This note helps procurement and legal teams understand where PilotBreak processes customer data today. It is not a full Data Processing Agreement (DPA). A signed DPA can be provided on request for paid engagements — contact pilot@askqa.app.
Primary database region
Customer workspace data (accounts, pilots, baselines, shadow register, leads, audit logs) is stored in Neon PostgreSQL with primary region AWS US East (N. Virginia) — us-east-1.
We state this honestly: if you are an EU/UK or Gulf buyer with data-residency requirements, US-East storage may not meet your policy today. We can discuss:
- Contractual safeguards (standard contractual clauses where applicable).
- What data categories you choose not to enter until residency options exist.
- Roadmap — an EU-region Neon project (or equivalent) when customer demand warrants it; not guaranteed on a fixed date.
Sub-processors (infrastructure)
- Neon — managed PostgreSQL (primary data store).
- Cloudflare — DNS, TLS edge, worker proxy (request routing; not primary DB).
- Railway — application hosting (processes requests; persistent data in Neon).
We do not use customer workspace data to train third-party AI models. Optional OpenAI features, if enabled for your deployment, would only process prompts you explicitly send — ask us for current status on your contract.
Roles
- For self-serve SaaS, you are typically the data controller for business data you enter; ASKQA acts as data processor on your instructions.
- For audit / design-partner services, roles and retention are defined in the statement of work.
Data categories processed
See our Privacy Policy for the full list. Typical categories:
- Account & contact identifiers (name, email, company).
- AI pilot inventory and governance records.
- Financial / KPI figures you enter for ROI proof.
- Shadow AI tool register entries.
- Lead & scorecard submissions from marketing flows.
Security measures
Summary: HTTPS, HMAC-signed session cookies, bcrypt password hashing, tenant-scoped APIs, auth rate limits. Details on the Security page.
Deletion & export
You can export registers and reports from the product. Deletion requests: email pilot@askqa.app. We will confirm scope and timing based on your contract and legal retention needs.