Back to milestra.app

Legal

Data Processing Agreement

Last updated September 2026

This agreement summarizes how Milestra processes personal data on behalf of customer organizations. It applies automatically to all paid and free workspaces. Organizations that require a signed, full-length DPA can request one at legal@milestra.app.

Roles

The customer organization is the data controller for personal data in its workspace; Milestra is the data processor. We process data only on documented instructions from the controller, including under these terms and the Privacy Policy.

Scope of processing

  • Subject matter: provision of the Milestra performance-management platform.
  • Categories of data: account identifiers (name, email, role) and workspace content (goals, KPIs, evidence, meeting notes) as entered by the customer.
  • Data subjects: customer employees and other users the customer invites.
  • Duration: for the term of the subscription, plus the deletion window described in the Privacy Policy.

Security measures

We maintain the technical and organizational measures described on our Security page, including encryption in transit and at rest, per-organization row-level isolation, least-privilege internal access, and audit logging of administrative actions.

Subprocessors

We engage the subprocessors listed on our Subprocessors page under written agreements with equivalent data-protection obligations. We will notify customers of additions at least 30 days in advance.

Data subject requests and incidents

We assist controllers in responding to data subject requests and notify affected customers without undue delay — and in any case within 72 hours — after becoming aware of a personal data breach.

Transfers

Where data is transferred outside the EEA/UK, transfers rely on Standard Contractual Clauses or an equivalent mechanism, together with supplementary measures described on the Security page.