GDPR Compliance
Last updated: 6 August 2026
Our Commitment to GDPR
MileKit is committed to full compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the UK GDPR as retained in UK law. This page explains our roles, lawful bases for processing, and the rights available to data subjects.
Data Controller vs. Data Processor
You determine the purposes and means of processing your clients' personal data. You are responsible for obtaining your clients' consent to receive SMS and email communications and for providing them with your own privacy notice.
MileKit processes your clients' data strictly on your instructions — to send appointment reminders, review requests, and recall messages. We never use client data for any other purpose.
Lawful Basis for Processing
Your Rights as a Data Subject
If you are an EU or UK resident, you have the following rights regarding your personal data held by MileKit:
To exercise any right, email support@milekit.com. We respond within 30 calendar days.
International Data Transfers
Some of our sub-processors (including Supabase and Vercel) operate servers in the United States. All transfers are covered by Standard Contractual Clauses (SCCs) as approved by the European Commission, ensuring your data is protected to EU standards regardless of where it is processed.
Data Retention
Account data is retained for the duration of your subscription plus 90 days. Client data you have entered is deleted within 30 days of account deletion. Payment records are retained for 7 years to comply with financial regulations. You can request early deletion at any time.
Data Protection Officer
For GDPR-related enquiries or to exercise your rights:
MileKit Ltd. — Data Protection
support@milekit.com
You also have the right to lodge a complaint with your national data protection authority. In the UK: Information Commissioner's Office (ICO).