top of page

Privacy Policy

Milo's Privacy Policy

August 1, 2026

Milo Labs Inc. ("Milo," "we," "our," or "us") provides MILO, a data integration service that reads data from a customer's source systems and writes it into that customer's Vena Solutions environment.

This policy explains what we do with data. It is written in two parts because we handle two fundamentally different kinds of data, under two different legal roles:

  • Part A - Customer Data. Data belonging to our business customers that passes through the MILO Service. For this data we act as a processor / service provider on the customer's documented instructions. We do not own it, do not decide what it is used for, and do not use it for our own purposes.

  • Part B - Personal Data we control. Data about website visitors, prospects, marketing contacts, and the named individuals who administer a MILO account. For this data we act as a controller.

If you are a business evaluating MILO for a Vena implementation, Part A is the section relevant to your security and privacy review.



1. Who we are and how to reach us


Legal entity

Milo Labs Inc.

Registered address

280 Simcoe Street, Toronto, Ontario, M5T 2Y5, Canada

Contact

Service

MILO - data integration into Vena


The MILO Service runs on Microsoft Azure infrastructure operated by Milo Labs Inc. within its own Azure tenancy. Milo Labs Inc. maintains a SOC 2 Type II report covering the Security, Availability and Confidentiality trust services criteria for that environment.



2. Definitions


Customer - the organization that has entered into a MILO Service Agreement with us.

Customer Data - any data that a Customer, or a Customer's source system, transmits to or through the MILO Service, and any data MILO writes into the Customer's Vena environment on the Customer's instruction. Customer Data includes financial, accounting, transactional, statistical and operational records; it also includes any Personal Information that a Customer chooses to submit, whether intentionally or incidentally.

Source System - a Customer's system of record from which MILO reads data, such as an ERP, general ledger, payroll, CRM, point-of-sale, or operational database, or a file the Customer supplies.

Vena - Vena Solutions Inc., the provider of the Vena platform. Vena is the destination for data written by MILO. Vena is not the provider of MILO.

Personal Information / Personal Data - information about an identified or identifiable individual, as those terms are defined under PIPEDA, the GDPR, the CCPA/CPRA, and other applicable laws.

Sub-processor - a third party engaged by us that processes Customer Data on our behalf.



PART A - CUSTOMER DATA PROCESSED THROUGH THE MILO SERVICE

3. What MILO does with Customer Data


MILO performs a single, narrow function: it reads data from a Customer's Source Systems and writes the resulting data into that Customer's Vena environment.

Specifically:

  1. Read. On a schedule or trigger configured by the Customer, MILO connects to the Customer's Source Systems using credentials the Customer supplies, and retrieves records within the scope the Customer has configured.

  2. Transform in transit. Records are mapped, aggregated, validated and reshaped into the structure required by the target Vena model. Transformation is deterministic and rule-based, defined by the Customer's configured mappings, and occurs in memory as part of the transfer operation.

  3. Write. The transformed records are written into the Customer's Vena environment through Vena's published interfaces.

  4. Retain an audit history. MILO stores a copy of each transfer, including the records transferred, for thirty (30) days, so that the Customer can verify and reconcile what moved. See Section 7.

MILO is not a data warehouse or reporting platform. It does not maintain a persistent replica of a Customer's Source System, and holds no Customer Data older than the thirty-day audit window described in Section 7.

MILO does not write data back into Source Systems. MILO does not read data out of Vena for any purpose other than the validation and reconciliation steps required to complete a write operation the Customer has requested. MILO does not transmit Customer Data to any other Customer, and does not aggregate Customer Data across Customers.



4. Express notice: data is processed outside Vena's systems


This section is provided so that Customers are placed on express notice, and to satisfy the disclosure expectations of Vena's partner program.

Customer Data processed by MILO is transmitted to, and processed and stored on, infrastructure operated by us - not by Vena, and outside the Vena Service.

  • MILO is a third-party connector. It is provided by Milo Labs Inc., not by Vena.

