← Back to Security

Data Processing Agreement

Our standard DPA is automatically incorporated into every paid subscription under Section 9 of the Terms of Service. You can download the latest version for your records below.

Michi DPA v1.0

Effective 2026-05-21 — covers Article 28 GDPR obligations, Standard Contractual Clauses (EU-US transfers), the sub-processor list, and security measures (Annex II).

Download DPA (PDF)

Note: this is a self-service template. If you need a counter-signed copy or custom terms (custom data residency, sub-processor restrictions, BAA for HIPAA workloads), contact us below.

Need a signed copy?

Enterprise customers on annual plans can request a counter-signed DPA at no extra cost. Email dpo@michiplatform.com with your organisation name and we'll return a signed PDF within 2 business days.

What the DPA covers

  • Roles: Michi is the Processor, you are the Controller.
  • Categories of data subjects and personal data (Annex I).
  • Sub-processor list and change-notification process — see /security/sub-processors.
  • Technical and organisational measures (Annex II).
  • International transfers — Standard Contractual Clauses 2021/914.
  • Audit rights and breach-notification timelines (72 hours per Art. 33).
  • Return and deletion of data upon termination.