Legal
Data Processing Agreement (DPA)
GDPR Article 28 data processing agreement when you enter your clients’ data in Mishka.
Last updated: 6 September 2026
1. Parties and scope
This Data Processing Agreement ("DPA") forms part of the Mishka Terms of Service between:
• Customer ("Controller"): the organization or user subscribing to Mishka
• Joris Ricard / Agence JRi ("Processor"): 19 rue Gambetta, 69270 Fontaines-sur-Saône, France
This DPA applies when the Customer processes personal data of its own clients, contacts or team members using Mishka.
2. Subject matter and duration
Processor processes personal data on behalf of Controller to provide the Mishka SaaS platform (project management, CRM, editorial calendar, credentials vault, collaboration). Processing lasts for the duration of the subscription plus applicable retention periods.
3. Nature and purpose of processing
Storage, organization, display, backup, export and deletion of data entered by Controller and its authorized users. Includes: client contacts, project data, tasks, comments, attachments, encrypted credentials, meeting notes and documents.
Client portal. Where Controller enables the client portal, processing also covers: opening authentication accounts for individuals outside its organization, invited by it by email, and sending the required messages (invitation, single-use login link, notifications); collecting and hosting the content those individuals create (requests, messages, comments, approval decisions and change requests, uploaded files); and collecting portal connection and usage metadata (invitation, first login and last seen dates, access status, assigned role, IP address, connection logs, portal technical cookies). Those operations are carried out on Controller instructions: it alone decides who is invited, with which role, and which data is exposed.
AI-assisted generation. Where Controller uses the AI features (Studio plans and above), processing also covers: transmitting to the subprocessor Anthropic PBC, at the explicit request of an authorized user and for that single request, the work content strictly necessary to the requested synthesis (project names and descriptions, tasks, comments, activity history, time tracked, meeting notes and documents), to the exclusion of client credentials, vault passwords and billing data; and storing the generated summaries and briefs in Controller’s workspace, under the same retention and deletion rules as its other content. The subprocessor does not use that data to train its models.
4. Types of personal data
Identification data (names, emails, phone numbers), professional data, content created by users, connection metadata, encrypted passwords for third-party accounts (credentials vault).
Where the client portal is enabled, this also covers: portal user account data (email address, technical identifier, display name, avatar, language, timezone, timestamp of acceptance of the terms), access data (linked client, role, status, last seen date), the content those users create, and portal connection metadata. No password is processed for those accounts: login is by single-use link.
Controller undertakes not to upload data falling under GDPR article 9 without a legal basis and appropriate safeguards.
5. Categories of data subjects
Controller's employees, freelancers and collaborators; contacts of Controller's clients; users of Controller's client portal - individuals outside its organization, invited by it to access the portal, whatever their role (viewer, validator, client_admin); and any individual whose data Controller or its authorized users upload to Mishka.
6. Processor obligations
Processor shall:
• Process data only on documented instructions from Controller
• Ensure confidentiality of authorized personnel
• Implement appropriate technical and organizational measures (encryption, RLS, access control)
• Assist Controller with data subject requests where technically feasible
• Notify Controller without undue delay of a personal data breach
• Delete or return data upon termination, subject to legal retention
• Make available information necessary to demonstrate compliance
7. Subprocessors
Controller authorizes Processor to engage the subprocessors listed in our Privacy Policy (/confidentialite). Processor imposes on each of them data protection obligations equivalent to those of this DPA.
Notice and objection. Processor shall inform Controller of any addition or replacement of a subprocessor, by email to the organization owner, giving at least 30 days notice before the subprocessor starts. Controller may raise a reasoned objection, by email to mishka-team@usemishka.com, within 30 days of that notice; failing which the change is deemed accepted.
Where a reasoned objection is raised, the parties shall seek in good faith a reasonable solution (keeping the existing provider, a technical alternative, restricting the scope). If no solution is found within 30 days, Controller may terminate its subscription without penalty, effective on the date the contested subprocessor starts, and obtain a pro rata refund of the prepaid unused period. Termination is then the sole remedy.
Where urgency relating to security or service continuity requires it, Processor may engage a subprocessor without prior notice; it shall then inform Controller without delay, and Controller retains the right of objection described above.
Standard Contractual Clauses apply for transfers outside the EEA.
8. Controller obligations
Controller shall:
• Have a legal basis to process and upload data to Mishka
• Inform its own data subjects where required
• Not upload unlawful content or sensitive data without proper safeguards
• Use the credentials vault responsibly and limit access within its team
• Configure roles and permissions correctly within its organization
Client portal - specific obligations. Where Controller invites an individual outside its organization to the client portal, it warrants that it has a legal basis to process their data and pass it to Processor; that it has informed them of the processing in accordance with GDPR articles 13 and 14, at the latest at the time of the invitation; that it exposes through the portal only data it is entitled to share with them; that it keeps the list of accesses up to date and revokes without delay those that have become pointless; and that it handles, as controller, any data subject request from those individuals, with Processor assistance.
9. Security
Processor maintains encryption at rest and in transit, daily database backups and weekly backups of uploaded files, role-based access, optional MFA, and AES-256-GCM encryption for stored client credentials. Details are in our Privacy Policy.
10. Audits
Upon reasonable request, Processor will provide information about its security measures. Enterprise customers may request additional audit documentation under a separate agreement.
11. Personal data breach
In the event of a personal data breach affecting the Business Data, Processor shall notify Controller without undue delay after becoming aware of it, and at the latest within 48 hours, so as to allow Controller to meet its own obligation to notify the supervisory authority within 72 hours (GDPR article 33) and, where applicable, to inform the data subjects (article 34).
The notification shall state, to the extent the information is available: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it. Processor shall cooperate with Controller and provide any information useful to its own assessment.
12. Termination
On termination of the service, Controller may use the export features to retrieve its Business Data. Once the retrieval window and the applicable retention periods have elapsed, the data is deleted, subject to legal retention obligations.
Fate of portal user accounts. Termination immediately closes the client portal accesses opened by Controller: those individuals can no longer log in to its workspace. The content they submitted follows the fate of Controller Business Data. Their authentication account is not deleted immediately - the same person may hold accesses opened by other organizations - but it is deleted automatically if it remains twelve months without any access (see section 5 of the Privacy Policy). Its deletion may also be requested at any time, by the data subject or by Controller, at mishka-team@usemishka.com.
13. Governing law
This DPA is governed by French law. The French version of the Privacy Policy and this DPA prevails.