Browse docs All docs
Docs / Data Processing Agreement (DPA)
Docdeploymill://docs/dpa

Data Processing Agreement (DPA)

Last updated: June 12, 2026

This Data Processing Agreement ("DPA") forms part of the agreement between DeployMill ("DeployMill", "we", "us") and the customer that accepts the Terms of Service or signs an enterprise order form referencing them (the "Customer", "you"), together, the "Agreement". It governs DeployMill's processing of personal data on your behalf when you use the DeployMill service: the neutral, agent-safe control plane for shipping web apps, including the MCP tool surface, the dashboard, and the managed primitives (compute, database, domain, secrets, source, object storage).

[Standard form.] This is DeployMill's standard DPA, published so that every customer processes under the same terms without a negotiation cycle. It applies automatically as part of the Terms of Service. Enterprise customers who need a signed and countersigned copy (for example, for a vendor file or an Article 28(9) written-form record) can request one from [email protected].

1. How this DPA is incorporated

  1. This DPA is incorporated into and forms part of the

    Terms of Service (or, where applicable, a signed enterprise agreement that references it). By using the service, you agree to this DPA on behalf of yourself and, to the extent required under Data Protection Law, on behalf of your authorized affiliates.

  2. If there is a conflict between this DPA and the Agreement regarding the

    processing of personal data, this DPA controls. If there is a conflict between this DPA and the Standard Contractual Clauses (where they apply), the Standard Contractual Clauses control.

  3. This DPA takes effect on the date the Customer accepts the Agreement and

    remains in force for as long as DeployMill processes Customer Personal Data.

2. Definitions

Terms such as "personal data", "processing", "controller", "processor", "data subject", and "supervisory authority" have the meanings given in Data Protection Law. In addition:

  • "Data Protection Law" means all data protection and privacy laws

    applicable to the processing of personal data under the Agreement, including the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the UK GDPR and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection ("FADP"), and applicable US state privacy laws (e.g. the CCPA/CPRA), in each case as amended or replaced.

  • "Customer Personal Data" means personal data contained in Customer

    Content that DeployMill processes on the Customer's behalf as a processor.

  • "Customer Content" means the data the Customer (or the Customer's

    connected AI agent, acting on the Customer's instructions) submits to or generates through the service: application source code, container images and build artifacts, database contents, object-storage objects, environment variables and secret values, application logs, and deployment configuration (including .deploymill/project.json).

  • "Account Data" means personal data relating to the Customer's own users

    of DeployMill (names, email addresses, authentication identifiers, organization membership, billing contacts, and support correspondence) for which DeployMill acts as an independent controller (see Section 3).

  • "Subprocessor" means a third party engaged by DeployMill to process

    Customer Personal Data on the Customer's behalf in connection with the service.

  • "Standard Contractual Clauses" or "SCCs" means the standard

    contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Implementing Decision (EU) 2021/914.

  • "UK Addendum" means the International Data Transfer Addendum to the EU

    SCCs issued by the UK Information Commissioner's Office under section 119A of the UK Data Protection Act 2018.

  • "Personal Data Breach" means a breach of security leading to the

    accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.

3. Roles of the parties

  1. **Customer application data: Customer is controller, DeployMill is

    processor.** For Customer Personal Data contained in Customer Content (the data inside the apps, databases, buckets, repositories, logs, and secrets you deploy and operate through DeployMill), the Customer is the data controller (or a processor acting for a third-party controller), and DeployMill is the Customer's processor. DeployMill engages Subprocessors as described in Section 7 and the maintained list at Subprocessors.

  2. Account and identity data: DeployMill is controller. For Account Data

    (the account, organization, authentication, billing, and support records of the Customer's own users of DeployMill), DeployMill is an independent controller. That processing is governed by the Privacy Policy, not by this DPA.

  3. Where the Customer is itself a processor for a third-party controller, the

    Customer warrants that its instructions to DeployMill, including this DPA, have been authorized by that controller, and DeployMill is engaged as the Customer's subprocessor.

