Last Updated: August 19, 2026
This Data Processing Addendum (“DPA”) is incorporated by reference into Milyli’s Terms of Service available at https://blackout.now/legal/tos or other agreement governing the use of Milyli’s services (“Agreement”) entered by and between you, the Customer (as defined in the Agreement) (collectively, “you”, “your”, “Customer”, “Client”), and Milyli, Inc. (“Milyli”, “us”, “we”, “our”) to reflect the parties’ agreement with regard to the Processing of Personal Data by Milyli solely on behalf of the Customer. Both parties shall be referred to as the “Parties” and each, a “Party”.
Capitalized terms not defined herein shall have the meanings assigned to such terms in the Agreement.
By using the Services, Customer accepts this DPA and you represent and warrant that you have full authority to bind the Customer to this DPA. If you cannot, or do not agree to, comply with and be bound by this DPA, or do not have authority to bind the Customer or any other entity, please do not provide Personal Data to us.
In the event of any conflict between certain provisions of this DPA and the provisions of the Agreement, the provisions of this DPA shall prevail over the conflicting provisions of the Agreement, solely with respect to the Processing of Personal Data.
Milyli Client Privacy & Security Agreement
1. Definitions
For the purposes of this Agreement, the following terms and those defined within the body of this Agreement apply.
2. Data Handling and Access
General Compliance. Client shall, in its use of the Services, at all times Process Personal Data, and provide Instructions for the Processing of Personal Data, in compliance with Applicable Data Protection Laws. Client shall ensure that its Instructions comply with all laws, rules and regulations applicable in relation to the Personal Data, and that the Processing of Personal Data in accordance with Client’s Instructions will not cause Milyli to be in breach of the Data Protection Laws. Client is solely responsible for (i) the accuracy, quality, and legality of (1) Client Personal Data, (2) the means by which Client acquired any Client Personal Data, and (3) the Instructions it provides to Milyli regarding the Processing of Client Personal Data; and (ii) its compliance with the Applicable Data Protection Laws, including as Controller and Processor. Milyli shall Process Client Confidential Information in compliance with the terms of this Agreement, Milyli’s then-current Privacy Notice and, all Applicable Data Protection Law(s).
Milyli and Third-Party Compliance. Milyli agrees to (i) enter into a written agreement with Third Parties regarding such Third Parties’ Processing of Client Confidential Information that imposes on such Third Parties data protection and security requirements for Client Confidential Information that are compliant with Applicable Data Protection Law(s), that are consistent with and similar to the requirements under this Agreement; (ii) enforce compliance with such written agreement on Milyli’s Third Parties; (iii) enforce compliance with this Agreement on Milyli’s employees; and (iv) remain responsible to Client for the actions or omissions of Milyli’s employees and Milyli’s Third Parties with respect to the Processing of Client Confidential Information
Authorization to Use Third Parties. Client hereby authorizes Milyli to engage Third Parties in connection with its provision of the Services. Notwithstanding the foregoing, any transfer of Client Personal Data shall comply with all Applicable Data Protection Law(s) including those related to the cross-border transfers of Client EU Personal Data, if applicable. Milyli agrees that its Third Parties are reviewed for its adherence to security, privacy and confidentiality practices related to data. Upon written request from Client, Milyli shall make available to Client the then-current list of Third Parties used to provide the Services. Subject to confidentiality obligations Milyli may have, Milyli will provide Client, upon Client’s request, any records that Processors are required to maintain and provide under Applicable Data Protection Law(s). Should Client object to the use of a Third Party, Client is to provide written notice to Milyli of its reasonable grounds of objection for using said Third Party. Milyli will use reasonable efforts to make available to Client a change in Services to avoid Processing of Client Personal Data by the objected-to Third Party without unreasonably burdening Client. If Milyli is unable to make available such change within a reasonable period of time (which shall not exceed thirty (30) days unless a longer period of time is agreed between parties), Client may terminate the applicable Agreement(s) with respect only to those Services which may not be provided by Milyli without the use of the objected-to Third Party by providing thirty (30) days written notice to Milyli. Both parties acknowledge and agree that said termination without penalty or refund is Client’s sole option and remedy for Client’s objection to the use of a Third Party. If a Third Party is discovered not be in compliance with applicable Data Protection Law(s) or this Agreement, Milyli agrees to take commercially reasonable corrective steps, and either cure the Third-Party performance or cease using such Third Party.