  • Between the moment data leaves a Source System and the moment it is written into the Customer's Vena environment, that data resides on our infrastructure, under our controls, subject to this policy and the MILO Service Agreement. A copy of the transferred data remains in our audit history for thirty (30) days after the transfer, as described in Section 7.

  • Milo Labs Inc., and not Vena, is responsible for the MILO Service. Vena has no obligation or liability in respect of MILO. Vena's own privacy policy, security commitments, and service levels govern the Vena platform and do not extend to MILO.

  • Customers remain responsible for ensuring that their use of MILO, and the data they instruct MILO to move, is consistent with their own agreements with Vena and with their own legal obligations.


5. Categories of Customer Data, and our position on Personal Information


MILO is built and sold to move financial, accounting, statistical and operational data. Typical categories include general ledger balances and transactions, sub-ledger detail, budget and forecast figures, dimension and hierarchy structures, member attributes, and operational statistics such as headcount, volumes, units, or occupancy.

MILO is not designed to process Personal Information, and Customers are instructed not to submit it. Under the MILO Service Agreement, Customers must configure their integrations so that Personal Information is excluded from scope wherever it is not strictly required, and must not submit special categories of personal data (as defined in Article 9 GDPR), payment card data, government identifiers, or health information.

We recognise that financial and operational records can carry Personal Information incidentally - for example, an employee name attached to a payroll cost line, a vendor contact name in an accounts-payable record, a salesperson identifier on a revenue transaction, or a free-text memo field. Because MILO retains a copy of transferred records for thirty days (Section 7), any such information is stored for that period. Where it is present:

  • It is treated as Customer Data and handled under this Part A and the applicable data processing agreement.

  • It is not enriched, profiled, analysed, or used to make any decision about the individual.

  • It is deleted with the rest of the audit history at the end of the thirty-day window.

  • We will work with the Customer to exclude or mask it at source or during mapping. Customers who require that no Personal Information be retained at rest should scope their integrations accordingly before go-live.

Before any Customer submits GDPR Personal Data through the MILO Service, a data processing agreement must be executed with us. Contact hello@meetmilo.co to put one in place.



6. Our role and lawful basis


For Customer Data, Milo Labs Inc. acts as a processor under the GDPR and UK GDPR, a service provider under the CCPA/CPRA, and a third-party service provider under PIPEDA. The Customer is the controller (or business) and determines the purposes and means of processing.

We process Customer Data only:

  • to provide, maintain, secure and support the MILO Service as configured by the Customer;

  • on the Customer's documented instructions, including instructions expressed through the Customer's own configuration of scope, schedules and mappings;

  • as required by applicable law, in which case we will inform the Customer unless legally prohibited.

We do not:

  • sell or share Customer Data, as those terms are defined under the CCPA/CPRA or any other law;

  • use Customer Data for advertising, marketing, benchmarking, or product analytics;

  • use Customer Data to train, fine-tune, evaluate, or prompt any machine learning or artificial intelligence model, whether our own or a third party's. The MILO Service does not use artificial intelligence or large language models in any part of the read, transform, or write path. Mapping and transformation logic is deterministic and rule-based;

  • retain, use, or disclose Customer Data outside the direct business relationship with the Customer;

  • combine Customer Data with data from any other source, except as permitted by the Customer's instructions.



7. Retention and deletion


Thirty (30) days. MILO retains a complete audit history of each transfer for thirty days from the date of the transfer. That history includes:

  • the records transferred, in full, as read from the Source System and as written to Vena;

  • run metadata - job identifier, initiating user or schedule, start and end timestamps, source and target identifiers, record counts, status, and duration;

  • error and exception detail for records that failed validation or write.

The audit history exists so that Customers can reconcile a Vena balance back to its source, diagnose a failed load, and evidence what moved and when. It is retained for no other purpose.

Automatic purge. Deletion is automatic and unconditional. At thirty days, records are purged by a scheduled process; the period is not extended, and there is no manual override to retain data longer. Expired data is removed from backup media within thirty (30) days of purge.

On termination. On expiry or termination of the MILO Service Agreement, all Customer Data and audit history are deleted within thirty (30) days, other than records we are required to retain by law. Credentials and connection secrets are revoked and destroyed on termination.