  4. Each party will comply with its own obligations under Data Protection Law

    in respect of its role.

4. Scope and subject matter of processing

  1. Subject matter. DeployMill's provision of the service described in the

    Agreement: building, deploying, running, and operating the Customer's web applications and previews; provisioning managed databases, object storage, domains, and TLS; storing source code and secrets; and exposing logs, health, and an audit trail, driven primarily through MCP tools by the Customer's connected AI agent.

  2. Duration. The term of the Agreement, plus the deletion period in

    Section 11.

  3. Nature and purpose. Hosting, storage, transmission, retrieval, backup,

    and deletion of Customer Content as necessary to provide the service, and as further documented in Annex I.

  4. Types of personal data and categories of data subjects. As described in

    Annex I. The Customer determines what personal data its applications collect and store. DeployMill does not control or monitor the contents of Customer applications.

5. Customer instructions

  1. DeployMill will process Customer Personal Data only on the Customer's

    documented instructions, including with regard to international transfers, unless required to do otherwise by law to which DeployMill is subject, in which case DeployMill will inform the Customer of that legal requirement before processing, unless the law prohibits doing so on important grounds of public interest.

  2. The Customer's documented instructions are: (a) the Agreement and this DPA;

    (b) the Customer's use of the service's features and configuration, including instructions issued by the Customer's connected AI agent through the MCP tool surface and API. Actions taken by an agent the Customer has authorized via OAuth are the Customer's instructions for the purposes of this DPA, and are recorded in the service's audit trail; and (c) any other written instructions agreed by the parties.

  3. DeployMill will inform the Customer without undue delay if, in its

    opinion, an instruction infringes Data Protection Law. DeployMill is not obligated to perform a legal review of the Customer's instructions.

6. DeployMill's obligations as processor

  1. Confidentiality of personnel. DeployMill ensures that persons it

    authorizes to process Customer Personal Data are bound by contractual or statutory obligations of confidentiality, and access Customer Personal Data only as needed to provide and support the service (least privilege).

  2. Security. DeployMill implements and maintains appropriate technical

    and organizational measures designed to protect Customer Personal Data against Personal Data Breaches, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing. The current measures are described in Section 9 and summarized in Annex II. DeployMill may update them over time provided the updates do not materially reduce the overall level of protection.

  3. Data-subject requests. Taking into account the nature of the

    processing, DeployMill will assist the Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling the Customer's obligation to respond to data-subject requests (access, rectification, erasure, restriction, portability, objection). In practice, the Customer can satisfy most requests directly: the Customer controls its applications, databases, and object storage through the service's tools. If a data subject contacts DeployMill directly about Customer Personal Data, DeployMill will not respond substantively except to direct the data subject to the Customer, unless legally required, and will notify the Customer of the request without undue delay.

  4. Breach notification. DeployMill will notify the Customer **without

    undue delay, and in any event within 72 hours**, after becoming aware of a Personal Data Breach affecting Customer Personal Data. See Section 10.

  5. DPIA assistance. DeployMill will provide reasonable assistance to the

    Customer with data protection impact assessments and prior consultations with supervisory authorities under Articles 35 and 36 GDPR, to the extent the information needed is available to DeployMill and not otherwise available to the Customer (including via Trust & Security and this DPA's annexes).

  6. Compliance information. DeployMill will make available to the Customer

    the information necessary to demonstrate compliance with Article 28 GDPR, as described in Section 12 (Audit and inspection).

7. Subprocessors

  1. General written authorization. The Customer grants DeployMill general

    written authorization to engage Subprocessors to provide the service.

  2. The maintained list. The current Subprocessors, the data categories

    each receives, and the purpose of each engagement are documented at Subprocessors. That page is the authoritative list and is incorporated into this DPA by reference (see Annex III). Because DeployMill's primitives are provider-neutral interfaces with swappable backends, the list also notes which Subprocessors are only engaged for particular configurations (for example, a Neon or Supabase database backend versus the internal Postgres default, under which no third party receives your database content).

