Legal
Data Processing Agreement
Last updated: June 21, 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between you (the “Controller”) and Milistack operating Militime (the “Processor”). It describes how we process personal data on your behalf when you use Militime, and applies where Quebec's Law 25, Canada's PIPEDA or the EU GDPR govern that processing.
1. Roles and scope
For personal data you and your team enter into Militime about your own clients, staff and contacts, you act as the Controller and Militime acts as the Processor (or service provider). For personal data about your own account holders and website visitors, Militime is the Controller — that handling is governed by our Privacy Policy, not this DPA.
Militime processes Controller personal data only on the Controller's documented instructions, including those given through the product, except where applicable law requires otherwise.
2. Subject matter, duration, nature and purpose
Subject matter: provision of the Militime time-tracking, reporting and billing service. Duration: for the term of your subscription, plus the limited retention described below. Nature and purpose: hosting, storing and processing the data needed to track time, manage clients and projects, generate invoices and reports, and provide optional AI summaries.
3. Categories of data and data subjects
Depending on how you use Militime, Controller personal data may include:
- Data subjects: your clients and their contacts, your staff and team members.
- Data categories: names, email addresses, roles, time entries and notes, project and client records, rates, and invoice and billing details you enter.
4. Subprocessors
Militime engages a short list of subprocessors to deliver the service. We remain responsible for their compliance and will give notice of material changes so you can object:
- Supabase — database, authentication and storage hosting.
- Stripe — subscription and payment processing (card data is handled by Stripe; we do not store full card numbers).
- Vercel — application and marketing-site hosting, edge delivery and the AI gateway.
- Anthropic — large-language-model provider for optional AI summaries. Your content is not used to train models.
5. Security measures
Militime maintains technical and organizational measures appropriate to the risk, including:
- Encryption in transit (TLS 1.3) and at rest.
- Row-level access controls and workspace isolation, with role-based permissions.
- Least-privilege access to production systems and audit logging of sensitive actions.
- Payment data handled by a PCI-DSS Level 1 provider (Stripe).
6. Assisting with data-subject requests
Taking into account the nature of the processing, Militime provides tools and reasonable assistance to help you respond to data-subject requests (access, rectification, erasure, portability) and to meet your obligations under applicable privacy law.
7. Personal data breach notification
Militime maintains a register of confidentiality incidents and will notify you without undue delay after becoming aware of a personal data breach affecting Controller personal data, with the information you reasonably need to meet your own notification obligations.
8. International transfers
Where Controller personal data is transferred outside its jurisdiction of origin, Militime relies on lawful transfer mechanisms (such as standard contractual clauses) and conducts the assessments required under Law 25, PIPEDA or the GDPR, as applicable.
9. Return and deletion
On termination, Militime provides data portability/export and, at your choice, deletes or returns Controller personal data within a commercially reasonable period, except where retention is required by law.
10. Audits
On reasonable written request, and subject to confidentiality, Militime makes available the information necessary to demonstrate compliance with this DPA.
11. Contact
Questions about this DPA, or to request a signed copy, can be sent to privacy@militime.ai. Security matters can be reported to security@militime.ai.