Data Processing Agreement
This Data Processing Agreement ("DPA") is entered into as of the date of last signature below by and between:
LanePilot Technology, LLC, a Pennsylvania limited liability company with its principal place of business at 8370 Wattsburg Road, Erie, PA 16509 ("LanePilot," "Processor," "we," or "us"); and
Customer, the entity identified in the signature block below ("Customer" or "Controller").
This DPA supplements and is incorporated into the Terms of Service and any Order Form or Master Services Agreement between LanePilot and Customer governing Customer's use of the LanePilot platform at LanePilotTech.com (the "Service Agreement"). It applies to the extent LanePilot processes Customer Personal Data on Customer's behalf.
1Definitions
- "Controller" means the party that decides why and how personal data is processed. Customer is the Controller of Customer Personal Data.
- "Processor" means the party that processes personal data on the Controller's behalf. LanePilot is the Processor of Customer Personal Data.
- "Customer Personal Data" means personal data that Customer, or Customer's authorized users, submit to or generate within the Service. This includes account information, shipment data, uploaded documents (bills of lading, invoices, carrier contracts, rate confirmations), invoice audit and dispute records, receiving records, vendor records and vendor contact details, inventory and product records, dock user account and activity records, and communications submitted through the Service, to the extent any of it identifies or relates to an identifiable individual.
- "Service" means LanePilot's business-to-business freight and warehouse platform, including rate comparison, booking, tracking, invoice audit, carrier scorecards, benchmarking, and LanePilot Warehouse.
- "Subprocessor" means a third party LanePilot engages to process Customer Personal Data in order to provide the Service, as listed in Exhibit A.
- "Data Subject Request" means a request from an individual to exercise rights over their personal data.
- "Security Incident" means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to Customer Personal Data.
Capitalized terms not defined here have the meaning given in the Service Agreement.
2Scope and Roles
LanePilot acts as a Processor. Customer acts as a Controller. LanePilot processes Customer Personal Data only to provide, maintain, secure, and support the Service, as necessary to perform under the Service Agreement, and on Customer's documented instructions.
The organization is the customer. The Customer entity, not any individual user, is the party to this DPA and the Controller of Customer Personal Data. Individual authorized users act as the Customer's agents. Where an individual asks LanePilot to erase their personal data, LanePilot removes or severs that individual's identifiers from the Customer's records rather than destroying the Customer's underlying business records, and informs the individual that is what it did.
Customer's personnel. Where Customer gives its own employees access, including dock users, Customer is responsible for providing them any notice required by law. This allocates responsibility between the parties. It does not prevent an individual contacting LanePilot directly, and LanePilot will handle such a request in accordance with applicable law.
Documented instructions. The Service Agreement, any Order Form, and LanePilot's Terms of Service together constitute Customer's complete documented instructions. Additional or different processing must be instructed in writing, and LanePilot may charge a reasonable fee for work outside the original scope.
Aggregated Market Intelligence
Customer acknowledges and authorizes LanePilot to process Customer Personal Data as reasonably necessary to create the Aggregated Market Intelligence described in Section 14.4 of the Terms of Service.
While Customer Personal Data is being selected, analyzed, aggregated, or de-identified, it remains Customer Personal Data and remains subject to the security, confidentiality, subprocessor, and other protections of this DPA.
LanePilot independently determines the purpose and essential means of creating and externally publishing Aggregated Market Intelligence. To the extent that activity constitutes processing of personal data, LanePilot acts as an independent controller, rather than as Customer's Processor, for that limited processing. LanePilot is responsible for the legal basis, transparency, security, and other controller obligations applicable to that processing.
Once an output has been aggregated and de-identified so that it no longer identifies or relates to an identifiable individual and cannot reasonably be linked back to an individual, that output is not Customer Personal Data and is outside the scope of this DPA. Customer-specific source records and any intermediate data that remain identifiable continue to be Customer Personal Data and remain subject to this DPA.
Nothing in this subsection permits LanePilot to use identifiable Customer Personal Data for its own marketing or advertising, to sell identifiable Customer Personal Data, or to train, fine-tune, or develop an artificial-intelligence or machine-learning model.
AI processing. LanePilot uses Anthropic, PBC's Claude API to read and interpret documents and free-text that users submit, to generate audit findings, summaries, and draft correspondence. This is part of providing the Service under Customer's documented instructions. LanePilot does not use Customer Personal Data to train or fine-tune any AI model, and Anthropic does not train its models on content submitted through its API. Anthropic's own retention applies and is stated in Exhibit A. Separately, and not under Customer's instruction, LanePilot uses the same API for its own internal business operations involving LanePilot's own prospect and business data, which is not Customer Personal Data and is described in LanePilot's Privacy Policy rather than this DPA.