  3. Notification of changes. DeployMill will update the

    Subprocessors page before authorizing a new Subprocessor to process Customer Personal Data, and will provide a mechanism on that page to subscribe to change notifications (or, for enterprise customers, email notice to a nominated contact). Notice will be given at least 30 days before the new Subprocessor begins processing Customer Personal Data, except where a replacement is required urgently for security or continuity reasons, in which case DeployMill will notify as soon as reasonably practicable.

  4. Right to object. The Customer may object to a new Subprocessor on

    reasonable, documented data-protection grounds by emailing [email protected] within 30 days of notice. The parties will discuss in good faith. Where the service's provider-neutral architecture allows, DeployMill may offer a configuration that avoids the objected-to Subprocessor (for example, a different database backend). If no resolution is reasonably available, the Customer may terminate the affected portion of the service (or, if it cannot be separated, the Agreement) and receive a pro-rated refund of prepaid, unused fees for the terminated portion. This is the Customer's sole remedy for an objection.

  5. Flow-down. DeployMill will impose on each Subprocessor, by written

    contract, data-protection obligations that are materially no less protective than those in this DPA, in particular the security obligations of Article 28(3) GDPR. DeployMill remains fully liable to the Customer for the performance of each Subprocessor's obligations.

8. International data transfers

  1. DeployMill may process Customer Personal Data in

    [hosting region(s), to be confirmed by the operator] and in the regions of the Subprocessors listed at Subprocessors.

  2. Where the processing involves a transfer of personal data from the European

    Economic Area to a country without an adequacy decision, the parties hereby enter into the EU Standard Contractual Clauses (Module Two: controller-to-processor, and Module Three: processor-to-processor, as applicable), which are incorporated into this DPA by reference and completed as follows: (a) the Customer is the "data exporter" and DeployMill is the "data importer"; (b) Clause 7 (docking) is included, Clause 9 Option 2 (general authorization) applies with the notice period in Section 7.3, Clause 11 optional language is omitted, Clause 17 is governed by the law of the EU member state in which DeployMill is established, and Clause 18 selects the courts of that member state; and (c) Annexes I and II of the SCCs are populated by Annex I and Annex II of this DPA, and Annex III of the SCCs by Annex III of this DPA.

  3. For transfers from the United Kingdom, the UK Addendum is incorporated

    by reference and completed with the information in this DPA's annexes. For transfers from Switzerland, the SCCs apply as adapted for the FADP (references to the GDPR read as references to the FADP, and the competent authority is the Swiss FDPIC).

  4. If DeployMill adopts an alternative valid transfer mechanism (for example,

    an adequacy decision or a certified framework), that mechanism may apply in place of the SCCs to the extent it is valid, and the SCCs remain as a fallback.

9. Technical and organizational measures (TOMs)

DeployMill maintains the following measures, described in more detail at Trust & Security and summarized in Annex II:

  • Encryption in transit. TLS for all traffic to the control plane and to

    deployed applications, with certificates issued and renewed automatically via Let's Encrypt (Caddy ingress).

  • Encryption at rest for secrets. Org-scoped secrets are encrypted at rest

    with AES-256-GCM in DeployMill's secrets vault.

  • Human-only secret hand-off. Secret values are entered by a human through

    a single-use browser hand-off, are never returned to MCP clients, and never appear in an agent transcript. The connected AI agent can bind a secret to an app but can never read its value.

  • Tenant isolation. Customer applications run as containers on

    DeployMill's self-operated Kubernetes (k3s) infrastructure with hard per-organization tenant isolation. Managed databases and object-storage buckets are provisioned per organization and per app with scoped credentials.

  • Access control and least privilege. Authentication via OAuth 2.0 with

    PKCE (Better Auth), organization roles, and optional enterprise SSO (OIDC/SAML). Backend infrastructure credentials are held server-side and never exposed to clients or agents.

