Data Processing Agreement
This beta Data Processing Agreement (DPA) describes how Milo Growth processes personal data on your behalf when you use the service. It is a readable beta template, not final legal text.
Parties
This DPA is between you (the "Controller") and Andersen Innovations (Andersen Innovations [legal entity details to be added]), operator of Milo Growth (the "Processor").
Subject matter
The processing of personal data by the Processor on behalf of the Controller as necessary to provide the Milo Growth service.
Duration
Processing lasts for as long as the Controller uses the service, and until data is deleted or returned as described below.
Nature and purpose of processing
To provide planning, content generation, publishing and analytics features — including hosting account and project data, generating AI-assisted content, sending content to connected websites, and reporting anonymous website analytics.
Categories of data
- Account data (email, authentication identifiers)
- Project / workspace and business profile data
- Content and website data created in Milo
- Anonymous website analytics (visitor/session IDs, events) — no full IP addresses
Categories of data subjects
- The Controller's authorised users
- Visitors to the Controller's websites that use Milo Analytics (anonymous)
Processor obligations
The Processor will:
- process personal data only on documented instructions from the Controller;
- ensure persons authorised to process data are bound by confidentiality;
- implement appropriate technical and organisational security measures;
- assist the Controller with data subject requests and security obligations where reasonable.
Controller obligations
The Controller is responsible for the lawfulness of the data it provides, for having an appropriate legal basis, and for ensuring it is permitted to connect and publish to any website it configures.
Subprocessors
The Controller authorises the Processor to use the subprocessors listed on the Subprocessors page. We will maintain that list and take reasonable steps to ensure subprocessors apply suitable safeguards.
Security measures
Security measures are summarised on the Security page, including authentication, row-level access control, server-side handling of secrets and privacy-conscious analytics.
Assistance with data subject rights
The Processor will assist the Controller, by appropriate technical and organisational measures, in responding to requests from data subjects to exercise their rights.
Breach notification
[Breach notification timelines to be finalised.] The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data.
Deletion or return of data
On termination, or on request, the Processor will delete or return the Controller's personal data, subject to any legal retention requirements. See the Privacy Policy for how to make a request.
International transfers
[International transfer mechanisms to be confirmed.] Where data is processed outside your country, the parties rely on appropriate safeguards as required by applicable law.
Contact
Data protection contact: support@milogrowth.com.