LanePilot will not use Customer Personal Data for its own marketing or advertising, sell Customer Personal Data, or use it to train or fine-tune any artificial intelligence or machine-learning model.
Carriers. Where Customer connects a carrier, Customer connects its own account with that carrier, using its own credentials. When Customer requests a rate, books a shipment, or tracks one, LanePilot transmits the shipment details and the contact information that shipment requires to that carrier, at Customer's direction and on Customer's own account with that carrier. In this workflow the carrier receives that data as Customer's transportation counterparty, under Customer's own account and agreement with it. LanePilot does not appoint the carrier to process Customer Personal Data on LanePilot's behalf and does not instruct it how to process that data. On those facts the carrier is not a Subprocessor of LanePilot and is therefore not listed in Exhibit A. The carrier handles that data as an independent controller under its own privacy policy and its own terms, which govern Customer's relationship with it, and Customer should refer to those privacy policies for how its carriers handle that data. LanePilot transmits these technical requests solely to perform the quoting, booking, and tracking functions Customer initiates. That is different from representing Customer. Consistent with the Service Agreement, LanePilot does not submit dispute correspondence, negotiate charges, or advance any claim or legal position to a carrier on Customer's behalf.
Notice of unlawful instructions. If LanePilot believes an instruction violates applicable data protection law, LanePilot will promptly notify Customer and is not required to follow an instruction it reasonably believes unlawful.
3Subprocessors
LanePilot uses the subprocessors in Exhibit A. Customer authorizes them as of the effective date of this DPA. Carriers that Customer connects are not Subprocessors, are not listed in Exhibit A, and are not authorized under this Section, for the reasons stated under Carriers in Section 2.
Before engaging a new subprocessor that will process Customer Personal Data, LanePilot will give Customer at least 30 days' advance notice by email or in-Service notice, and will keep Exhibit A or an equivalent current list available to Customer.
If Customer reasonably objects on legitimate data-protection grounds within 15 days of that notice, the parties will discuss the objection in good faith. If it cannot be resolved, Customer may terminate the affected portion of the Service as its sole remedy, without penalty, on written notice within 30 days. A reasonable data-protection objection means a specific, articulated concern about the proposed subprocessor's handling of Customer Personal Data, not a general preference. LanePilot may propose an alternative provider or a mitigating control before termination takes effect. On termination under this paragraph LanePilot will refund any prepaid fees covering the terminated portion for the remainder of the then-current term.
LanePilot imposes data protection obligations on each subprocessor substantially consistent with this DPA and remains responsible for each subprocessor's performance of those obligations to the same extent as if LanePilot performed the processing itself. This applies to each subprocessor's processing of Customer Personal Data on LanePilot's behalf. Where Exhibit A notes that a provider also acts as an independent controller for its own regulatory purposes, that separate processing is determined by that provider under its own terms, is not carried out on LanePilot's instructions, and is not covered by this paragraph.
4Security Measures
LanePilot maintains administrative, technical, and physical safeguards appropriate to the sensitivity of Customer Personal Data, including:
- Encryption in transit, using TLS 1.2 or higher.
- Encryption at rest for sensitive data fields.
- Encryption of stored carrier credentials.
- Logical data isolation separating each customer's data within the hosting environment.
- Access controls restricting internal access to personnel who need it, with authentication provided by Clerk, a third-party identity provider. Users sign in with an email address and a password. Clerk stores and manages those passwords under its own security controls. LanePilot does not store user passwords and cannot access them.
- Account lockout and abuse-prevention controls.
- Network and bot protection through Cloudflare, including denial-of-service protection, web application firewall functions, and edge security monitoring.
- Error monitoring through Sentry.
- Vendor security review when selecting subprocessors.
One limitation LanePilot discloses rather than obscures. For a small number of carriers, that carrier's own interface requires credentials to be transmitted as part of the request address, which means they may appear in that carrier's server logs. This is a property of those carriers' systems, and LanePilot cannot control what a carrier records in its own systems. LanePilot identifies the affected carriers at the point where the credentials are entered, and applies the controls available to it to keep credentials out of the logs and monitoring systems that LanePilot controls.
LanePilot reviews and updates these safeguards as the Service evolves. No security measure is perfect, and this DPA does not guarantee that a Security Incident will never occur.
