Data Processing Agreement
This agreement forms part of the Terms of Service between your organisation and us, and applies whenever we process personal information in your workspace on your behalf.
1. Roles
You are the controller (the “responsible party” under the Protection of Personal Information Act, POPIA) of the personal information in your workspace. Applied Optimisation UK Ltd is your processor (“operator” under POPIA) and processes it only to provide Mittral.
2. Details of the processing
| Subject matter and purpose | Providing Mittral: purchase requests, approvals, purchase orders (POs), emailing POs to suppliers, notifications, storage of attachments, billing administration and support. |
|---|---|
| Duration | While you use Mittral, then until deletion under clause 9. |
| Data subjects | Your users; your suppliers’ contacts; other people named in requests, notes or attachments. |
| Personal information | Names, business email addresses, roles, approval decisions and audit records; supplier contact details; any personal information in requests, notes or attached files. |
| Special personal information | Not needed for the service. Please don’t put it in requests or attachments. |
3. Instructions
We process personal information only on your documented instructions, which are these terms and the way you and your users configure and use Mittral, unless the law requires otherwise; in that case we will tell you first where the law allows. We will tell you if we believe an instruction breaks data-protection law.
4. Confidentiality
Everyone we authorise to process your personal information is bound by confidentiality.
5. Security
We apply the technical and organisational measures in the annex, as required by Article 32 GDPR and sections 19 and 21 of POPIA, and keep them appropriate to the risk.
6. Subprocessors
You authorise us to use the subprocessors on our subprocessors page. We impose data-protection obligations on them equivalent to this agreement and remain responsible for them. We will notify your workspace admins of a new subprocessor at least 30 days in advance; if you object on reasonable data-protection grounds and we can’t resolve it, you may end the affected service.
7. Helping you
Taking into account the nature of the processing, we will help you respond to requests from data subjects, and with security, breach notification, impact assessments and consultations with supervisory authorities.
8. Personal-information breaches
We will tell you without undue delay, and in any case within 72 hours, after becoming aware of a breach affecting your personal information (a security compromise under section 22 of POPIA), with the information you need to meet your own obligations.
9. Return and deletion
Your workspace admins can export all personal information in your workspace at any time during the service, from Settings → Workspace data, as JSON and CSV files with every stored file.
When a workspace admin deletes the workspace, it is closed at once, and 30 days later we delete it permanently: its records in our database, its files in storage, and its organisation with our sign-in provider. Until then your admins can cancel the deletion or export the data. People’s sign-in accounts are not deleted with a workspace, because they may use other workspaces. A person can delete their own account: they leave every workspace, their drafts and devices are deleted, and their name and email are removed from their account and their sign-in deleted; the requests, approvals, purchase orders and activity records they took part in stay in your workspace, under the name they were made with, until you delete them with the workspace. Deleted information can remain in our point-in-time recovery and encrypted backups for up to 90 days, after which it is overwritten; we don’t use it in that time other than to restore the service.
Records we must keep by law, such as billing records, are kept only as long as required.
10. Information and audits
We will make available the information needed to show compliance with this agreement and allow for reasonable audits. We will first answer written questions and share our providers’ security reports where we can. If that isn’t enough to show compliance, you (or an independent auditor bound by confidentiality) may audit us no more than once in any 12 months, unless a breach or a regulator requires more, on at least 30 days’ written notice, during business hours, without access to other customers’ information, and at your cost.
11. International transfers
We are based in the United Kingdom, and the database and files are held in Western Europe. Our providers may process personal information outside the United Kingdom and the European Economic Area, mainly in the United States. Where they do, and the country is not covered by a UK or EU adequacy decision, the transfer is protected by the safeguards in our agreements with them: the UK International Data Transfer Addendum or the EU standard contractual clauses, or the provider’s certification under the UK–US Data Bridge and the EU–US Data Privacy Framework. Where you are in the European Economic Area or the United Kingdom and a transfer from you to us needs a safeguard, the EU standard contractual clauses (module two, controller to processor) and the UK Addendum to them are incorporated into this agreement, with the details of the processing in clause 2 and the measures in the annex.
12. Liability
Each party’s liability under this agreement is subject to the limits in the Terms of Service. Nothing in this agreement limits the rights of data subjects or of supervisory authorities.
Annex: technical and organisational measures
- Encryption in transit: Mittral and its providers are reached only over HTTPS (TLS).
- Workspace isolation: every query for workspace data is scoped to the workspace in code, the database refuses links between workspaces, and automated tests check that one workspace can’t read or change another’s data.
- Access control: sign-in through our identity provider with email verification and optional multi-factor authentication; roles per workspace; administrative actions limited to workspace admins.
- Files: attachments and PO PDFs are private and served only after checking the person may see them; there are no public file links. File types are checked from their content, and only PDF, JPEG and PNG files are accepted.
- Secrets: API keys and credentials are held as encrypted platform secrets, never in source code.
- Audit trail: approval decisions and important settings changes are recorded with who made them and when.
- Resilience: the database can be restored to any point in the last 30 days, and we keep separate encrypted backups outside our hosting provider.
- Email safeguards: supplier emails only from verified accounts, with daily sending limits per workspace.