Privacy Policy

MIGLASS OÜ · Last updated: 8 August 2026

This policy explains how MIGLASS OÜ processes personal data in connection with the milog website (milog.org) and the milog customer portal (portal.milog.org), together the “Service”.

1. Who we are

ControllerMIGLASS OÜ
Registry code17279377
VAT numberEE102879090
AddressTiigi tn 2b, Narva 20104, Estonia
Contact for privacy mattersinfo@milog.org

We have not appointed a Data Protection Officer, as we are not required to under Article 37 of the GDPR. Privacy questions are handled at the address above.

2. Two different roles

Please note the distinction, because it determines who you should contact about your data:

3. What we process and why

CategoryExamplesPurposeLegal basis (Art. 6 GDPR)
Account data Name, e-mail address, password (stored only as a bcrypt hash), declared country, company name, role Creating and running your account, authentication, support Performance of a contract, 6(1)(b)
Technical and security data IP address, browser type, timestamps, server and audit logs, sign-in events, failed sign-in counters Keeping the Service available and secure, preventing abuse and brute-force attacks, investigating incidents Legitimate interest, 6(1)(f) — securing our systems and our customers’ data
Business data you enter Counterparties, contacts, quotes, consignments, invoices, tracking data; e-mail content if you connect a mailbox Providing the functionality you use Performance of a contract, 6(1)(b); for data about third parties we act as processor (section 2)
Billing data Subscription plan, invoices, payment status, company and VAT details Charging for the Service and meeting accounting duties Contract 6(1)(b); legal obligation 6(1)(c)
Communications Support correspondence, service notifications Answering you, notifying you about the Service Contract 6(1)(b); legitimate interest 6(1)(f)
Optional features Push notifications, AI assistance, read receipts, marketing e-mails Only the features you switch on (see section 5) Consent, 6(1)(a) — withdrawable at any time

4. Cookies and local storage

The portal uses strictly necessary storage only. We do not run advertising or analytics cookies in the portal, and therefore no cookie consent banner is shown there.

Clearing your browser storage signs you out; it does not delete your account.

5. Optional features that involve extra processing

AI assistance

Some features (message summaries, suggested replies, translation, customs classification hints, AI chat) send the text you selected to an AI provider so that it can generate an answer. This happens only when you use such a feature. Providers are listed in section 6. If you do not want your content sent outside our servers, do not use these features.

Read receipts in outgoing e-mail

The mail module can add an invisible 1×1 image to outgoing messages that tells the sender when the recipient opened the e-mail. This is switched off by default. If a customer enables it, that customer is the controller of the resulting information and is responsible for having a lawful basis under the GDPR and Article 5(3) of the ePrivacy Directive, and for disclosing it in its own privacy notice.

Push notifications

If you allow notifications, your browser creates a push subscription with the push service of your browser vendor (for example Google, Mozilla or Apple). We store that subscription in order to deliver notifications and delete it when you turn notifications off.

Marketing and newsletters

Newsletters sent through the Service use confirmed opt-in and every message carries an unsubscribe link. Unsubscribing is honoured immediately and the address is added to a suppression list so it is not contacted again.

6. Who receives data

We do not sell personal data and we do not share it for advertising. Data is disclosed only to the service providers we need in order to run the Service:

RecipientRoleLocation
P.A.G.M. OÜ (AS198068)Server hosting — all application data and databasesEstonia (EU)
Anthropic PBCAI processing of content you submit to AI featuresUnited States
OpenRouter, Inc.Routing of requests to AI models, AI image generationUnited States
European Commission (VIES)Validation of VAT numbers you enterEU
Browser push services (Google, Mozilla, Apple and similar)Delivery of push notifications you enabledVaries by vendor
Social networks (e.g. VK)Only if a customer connects such an account for publishing its own postsVaries by vendor

We may also disclose data to public authorities where we are legally required to do so, and to professional advisers under a duty of confidentiality.

7. Transfers outside the EEA

Our servers and databases are located in Estonia, inside the European Union. Transfers outside the EEA occur only for the AI features described above, where content is transmitted to providers in the United States. Those transfers rely on the European Commission’s Standard Contractual Clauses and the providers’ supplementary safeguards. You can avoid such transfers entirely by not using AI features.

8. How long we keep data

9. How we protect data

No system can be guaranteed to be perfectly secure, but we work to a level appropriate to the risk, as required by Article 32 of the GDPR.

10. Your rights

Under the GDPR you may ask us to:

Write to info@milog.org. We answer within one month. We may need to verify your identity before acting. Where we act as a processor on behalf of a customer (section 2), we will forward your request to that customer.

You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, info@aki.ee, www.aki.ee, or with the supervisory authority of your country of residence.

11. Automated decision-making

We do not make decisions producing legal or similarly significant effects about you by automated means. AI features produce suggestions for a human to review; they do not decide anything on their own.

12. Children

The Service is a business tool and is not directed at children. We do not knowingly collect data from persons under 16.

13. Changes to this policy

We may update this policy. The date at the top always shows the current version. If a change is material, we will notify account holders by e-mail or through the portal before it takes effect.