Privacy Policy Statement
Last updated: May 2026
1. Data Controller
Controller under GDPR: Milles, Leystrasse 4/3/35, 1200 Wien, Austria (commercial register FN 641781 x).
Representative: Boris Milic, M.A.
Email: contact@milles.fr
2. Scope
This Privacy Policy describes how milles at milles.fr—including the Austria-wide mediation marketplace linking customers with independent tradespeople ancillary web content and conversational assistance named milles-Orb processes personal data when you browse register or actively use marketplace features.
3. Personal data collected
Depending on use we may collect:
- Information you voluntarily give us: identifiers contact details invoicing particulars trade category profile copy optional photos passwords for registered accounts;
- Service interaction data relating to mediated jobs: postings offers chat threads review content transaction metadata;
- Technical access data typical of web stacks: shortened or full IP timestamps user agent device category language referrer web server logs;
- Inbound communication when you email us or submit contact forms;
- Information from supplementary sources publicly available chamber or trade-register extracts when needed to corroborate business credentials.
4. Purposes and legal bases
- Art 6(1)(b) GDPR contractual necessity: account onboarding delivering matching infrastructure billing paid membership features user support;
- Art 6(1)(c) GDPR statutory duties: bookkeeping tax retention supervisory requests platform regulation e.g Regulation EU 2019/1150 platform-to-business disclosures where mandated Digital Platforms Reporting Duty Act Austrian DPMG thresholds if applicable;
- Art 6(1)(f) GDPR overriding legitimate interests: secure reliable operation misuse detection limited analytics product improvement personalization absent solely automated legally significant profiling;
- Art 6(1)(a) consent: optional marketing newsletters not covered by transactional email privilege under Austrian UWG where applicable non-essential cookies voluntary profile enrichments;
- Direct-email service updates resembling offers to registered users may rely on Austrian UWG Section 7(3)—you may unsubscribe cost-free except transmission rates according to tariff;
5. milles-Orb and automated assistance
Inputs may drive probabilistic summaries category suggestions illustrative price corridors and ranking support;
We do not make solely automated Article 22 GDPR decisions producing legal effects; human escalation remains available complaints sanctions.
6. Recipients and disclosure categories
We neither sell profiling dossiers nor barter postal lists.
- Processors under Art 28 hosting email delivery backups analytics payment gateways each bound by GDPR-compliant DPAs;
- Counterpart marketplace users needing contact information to fulfil a mediated enquiry;
- Authorities courts when legally commanded;
- Lawyers auditors debt collectors enforcing permitted claims;
7. Third-country transfers
Where processors sit outside EU/EEA safeguards follow Chapter V GDPR SCCs plus supplementary Measures as needed.
8. Retention
Operational storage lasts while contractual relationship persists or archiving duties require;
Typical bookkeeping retention about seven Austrian fiscal years absent divergent mandates thereafter deletion or anonymization unless litigation reserves remain.
9. Your GDPR rights
- Access rectify erase restrict portability object against processing based legitimate interest—direct marketing objections anytime withdraw consent;
- Lodge supervisory complaint Austrian Data Protection Authority Barichgasse 40‑42 A‑1030 Vienna dsb@gv.at;
10. Account deletion by email
You may request deletion of your milles member account tied personal data anytime by emailing contact@milles.fr from your registered inbox briefly stating deletion intent.
- We acknowledge receipt and finalize erasure reasonably promptly respecting statutory freezes tax anti-fraud or ongoing proceedings requiring blocked records until grounds lapse.
11. Security
Industry-standard TLS role-based controls logging patching vendor diligence;
Breach notifications to supervisory authority Article 33 and where high risk arises data subjects Article 34.
12. Cookies
Strictly necessary technical storage enables sessions anti-abuse telemetry—Art 6(1)(f) plus Austrian TKG prerequisites;
Non-essential cookies require prior opt-in;
Browser help documentation explains blocking erasure;
13. Links
External sites impose their controllers review each policy separately—we assume no vicarious GDPR liability.
14. Children
Platform isn't directed knowingly collect under-18 minors' identifiable data discontinue if discovered unintended collection.
15. Changes
Updates appear here materially impactful communications follow procedures under our Terms & Conditions. Revisit periodically for the freshness marker.
16. Contact
Write contact@milles.fr or postal address above concerning privacy grievances corrections rights exercises.