you manually upload from Amazon Logistics platforms (such as Scorecards, Netradyne exports, and compliance reports). We do not connect to, scrape, or access Amazon systems directly. All data transfers are initiated by you.
No Credentials Policy: We never request, store, or access your Amazon account credentials. Do not share Amazon login details with DSPilot or any third party. Report any requests for Amazon credentials as potential fraud.
Data We Process (via your uploads):
- Weekly Performance Scorecards
- Netradyne safety exports
- Contact Compliance reports
- POD (Photo on Delivery) compliance reports
- Customer escalation summaries
- Daily operational reports
Data We Do Not Process:
- Customer personal information (names, addresses, contact details)
- Package or shipment tracking data
- Amazon payment or financial data
- Amazon Flex driver information
Retention: Performance metrics are retained for up to 24 months to enable trend analysis. Netradyne daily logs are retained for 12 months. All data is deleted within 90 days of account termination.
6. Subscription and Payment
Free Trial: We offer a 14-day free trial with full access to the Service. No credit card is required for the trial.
Billing: After the trial, you will be invoiced monthly or annually based on your chosen plan and driver count. Payment is due within 14 days of invoice date.
Price Changes: We may adjust pricing with 30 days' notice. Continued use after price changes constitutes acceptance.
7. Intellectual Property
The Service, including its design, features, and documentation, is owned by DSPilot and protected by intellectual property laws. You receive a limited, non-exclusive, non-transferable licence to use the Service during your subscription. You may not copy, modify, or create derivative works from the Service.
8. Limitation of Liability
To the maximum extent permitted by law:
- The Service is provided "as is" without warranties of any kind, whether express or implied.
- We shall not be liable for any indirect, incidental, special, consequential, or punitive damages.
- Our total liability shall not exceed the fees paid by you in the 12 months preceding the claim.
Nothing in these Terms excludes or limits liability for death or personal injury caused by negligence, fraud, or any other liability that cannot be excluded by law.
9. Termination
By You: You may terminate your account at any time by contacting us. You will remain liable for any outstanding fees.
By Us: We may suspend or terminate your access if you breach these Terms, fail to pay fees, or for any reason with 30 days' notice.
Effect of Termination: Upon termination, you may request export of Your Data within 30 days. After this period, we will delete Your Data in accordance with our data retention policy.
10. Indemnification
You agree to indemnify and hold harmless DSPilot from any claims, damages, or expenses arising from your use of the Service, your breach of these Terms, or your violation of any rights of another party.
11. Changes to Terms
We may modify these Terms at any time. We will notify you of material changes via email or through the Service. Continued use after changes constitutes acceptance. If you do not agree to modified Terms, you must stop using the Service.
12. Governing Law
These Terms are governed by the laws of England and Wales. Any disputes shall be subject to the exclusive jurisdiction of the courts of England and Wales.
13. Severability
If any provision of these Terms is found to be unenforceable, the remaining provisions will continue in full force and effect.
14. Contact Us
For questions about these Terms, please contact us at hello@dspilot.co.uk.
Schedule 1: Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Controller") and DSPilot ("Processor") for the processing of personal data as required under Article 28 of the UK General Data Protection Regulation.
1. Definitions
"Personal Data", "Data Subject", "Processing", "Controller", and "Processor" have the meanings given in UK GDPR. "Services" means the DSPilot platform as described in these Terms.
2. Scope and Purpose of Processing
The Processor shall process Personal Data on behalf of the Controller solely for the purpose of providing the Services, including:
- Storing and displaying schedules
- Processing driver availability submissions
- Tracking and displaying performance metrics
- Generating analytics and reports
- Sending operational notifications
3. Categories of Data Subjects
- Delivery drivers employed or contracted by the Controller
- Administrative staff and managers of the Controller
4. Categories of Personal Data
- Contact information (names, email addresses, phone numbers)
- Employment identifiers (Transporter IDs)
- Scheduling data (availability, shift assignments)
- Performance metrics (delivery quality, compliance scores)
- Safety data (driving behaviour metrics from Netradyne)
5. Processor Obligations
The Processor shall:
- Process Personal Data only on documented instructions from the Controller
- Ensure persons authorised to process data are bound by confidentiality
- Implement appropriate technical and organisational security measures
- Not engage sub-processors without prior written authorisation
- Assist the Controller in responding to data subject requests
- Assist the Controller with DPIA and prior consultation where required
- Delete or return all Personal Data upon termination at Controller's choice
- Make available information necessary to demonstrate compliance
6. Authorised Sub-Processors
The Controller authorises the use of the following sub-processors:
- Supabase Inc. – Database hosting, authentication, and backend services. Location: European Union.
- Resend Inc. – Transactional email delivery. Location: United States (with SCCs).
- Twilio Inc. – SMS and WhatsApp messaging services. Location: United States (with SCCs).
7. Security Measures
The Processor implements the following security measures:
- Encryption of data in transit using TLS 1.2+
- Encryption of data at rest using AES-256
- Row-Level Security ensuring data isolation between DSPs
- Multi-factor authentication for administrative access
- Regular security assessments and penetration testing
- Comprehensive audit logging of all data access and modifications
8. Data Breach Notification
In the event of a Personal Data breach, the Processor shall notify the Controller without undue delay (and in any event within 72 hours) after becoming aware of the breach, providing sufficient information to enable the Controller to meet any obligations to report the breach to the ICO.
9. Audit Rights
The Processor shall allow for and contribute to audits conducted by the Controller or an auditor mandated by the Controller, with reasonable notice and during business hours.
10. Duration
This DPA shall remain in effect for the duration of the Terms of Service and for as long as the Processor continues to process Personal Data on behalf of the Controller.