MiseOS

Data Processing Agreement

Incorporated into the MiseOS Terms of Service.

Published draft. Complete in substance; undergoing final solicitor review. Company details will be completed on incorporation.

This DPA is entered into between the Customer (the Controller) and [company legal name] (the Processor) and applies to personal data within Customer Data processed by the Processor on the Controller's behalf in providing the MiseOS service. Terms defined in the Terms of Service and in UK GDPR have the same meaning here.

1. Roles and scope

The Controller determines the purposes and means of processing personal data entered into its Venues; the Processor processes it only to provide, support and secure the Service. Details of the processing are set out in Annex A.

2. Processor obligations

The Processor shall:

  1. process personal data only on the Controller's documented instructions (which include the Terms of Service, this DPA, and the Controller's use of the Service's features), unless required otherwise by law, in which case the Processor will inform the Controller unless prohibited;
  2. ensure persons authorised to process the data are bound by confidentiality;
  3. implement the technical and organisational measures in Annex B;
  4. assist the Controller, taking into account the nature of processing, in responding to data subject rights requests; the Controller manages its own staff's requests using the Service's tools where possible, with Processor assistance where needed;
  5. assist the Controller with obligations under Articles 32–36 UK GDPR (security, breach notification, DPIAs) taking into account the information available to the Processor;
  6. notify the Controller without undue delay, and in any event within 48 hours of becoming aware, of a personal data breach affecting the Controller's personal data, providing information reasonably required for the Controller's own notifications;
  7. at the end of provision of the Service, make Customer Data exportable for 30 days and then delete personal data from live systems, with backup copies overwritten in the normal backup cycle (not exceeding [35] days), unless retention is required by law;
  8. make available information reasonably necessary to demonstrate compliance with this DPA and, no more than once in any 12-month period and on at least 30 days' notice, allow an audit limited in scope to the Processor's compliance with this DPA, at the Controller's cost and without access to other customers' data.

3. Subprocessors

  1. The Controller gives general authorisation to the subprocessors listed in Annex C (also published at /subprocessors).
  2. The Processor will give at least 14 days' notice of intended additions or replacements via that page [and email to account holders]; the Controller may object on reasonable data-protection grounds, in which case the parties will discuss in good faith and the Controller may cancel affected Venues if the objection cannot be resolved.
  3. The Processor imposes data-protection obligations on subprocessors materially equivalent to this DPA and remains responsible for their performance.

4. International transfers

Where processing involves transfer of personal data outside the UK, the Processor ensures a valid transfer mechanism: UK adequacy regulations (including the UK–US Data Bridge where the recipient is certified) or the UK International Data Transfer Addendum to the EU SCCs.

5. Controller obligations

The Controller warrants it has a lawful basis for the personal data it records; will inform its staff about the processing (the Processor's privacy policy §1 supports this); will not record special-category data (for example health details in time-off notes) — free-text fields are not intended for such data and the Service does not solicit it; and will manage Team Member access and removal.

6. Liability

Liability under this DPA is subject to the exclusions and cap in the Terms of Service, to the extent permitted by data protection law.

Annex A — Details of processing

Annex B — Technical and organisational measures

Annex C — Authorised subprocessors

SubprocessorPurposeRegion
SupabaseDatabase, authentication, storage, syncEU (Frankfurt)
NetlifyApplication hosting and serverless functionsUS/global
StripePayment processingUS/EU
AnthropicAI text processing on instructionUS
Google (Gemini API)Voice synthesis on instructionUS
[email provider]Transactional email (invites, notices)[region]
← Back to MiseOS