5Breach Notification
If LanePilot confirms a Security Incident affecting Customer Personal Data, LanePilot will notify Customer without undue delay and in any event within 72 hours of confirming it.
The notice will describe, so far as then known, the nature of the incident, the categories and approximate number of data subjects and records affected, the likely consequences, and the steps taken or planned to address it and mitigate its effects. LanePilot may provide information in phases as it becomes available.
LanePilot will reasonably cooperate with Customer's own investigation and notification obligations, including under Pennsylvania's Breach of Personal Information Notification Act. Notification is not an admission of fault or liability.
6Audit Rights
Annual security summary. Once per year Customer may request a written summary of LanePilot's security practices relevant to this DPA, which LanePilot will provide within 30 days.
Enterprise audit cooperation. LanePilot will cooperate in good faith with reasonable audit requirements from an enterprise Customer, subject to: at least 30 days' advance written notice; no more than once per 12-month period unless a Security Incident or legal requirement justifies more; during normal business hours without unreasonable interference; a confidentiality agreement reasonably acceptable to LanePilot; and LanePilot's option to satisfy the request with existing certifications, audit reports, or written security summaries where those reasonably address it.
Customer bears its own audit costs. LanePilot may charge reasonable costs for audits beyond this scope.
7Data Subject Requests
If LanePilot receives a Data Subject Request directly that relates to Customer Personal Data, LanePilot will promptly forward it to Customer unless legally prohibited.
LanePilot will reasonably assist Customer in responding, including by providing the ability to access, export, correct, or delete Customer Personal Data through the Service where technically feasible, and reasonable additional support where self-service tools do not fully address the request.
As Controller, Customer remains primarily responsible for determining whether and how to respond and for communicating with the individual. LanePilot may charge a reasonable fee for assistance requiring material engineering or administrative effort beyond standard tools.
8Retention, Return, and Deletion
Retention schedule. LanePilot retains Customer Personal Data in accordance with the retention schedule published in its Privacy Policy. Categories retained beyond the Service's active use of them, such as tax and financial records, are retained because law requires it.
Legal hold. LanePilot may retain data beyond the stated periods where necessary to establish, exercise, or defend legal claims or to comply with a legal obligation. Where a hold applies, affected records are withheld from deletion and LanePilot's erasure record notes them as withheld rather than deleted. A legal hold never retains a live carrier credential, which is deleted in all cases.
On termination. Upon termination or expiration of the Service Agreement, LanePilot will, at Customer's written election made within 30 days, either return Customer Personal Data in a commonly used format or delete it from LanePilot's production systems. LanePilot will complete the election within a reasonable period not exceeding 90 days, except as stated below.
Exceptions. LanePilot may retain Customer Personal Data to the extent required by applicable law, contained in routine backups until they cycle out in the ordinary course (backup copies expire on a 35-day rotation and retained backup data is not used for any active purpose), or needed to resolve disputes, enforce agreements, or comply with legal obligations.
If Customer makes no election within 30 days, LanePilot may delete in accordance with its standard retention practices. This Section applies in addition to any retention or deletion provisions relating to the Pause tier or the recovery window described in the Terms of Service and Privacy Policy.
The return and deletion obligations in this DPA do not require LanePilot to delete Aggregated Market Intelligence that was created in compliance with Terms of Service Section 14.4 and that no longer constitutes Customer Personal Data, but they continue to apply to all identifiable source and intermediate data.
9International Transfers
LanePilot processes Customer Personal Data primarily in the United States, using its hosting infrastructure and the subprocessors in Exhibit A, which are based in or operate primarily from the United States.
This DPA does not include international data transfer mechanisms such as Standard Contractual Clauses, the EU-U.S. Data Privacy Framework, or a UK International Data Transfer Addendum. Customer must not submit Customer Personal Data that requires such a mechanism unless the parties first execute an appropriate transfer addendum. If Customer or its end users are located outside the United States, the parties will execute that addendum before any such Customer Personal Data is processed under this DPA.
10Liability
This DPA does not create or expand liability beyond the Service Agreement. Each party's total liability arising out of or relating to this DPA, including any Security Incident, is subject to the caps, exclusions, and limitations in the Service Agreement, except to the extent applicable law prohibits limiting liability for a particular claim. Warranties and disclaimers applying to the Service are set out in the Service Agreement and are not modified here.
