Legal
Data Processing Agreement
Last updated: 2026-08-30. These terms apply when an organization enrolls its own people on Miatz and personal data about those people is processed on the organization’s behalf. They do not change anything for an individual who signed up on their own; that relationship is governed by the privacy policy.
In plain terms: your people’s data is yours. Miatz Private Limited holds it to run the program you asked for, on your written instruction, with the vendors named on the subprocessor register and nobody else. You can get it back, and you can have it deleted.
1. Parties, and how this takes effect
This agreement is between Miatz Private Limited (“miatz”, the processor) and the organization that enrolls its people (the “Customer”, the controller). It takes effect by reference from the order form, engagement letter or written agreement between us, and it forms part of the terms of service. Where a signed agreement and this page conflict, the signed agreement wins for the Customer that signed it.
An organization that wants this counter-signed as a standalone document, or that needs its own paper, should email hello@miatz.com. Nothing on this website takes payment; every engagement is invoiced against a written agreement, so there is always a document for this to attach to.
2. Roles
The Customer is the controller and determines the purposes and means of the processing. Miatz is the processor and acts only on the Customer’s documented instructions, which are: this agreement, the signed agreement between us, and the configuration choices the Customer’s administrators make in the product. Miatz will tell the Customer if an instruction appears to breach applicable data protection law, and may pause that processing until it is resolved.
Miatz is a controller in its own right for a narrow set of data it needs to run its own business — account security records, billing records, and aggregate product telemetry that identifies no individual. That processing is described in the privacy policy, not here.
3. What is processed (Annex 1)
- Subject matter and duration. Providing the learning platform to the Customer’s people, for as long as the agreement between us is in force, plus the return-or-delete window in §9.
- Nature and purpose. Hosting, storage, delivery of lessons and assessments, grading, progress and engagement reporting to the Customer’s administrators, notifications, support, and AI assistance where the Customer enables it.
- Categories of data subject. The Customer’s employees, contractors, interns, candidates and other people it enrolls, and the administrators it appoints.
- Categories of personal data. Identity and contact details; account credentials and sign-in method; role and organization membership; learning and assessment records, including submitted work, answers and the reasoning submitted with them; progress, engagement and presence signals; support and bug-report content; device and notification tokens; and the content of AI prompts and responses where AI assistance is enabled.
- Special categories. None are requested, and the product has no field for them. A Customer must not instruct miatz to process them.
- Frequency. Continuous, for the duration of the agreement.
4. Security (Annex 2)
Miatz maintains technical and organisational measures appropriate to the risk, and will not weaken them during the term. The measures in force are:
- Encryption in transit over HTTPS, and encryption at rest in the managed database and file storage.
- Row-level security in the database, so a person reaches only their own records and an administrator reaches only their own organization’s.
- Secrets — AI provider keys, calendar tokens, machine credentials — encrypted server-side and never returned to a browser. Machine credentials are stored hashed.
- Access to production restricted to the people who need it, with individual accounts and multi-factor sign-in.
- Managed, point-in-time database backups held by the hosting subprocessor named in the register.
- A published vulnerability disclosure policy with stated response times, and an internal record of every security incident, including the ones below the notification threshold.
Miatz holds no third-party security certification today. SOC 2 is on the roadmap; until it is complete, this list is the honest description of what is in place, and a Customer is entitled to treat it as a contractual commitment rather than marketing copy.
5. Confidentiality and personnel
Everyone at miatz with access to Customer personal data is bound by a written confidentiality obligation that survives the end of their engagement, is granted access only for a stated reason, and loses it when the reason ends. Mentors and reviewers see the work of the cohort they are assigned to, and nothing beyond it.
6. Subprocessors
The Customer gives general written authorisation for miatz to engage the subprocessors published on the subprocessor register. Each is engaged under a written contract imposing data protection obligations no less protective than these, and miatz remains liable to the Customer for their performance.
Before a new subprocessor starts processing, miatz publishes it on the register and gives at least 30 days’ notice to the Customer’s administrator contact. A Customer may object within that period; if miatz cannot offer a way to run without the new subprocessor, the Customer may terminate the affected service without penalty for the unused remainder of its term.
7. Helping you meet your own obligations
- Requests from your people. If someone at the Customer asks miatz directly for access, correction or erasure, miatz refers them to the Customer rather than acting on it, unless the Customer has instructed otherwise in writing. Miatz assists the Customer in answering, through the product where possible and by export where not.
- Impact assessments. Miatz provides the information reasonably needed for the Customer’s data protection impact assessment and any prior consultation with a regulator.
- Regulator contact. If a regulator contacts miatz about processing carried out for the Customer, miatz notifies the Customer unless the law forbids it.
8. Personal data breach
Miatz notifies the Customer without undue delay, and in any case within 72 hours of becoming aware of a personal data breach affecting the Customer’s data. The notice states what happened, the categories and approximate number of records involved, the likely consequences, what has been done to contain it, and the contact point for follow-up. Miatz notifies the Data Protection Board of India where the Digital Personal Data Protection Act 2023 requires it, and cooperates with the Customer’s own notifications.
9. Return and deletion
On termination, and at any time on written request, miatz exports the Customer’s data in a machine-readable format and then deletes it. Deletion happens within 30 days of the request or of the end of the agreement, whichever is later, except for records miatz must keep by law and for backups, which age out on their own retention cycle and are not restored for any other purpose.
A learner’s own credential record is theirs, not the Customer’s: a credential already issued to a person survives the organization leaving, because the whole point of it is that a stranger can still check it.
10. Audit
Miatz makes available the information needed to demonstrate compliance with this agreement, and allows an audit — by the Customer or an independent auditor it appoints — once in any twelve-month period, on thirty days’ notice, during business hours, at the Customer’s cost, and without access to another customer’s data or to any system a third party operates. A regulator’s audit is not limited by this paragraph.
11. Transfers out of India
Account, learning and assessment data is stored in India, in the regions named on the subprocessor register. The transfers that do leave India, and what each one carries, are itemised in the privacy policy. For those transfers miatz relies on its data processing agreement with each subprocessor, and where a transfer is also subject to EU or UK law, on the transfer mechanism in that subprocessor’s terms — typically the standard contractual clauses, which are incorporated into this agreement by reference for that purpose.
12. Liability, changes and contact
Liability under this agreement is governed by the limits in the signed agreement between us, and nothing here creates a separate cap or a separate exclusion. Miatz may update these terms as the product or the law changes; a change that materially reduces a Customer’s rights is notified to the administrator contact at least 30 days before it takes effect, and a Customer that objects may terminate the affected service without penalty. This agreement is governed by the laws of India, with the courts of Karnataka having jurisdiction.