  • Audit logging. An append-only audit trail attributes every change to the

    authenticated identity (human or authorized agent) that made it.

  • Change safety. Preview environments are isolated from production

    (copy-on-write database branches and fresh storage per preview), deploys are health-gated with automatic rollback on failure, and configuration changes support dry-runnable diff/plan/apply.

  • Backups and recovery. Routine backups of the control-plane database and

    managed-database backends, with documented recovery procedures.

  • Personnel. Confidentiality obligations, least-privilege access, and

    security review of changes to high-risk areas (secrets hand-off, idempotency, tenancy boundaries).

10. Personal data breach notification

  1. DeployMill will notify the Customer without undue delay, and in any event

    within 72 hours of becoming aware of a Personal Data Breach, by email to the Customer's registered account email (and the nominated security contact, if one is on file).

  2. The notification will describe, to the extent then known: the nature of the

    breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed to address the breach, and a contact point ([email protected]). Information may be provided in phases as the investigation progresses.

  3. DeployMill will take reasonable steps to contain and remediate the breach

    and will cooperate with the Customer's reasonable requests for information needed for the Customer's own notification obligations. DeployMill's notification is not an acknowledgment of fault or liability.

  4. Operational incidents and status updates are also communicated via support

    channels. See [email protected] and the SLA for status communication.

11. Return and deletion of data

  1. During the term, the Customer can retrieve and delete Customer Content

    directly using the service's tools (source via the connected repository, database exports via the managed-database connection, object-storage objects via the bucket credentials, app deletion via delete_app).

  2. Upon termination or expiry of the Agreement, DeployMill will, at the

    Customer's choice, return (by making available for export for at least 30 days) and then delete, or delete without return, all Customer Personal Data (including managed databases, object-storage buckets, secrets, and stored configuration) unless retention is required by law, in which case DeployMill will isolate and protect the retained data and delete it when the legal requirement ends.

  3. Deletion from backups occurs as backups expire on their routine rotation

    schedule. Backups are not restored except for disaster recovery. Source code in the Customer's own GitHub repositories remains under the Customer's control and is not deleted by DeployMill.

  4. Upon written request to [email protected], DeployMill will

    confirm deletion in writing.

12. Audit and inspection

  1. DeployMill will make available to the Customer information reasonably

    necessary to demonstrate compliance with this DPA and Article 28 GDPR. In the first instance this is satisfied by: the Trust & Security documentation, the maintained Subprocessors list, this DPA's annexes, available third-party audit reports or certifications (as and when published), and written responses to reasonable security questionnaires (enterprise plans; request via [email protected]).

  2. Where Data Protection Law grants the Customer a mandatory audit right that

    the materials above do not satisfy, the Customer (or an independent auditor that is not a competitor of DeployMill, bound by confidentiality) may conduct an audit of DeployMill's relevant processing, subject to: at least 30 days' written notice, at most once per 12-month period (except after a Personal Data Breach affecting the Customer or where required by a supervisory authority), during business hours, without access to other customers' data or to information that would compromise platform security, and at the Customer's expense.

  3. DeployMill will inform the Customer if it believes an audit instruction

    infringes Data Protection Law.

13. Liability and relationship to the Agreement

  1. Each party's liability arising out of or related to this DPA (including the

    SCCs, to the extent permitted) is subject to the limitations and exclusions of liability in the Terms of Service. This DPA does not create a separate or additional cap.

  2. Nothing in this section limits either party's liability to data subjects

    under the third-party-beneficiary provisions of the SCCs or any liability that cannot be limited under applicable law.

  3. This DPA supersedes any prior data-processing terms between the parties for

    the same subject matter. Except as amended by this DPA, the Agreement remains in full force. This DPA is governed by the law of the jurisdiction in which DeployMill is established, except where the SCCs require otherwise.

14. Contact

Questions about this DPA or DeployMill's data protection practices: [email protected]. Contract requests (including a countersigned copy of this DPA): [email protected].