Following Instructions. Milyli shall Process Client Confidential Data only in accordance with the Instructions of Client or as specifically authorized by this Agreement or the Agreement. If Milyli reasonably believes that there is a conflict between Client’s Instructions and applicable law or otherwise seeks to Process Client Confidential Data in a manner that is inconsistent with Client’s Instructions, Milyli agrees to, unless legally prohibited from doing so, (i) promptly inform Client; (ii) cooperate with Client in good faith to resolve any conflict; and (iii) not Process Client Confidential Data outside of Client’s Instructions until Client expressly authorizes Milyli in writing to do so.
Confidentiality. Any person authorized to Process Client Confidential Information must expressly agree in writing to maintain the confidentiality of such information or be under an appropriate statutory or contractual obligation of confidentiality. Client Confidential Information shall not be sold, rented or leased to any third party. Client Confidential Information shall not be disclosed to any third party without the prior written consent of Client, except as may be otherwise expressly permitted in the Agreement.
Security of Processing. Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Client and Milyli shall, in relation to Client Personal Data, implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including as appropriate: (i) the pseudonymization and encryption of Personal Data; (ii) the ability to ensure the ongoing confidentiality, integrity, availability and resilience of Processing systems and services with respect to Client’s Personal Data; (iii) the ability to restore the availability and access to Client’s Personal Data in a timely manner in the event of a physical or technical incident; and (iv) a process for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures for ensuring the security of the Processing of Client’s Personal Data.
Personal Data Inquiries and Requests. Milyli agrees to comply with all reasonable Instructions from Client related to (i) any questions or complaints received from individuals regarding Client Personal Data received or collected by Milyli (“Privacy Inquiry”) and (ii) any requests from individuals exercising their rights in Client Personal Data received or collected by Milyli granted to them under Applicable Data Protection Law(s) or Milyli’s then-current Privacy Notice (“Privacy Request”) and, upon Client’s request, confirm its compliance with the foregoing to Client within a reasonable time. If Milyli is directly contacted with a Privacy Inquiry or Privacy Request, Milyli must forward such inquiry to Client without undue delay within three (3) business days. If Milyli receives a Privacy Request and the period to provide an answer to it under Applicable Data Protection Law(s) is equal to or shorter than 72 hours, Milyli must forward such Privacy Request to Client within 48 hours. Unless otherwise required by Applicable Data Protection Law(s), Milyli must take action regarding a Privacy Inquiry or a Privacy Request only as approved or directed by Client. At Client’s request and without undue delay, Milyli agrees to assist Client in answering to or complying with any Privacy Inquiry or Privacy Request. Additionally, Milyli agrees to put in place commercially reasonable technical and organizational measures to assist Client in complying with Privacy Requests if required by Applicable Data Protection Law(s).
3. EU – U.S. Compliance
This Section applies where the Client transfers Client EU Personal Data outside of the European Union to Milyli. Notwithstanding the foregoing, Client agrees that any Client EU Personal Data transferred outside of the European Union to Milyli shall be transferred out of the European Union directly by Client to Milyli.
Client Cross-Border Data Transfer Mechanism. Client agrees to transfer Client EU Personal Data to Milyli in accordance with Applicable Data Protection Laws.
Milyli Data Transfer Mechanism. Milyli shall comply with the data transfer mechanism below to receive Client EU Personal Data outside the European Union from Client. Milyli and Client agree to process Client EU Personal Data in accordance with the “Standard Contractual Clauses” as described at https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en, as such may be amended from time to time by Applicable Data Protection Laws.
Compliance. Milyli agrees to keep records of its Processing in compliance with Applicable Data Protection Law(s) and provide such records to Client upon request. If Milyli collects Client EU Personal Data on Client’s behalf, such records shall include but not be limited to (i) the legal basis for Processing and (ii) records of the verifiable consent under Applicable Data Protection Law(s).
