Skip to the content

Legal

Data Processing Agreement

Version 2026-10-11 · Effective 11 October 2026

How we process, on your behalf, the personal data you send through Milkxi: the agreement Article 28 of the GDPR asks a controller and a processor to have.

01The parties, and how this agreement applies

This Data Processing Agreement (the “DPA”) is between you, the customer under the Terms of Service, and QWEST Ι.Κ.Ε. (“we”, “us”). For the personal data you send through Milkxi, you are the controller and we are the processor, in the sense that Article 4 of the General Data Protection Regulation (GDPR) gives those words.

Legal name
QWEST Ι.Κ.Ε. (QWEST P.C.)
Legal form
a private company (Ιδιωτική Κεφαλαιουχική Εταιρεία) under the laws of Greece
Registered office
Aristotelous 11-15, 104 32 Athens, Greece
General Commercial Registry (Γ.Ε.ΜΗ.)
189031301000
VAT number
EL803084930
Email
aristogiannisphilippis@gmail.com

The DPA is part of the Terms of Service. It applies whenever you send personal data through the service, from the moment you accept the terms, and it needs no signature. If you need a signed copy, write to us (clause 13) and we send one. Where this DPA and the terms say different things about personal data, this DPA prevails.

If the GDPR does not apply to you, this DPA still describes how we process the data you send, and where the data protection law of your own country has rules of the same kind, they take the place of the articles named here.

02Definitions

GDPR
Regulation (EU) 2016/679, the General Data Protection Regulation.
Personal data, processing, controller, processor, data subject, personal data breach
What Article 4 of the GDPR says they are.
Customer data
The personal data in what you send to the API and in what it sends back: your prompts, the messages of your users, and the answers.
Sub-processor
A company we use to process customer data on your behalf.
Standard contractual clauses
The clauses the European Commission adopted for transfers of personal data to a country outside the European Economic Area (Decision (EU) 2021/914).

03What is processed, why, and for how long

Subject matter and purpose. We receive each request you send to the API, pass it to the model that answers it, and return the answer to you. We record the metadata of the request for billing, as the Privacy Policy describes. That is the whole of the processing.

Nature. Transmission and transient processing in memory, to produce the answer. We don't store your prompts or completions. Customer data is written to no database, log or backup of ours.

Duration. For as long as the Terms of Service are in force between us. Each request is processed for the seconds or minutes it takes to answer, and nothing of it is kept afterwards.

Types of personal data. Whatever you put in a request. We neither know nor control it; typically it is the text your users write, with the names, contact details and other facts that such text contains. It may include special categories of personal data only where you have a lawful basis to process them (clause 4).

Categories of data subjects. The users of your product, your staff, and the people your requests are about.

04Your responsibilities

As the controller, you:

  • have a lawful basis for the processing you ask us to do, give your own users the information the GDPR requires, and answer for your own compliance with it;
  • give us your instructions through the terms, this DPA and the requests you send to the API, and send no instruction that would break the law;
  • send no personal data you have no right to send, and no special categories of personal data, data about criminal convictions, or data of children, unless you have a lawful basis for it and have taken the care such data needs;
  • keep to the acceptable-use clause of the Terms of Service;
  • keep your API keys secret and revoke a key that may have leaked: a request made with your key is your instruction.

05Our obligations

As your processor, under Article 28(3) of the GDPR, we:

  • process customer data only on your documented instructions, including for a transfer to a country outside the European Economic Area, unless the law we are subject to requires otherwise, in which case we tell you first unless that law forbids it; and we tell you at once if we think an instruction breaks the GDPR or another data protection law;
  • make sure that everyone we allow to process customer data is bound by a duty of confidentiality, by contract or by law;
  • take the technical and organisational measures of clause 12;
  • engage sub-processors only as clause 6 allows;
  • help you answer requests from data subjects who use their rights. Because we store no customer data, such a request can only be answered from what you hold; we help with what we do hold, which is the metadata of requests;
  • help you meet your obligations under Articles 32 to 36 of the GDPR, on security, on personal data breaches, on data protection impact assessments and on prior consultation, taking into account what we know and what we have;
  • at the end of the agreement, delete customer data. Because we keep none, there is nothing to delete or return; the metadata of requests is kept and then deleted as the Privacy Policy says, and backups of our database, which hold no customer data, are kept for 7 days;
  • give you the information you need to show that we meet these obligations: we answer written questions, we provide our security documentation, and, where that does not suffice, we allow an audit by you or by an auditor you appoint, once in any twelve months, on 30 days’ notice, during working hours, under confidentiality, without access to the data of other customers, and at your cost. An audit required by a supervisory authority is allowed whenever the authority requires it.

