Last revised: 05.10.2026.
This Data Processing Addendum (DPA) is automatically incorporated by reference into the ToS between Mily Technologies and the Customer and applies to the extent Mily Technologies (as Data Processor) processes Customer personal data on behalf of the Customer (as Data Controller). No signature is required to make this DPA effective. However, in case the Customer requires a countersigned copy, please email sales@milytech.com
Preamble
This DPA specifies the obligations under data protection law for the processing of personal data by the Data Processor and supplements the Master Service Agreement (MSA), Terms of Service (ToS), Order Form or other such titled written or electronic agreement concluded between Mily Technologies and the Customer identified in any above agreement regarding the provision of Services by Mily Technologies to the Customer (Agreement). In the event of any conflict or inconsistency between the terms of the Agreement and this DPA concerning the processing of personal data or compliance with data protection laws, the terms of this DPA shall prevail.
1. Definitions
1.1. Data processing on behalf
Data processing on behalf is the storage, modification, transmission, restriction of processing, deletion or other processing of personal data by the Data Processor on behalf of and at the instruction of the Data Controller. Data Processor will process personal data for which the Data Controller is responsible in accordance with the GDPR.
1.2. Instruction
Instruction is the order of the Data Controller directed to a specific data protection handling (for example anonymization, restriction of processing, deletion, surrender) of the Data Processor with personal data. The instructions may be amended, supplemented or replaced by the Data Controller by means of an individual instruction.
2. Subject
The subject and purpose of processing operations and the nature and categories of personal data to be processed by the Data Processor are set out in Annex 1.
In doing so, the Data Processor shall process personal data for the Data Controller within the meaning of Art. 4 No. 2 and Art. 28 GDPR on the basis of this DPA.
The processing shall be provided exclusively in a member state of the European Union or in a contracting state of the Agreement on the European Economic Area. Any relocation of the processing or parts thereof to a third country requires the prior consent of the Data Controller and may only take place if the special requirements of Art. 44 et seq. GDPR are fulfilled.
3. Rights, duties as well as powers of instruction of the Data Controller
3.1. The Data Controller shall be solely responsible for assessing the permissibility of the processing and for safeguarding the rights of the data subjects in accordance with Articles 12 to 22 of the GDPR. Nevertheless, the Data Processor is obligated to immediately forward all such requests to the Data Controller, provided they are recognizably directed exclusively to the Data Controller.
3.2. Data Controller confirms that all the Personal Data provided to Data Processor has been collected lawfully, fairly and in a transparent manner.
3.3. Changes to the object of processing and process changes shall be agreed jointly between the Data Controller and the Data Processor and shall be specified in writing or in a documented electronic format.
3.4. The Data Controller shall issue all orders and instructions in a documented electronic format or in writing. Verbal instructions shall be confirmed immediately in writing or in a documented electronic format.
3.5. The Data Controller shall be entitled, as set forth in section 5.9 to convince itself prior to the start of the processing and thereafter regularly in an appropriate manner of the compliance with the technical and organizational measures taken by the Data Processor and the obligations set forth in this Agreement.
3.6. The Data Controller shall inform the Data Processor without undue delay if it detects any errors or irregularities in processing.
4. Persons authorized to issue instructions to the Data Controller, recipients of instructions at the Data Processor
The Data Controller is entitled to issue instructions to the Data Processor. The Data Processor’s designated recipient to receive, confirm, and coordinate instructions on behalf of the Data Processor is:
Aleksandar Buha (or such other representative as notified by the Data Processor in writing).
The Data Controller’s authorized representatives for issuing instructions are specified in the applicable Order Form or signature block.
In the event of a change or long-term prevention of the contact persons, the respective party must be informed immediately and in principle in writing or electronically of the successors or the representatives. The instructions shall be retained for their period of validity and subsequently for three full calendar years.
5. Duties of the Data Processor
5.1. The Data Processor shall process personal data exclusively according to this DPA, the Agreement and the Data Controller's instructions, unless the Data Processor is required to do otherwise by the law of the European Union or the Member States to which the Data Processor is subject; in such a case, the Data Processor shall notify the Data Controller of such legal requirements prior to the processing, unless the law in question prohibits such notification due to an important public interest.
5.2. The Data Processor shall process personal data exclusively in accordance with this DPA, the Data Controller’s documented instructions, and the Agreement. The Data Processor shall not use or process personal data for any purpose other than providing the Services, except as expressly instructed by the Data Controller or as permitted under applicable law
5.3. In accordance with the consent granted by the Data Controller under the Agreement or separately in writing, the Data Processor is authorized to collect, aggregate, and analyze Data Controller Data derived from the provision and use of the Services. The Data Processor may utilize such information to maintain, optimize, develop, and secure its services and offerings, provided that any resulting data is irreversibly anonymized or de-identified such that it no longer constitutes personal data under the GDPR before use for the Data Processor’s own analytical or development purposes.
