This Privacy Policy explains how DD Axis Ltd ("DDAXIS") collects, uses, stores, processes, and shares information in connection with the MILO platform and the MILO browser extension.
1. General
MILO is a workplace automation platform and browser extension operated by DD Axis Ltd ("DDAXIS", "we", "us"). This Privacy Policy explains how we collect, use, store, process, and share information in connection with MILO.
This policy applies to the MILO platform, the MILO browser extension, the MILO marketing website, pilots, demos, onboarding, support, and related services.
2. Limited use and no advertising
MILO does not sell user data. MILO does not use browser activity, website content, action recordings, workflow data, customer business content, extension telemetry, or run logs for advertising, retargeting, unrelated profiling, or any purpose unrelated to providing, securing, supporting, and improving MILO's user-facing automation features.
We do not transfer or share user data with third parties for advertising or unrelated profiling purposes.
3. Privacy roles
DD Axis Ltd acts as controller with respect to account data, login and security data, platform usage data, billing and contact data, website data, support data, and other operational data for which we determine the purposes and means of processing.
DD Axis Ltd acts as processor on behalf of the Customer with respect to Customer Content processed through MILO, including workflow data, action recordings, run logs, operational content, and other automation-related customer data, in accordance with the Customer's instructions and the Data Processing Addendum.
4. Categories of information processed
MILO processes only the limited operational and browser-extension data required to provide its automation features. This may include: account data; organization data; extension installation identifier; device identifier; extension version; connection status; approved domain and URL metadata where the extension is active; screen titles and page context where required for workflow detection; field labels; button labels; form interaction metadata; click, select, and input event metadata; copy and paste event metadata; workflow step metadata; workflow suggestions; workflow approval events; run logs; audit logs; error logs; security and rate-limit events; support requests; and marketing communication data where provided by the user or organization.
MILO does not intentionally collect or store: full page HTML; screenshots; passwords; authentication cookies; raw authentication tokens; API keys; full payment card data; or unnecessary full sensitive field values.
The MILO browser extension is not intended to collect or store raw sensitive personal data, and is not designed to operate as a surveillance, screen-capture, or credential-harvesting tool.
5. Sensitive information and data minimization
MILO is not intended to collect or store raw sensitive personal data. The MILO browser extension does not intentionally collect passwords, authentication cookies, raw tokens, API keys, full payment card data, or unnecessary sensitive field values.
Where possible, sensitive values are masked, summarized, hashed, excluded, or stored only as metadata rather than raw content.
MILO is designed to collect the minimum data reasonably required to provide its automation features. Where possible, sensitive values are masked, summarized, hashed, excluded, or stored as metadata rather than raw content.
6. Browser extension data and permissions
The MILO browser extension requests only the permissions required to provide its stated functionality: detecting repetitive browser-based work patterns, creating workflow suggestions, syncing approved workflows, presenting user approvals, and reporting execution logs. The extension is intended to operate only within approved work environments, approved domains, and according to the Customer's organizational configuration.
The extension does not use data for advertising, retargeting, unrelated profiling, or sale of data.
Users and administrators can disable, revoke, disconnect, or remove the extension at any time through MILO product settings and the browser's extension controls. Disconnecting the extension stops further collection from the affected device.
MILO provides visibility into what the extension records, stores, and sends through in-product approvals, audit logs, and run logs available to authorized users and administrators.
6.1 Browser Extension Informed Consent
Before the MILO browser extension starts recording browser interaction metadata or transmitting workflow-related data, the user is presented with an informed-consent notice and a link to this Privacy Policy. The user must actively confirm the notice by selecting an acknowledgement checkbox that is not pre-selected. If the user does not provide consent, the extension will not start recording browser interaction metadata, create workflow suggestions, sync approved workflows, or report execution logs, except for strictly necessary technical data required to operate the consent flow or manage installation status.
The consent notice describes what the extension may record: approved domain and URL metadata, screen titles and page context, field labels, button labels, interaction metadata, click, select, and input events, copy and paste event metadata, workflow step metadata, workflow suggestions, approval events, run logs, audit logs, error logs, and security and rate-limit events.
The consent notice describes what the extension does not intentionally collect or store: passwords, authentication cookies, raw tokens, API keys, full payment card data, full page HTML, screenshots, or unnecessary full sensitive field values.
The consent notice states that MILO does not sell user data, and that MILO does not use extension data, browser activity, website content, action recordings, workflow data, customer business content, extension telemetry, or run logs for advertising, retargeting, unrelated profiling, or any purpose unrelated to providing, securing, supporting, and improving MILO.
The consent notice includes a visible link to this Privacy Policy at /legal/privacy.
Administrator approval or organization-level installation approval does not replace the end-user informed-consent notice. Consent is recorded with timestamp, Privacy Policy version, language, applicable user or device identifier, and applicable organization or workspace context, and is auditable. When the Privacy Policy version changes, MILO may require renewed consent before further recording.
7. Use of AI models
MILO uses AI model providers to interpret recorded workflow steps, summarize user actions, suggest workflow structure, classify risk, draft user-facing text, and improve workflow reliability.
AI processing is used only to provide, secure, support, and improve MILO's user-facing automation features. Browser activity, website content, action recordings, workflow data, customer business content, extension telemetry, and run logs are not used for advertising, retargeting, or unrelated profiling.
Where possible, sensitive values are minimized, masked, summarized, or excluded before AI processing. We do not claim that no data is ever sent to AI providers; AI APIs are an integral part of several MILO features.
Current AI providers include OpenAI, Anthropic, and Google. Each is engaged under its own terms and is listed in the subprocessor section below.
8. Purposes of processing
Information is processed solely to: provide MILO's automation features; identify repetitive browser-based work patterns; create workflow suggestions; sync approved workflows; present user approvals; report execution logs; maintain audit trails; secure the platform and prevent abuse; provide customer support; comply with legal obligations; and improve product reliability and user-facing automation features.
Information is not processed for advertising, retargeting, unrelated profiling, or the sale of personal data.
9. Possible legal bases
Where applicable law requires a legal basis, processing may rely on performance of a contract, legitimate interests (operating, securing, and improving MILO), consent, compliance with a legal obligation, or Customer instructions where DD Axis Ltd acts as processor.
11. International transfers
Information may be processed in Israel, the European Economic Area, the United States, and other locations where MILO or its subprocessors operate.
Such transfers are carried out in accordance with applicable law, appropriate contractual protections, and customary security measures.
12. Retention
We retain information only for as long as needed to provide the Service, meet legal obligations, support audits, and protect rights. Default retention periods are:
Action recordings: 30–90 days by default, depending on workspace configuration and operational need.
Run logs: 12 months.
Audit logs: 24–36 months.
Device records: retained while the extension remains connected, and for 90–180 days after disconnection.
Support data: 24 months.
Marketing data: retained until the user unsubscribes, requests deletion, or the data is no longer needed.
Account data is retained while the account is active and for a reasonable period afterwards to meet legal, audit, and dispute-resolution needs.
13. Information security
Personal and sensitive user data is transmitted using secure encrypted connections such as HTTPS and WSS.
Data stored by MILO is protected using appropriate security controls, including tenant separation, access controls, row-level security where applicable, hashed device tokens (raw device tokens are not stored where hashed tokens are used), audit logging, rate limiting, role-based access controls, and encryption at rest where supported by the underlying infrastructure.
Access to organization data is limited according to user permissions, organization membership, and role-based controls.
No system is completely secure. In the event of a material security incident, DD Axis Ltd will act in accordance with applicable law and customer agreements.
14. Data subject rights
Subject to applicable law, individuals whose personal information is processed in MILO may have the right to request access, correction, deletion, restriction, objection, portability, or additional information about the processing.
Where information is processed on behalf of an organizational Customer, requests will generally be directed to that Customer, which determines the purposes and means of processing. DD Axis Ltd will assist the Customer in responding to such requests in accordance with the agreement and applicable law.
Data subject requests may be sent to gil@ddaxis.com.
15. Employee privacy
MILO may operate in employee work environments and record digital actions necessary for workflow detection and automation.
The Customer is responsible for informing employees, obtaining consents where required, updating internal policies, and ensuring that use of MILO complies with employment law, privacy law, information-security requirements, and relevant agreements.
17. Minors
MILO is intended for professional organizational use and is not intended for personal use by minors.
18. Policy updates
DD Axis Ltd may update this policy from time to time. This version is 1.1.0 with effective date 2026-06-22.
Material changes will be displayed in the platform or sent to customers using available contact details. Continued use of MILO after an update constitutes acceptance of the updated policy, subject to applicable law.
19. Contact
Operator: DD Axis Ltd (DDAXIS).
Privacy questions: gil@ddaxis.com.
Security questions and incident reports: gil@ddaxis.com.
Data access, correction, deletion, and objection requests: gil@ddaxis.com.