06Sub-processors

You authorise us in general terms to use sub-processors. Those we use now, with what each does, where, and what safeguards the transfer, are:

  • Amazon Web Services, Inc. — hosts the site, the API and the database, runs the model that answers requests, and sends our email. Location: United States (the us-east-1 region, in Northern Virginia). Transfer safeguard: certified under the EU-U.S. Data Privacy Framework; its data processing addendum includes the standard contractual clauses of the European Commission.
  • Stripe, Inc. and Stripe Payments Europe, Limited — takes payments: it collects card details, the billing address and the tax ID on its own pages, charges the card and emails the receipt. Location: United States and Ireland. Transfer safeguard: Stripe, Inc. is certified under the EU-U.S. Data Privacy Framework; its data processing agreement includes the standard contractual clauses of the European Commission.

Before a new sub-processor processes customer data, or an existing one takes on a new role, we tell the owners of your workspaces by email at least 30 days in advance, and we update this page. You may object within those 30 days, on reasonable grounds relating to data protection, by writing to us. If we cannot meet the objection, you may end the Terms of Service before the change takes effect, and we refund the unused purchased credits of your workspaces.

We hold every sub-processor to data protection obligations no less protective than those of this DPA, by a written contract, and we remain fully liable to you for what a sub-processor does with customer data.

07International transfers

The model runs, and our data is held, in the United States, as clause 6 says. Customer data therefore leaves the European Economic Area each time a request is answered.

Each transfer is safeguarded in two ways. The companies in clause 6 are certified under the EU-U.S. Data Privacy Framework, which the European Commission has found to give adequate protection (its decision of 10 July 2023). In addition, our agreement with each of them includes the standard contractual clauses, so that the transfer stays lawful should the Framework ever cease to apply. We assess the law of the country of destination before we rely on the clauses, and we keep the assessment; you may ask us for a copy of it and of the clauses.

You authorise these transfers. If you yourself are outside the European Economic Area, you are responsible for the lawfulness of the transfer of customer data from your own country to us.

08Personal data breaches

If we become aware of a personal data breach that affects customer data, we tell the owners of the affected workspaces by email without undue delay, and in any case within 48 hours of becoming aware of it. The notice says what happened, which data and how many people are likely affected, what the consequences are likely to be, and what we have done and propose to do about it, as far as we know at the time; we send what we learn later as we learn it.

We help you meet your own duties to the supervisory authority and to the people affected, under Articles 33 and 34 of the GDPR. A notice from us is not an admission of fault.

09Liability

Each of us is liable to the other for a breach of this DPA as the Terms of Service say, including their limit of liability and its carve-outs. Nothing in this DPA limits the liability of either of us to a data subject under Article 82 of the GDPR.

10Term and termination

This DPA is in force for as long as the Terms of Service are, and ends with them. Clause 5 applies to the end of the processing. Clauses 8, 9 and 11 outlast the DPA for as long as the law gives them effect.

11Governing law

This DPA is governed by the law that governs the Terms of Service, Greek law, and the courts of Athens, Greece decide disputes about it, as the terms say.

12Technical and organisational measures

The measures we take to protect customer data and the other personal data we hold, as Article 32 of the GDPR requires, are these:

  • Encryption in transit. Every connection to the site and to the API, and every connection from our servers to our sub-processors, uses TLS.
  • Encryption at rest. The database, its backups and the secrets of the service are encrypted at rest by our hosting provider.
  • No storage of customer data. Prompts and answers are processed in memory and written to no database, log or backup. Logs hold the metadata of a request and never its content; per-request metadata is deleted after 90 days.
  • Access control. API keys are stored as hashes and shown once; the dashboard holds each member to the role they were given; access to production systems is limited to the people who operate the service, who sign in with their own credentials; the servers and the database are reachable only from inside our private network.
  • Least privilege. Each part of the service holds only the permissions it needs, and secrets are kept in a secrets manager, never in code.
  • Resilience. The database is backed up daily, and the backups are kept for 7 days; the service runs on more than one server, and alarms tell the people who operate it of errors, of unusual spending and of a slow or failing provider.
  • Accountability. Changes made in a workspace are written to an audit log with who made them, and so are the actions the people who operate the service take on it.
  • Supply chain. Our dependencies are pinned and installed from a locked list, and every change to the service passes automated tests, including tests that no output of the API names a provider or holds a secret.

13Contact

If you have a question about this agreement, write to aristogiannisphilippis@gmail.com.