Earlier deletion. A Customer may request deletion of specific audit history, or of all of its audit history, at any time by contacting hello@meetmilo.co. We will action such requests within five (5) business days.

No extension. Any change to the retention periods stated in this section will be notified to Customers in advance, in writing.



8. Where data is processed - residency and cross-border transfers


All MILO production infrastructure that processes or stores Customer Data is hosted on Microsoft Azure in Canada:

Role

Region

Primary

Canada Central

Secondary / failover

Canada East


Customer Data does not leave Canada. We do not replicate Customer Data to regions outside Canada, and we use no sub-processor that stores Customer Data outside Canada.

Consequently, no cross-border transfer mechanism (such as Standard Contractual Clauses) is required for Customer Data in the ordinary course. Where a Customer's own circumstances require a transfer mechanism, or where a Customer is subject to residency or localization requirements that Canada Central and Canada East do not satisfy, that must be raised before onboarding; contact hello@meetmilo.co.

Note separately that the destination of the data - the Customer's Vena environment - is hosted by Vena in the region the Customer has selected with Vena. That region is governed by the Customer's agreement with Vena, not by this policy.



9.  Sub-processors

Microsoft Corporation is our only sub-processor.


Sub-processor

Purpose

Location of processing

Microsoft Corporation (Microsoft Azure)

Cloud hosting, compute, storage, monitoring, identity (Microsoft Entra External ID), key management (Azure Key Vault)

Canada Central, Canada East


We engage no other sub-processor in connection with the MILO Service. In particular, we use no third-party analytics, error-tracking, data-enrichment, or artificial intelligence provider in the processing of Customer Data.


Microsoft is bound by written terms imposing data protection and confidentiality obligations no less protective than those in this policy and in our customer agreements. We remain responsible to Customers for the acts and omissions of our sub-processors.


We will give Customers at least thirty (30) days' notice before adding or replacing a sub-processor that processes Customer Data. Customers may subscribe to sub-processor change notifications by writing to hello@meetmilo.co.



10. Security


We maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the data. The MILO Service operates within an environment audited under SOC 2 Type II (Security, Availability, Confidentiality). A copy of the current report is available to Customers and prospective Customers under NDA on request to hello@meetmilo.co.

Controls include:

Encryption

  • Encryption in transit using TLS across all layers, including connections to Source Systems, internal service-to-service traffic, and writes into Vena.

  • Encryption at rest using Azure-native encryption, with keys managed in Azure Key Vault. This includes the thirty-day audit history described in Section 7.

Identity and access

  • Role-based access control, with production access restricted to defined roles under least privilege.

  • Multi-factor authentication enforced through Microsoft Entra External ID for all access to systems holding Customer Data.

  • Source System and Vena credentials, API keys and connection secrets stored in Azure Key Vault, never in application code, configuration files, or logs.

  • Access is granted only after security training, execution of a confidentiality agreement, and completion of background checks, and is revoked on termination or role change under a documented offboarding procedure.

  • Periodic access reviews and recertification.

  • Logical separation of each Customer's data, credentials and audit history.

Infrastructure

  • Network segmentation and a web application firewall.

  • Centralised logging and monitoring, with alerting on anomalous activity.

  • Vulnerability scanning and a documented patch management process.

Software development

  • A secure development lifecycle aligned to OWASP guidance, with mandatory code review and pre-deployment security scanning.

  • Defined remediation windows for critical- and high-severity findings.

  • Independent third-party penetration testing.

No system is perfectly secure, and we do not represent that the MILO Service is immune from compromise. Customers are responsible for the security of the credentials they issue to MILO, for scoping those credentials to the minimum permissions required, and for the security of their own Source Systems and Vena environment.



11. Security incidents


We maintain a documented and tested incident response plan.


On becoming aware of a security breach affecting Customer Data, we will notify the affected Customer without undue delay and in any event within forty-eight (48) hours of awareness, and will provide the information reasonably required for the Customer to meet its own notification obligations, including the nature of the incident, the categories and approximate volume of data involved, the likely consequences, and the measures taken or proposed. We will provide follow-up information as the investigation progresses, cooperate with the Customer's investigation, and conduct a post-incident review and root cause analysis.