Third Party Processing. If Milyli engages a Third Party to Process Client EU Personal Data in connection with its provision of the Services, Milyli agrees that data protection obligations equivalent to those set forth in this Agreement shall be imposed on such Third Party by way of a contract or Applicable Data Protection Laws, including the obligation to provide sufficient guarantees to implement appropriate technical and organizational measures in such a manner that the processing will meet the requirements of the Applicable Data Protection Laws.
Notice of Non-Compliance. Milyli must promptly notify Client’s Security POC (defined below, Section 10) if it can no longer meet its obligations under this Section 3.
Data Protection Impact Assessment and Prior Consultation. Milyli shall provide reasonable assistance to Client with any data protection impact assessments, and prior consultations with supervising authorities or other competent data privacy authorities, which is required of Client under Applicable Data Protection Laws solely in relation to Milyli’s Processing of Client EU Personal Data.
Access for Audit. Milyli shall make available to Client on request all information reasonably necessary to demonstrate compliance with this Data Processing Addendum, and shall allow for audits, including inspections, by Client or an auditor mandated by Client in relation to Milyli’s Processing of Client EU Personal Data. Information and audit rights of Client only arise under the foregoing the extent that the Agreement does not otherwise give them information and audit rights meeting the relevant requirements of the Applicable Data Protection Law.
4. Information Security Program
Milyli agrees to maintain a comprehensive written information security program (“Information Security Program”) designed to implement technical and organizational measures to protect Client Confidential Information as required by Applicable Data Protection Law(s), the Agreement and this Agreement. Milyli agree to implement and train its employees on its Information Security Programs in a way that produces the same degree of care as is used with their own Personal Data and Confidential Information, but not less than a reasonable degree of care, to prevent the unauthorized collection, use, sharing, retention, destruction, and other inappropriate or prohibited use of Client Confidential Information.
5. Assessments, Audits and Remediation
Assessments. Records to demonstrate compliance with this Agreement and Applicable Data Protection Law(s) shall be maintained by Milyli and provided to Client upon request. Milyli agrees to (i) provide access to reputable scan results and (ii) complete reasonably requested data protection questionnaires, if any, provided by Client.
Audits. For the purpose of verifying Milyli’s compliance with Applicable Data Protection Law(s) and this Agreement, Milyli agrees to provide independent third-party audit reports to Client upon written request by Client.
Remediation. Milyli agrees to (i) promptly take commercially reasonable action to correct any material security issue affecting Client Confidential Information, and (ii) inform Client of such actions if it is related to a Security Incident affecting Client Confidential Information. If such action is not promptly taken to Client’s reasonable satisfaction, Client may, without penalty or refund, terminate the Agreement at Client’s discretion for cause after (i) Milyli is provided written notice by Client, and (ii) Milyli is afforded the opportunity to remediate within the cure period in accordance with the Agreement, provided, however, that if a regulator or other data protection authority requires immediate termination of the Agreement, Client may do so without penalty or refund notwithstanding any time to cure provision in the Agreement.
6. Secure Disposal
Client Confidential Information shall be securely disposed (i) during the duration of the Agreement upon Client’s written request if such information is no longer reasonably required to perform the Services, (ii) within thirty (30) days of the termination of the provision of the Services. Milyli may retain Client Confidential Information to the extent that it is required to do so under Applicable Data Protection law(s). When disposing of Client Confidential Information, Milyli agrees to destroy and/or delete such data from any media (including back-up copies) such that the media contains no residual data.
7. Changes to Requirements
The parties shall agree to amend or supplement this Agreement from time to time to reflect requirements under Applicable Data Protection Law(s). If either party refuses to amend this Agreement to meet requirements under Applicable Data Protection Law(s), in addition to any termination rights provided in the Agreement, the other party may terminate the Agreement upon thirty (30) days’ written notice to such party without liability, penalty or refund.
8. Security Incident
Security Incident Procedure. Milyli agrees to deploy and follow policies and procedures to detect, respond to, and otherwise address Security Incidents pertaining to Client Confidential Information including procedures to (i) monitor systems and detect successful and attempted attacks on or intrusions into Client Confidential Information or information systems relating thereto, (ii) identify and respond to suspected or known Security Incidents, mitigate harmful effects of Security Incidents, document Security Incidents and their outcomes, in each case, as they pertain to Client Confidential Information, and (iii) restore the availability or access to Client Confidential Information in a timely manner. Client agrees to notify Milyli of any known or suspected Security Incident. The obligations described in this Section 8 shall not apply in the event that a Security Incident results from the actions or omissions of Client. Milyli’s obligation to report or respond to a Security Incident will not be construed as an acknowledgement by Milyli of any fault or liability with respect to the Security Incident.
