Data Processing Agreement
Version 1.0 · Effective date: September 3, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Mise, operated by Mubangizi Moses ("Processor", "we"), and the organisation that uses the Service ("Controller", "you"). It applies wherever you use Mise to process personal data governed by the EU or UK General Data Protection Regulation, and it is entered into on the terms below when you accept the Terms of Service. It is available in English only; the English text governs.
1. Roles of the parties
You are the controller. You decide what operational data to put into Mise and why — your staff, your suppliers, your requests, purchase orders and prices. We process it only to provide the Service to you.
We are the processor for that data, and act only on your documented instructions. Your instructions are your use of the Service through its interface and any written instruction you send to privacy@miseapp.app. If we believe an instruction infringes data protection law we will tell you and may pause that processing.
Separately, we are an independent controller for the account and billing data of the individual who signs up, and for our own security logs. That processing is described in our Privacy Policy and is outside this DPA.
2. Subject matter, duration, nature and purpose
- Subject matter: provision of the Mise procurement and approval workflow service.
- Duration: the term of your subscription, plus the deletion window in section 9.
- Nature: storage, retrieval, organisation, transmission and deletion by automated means.
- Purpose: operating request approval, purchase ordering, delivery receipt, inventory and reporting for your organisation.
3. Categories of data subjects and personal data
| Data subjects | Personal data |
|---|---|
| Your staff and users | Name, email address, role and capabilities, location and department assignment, approval history, actions recorded in the audit log |
| Your suppliers' contacts | Contact name, business email, phone number, language preference, order and communication history |
| Anyone appearing in an uploaded image | Whatever appears on a delivery note or receipt photograph you upload, including handwriting and signatures |
Mise is not designed for special category data under Article 9. Please do not put it into the Service.
4. Our obligations
In accordance with Article 28(3) we:
- process personal data only on your documented instructions, including for transfers to a third country, unless required otherwise by law — in which case we will inform you first unless that law forbids it;
- ensure that everyone authorised to process the data is bound by confidentiality;
- take the security measures required by Article 32, described in section 6;
- engage sub-processors only on the terms in section 5;
- assist you, by appropriate technical and organisational measures, to respond to requests from data subjects exercising their rights;
- assist you with your obligations under Articles 32 to 36, including security, breach notification and data protection impact assessments;
- delete or return the data at the end of the service, per section 9;
- make available the information needed to demonstrate compliance with this Article, and allow for and contribute to audits per section 8.
5. Sub-processors
You give general written authorisation for us to engage the sub-processors listed below. We impose data protection obligations on each of them no less protective than those in this DPA, and we remain fully liable to you for their performance.
| Sub-processor | Purpose |
|---|---|
| Supabase | Database and authentication — holds all Service data |
| Vercel | Application hosting and edge delivery |
| Resend | Transactional email |
| Meta | WhatsApp Business Cloud API — supplier order notifications |
| Google Cloud Vision | OCR on delivery note images |
| Groq | AI parsing of inbound supplier messages |
| Upstash | Rate limiting — briefly holds IP addresses |
| Sentry | Error monitoring — payloads can carry personal data |
| Dodo Payments | Merchant of record for payments and invoicing |
We will give you at least 30 days' notice by email before adding or replacing a sub-processor. If you reasonably object on data protection grounds within that period, you may terminate your subscription for the affected service without penalty and receive a pro-rata refund of prepaid fees.
6. Security
Measures in place include:
- encryption in transit (TLS) and at rest;
- tenant isolation enforced in the database by row level security, not only in the application, so a bug in the interface cannot expose another organisation's data;
- role and capability based access control, enforced on every server action and every database policy;
- an append-only audit log of approvals, rejections, deliveries and issuances, recording the acting user and timestamp;
- least-privilege credentials, rotated on suspicion of exposure;
- automated dependency and database security advisories, reviewed and acted on.
7. Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting personal data we process for you, so that you can meet your own 72-hour deadline to your supervisory authority. Our notice will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Where we cannot provide all of it at once we will provide it in phases without further undue delay.
8. Audit
On reasonable written request, and no more than once in any twelve-month period unless a breach or a supervisory authority requires otherwise, we will provide the information necessary to demonstrate compliance with this DPA, and will contribute to an audit conducted by you or an independent auditor you mandate. Audits must be conducted during business hours, with reasonable notice, subject to confidentiality, and without unreasonably disrupting the Service or affecting other customers.
9. Return and deletion
You can export your data at any time during your subscription. On termination we delete the personal data we process for you within 30 days, unless retention is required by law, in which case we isolate it and stop all other processing. Backups are purged on their normal rotation, no later than 90 days.
10. International transfers
Mise is operated from outside the European Economic Area, and the sub-processors above operate globally. Where personal data is transferred out of the EEA or the UK to a country without an adequacy decision, the transfer is made under the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where UK data is involved, which are incorporated into this DPA by reference. We carry out transfer risk assessments and apply supplementary measures where required.
11. How to enter into this DPA
This DPA takes effect when you accept the Terms of Service, without any further signature. If your procurement process requires a signed copy or your own paper, write to legal@miseapp.app and we will execute one.
Questions about this agreement or about how we process data: privacy@miseapp.app