Where the incident involves data or systems associated with the Vena Service, we will also notify Vena within the timeframes required by our partner agreement.


Report a suspected vulnerability or incident to hello@meetmilo.co.



12. Assisting Customers with their obligations


Taking into account the nature of the processing, we will provide reasonable assistance to Customers in relation to:

  • responding to requests from individuals exercising rights of access, correction, deletion, restriction, objection, or portability, where the relevant data is held in MILO's audit history;

  • data protection impact assessments and prior consultations with supervisory authorities;

  • security of processing and breach notification obligations.

Individuals should direct requests to the Customer, not to us. We do not have a direct relationship with the individuals whose information may appear incidentally in Customer Data, and we are not in a position to verify their identity. If we receive such a request directly, we will refer it to the relevant Customer and will not respond substantively except on that Customer's instruction.



13. Audit and compliance documentation


On request, and subject to confidentiality obligations, we will provide Customers and Vena with documentation reasonably required to verify our compliance, including the current SOC 2 Type II report, security policy summaries, penetration test summaries, our sub-processor list, and completed security questionnaires. Audit rights, including any on-site or architecture review rights, are governed by the MILO Service Agreement or the applicable data processing agreement.



PART B - PERSONAL DATA WE COLLECT AS CONTROLLER



This Part applies to our website at https://meetmilo.co, our marketing and advertising activity, our sales process, and the administration of MILO accounts. For this data, Milo Labs Inc. is the controller.

This Part does not apply to Customer Data moved by the MILO Service. That is covered in Part A.


14. Information we collect


Information you provide directly

  • Name, email address, telephone number

  • Company name and job title

  • The content of enquiries, demo requests, and support tickets

  • Information submitted through forms on our website or through LinkedIn Lead Gen Forms

Account administration information

  • The name, business email address and role of individuals authorised to configure or administer a MILO account

  • Authentication and session records for those individuals

  • Support correspondence relating to a Customer's use of the Service

Information collected automatically

  • IP address

  • Browser type and device information

  • Pages visited, time on page, and referring URLs

Information from third parties

  • Engagement data from advertising platforms such as LinkedIn

  • Analytics providers



15. How we use it


  • To respond to enquiries and to communicate with you

  • To provide, administer and support MILO accounts, including authenticating administrators

  • To perform business development, lead nurturing, and sales follow-up relating to the services you enquired about

  • To deliver and measure advertising, including LinkedIn Ads

  • To operate, secure and improve our website

  • To comply with legal, tax, accounting and audit obligations


We may use automated systems to categorise or score leads based on professional information you provide, so that our outreach is relevant. This produces no legal or similarly significant effect on you.



16. Lawful basis (GDPR / UK GDPR)


Purpose

Basis

Cookies (non-essential) and targeted advertising

Consent

Providing services and administering accounts you have requested

Performance of a contract

Business development, marketing to business contacts, analytics, site security

Legitimate interests, balanced against your rights

Tax, accounting, audit and regulatory retention

Legal obligation


Where we rely on consent, you may withdraw it at any time. Where we rely on legitimate interests, you may object; see Section 21.



17. Cookies and tracking


We use cookies, pixels and similar technologies, including the LinkedIn Insight Tag, to measure advertising conversions, retarget visitors, and analyse site performance.


Non-essential cookies - including advertising and analytics cookies - are placed only after you give consent through our cookie banner. You can manage or withdraw consent through that banner at any time, and can control cookies through your browser settings.


Do Not Track. Our website does not currently respond to browser Do Not Track signals. Use the cookie banner and your browser settings to manage your preferences.



18. Disclosure


We disclose Personal Data covered by this Part to:

  • advertising partners, such as LinkedIn, to deliver and measure advertising;

  • service providers, including cloud hosting, website hosting, analytics, email, and CRM providers;

  • professional advisers, including legal, accounting and audit advisers, under duties of confidentiality;

  • an acquirer or successor entity in connection with a merger, acquisition or sale of assets, subject to this policy;

  • legal or regulatory authorities where required by law.

