Legal

GDPR Compliance

Last updated: 6 August 2026

Our Commitment to GDPR

MileKit is committed to full compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the UK GDPR as retained in UK law. This page explains our roles, lawful bases for processing, and the rights available to data subjects.

Data Controller vs. Data Processor

Data Controller
You (the MileKit customer)

You determine the purposes and means of processing your clients' personal data. You are responsible for obtaining your clients' consent to receive SMS and email communications and for providing them with your own privacy notice.

Data Processor
MileKit Ltd.

MileKit processes your clients' data strictly on your instructions — to send appointment reminders, review requests, and recall messages. We never use client data for any other purpose.

Lawful Basis for Processing

Contract: Processing your account data is necessary to perform our contract with you (providing the MileKit Service).
Legitimate Interest: Processing usage and analytics data to improve the platform, prevent fraud, and ensure security.
Legal Obligation: Retaining payment and billing records for 7 years to comply with tax and financial regulations.
Consent (your clients): Your clients' data is processed under the consent they have given you (as their service provider) to receive reminder communications.

Your Rights as a Data Subject

If you are an EU or UK resident, you have the following rights regarding your personal data held by MileKit:

1
Right of Access — request a copy of your data
2
Right to Rectification — correct inaccurate data
3
Right to Erasure — request deletion of your data
4
Right to Restriction — limit how we use your data
5
Right to Portability — receive your data in a portable format
6
Right to Object — object to direct marketing processing
7
Right to Withdraw Consent — withdraw at any time
8
Right to Lodge a Complaint — with your supervisory authority

To exercise any right, email support@milekit.com. We respond within 30 calendar days.

International Data Transfers

Some of our sub-processors (including Supabase and Vercel) operate servers in the United States. All transfers are covered by Standard Contractual Clauses (SCCs) as approved by the European Commission, ensuring your data is protected to EU standards regardless of where it is processed.

Data Retention

Account data is retained for the duration of your subscription plus 90 days. Client data you have entered is deleted within 30 days of account deletion. Payment records are retained for 7 years to comply with financial regulations. You can request early deletion at any time.

Data Protection Officer

For GDPR-related enquiries or to exercise your rights:
MileKit Ltd. — Data Protection
support@milekit.com

You also have the right to lodge a complaint with your national data protection authority. In the UK: Information Commissioner's Office (ICO).