Data Processing Agreement

Version 1.0 · Effective date: September 3, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Mise, operated by Mubangizi Moses ("Processor", "we"), and the organisation that uses the Service ("Controller", "you"). It applies wherever you use Mise to process personal data governed by the EU or UK General Data Protection Regulation, and it is entered into on the terms below when you accept the Terms of Service. It is available in English only; the English text governs.

1. Roles of the parties

You are the controller. You decide what operational data to put into Mise and why — your staff, your suppliers, your requests, purchase orders and prices. We process it only to provide the Service to you.

We are the processor for that data, and act only on your documented instructions. Your instructions are your use of the Service through its interface and any written instruction you send to privacy@miseapp.app. If we believe an instruction infringes data protection law we will tell you and may pause that processing.

Separately, we are an independent controller for the account and billing data of the individual who signs up, and for our own security logs. That processing is described in our Privacy Policy and is outside this DPA.

2. Subject matter, duration, nature and purpose

  • Subject matter: provision of the Mise procurement and approval workflow service.
  • Duration: the term of your subscription, plus the deletion window in section 9.
  • Nature: storage, retrieval, organisation, transmission and deletion by automated means.
  • Purpose: operating request approval, purchase ordering, delivery receipt, inventory and reporting for your organisation.

3. Categories of data subjects and personal data

Data subjectsPersonal data
Your staff and usersName, email address, role and capabilities, location and department assignment, approval history, actions recorded in the audit log
Your suppliers' contactsContact name, business email, phone number, language preference, order and communication history
Anyone appearing in an uploaded imageWhatever appears on a delivery note or receipt photograph you upload, including handwriting and signatures

Mise is not designed for special category data under Article 9. Please do not put it into the Service.

4. Our obligations

In accordance with Article 28(3) we:

  1. process personal data only on your documented instructions, including for transfers to a third country, unless required otherwise by law — in which case we will inform you first unless that law forbids it;
  2. ensure that everyone authorised to process the data is bound by confidentiality;
  3. take the security measures required by Article 32, described in section 6;
  4. engage sub-processors only on the terms in section 5;
  5. assist you, by appropriate technical and organisational measures, to respond to requests from data subjects exercising their rights;
  6. assist you with your obligations under Articles 32 to 36, including security, breach notification and data protection impact assessments;
  7. delete or return the data at the end of the service, per section 9;
  8. make available the information needed to demonstrate compliance with this Article, and allow for and contribute to audits per section 8.

5. Sub-processors

You give general written authorisation for us to engage the sub-processors listed below. We impose data protection obligations on each of them no less protective than those in this DPA, and we remain fully liable to you for their performance.

Sub-processorPurpose
SupabaseDatabase and authentication — holds all Service data
VercelApplication hosting and edge delivery
ResendTransactional email
MetaWhatsApp Business Cloud API — supplier order notifications
Google Cloud VisionOCR on delivery note images
GroqAI parsing of inbound supplier messages
UpstashRate limiting — briefly holds IP addresses
SentryError monitoring — payloads can carry personal data
Dodo PaymentsMerchant of record for payments and invoicing

We will give you at least 30 days' notice by email before adding or replacing a sub-processor. If you reasonably object on data protection grounds within that period, you may terminate your subscription for the affected service without penalty and receive a pro-rata refund of prepaid fees.

6. Security

Measures in place include:

  • encryption in transit (TLS) and at rest;
  • tenant isolation enforced in the database by row level security, not only in the application, so a bug in the interface cannot expose another organisation's data;
  • role and capability based access control, enforced on every server action and every database policy;
  • an append-only audit log of approvals, rejections, deliveries and issuances, recording the acting user and timestamp;
  • least-privilege credentials, rotated on suspicion of exposure;
  • automated dependency and database security advisories, reviewed and acted on.

7. Personal data breaches

We will notify you without undue delay after becoming aware of a personal data breach affecting personal data we process for you, so that you can meet your own 72-hour deadline to your supervisory authority. Our notice will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Where we cannot provide all of it at once we will provide it in phases without further undue delay.

8. Audit

On reasonable written request, and no more than once in any twelve-month period unless a breach or a supervisory authority requires otherwise, we will provide the information necessary to demonstrate compliance with this DPA, and will contribute to an audit conducted by you or an independent auditor you mandate. Audits must be conducted during business hours, with reasonable notice, subject to confidentiality, and without unreasonably disrupting the Service or affecting other customers.

9. Return and deletion

You can export your data at any time during your subscription. On termination we delete the personal data we process for you within 30 days, unless retention is required by law, in which case we isolate it and stop all other processing. Backups are purged on their normal rotation, no later than 90 days.

10. International transfers

Mise is operated from outside the European Economic Area, and the sub-processors above operate globally. Where personal data is transferred out of the EEA or the UK to a country without an adequacy decision, the transfer is made under the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where UK data is involved, which are incorporated into this DPA by reference. We carry out transfer risk assessments and apply supplementary measures where required.

11. How to enter into this DPA

This DPA takes effect when you accept the Terms of Service, without any further signature. If your procurement process requires a signed copy or your own paper, write to legal@miseapp.app and we will execute one.

Questions about this agreement or about how we process data: privacy@miseapp.app