Annex I. Details of processing

A. List of parties

RoleParty
Data exporter (controller, or processor for a third-party controller)The Customer, the organization that accepted the Agreement; contact details as registered in the Customer's DeployMill account
Data importer (processor)DeployMill, contact: [email protected]

B. Categories of data subjects

  • End users of the Customer's deployed applications (visitors, customers, and

    account holders of the Customer's apps).

  • The Customer's employees, contractors, and agents whose personal data

    appears in Customer Content (e.g. in source code, commits, configuration, application logs, or database records).

  • Any other individuals whose personal data the Customer chooses to store or

    process in its applications, databases, or object storage.

C. Categories of personal data

Determined by the Customer. Customer Content may include, by way of example:

  • Application database contents (internal Postgres by default, or Neon /

    Supabase backends), any personal data the Customer's app stores.

  • Objects in object storage (Cloudflare R2), uploads, media, datasets.
  • Application source code and repository contents (GitHub), which may

    incidentally contain personal data such as author names and emails.

  • Environment variables and secret values bound to the Customer's apps.
  • Application runtime logs, which may contain identifiers such as IP

    addresses, user IDs, or email addresses depending on what the Customer's app logs.

  • Deployment configuration and metadata (.deploymill/project.json, app and

    preview metadata, domains).

D. Special categories of personal data

None required by the service. The Customer determines whether its applications process special-category data. If so, the Customer is responsible for ensuring a lawful basis and for any heightened safeguards required, and should contact [email protected] before processing special-category data at scale on the service.

E. Nature and purpose of processing

Hosting, building, deploying, executing, storing, transmitting, backing up, exposing logs and health information for, and deleting the Customer's web applications and associated data, as instructed through the Customer's use of the service (including instructions issued by the Customer's authorized AI agent via MCP tools).

F. Duration of processing and retention

For the term of the Agreement, plus the return/deletion period in Section 11 (export window of at least 30 days, then deletion, and backups expire on routine rotation).

G. Frequency of the transfer

Continuous, for the duration of the service.

H. Subprocessor transfers

As set out in Annex III: subject matter, nature, and duration of subprocessor processing are documented per-vendor at Subprocessors.

Annex II. Technical and organizational measures (summary)

MeasureImplementation
Encryption in transitTLS on all control-plane and application traffic; automated certificate issuance/renewal (Caddy + Let's Encrypt)
Encryption at rest (secrets)AES-256-GCM secrets vault; secret values never returned to MCP clients or agent transcripts
Secret hand-offSingle-use, human-only browser hand-off for secret entry; agents may bind but never read secrets
Tenant isolationPer-organization isolation on self-operated Kubernetes (k3s); per-org/per-app databases and buckets with scoped credentials
Access controlOAuth 2.0 + PKCE (Better Auth); organization roles; enterprise SSO (OIDC/SAML); backend credentials held server-side only
AuditabilityAppend-only audit trail attributing every change to the authenticated human or agent identity
Change safetyIsolated preview environments (copy-on-write DB branches, fresh storage); health-gated deploys with automatic rollback; dry-runnable diff/plan/apply
Availability & recoveryRoutine backups of control-plane and managed databases; documented recovery runbooks; see the SLA
Personnel & processConfidentiality obligations; least-privilege access; security review of changes to high-risk areas
Subprocessor managementWritten flow-down contracts; maintained public inventory with data categories per vendor

Full descriptions: Trust & Security.

Annex III. Subprocessors

The authorized Subprocessors, the categories of Customer Personal Data each receives, the purpose of each engagement, and configuration-dependent notes (including which backends are engaged only when the Customer selects them) are maintained at Subprocessors, which is incorporated into this DPA by reference. That page (not a static list in this annex) is the source of truth: because DeployMill's primitives are provider-neutral with swappable backends, the vendor list can change, and the page is updated before any new Subprocessor processes Customer Personal Data, with notice and objection rights as described in Section 7.