Data Processing Agreement
Last updated: 3 October 2026
This Data Processing Agreement ("DPA") forms part of the MileMuster Terms of Service between Martinas Karinauskas, trading as MileMuster ("MileMuster", "we") and the business that subscribes to MileMuster (the "Customer", "you"). It applies whenever we process personal data on your behalf, and meets the requirements of Article 28 of the UK GDPR. You accept it by using the service; no signature is needed. If you'd like a signed copy, email hello@milemuster.co.uk.
1. Roles
For personal data you or your team, drivers and depot staff put into MileMuster ("Customer Personal Data"), you are the controller and MileMuster is the processor. For our own customer, billing and website data, MileMuster is the controller, as described in our Privacy Policy.
2. Details of the processing
| Subject matter | Providing the MileMuster route staffing service. |
|---|---|
| Duration | The length of your subscription, plus up to 90 days for deletion, and up to 30 days more for backups to expire. |
| Nature and purpose | Storing, organising, displaying and sending data so you can plan routes, contact and manage drivers and depot staff, record depot activity, calculate pay and hours, keep documents and sheets, and send phone alerts. |
| Categories of data subjects | Your drivers (usually self-employed), depot and office staff, and people named in sheets you create (e.g. contacts). |
| Types of personal data | Names, phone numbers, emails (office logins), availability and areas, licence and insurance expiry dates, uploaded documents (e.g. driving licence, insurance, right to work, photo ID), route bookings, timesheets, pay, hours and wages, notes, custom fields, sheet contents, device push-alert tokens, and activity logs. |
| Special category data | Not intended. Please don't record health or other special category data except where you have a lawful basis (for example, a sick day reason you choose to note). |
3. Our obligations
- We process Customer Personal Data only on your documented instructions, which are these terms and your use of the service, unless UK law requires otherwise (we'll tell you first where the law allows).
- Everyone at MileMuster who can access the data is bound by confidentiality.
- We keep appropriate technical and organisational security measures (see section 6).
- We use sub-processors only as set out in section 5.
- We help you respond to requests from people exercising their data rights (most can be handled directly in the app, e.g. exporting or deleting a driver).
- We help you with security, breach notification and data protection impact assessments, taking into account the information available to us.
- We tell you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting your data, with the information you need to meet your own obligations.
- At the end of the service we delete Customer Personal Data within 90 days (backups expire within a further 30 days), unless the law requires us to keep it. You can export your data at any time before then.
- We make available the information needed to show we meet these obligations, and allow for reasonable audits (normally by written questions, at most once a year, with 30 days' notice).
4. Your obligations
You confirm you have a lawful basis for the personal data you put into MileMuster, that you've told your drivers and staff how their data is used (you can link to our Privacy Policy), and that your instructions to us comply with data protection law.
5. Sub-processors
You authorise us to use these sub-processors. We'll give at least 30 days' notice of any new one (by email or in the app) so you can object; if we can't resolve a reasonable objection you may cancel and we'll refund any prepaid unused period.
| Sub-processor | What for | Location |
|---|---|---|
| Render Services, Inc. | Hosting the app and database | EU (Frankfurt, Germany) |
| Cloudflare, Inc. | Domain name service and email forwarding | Global network |
| Google (Firebase Cloud Messaging), Apple, Mozilla | Delivering phone alerts to devices that turned alerts on (alert text only) | Global |
| Backblaze, Inc. | Encrypted off-site backups (when enabled) | EU (Amsterdam, Netherlands) |
| Resend, Inc. | Sending account emails such as password resets (when enabled) | EU / USA |
Stripe (payments) and Anthropic (website support chat) process our own customer data as described in the Privacy Policy, not your drivers' or staff data. Where data is transferred outside the UK we rely on UK adequacy regulations or the International Data Transfer Agreement / Addendum.
6. Security measures
- Encrypted connections (HTTPS with HSTS) everywhere; strict browser security headers.
- Each customer's data is separated: every request is checked against the signed-in company.
- Passwords are stored hashed; drivers and depot staff use long random personal links that can be replaced at any time.
- Roles limit what each person sees (owner, driver manager, depot staff); depot staff only see what you share.
- Uploaded documents are stored outside any public folder, only served to the driver or the company's office, never cached.
- Protection against form forgery and brute force (rate limits on log in and sign-up).
- Activity log of who did what; daily backups; errors alert us immediately.
7. General
If this DPA conflicts with the Terms of Service, this DPA wins for data protection matters. Liability is as set out in the Terms of Service. This DPA is governed by the law of England and Wales.