Data Processing Addendum

Last updated: August 11, 2026

This DPA forms part of the MilkVein Terms of Service between MilkVein Technologies LLC, a Pennsylvania limited liability company ("Processor"), and the customer organization ("Controller") when Processor processes personal data on the Controller's behalf.

1. Scope & roles

Controller determines the purposes of processing (operating its hauling, co-op, or plant business). Processor processes data only on documented instructions.

2. Subject matter & duration

Processing covers user accounts, farms, routes, pickups, BOLs, lab results, invoices, and related media, for the duration of the subscription.

3. Categories of data

Names, emails, phone numbers, license numbers, signatures, photos of equipment/tags, location of pickup points.

4. Subprocessors

Listed in the Privacy Policy. We provide 30 days' notice of new subprocessors; Controller may terminate if it reasonably objects.

5. Security

TLS in transit, AES at rest, RBAC, row-level security, audit logging, principle of least privilege, secret rotation.

6. International transfers

Where applicable, transfers rely on the EU Standard Contractual Clauses and the UK Addendum.

7. Breach notification

Processor notifies Controller without undue delay (and within 72 hours where feasible) of any confirmed personal-data breach affecting Controller data.

8. Audits

Processor provides annual security summaries on request. On-site audits available for Enterprise customers on reasonable notice.

9. Deletion

On termination, Controller may export data for 30 days; thereafter Processor deletes Controller data within 90 days, subject to legal holds.

To countersign a copy of this DPA, email legal@milkvein.com.
Notices: MilkVein Technologies LLC, 502 W 7th St, Ste 100, Erie, PA 16502.

© 2026 MilkVein Technologies LLC. All rights reserved.