We do not sell Personal Data for monetary consideration. Our use of third-party advertising pixels may constitute "sharing" for cross-contextual behavioural advertising under California law. You may opt out through the "Do Not Sell or Share My Personal Information" link in our website footer, through our cookie banner, or through your LinkedIn privacy settings.



19. International transfers


Personal Data covered by this Part may be processed outside Canada by our service providers. Where it is, we put appropriate safeguards in place, including Standard Contractual Clauses where required, and contractual commitments requiring a comparable level of protection consistent with PIPEDA. Where applicable, we also comply with the Swiss Federal Act on Data Protection.

Data covered by this Part may be subject to the laws of the jurisdictions in which it is stored. This does not apply to Customer Data, which remains in Canada - see Section 8.



20. Retention


Data

Period

Leads and enquiries

Up to 24 months from last meaningful interaction, then deleted or anonymised

Account administrator records

Duration of the Customer relationship, plus 12 months

Contract, billing and engagement records

Duration of the contract plus 7 years, for tax, audit and legal purposes

Website analytics

Up to 14 months; advertising and tracking cookies per the provider's stated period


We may retain data longer where required to comply with a legal obligation, establish or defend a legal claim, or enforce our agreements.



21. Your rights


Depending on where you live, you may have the right to access your Personal Data, correct it, request its deletion, object to or restrict processing, withdraw consent, request portability, and lodge a complaint with a supervisory authority - in Canada, the Office of the Privacy Commissioner of Canada.

To exercise any right, contact hello@meetmilo.co. We will verify your request by matching the identifying information you provide against our records, and will respond within the period required by applicable law. You may appoint an authorised agent to act for you.



22. Additional notice for California residents (CCPA/CPRA)


This section applies to residents of California and to Personal Data covered by Part B. Customer Data is handled by Milo Labs Inc. as a service provider and is governed by Part A and the applicable data processing agreement.

Notice at collection. We collect the following categories: identifiers (name, business email, telephone number, IP address); professional or employment information; and internet or network activity. We collect these to respond to enquiries, provide and administer the MILO Service, and operate advertising campaigns. Retention periods are set out in Section 20.

Your rights. You may request to know the categories and specific pieces of Personal Data we have collected about you; request correction of inaccurate data; request deletion, subject to legal exceptions; and opt out of "sharing" for cross-contextual behavioural advertising as described in Section 18. Milo Labs Inc. does not sell Personal Data for monetary consideration.

Sensitive personal information. We use sensitive personal information - such as credentials supplied to configure an integration - only to perform the services reasonably expected by you. We do not use it to infer characteristics.

Non-discrimination. We will not discriminate against you for exercising these rights. We do not offer financial incentives in exchange for the retention or sale of Personal Data.

Shine the Light. California Civil Code § 1798.83 permits California residents to request information about disclosures of Personal Data to third parties for those parties' direct marketing purposes. Direct such requests to hello@meetmilo.co.

How to exercise. Contact hello@meetmilo.co.



23. Security of Personal Data we control


We apply technical and organisational measures appropriate to the risk, consistent with those described in Section 10. Where a personal data breach occurs, we will notify affected individuals and the applicable regulatory authorities as required by law.



24. Third-party links


Our website links to third-party sites, including LinkedIn. We are not responsible for their privacy practices.



25. Children


The MILO Service and our website are directed to businesses, not to individuals under 16. We do not knowingly collect Personal Data from children. If we learn that we have, we will delete it promptly.



26. Changes to this policy


We may update this policy. Material changes affecting Customer Data - including changes to retention periods, hosting regions, or sub-processors - will be notified to Customers in advance, in writing, and where practicable at least thirty (30) days before taking effect. Other changes take effect when posted, with the revision date updated at the top of this page.



27. Contact


Milo Labs Inc.

280 Simcoe Street, Toronto, Ontario, M5T 2Y5, Canada

hello@meetmilo.co

This Privacy Policy is governed by the laws of the Province of Ontario and the applicable federal laws of Canada.




bottom of page