Privacy Policy
Milo's Privacy Policy
August 1, 2026
Milo Labs Inc. ("Milo," "we," "our," or "us") provides MILO, a data integration service that reads data from a customer's source systems and writes it into that customer's Vena Solutions environment.
This policy explains what we do with data. It is written in two parts because we handle two fundamentally different kinds of data, under two different legal roles:
Part A - Customer Data. Data belonging to our business customers that passes through the MILO Service. For this data we act as a processor / service provider on the customer's documented instructions. We do not own it, do not decide what it is used for, and do not use it for our own purposes.
Part B - Personal Data we control. Data about website visitors, prospects, marketing contacts, and the named individuals who administer a MILO account. For this data we act as a controller.
If you are a business evaluating MILO for a Vena implementation, Part A is the section relevant to your security and privacy review.
1. Who we are and how to reach us
Legal entity | Milo Labs Inc. |
Registered address | 280 Simcoe Street, Toronto, Ontario, M5T 2Y5, Canada |
Contact | |
Service | MILO - data integration into Vena |
The MILO Service runs on Microsoft Azure infrastructure operated by Milo Labs Inc. within its own Azure tenancy. Milo Labs Inc. maintains a SOC 2 Type II report covering the Security, Availability and Confidentiality trust services criteria for that environment.
2. Definitions
Customer - the organization that has entered into a MILO Service Agreement with us.
Customer Data - any data that a Customer, or a Customer's source system, transmits to or through the MILO Service, and any data MILO writes into the Customer's Vena environment on the Customer's instruction. Customer Data includes financial, accounting, transactional, statistical and operational records; it also includes any Personal Information that a Customer chooses to submit, whether intentionally or incidentally.
Source System - a Customer's system of record from which MILO reads data, such as an ERP, general ledger, payroll, CRM, point-of-sale, or operational database, or a file the Customer supplies.
Vena - Vena Solutions Inc., the provider of the Vena platform. Vena is the destination for data written by MILO. Vena is not the provider of MILO.
Personal Information / Personal Data - information about an identified or identifiable individual, as those terms are defined under PIPEDA, the GDPR, the CCPA/CPRA, and other applicable laws.
Sub-processor - a third party engaged by us that processes Customer Data on our behalf.
PART A - CUSTOMER DATA PROCESSED THROUGH THE MILO SERVICE
3. What MILO does with Customer Data
MILO performs a single, narrow function: it reads data from a Customer's Source Systems and writes the resulting data into that Customer's Vena environment.
Specifically:
Read. On a schedule or trigger configured by the Customer, MILO connects to the Customer's Source Systems using credentials the Customer supplies, and retrieves records within the scope the Customer has configured.
Transform in transit. Records are mapped, aggregated, validated and reshaped into the structure required by the target Vena model. Transformation is deterministic and rule-based, defined by the Customer's configured mappings, and occurs in memory as part of the transfer operation.
Write. The transformed records are written into the Customer's Vena environment through Vena's published interfaces.
Retain an audit history. MILO stores a copy of each transfer, including the records transferred, for thirty (30) days, so that the Customer can verify and reconcile what moved. See Section 7.
MILO is not a data warehouse or reporting platform. It does not maintain a persistent replica of a Customer's Source System, and holds no Customer Data older than the thirty-day audit window described in Section 7.
MILO does not write data back into Source Systems. MILO does not read data out of Vena for any purpose other than the validation and reconciliation steps required to complete a write operation the Customer has requested. MILO does not transmit Customer Data to any other Customer, and does not aggregate Customer Data across Customers.
4. Express notice: data is processed outside Vena's systems
This section is provided so that Customers are placed on express notice, and to satisfy the disclosure expectations of Vena's partner program.
Customer Data processed by MILO is transmitted to, and processed and stored on, infrastructure operated by us - not by Vena, and outside the Vena Service.
MILO is a third-party connector. It is provided by Milo Labs Inc., not by Vena.
Between the moment data leaves a Source System and the moment it is written into the Customer's Vena environment, that data resides on our infrastructure, under our controls, subject to this policy and the MILO Service Agreement. A copy of the transferred data remains in our audit history for thirty (30) days after the transfer, as described in Section 7.