11Term
This DPA begins on its effective date and continues for as long as LanePilot processes Customer Personal Data under the Service Agreement. It terminates automatically when the Service Agreement terminates, except that Sections 5, 8, 10, and 12 survive to the extent needed to give them effect.
12Governing Law and Venue
This DPA is governed by the laws of the Commonwealth of Pennsylvania, without regard to conflict-of-laws rules. The parties consent to the exclusive jurisdiction and venue of the state courts of Erie County, Pennsylvania, or the U.S. District Court for the Western District of Pennsylvania, consistent with the Service Agreement.
13Execution
Each party may sign electronically. An electronic signature is valid and binding to the same extent as a handwritten signature, consistent with the Pennsylvania Uniform Electronic Transactions Act. This DPA is effective only when both parties have signed.
14General
Order of precedence. If this DPA conflicts with the Service Agreement regarding the processing of Customer Personal Data, this DPA controls. For all other matters the Service Agreement controls.
Amendment. LanePilot may update this DPA to reflect changes in applicable law or its processing practices, with at least 30 days' notice of any material change. If Customer objects to a material change, Customer may terminate the Service Agreement as its sole remedy.
Severability. If any provision is unenforceable, the remainder stays in effect.
Entire agreement. This DPA, with the Service Agreement and its exhibits, is the entire agreement regarding the processing of Customer Personal Data.
15Signature Blocks
IN WITNESS WHEREOF, the parties have executed this Data Processing Agreement as of the dates below.
16Exhibit A: Subprocessors
| Subprocessor | Function | Customer Personal Data categories |
|---|---|---|
| Clerk | Identity and authentication | Email address, name, session and authentication tokens. Stores user passwords under its own controls; LanePilot does not |
| Bubble | Primary application hosting and database | All Customer Personal Data submitted to or generated within the Service |
| Cloudflare, Inc. | Application workers, object storage, key-value storage, security, denial-of-service protection, TLS, edge analytics | Uploaded documents, IP address, traffic metadata, cookie data |
| Vercel, Inc. | Website and application hosting | Request data, IP address, technical logs |
| Stripe, Inc. | Payment processing. Also acts as an independent controller for fraud prevention and anti-money-laundering and know-your-customer compliance | Billing address, payment method details (last four digits and card brand; full card numbers go directly to Stripe and never reach LanePilot's servers), transaction records. As independent controller, Stripe retains data on its own terms, generally five or more years from the end of the relationship or last transaction |
| Anthropic, PBC | AI processing via the Claude API, for parsing documents and free-text submitted through the Service and generating findings and draft correspondence | Document content, query text, and communications submitted through the Service. Anthropic does not train its models on this content. Retained by Anthropic for up to 30 days by default, and up to two years where flagged under its usage policies. LanePilot does not hold a Zero Data Retention agreement |
| Twilio SendGrid, Inc. | Transactional customer email only | Recipient email addresses and the content of the account, billing, deletion, and restore emails LanePilot sends to its own customers. Not used for prospecting or cold outreach. Also receives a deleted user's email address for SendGrid's suppression list |
| Google LLC / Google Workspace | Email intake for document and contract intake addresses, and internal business records | Documents and contact details sent to intake addresses, customer communications, internal business records |
| Sentry | Error and performance monitoring | Error reports and diagnostic context, which may include limited technical identifiers |
| PostHog | Product analytics | Usage events, pseudonymous identifiers, session data |
Providers not listed above, and why. CloudConvert was removed from the Service on 2026-07-18 and Apollo on 2026-07-17. Neither receives any data. LanePilot retains the executed data processing agreement for CloudConvert covering the historical processing period only. SMC3 was listed in an earlier draft of this Exhibit. It is inert in the Service, is not engaged as a subprocessor, and receives no data, so it does not appear above. If LanePilot engages SMC3 in future it will be added to this Exhibit with notice under Section 3 before any processing begins. Hunter was also listed in an earlier draft of this Exhibit and has been removed, though unlike the providers above it has not exited and LanePilot still uses it. Hunter supports LanePilot's own business prospecting and receives only publicly available business contact information about individuals who are not LanePilot users. It never receives Customer Personal Data, so it is not a Subprocessor as Section 1 defines that term and does not belong in this Exhibit. Hunter remains disclosed in LanePilot's Privacy Policy, which covers LanePilot's own prospecting activity.
LanePilot will keep this Exhibit current and will provide notice of changes in accordance with Section 3.
© 2026 LanePilot Technology, LLC · Erie, Pennsylvania · Terms of Service · Privacy Policy ·