Your data, protected
by design
Mylla combines encrypted transport and storage, server-side access checks, operations-managed retention, and documented service providers to protect business and caller data.
Eight security pillars
Built to earn your trust
Encryption controls
Public endpoints use TLS 1.2 or newer, managed storage uses encryption at rest, and selected OAuth integration credentials are encrypted at the application layer before storage.
Business isolation
Database row-level security and server-side authorization checks scope application data to the signed-in business and role.
Audit trail
Selected security-relevant actions are recorded with actor, timestamp, and resource context. Business audit logs reject ordinary updates and deletes and follow a three-year retention policy.
Managed data retention
Retention periods are managed by Mylla operations according to the service configuration and applicable legal or contractual requirements. Contact support to discuss the settings for your business.
Data portability & erasure
Request an applicable data export or account deletion by contacting support. We verify authority and review legal, security, and contractual retention obligations before taking action.
Minimized diagnostics
Structured logging redacts common identifiers such as phone numbers and email addresses. Access-controlled diagnostic services may still receive limited technical context needed to investigate failures.
Transparent vendor management
Our public register lists active and conditional providers, the data and purpose involved, published DPA status, and the transfer mechanism or any verification still pending.
Security checks
Code review and automated checks cover authentication, input validation, personal-data handling, and dependency risk on the repository paths that trigger those checks.
Privacy rights support
Your rights, our responsibility
For caller data, the business normally acts as controller and Mylla acts as its processor. For account, billing, security, and direct website data, Barking Studio may act as controller. We help route and review applicable privacy requests in either role.
Right of access
Request access through the responsible business or contact Mylla support for assistance.
Right to rectification
Authorized business users can correct records, or a person can submit a correction request.
Right to erasure
Contact support to request deletion. We coordinate with the responsible business and review applicable retention obligations.
Right to data portability
Contact support to request a machine-readable export of applicable business data.
Right to restriction
Contact the responsible business or Mylla support to request a review of applicable processing.
Right to object
Contact us to review the processing purpose and legal basis that apply to your data.
Questions about our security practices?
For security inquiries or privacy requests, contact our team. The public register documents the providers that may process service data.
View the subprocessor register