Skip to main content
Security & Privacy

Your data, protected
by design

Mylla combines encrypted transport and storage, server-side access checks, operations-managed retention, and documented service providers to protect business and caller data.

AES-256Storage encryption
TLS 1.2+Encrypted transport
6Privacy rights supported
26Listed providers

Eight security pillars

Built to earn your trust

Encryption controls

Public endpoints use TLS 1.2 or newer, managed storage uses encryption at rest, and selected OAuth integration credentials are encrypted at the application layer before storage.

Business isolation

Database row-level security and server-side authorization checks scope application data to the signed-in business and role.

Audit trail

Selected security-relevant actions are recorded with actor, timestamp, and resource context. Business audit logs reject ordinary updates and deletes and follow a three-year retention policy.

Managed data retention

Retention periods are managed by Mylla operations according to the service configuration and applicable legal or contractual requirements. Contact support to discuss the settings for your business.

Data portability & erasure

Request an applicable data export or account deletion by contacting support. We verify authority and review legal, security, and contractual retention obligations before taking action.

Minimized diagnostics

Structured logging redacts common identifiers such as phone numbers and email addresses. Access-controlled diagnostic services may still receive limited technical context needed to investigate failures.

Transparent vendor management

Our public register lists active and conditional providers, the data and purpose involved, published DPA status, and the transfer mechanism or any verification still pending.

Security checks

Code review and automated checks cover authentication, input validation, personal-data handling, and dependency risk on the repository paths that trigger those checks.

Privacy rights support

Your rights, our responsibility

For caller data, the business normally acts as controller and Mylla acts as its processor. For account, billing, security, and direct website data, Barking Studio may act as controller. We help route and review applicable privacy requests in either role.

Art. 15

Right of access

Request access through the responsible business or contact Mylla support for assistance.

Art. 16

Right to rectification

Authorized business users can correct records, or a person can submit a correction request.

Art. 17

Right to erasure

Contact support to request deletion. We coordinate with the responsible business and review applicable retention obligations.

Art. 20

Right to data portability

Contact support to request a machine-readable export of applicable business data.

Art. 18

Right to restriction

Contact the responsible business or Mylla support to request a review of applicable processing.

Art. 21

Right to object

Contact us to review the processing purpose and legal basis that apply to your data.

Questions about our security practices?

Jurisdiction: Netherlands · United States
Autoriteit Persoonsgegevens

For security inquiries or privacy requests, contact our team. The public register documents the providers that may process service data.

View the subprocessor register

Ready to see how we protect your data?

Start your free trial and review the security and privacy controls available from day one.

14-day free trial · Payment method required · Cancel anytime