5.4. The Data Processor assures that the data processed for the Data Controller are separated from other data files.
5.5 Taking into account the nature of the processing, the Data Processor shall assist the Data Controller by implementing appropriate technical and organizational measures, insofar as possible, for the fulfilment of the Data Controller's obligation to respond to requests for exercising data subject rights under Articles 12 to 22 GDPR. The Data Processor shall further assist the Data Controller in ensuring compliance with obligations pursuant to Articles 32 to 36 GDPR (including security of processing, breach notifications, data protection impact assessments, and prior consultation with supervisory authorities), taking into account the nature of processing and information available to the Data Processor. To the extent such assistance requires resources beyond standard product features, reasonable and documented costs may be charged as agreed between the Parties.
5.6. The Data Processor shall immediately draw the Data Controller's attention to the fact if, in its opinion, an instruction issued by the Data Controller violates statutory provisions. The Data Processor shall be entitled to suspend the implementation of the relevant instruction until it is confirmed or amended by the responsible person at the Data Controller after review.
5.7. The Data Processor shall correct, delete or restrict the processing of personal data arising from the contractual relationship if the Data Controller requests this by means of an instruction and the Data Controller's legitimate interests do not conflict with this.
5.8. The Data Processor may only provide information about personal data from the contractual relationship to third parties or the person concerned after prior instruction or approval by the Data Controller.
5.9. The Data Controller shall be entitled to convince itself of the compliance with the provisions on data protection and data security to a reasonable and necessary extent itself or through third parties commissioned by the Data Controller. For this purpose the Data Processor provides the Data Controller upon request with further documentation (e.g. certificates, list of processing activities, etc.)
5.10. The Data Processor confirms that it is aware of the data protection regulations of the GDPR that are relevant for the processing.
5.11. The Data Processor warrants that it will familiarize the staff employed in the performance of the work with the data protection provisions applicable to them before they commence their activities and that it will oblige them in an appropriate manner to maintain confidentiality for the duration of their activities as well as after termination of the employment relationship.
5.12. The Data Processor’s data protection officer can be contacted at dpo@milytech.com. The Data Controller must be informed immediately of any change of data protection officer.
6. Notification obligations of the Data Processor in the event of processing disruptions and personal data protection violations
The Data Processor shall notify the Data Controller without undue delay of any disruptions, violations of provisions under data protection law by the Data Processor or the persons employed by the Data Processor, as well as of any suspected data protection violations or irregularities in the processing of personal data.
Data Processor shall notify Data Controller without undue delay after becoming aware of a personal data breach. Furthermore, Data Processor assures to adequately assist Data Controller, taking into account the nature of the processing and the information available to Data Processor, in ensuring compliance with Data Controller’s obligations pursuant to Art. 33 and Art. 34 GDPR to (i) document any personal data breach, (ii) notify the applicable supervisory authority on any personal data breach and (iii) communicate such personal data breach to the data subject in accordance with GDPR.
7. Subprocessors
The Data Processor shall only be permitted to appoint subprocessors to process the Data Controller's data with the Data Controller's prior express written consent. The Data Processor must ensure that it carefully selects the subprocessor, paying particular attention to the suitability of the technical and organizational measures taken by the subprocessor within the meaning of Article 32 of the GDPR.
Subprocessors that process personal data in third countries may only be engaged if the special requirements of Art. 44 et seq. GDPR are met.
The Data Processor shall contractually ensure that the agreed regulations between the Parties also apply to subprocessors. In the contract with the subprocessor, the details shall be specified in such concrete terms that the responsibilities of the processor and the subprocessor are delimited from each other. If subprocessors are appointed, the Data Controller is entitled to carry out checks regarding the processing activities of those subprocessors in the same way the Data Processor is entitled.
The contract with the subprocessor must be in writing.
The Data Processor shall be liable to the Data Controller for ensuring that the Subprocessor complies with the data protection obligations contractually imposed on it by the Data Processor in accordance with this section of the Agreement.
At present, the subprocessors specified in Annex 2 with name, address and order content are engaged by the Data Processor with the processing of personal data to the extent specified therein. The Data Controller declares its consent to the commissioning of these subprocessors.