Milo Labs Inc., and not Vena, is responsible for the MILO Service. Vena has no obligation or liability in respect of MILO. Vena's own privacy policy, security commitments, and service levels govern the Vena platform and do not extend to MILO.
Customers remain responsible for ensuring that their use of MILO, and the data they instruct MILO to move, is consistent with their own agreements with Vena and with their own legal obligations.
5. Categories of Customer Data, and our position on Personal Information
MILO is built and sold to move financial, accounting, statistical and operational data. Typical categories include general ledger balances and transactions, sub-ledger detail, budget and forecast figures, dimension and hierarchy structures, member attributes, and operational statistics such as headcount, volumes, units, or occupancy.
MILO is not designed to process Personal Information, and Customers are instructed not to submit it. Under the MILO Service Agreement, Customers must configure their integrations so that Personal Information is excluded from scope wherever it is not strictly required, and must not submit special categories of personal data (as defined in Article 9 GDPR), payment card data, government identifiers, or health information.
We recognise that financial and operational records can carry Personal Information incidentally - for example, an employee name attached to a payroll cost line, a vendor contact name in an accounts-payable record, a salesperson identifier on a revenue transaction, or a free-text memo field. Because MILO retains a copy of transferred records for thirty days (Section 7), any such information is stored for that period. Where it is present:
It is treated as Customer Data and handled under this Part A and the applicable data processing agreement.
It is not enriched, profiled, analysed, or used to make any decision about the individual.
It is deleted with the rest of the audit history at the end of the thirty-day window.
We will work with the Customer to exclude or mask it at source or during mapping. Customers who require that no Personal Information be retained at rest should scope their integrations accordingly before go-live.
Before any Customer submits GDPR Personal Data through the MILO Service, a data processing agreement must be executed with us. Contact hello@meetmilo.co to put one in place.
6. Our role and lawful basis
For Customer Data, Milo Labs Inc. acts as a processor under the GDPR and UK GDPR, a service provider under the CCPA/CPRA, and a third-party service provider under PIPEDA. The Customer is the controller (or business) and determines the purposes and means of processing.
We process Customer Data only:
to provide, maintain, secure and support the MILO Service as configured by the Customer;
on the Customer's documented instructions, including instructions expressed through the Customer's own configuration of scope, schedules and mappings;
as required by applicable law, in which case we will inform the Customer unless legally prohibited.
We do not:
sell or share Customer Data, as those terms are defined under the CCPA/CPRA or any other law;
use Customer Data for advertising, marketing, benchmarking, or product analytics;
use Customer Data to train, fine-tune, evaluate, or prompt any machine learning or artificial intelligence model, whether our own or a third party's. The MILO Service does not use artificial intelligence or large language models in any part of the read, transform, or write path. Mapping and transformation logic is deterministic and rule-based;
retain, use, or disclose Customer Data outside the direct business relationship with the Customer;
combine Customer Data with data from any other source, except as permitted by the Customer's instructions.
7. Retention and deletion
Thirty (30) days. MILO retains a complete audit history of each transfer for thirty days from the date of the transfer. That history includes:
the records transferred, in full, as read from the Source System and as written to Vena;
run metadata - job identifier, initiating user or schedule, start and end timestamps, source and target identifiers, record counts, status, and duration;
error and exception detail for records that failed validation or write.
The audit history exists so that Customers can reconcile a Vena balance back to its source, diagnose a failed load, and evidence what moved and when. It is retained for no other purpose.
Automatic purge. Deletion is automatic and unconditional. At thirty days, records are purged by a scheduled process; the period is not extended, and there is no manual override to retain data longer. Expired data is removed from backup media within thirty (30) days of purge.
On termination. On expiry or termination of the MILO Service Agreement, all Customer Data and audit history are deleted within thirty (30) days, other than records we are required to retain by law. Credentials and connection secrets are revoked and destroyed on termination.
Earlier deletion. A Customer may request deletion of specific audit history, or of all of its audit history, at any time by contacting hello@meetmilo.co. We will action such requests within five (5) business days.
No extension. Any change to the retention periods stated in this section will be notified to Customers in advance, in writing.