Notice. Milyli agrees to provide prompt written notice within the time frame required under Applicable Data Protection Law(s) to Client’s Security POC (defined below, Section 10) if it knows that a Security Incident pertaining to Client Confidential Information has taken place. Such notice will include all available and applicable details required under Applicable Data Protection Law(s) for Client to comply with its own notification obligations to regulatory authorities or individuals affected by the Security Incident. Milyli shall provide regular updates to Client on the status of the Security Incident, as available.
Remediation. Milyli agrees to indemnify and reimburse Client for any and all direct damages, losses, fees or costs actually incurred as a result of such Security Incident pertaining to Client Confidential Information if the Security Incident arises from (i) Milyli’s grossly negligent or willful act or omission or (ii) Milyli’s breach of the Agreement or this Agreement. Additionally, to the extent that such a Security Incident pertaining to Client Confidential Information that arises from (i) or (ii) in the foregoing sentence gives rise to a need to: (A) provide notification to public and/or regulatory authorities, individuals, or other persons, or (B) undertake other reasonable remedial measures (including notice and the establishment of a call center to respond to inquiries – collectively, “Remedial Action”), Milyli agrees to undertake such Remedial Actions. Notwithstanding anything contrary to the foregoing or elsewhere in the Agreement or this Agreement, if any of the Remedial Actions or damages, settlements, losses, liabilities, penalties, fines, costs, or expenses are caused by the gross negligence, material omissions, willful misconduct or breach of this Agreement by Client or Client’s personnel, Milyli shall have no obligation to indemnify Client, and Client shall indemnify and reimburse Milyli, for such occurrences nor have the responsibility to take on the Remedial Actions, including the cost or delivery thereof.
Limitations. IN NO EVENT SHALL EITHER PARTY BE LIABLE TO THE OTHER FOR ANY INDIRECT, INCIDENTAL, CONSEQUENTIAL, PUNITIVE OR EXEMPLARY DAMAGES, WHETHER IN CONTRACT, TORT OR OTHERWISE, AND WHETHER OR NOT SUCH PARTY HAS BEEN ADVISED OF THE LIKELIHOOD OF ANY SUCH DAMAGES.
9. Termination Obligations
Termination. Notwithstanding anything to the contrary in the Agreement or this Agreement, either party may, without liability, penalty or refund, terminate the Agreement or any relevant portion thereof immediately upon written notice to the other party in the event a data protection or other regulatory authority or other tribunal or court in any country finds there has been a breach of Applicable Data Protection Law(s) by the breaching party in connection with the Agreement.
Effect of Termination or Expiration. If requested by Client, Milyli shall, after the termination or expiration of the Agreement, return or delete Client Confidential Information in its possession or control unless Milyli is required to retain such information under Applicable Data Protection law(s) or other applicable law, rule or regulation. Milyli’s obligations to protect Client Confidential Information will continue in respect of any Client Confidential Information retained by Milyli until all such information has been returned or deleted, including from any backup.
10. Contact Information
Milyli agrees to designate a point of contact as its “Privacy and Security Coordinator”, who will: (i) maintain responsibility for applying the relevant protections to Client Confidential Information, including the development, implementation, and maintenance of its Information Security Program, (ii) oversee application of Milyli’s compliance with the requirements of this Agreement, and (iii) serve as a point of contact for internal communications and communications with Client pertaining to this Agreement and compliance therewith or any breaches thereof.
Additionally, both Client and Milyli agree to designate a point of contact for urgent security issues (a “Security POC”) and provide contact information for such Security POC. Both parties agree that either the Security POC or appointed alternate will be available 24 hours per day, 365 days per year, without limitation. The Security POC for both parties are:
Milyli Security Point of Contact: Damian Styga (damian@milyli.com, 773-910-9040) Alternate Peter Brown (pete@milyli.com) Alternate Charles Kinnan (chuck@milyli.com) |
© 2026 Blackout, All rights reserved.