8. Transfers to third countries
If Data Processor transfers personal data outside the EU/EEA or engages a Sub-Processor to process personal data outside the EU/EEA, Data Processor shall do so in accordance with applicable legislation (GDPR) and shall demonstrate that a valid legal ground applies to the transfer.
In addition, at least one of the following prerequisites shall be fulfilled:
When relevant, Data Processor shall enter into the European Commission’s Standard Contractual Clauses with any Sub-processor.
9. Technical and organizational measures
A level of protection appropriate to the risk to the rights and freedoms of the natural persons concerned by the processing is ensured for the specific commissioned processing. To this end, the protection objectives of Article 32 (1) of the GDPR, such as confidentiality, integrity and availability of the systems and services, as well as their resilience in relation to the type, scope, circumstances and purpose of the processing operations, are taken into account in such a way that the risk is permanently mitigated by appropriate technical and organizational remedies.
The Data Processor has carried out a risk assessment in accordance with the requirements of Article 32 of the GDPR and, taking into account the result of the risk assessment, has taken the technical and organizational measures set out in Annex 3.
The Data Processor shall, as the occasion arises, but at least annually, conduct a review, assessment and evaluation of the effectiveness of the technical and organizational measures to ensure the security of the Processing.
The measures taken by the Data Processor may be adapted to technical and organizational developments during the course of the contractual relationship, but must not fall below the agreed standards.
Data Processor shall reasonably inform Data Controller from time to time in advance of any changes to the previously agreed upon technical and organisational measures it plans to implement in order to protect the personal data processed on behalf of Data Controller.
Data Processor shall ensure that (i) only authorized employees who need access to the personal data in order for Data Processor to provide the Services under this DPA have access to the personal data, (ii) the authorized employees process such personal data only in accordance with this DPA and Data Controller’s instructions and (iii) each authorized employee is bound by a confidentiality undertaking towards Data Processor in relation to the personal data.
10. Obligations of the Data Processor upon termination
After termination or expiry of the Agreement, and unless instructed otherwise in writing by Data Controller, the Data Processor shall hand over to the Data Controller or, at the Data Controller's discretion, delete or have destroyed in accordance with data protection law all data, documents and processing or utilization results created which come into its possession and to subprocessors and which are related to the contractual relationship and with regard to which the Data Controller is the responsible party within the meaning of the GDPR. Data Processor is, in any way, exempted from such erasure where storage of personal data is required pursuant to European Union law or the Member State’s national law. If the Data Controller chooses to delete or destroy data and documents instead of handing them over, the costs incurred in this connection shall be borne by the Data Controller. Subject to written request by the Data Controller, Data Processor shall erase all existing copies of personal data within thirty (30) days following the effective date of termination or receipt of the Data Controller's written instructions.
The deletion or destruction shall be confirmed to the Data Controller in writing or in a documented electronic format, stating the date.
11. Term and Termination
The DPA ends when the Agreement ends.
Both Parties may terminate this DPA at any time without notice if there is a serious breach of data protection regulations or the provisions of this DPA by one of the Parties.
12. Confidentiality
The provisions regarding confidentiality made in the Agreement between the parties shall apply.
13. Liability
The regulations of Art. 82 GDPR apply.
For the avoidance of doubt, administrative fines are imposed on the Party in breach of its obligations and, in consequence, neither Party will bear the other Party’s administrative fines.
14. Miscellaneous
Amendments to this DPA must be made in writing or by Mily Technologies updating this webpage, provided that material changes will take effect 30 days after notice to Customer.
Should individual parts of this agreement be invalid, this shall not affect the validity of the remainder of the agreement.
Governing law and dispute resolution shall be governed in accordance with the provisions as stipulated in the Agreement.
Attachments
Annex 1 - Overview of the subject and purpose of the order and the nature and categories of personal data
Annex 2 - Overview of subprocessors
Annex 3 - Overview of the technical and organizational measures
Annex 1
Subject matter and purpose of the order as well as type and categories of personal data and processing operations
1. Description of the subject and purpose of the order and data processing:
The Data Processor processes the following data for the purposes of providing services under the Agreement and the applicable Order Form.
2. Processing operations
3. Categories of persons concerned (Data subjects)
4. Categories and types of personal data (Employees of the Data Controller)
5. Categories and types of personal data (End customers)
6. Categories of recipients of personal data
Annex 2
Overview of subprocessors appointed by the Data Processor
Annex 3
Overview of the technical and organizational measures
Pursuant to Article 32 GDPR, the Data Processor has implemented and maintains the following technical and organizational security measures to ensure a level of security appropriate to the risk of processing personal data: