This Data Processing Addendum ("DPA") forms part of the Terms of Service between you ("Customer", "Controller") and SIA "MIMIR", Reg. No. 40203749446, Riga, Latvia ("MIMIR", "Processor"). It governs our processing of personal data on your behalf. No signature is required — it applies automatically to every customer from the moment the Terms are accepted. If your organisation needs a counter-signed copy, write to hello@mimirdesk.com.
"Personal Data", "Processing", "Controller", "Processor", "Data Subject", "Personal Data Breach" and "Supervisory Authority" have the meanings given in the GDPR (Regulation (EU) 2016/679). "CCPA" means the California Consumer Privacy Act as amended by the CPRA and its regulations. "Applicable Data Protection Law" means the GDPR, the UK GDPR, the CCPA and any other privacy law applicable to a party's processing under the Terms. Customer Data means personal data that you submit to, or that is generated within, your workspace.
2.1 You are the Controller and we are the Processor of Customer Data. You determine whose data enters the workspace, why, and who is contacted.
2.2 For US privacy law we act as a Service Provider (CCPA) or the equivalent processor role under other state laws.
2.3 We are an independent Controller of the account, billing, support and website data described in §2 of the Privacy Policy. That data is outside this DPA.
2.4 Managed versus bring-your-own AI. Where you use MIMIR-managed AI credit, we transmit the relevant Customer Data to our AI subprocessors under our own accounts, and they are our subprocessors. Where you connect your own provider keys, you contract those providers directly and they are your processors, not our subprocessors; our role is limited to relaying your instruction.
| Item | Detail |
|---|---|
| Subject matter | Provision of the MIMIR platform under the Terms of Service. |
| Duration | The term of the Terms, plus the deletion window in §10. |
| Nature and purpose | Lead research; drafting and, on your approval, sending outreach email; drafting and, on your approval, placing outbound AI calls; messaging on channels you connect; CRM and pipeline storage; generation of preview sites, reports, proposals and invoices; analytics on your own data — all on your instruction. |
| Categories of Data Subjects | Your prospects and clients (business contacts and their personnel), visitors who interact with a chat assistant you deploy, and your own staff who operate the workspace. |
| Categories of Personal Data | Business contact details (name, role, business email, business phone, company, website, public listing data); notes and correspondence you or your agents create; email and call content and metadata; approval and audit records; workspace login identifiers. |
| Special categories | None. The platform is not designed for special-category data under Art. 9 or for data about children, and you must not submit it. |
4.1 We process Customer Data only on your documented instructions — the Terms, this DPA, and the instructions you give through the platform, such as approving a send or a call — unless required otherwise by EU or Member State law, in which case we notify you first unless that law prohibits it.
4.2 We will tell you if, in our opinion, an instruction infringes Applicable Data Protection Law. We are not obliged to monitor your compliance and do not do so.
4.3 You warrant that you have a lawful basis for the data you put into the workspace and for the outreach you direct, that you have given any notice and obtained any consent required, that you are the sender and caller of record, and that your instructions comply with Applicable Data Protection Law. See the Acceptable Use Policy.
We ensure that any person authorised to process Customer Data is subject to an appropriate duty of confidentiality and processes it only on our instructions.
We implement appropriate technical and organisational measures, including: per-tenant logical isolation of data; encryption in transit (TLS); encryption at rest of connected provider secrets, with a key never shipped to the browser; licence key plus PIN authentication; least-privilege administrative access over SSH keys; approval-gating of outbound sending and calling; audit logging of security-relevant events; and regular, integrity-verified off-site backups. We may change these measures provided the level of protection is not reduced.
7.1 You give general written authorisation for us to engage subprocessors. The current list, with purpose and location, is published at mimirdesk.com/subprocessors.html.
7.2 We impose data-protection obligations on each subprocessor that are no less protective than this DPA, and we remain fully liable to you for their performance.
7.3 We give at least 30 days' notice before adding or replacing a subprocessor, by updating that page and — if you ask us to put you on the notification list — by email. You may object within that period on reasonable, documented data-protection grounds; if we cannot resolve your objection, you may terminate the affected part of the Service without penalty and receive a pro-rata refund of prepaid fees for the terminated portion.
8.1 Taking into account the nature of the processing, we assist you with appropriate technical and organisational measures in responding to requests to exercise rights of access, rectification, erasure, restriction, portability and objection. The platform provides self-service export and deletion for this purpose.
8.2 If a Data Subject contacts us directly about Customer Data, we will not respond substantively; we will refer them to you and pass the request on without undue delay.
We notify you without undue delay and, where feasible, within 72 hours of becoming aware of a Personal Data Breach affecting Customer Data. The notice will describe the nature of the breach, the categories and approximate volume of data and Data Subjects affected, the likely consequences and the measures taken, to the extent that information is available to us, and we will provide updates as we learn more. We assist you with your own notification duties under Arts. 33 and 34, and with data-protection impact assessments and prior consultation under Arts. 35 and 36, taking into account the information available to us.
On termination or expiry, you may export your data from the platform at any time until access ends. At your choice we will return or delete Customer Data within 30 days of your request, and delete existing copies, unless EU or Member State law requires retention. Backup copies are deleted on the ordinary backup-rotation cycle and remain protected by this DPA until they are.
We make available the information necessary to demonstrate compliance with Art. 28 and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. Audits take place no more than once per twelve months — unless a Supervisory Authority requires otherwise or a Personal Data Breach has occurred — on at least 30 days' written notice, during business hours, subject to confidentiality, without unreasonable disruption, and at your cost. We may satisfy an audit request by providing an up-to-date description of our measures and answering a reasonable security questionnaire.
Our infrastructure is in the European Union. Where processing involves transferring Customer Data outside the EEA or the UK to a country without an adequacy decision, the transfer is made under the European Commission's Standard Contractual Clauses (Decision 2021/914), with the UK International Data Transfer Addendum and the Swiss addendum applying where relevant, or under the recipient's certification to the EU–US Data Privacy Framework where it holds one.
Where the SCCs apply and we act as your processor, Module Two (controller to processor) applies with you as data exporter and us as data importer; where we onward-transfer to a subprocessor, Module Three (processor to processor) applies. The SCCs are incorporated into this DPA by reference and take precedence over it in case of conflict. For the purposes of the SCC annexes: Annex I(A) parties are as identified above; Annex I(B) is §3 of this DPA; Annex I(C) supervisory authority is the Latvian Datu valsts inspekcija; Annex II is §6 of this DPA; and Annex III is the subprocessor list.
We act as a Service Provider under the CCPA and as a processor under other US state privacy laws. We will not: (a) sell or share Customer Data, as those terms are defined by the CCPA; (b) retain, use or disclose it for any purpose other than performing the Service specified in the Terms, or otherwise outside our direct business relationship with you; or (c) combine it with personal information received from another source, except as the CCPA permits. We certify that we understand these restrictions and will comply with them. We will notify you if we determine we can no longer meet our obligations, and you may take reasonable steps to stop and remediate unauthorised use.
Liability under this DPA is subject to the limitations and exclusions in the Terms, except where Applicable Data Protection Law does not permit that. In case of conflict on data-protection matters, this DPA prevails over the Terms, and the SCCs prevail over this DPA.
Privacy and data-protection contact: hello@mimirdesk.com, or SIA "MIMIR", Stabu iela 26–2A, Riga, LV-1011, Latvia. We have not appointed a Data Protection Officer; we are not required to. Our lead supervisory authority is the Data State Inspectorate (Datu valsts inspekcija), Latvia.