MIMIR

Privacy Policy

Version 2.0 · Last updated: 29 July 2026

This policy explains how SIA "MIMIR", Reg. No. 40203749446, Stabu iela 26–2A, Riga, LV-1011, Latvia ("MIMIR", "we") handles personal data on mimirdesk.com and app.mimirdesk.com. We are established in the European Union, so the GDPR applies to us directly; US state privacy laws apply to the personal data of US residents we handle.

TermsAcceptable UsePrivacyDPASubprocessorsRefundCopyright

1. Two different roles — read this first

We are the controller of data about you, our customer: your account, your billing, your support messages, and how you use our website.

We are only a processor of the data inside your workspace — the leads, prospects, clients, notes, call records and message content your AI agents work with. That data is yours. You decide whose details go in, why, and who gets contacted; we only act on your instructions. If you are a prospect who received outreach and want your details removed, the business that contacted you is the controller and is who you need — we will pass your request on and tell you who they are where we lawfully can. The Data Processing Addendum governs that relationship.

2. What we collect as controller, and why

DataWhy we have itLegal basis (GDPR Art. 6)
Email address, brand name, hashed login PIN, licence keyTo create and secure your account and let you sign in. The PIN is never stored in readable form.Performance of a contract
Subscription and payment records — amount, date, reference, credit ledgerBilling, refunds, accounting and tax recordsContract; legal obligation
Connected provider keys, where you choose to connect your ownTo run your workspace on your own provider accounts. Stored encrypted at rest with a key never sent to your browser; we do not read them or use them for anything else.Contract
Operational logs — request metadata, AI usage and cost records, error logs, security eventsTo run, bill, debug and secure the platform, and to investigate abuseLegitimate interests (operating and securing a service we are responsible for)
Support correspondenceTo answer you and keep a record of what was agreedContract; legitimate interests
Website usage counts (see §6)To understand which pages workLegitimate interests (cookieless, non-identifying)
Advertising measurement, only if you opt inTo see which ads bring customersConsent

Where we rely on legitimate interests, we have considered your interests and rights and use the least intrusive option that achieves the purpose. You can object — see §9.

3. Payments

Subscriptions and credit top-ups are processed by Stripe. Card details are entered on and held by Stripe; we never receive or store them. We keep the resulting order and ledger records for billing, accounting and statutory retention. Stripe handles that payment data under its own privacy terms and as an independent controller for its own compliance purposes.

4. How the AI processing works

To run your AI team, the content an action needs — your instructions plus the relevant lead or client data — is sent to an AI provider for processing.

Beyond the providers needed to carry out an action you asked for — your email provider to deliver an email you approved, your telephony provider to place a call you approved, a messaging platform to deliver a message — we do not share workspace data with third parties. We do not sell personal data, we do not share it for cross-context behavioural advertising, and we never give your leads, clients, notes or messages to an advertising network. We do not use your workspace data to train our own models.

The current list of providers is at mimirdesk.com/subprocessors.html, which we keep up to date and give notice against under the DPA.

5. Where data lives, and international transfers

The platform, its database and its backups run on servers in the European Union. Some of the providers above are established in the United States, so operating the Service involves transferring personal data outside the EEA.

For those transfers we rely on the European Commission's Standard Contractual Clauses, or on the provider's certification under the EU–US Data Privacy Framework where it holds one, together with the supplementary measures the transfer requires — principally encryption in transit and data minimisation, so that only the content an action actually needs leaves the EU. You may request a copy of the relevant transfer mechanism at hello@mimirdesk.com.

6. Cookies, analytics and advertising

Analytics — cookieless by default. We measure traffic with Umami, self-hosted on our own server and served from our own domain. It sets no cookies, stores no IP addresses and builds no cross-site profile; the anonymous counts never leave our infrastructure. It is not a third-party processor.

Advertising — only with your consent. We advertise MIMIR on platforms including Meta (Facebook and Instagram) and Google. Their measurement tags load only if you actively opt in to marketing cookies. If you opt in, those tags may set cookies and tell the platform that you visited or subscribed, so we can tell which ads work — that is the only purpose we use them for. If you do not opt in, no advertising tag loads and we set no advertising cookie.

Web fonts. These legal pages and our marketing site serve their typefaces from our own domain, so reading them sends no request to any third party. The signed-in app, and the preview sites the site Builder generates, still load fonts from Google's font CDN (fonts.googleapis.com / fonts.gstatic.com); a browser's request to that CDN discloses its IP address to Google. We are moving those surfaces to self-hosted fonts as well.

Changing your mind. Choose the necessary-cookies-only option where a cookie choice is offered, or clear this site's cookies and stored site data — after that no advertising tag loads again unless you opt in anew. To switch the cookieless analytics off as well, set umami.disabled=1 in this site's localStorage.

7. Retention

8. Security

We apply measures appropriate to the risk, including: per-tenant logical isolation; TLS in transit; encryption at rest for connected provider secrets, with a key never shipped to the browser; licence key plus PIN authentication; least-privilege server access over SSH keys; approval-gating of outbound sending; audit logging of security-relevant events; and regular, integrity-verified off-site backups. No system is perfectly secure. If a breach affects your personal data and is likely to result in a high risk to you, we will notify you and the competent supervisory authority as the GDPR requires.

9. Your rights

If the GDPR applies to you (you are in the EEA or UK), you have the right to access your data, to have it corrected or erased, to restrict or object to processing, to data portability, and to withdraw consent at any time without affecting processing already carried out. You also have the right to lodge a complaint with a supervisory authority — ours is the Data State Inspectorate (Datu valsts inspekcija) in Latvia, and you may also complain to the authority where you live.

If a US state privacy law applies to you, you may have the right to know what we hold, to access a copy, to correct it, to delete it, to opt out of sale, sharing or targeted advertising, to limit the use of sensitive personal information, and not to be discriminated against for exercising a right. We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of on that front. Note that California's law, unlike other US state laws, has no business-to-business exemption, so a named business contact has rights there too.

How to exercise a right. Email hello@mimirdesk.com from the address on your account, or with enough detail for us to find you. We answer within one month under the GDPR and within the period the applicable US state law requires (usually 45 days, extendable once). We will not charge you unless a request is manifestly unfounded or excessive, and we may need to verify your identity first. You may use an authorised agent where the law allows.

If we refuse. You may appeal by replying to our decision with the word "appeal" and your reasons. We will review and respond in writing with the outcome, and if we still refuse we will tell you how to complain to your regulator. Several US state laws require this appeal route and we offer it to everyone.

Self-service. You can export your leads, clients, tasks and memory at any time from Settings → Download my data, and request deletion of the workspace at any time.

10. Requests about someone we contacted on a customer's behalf

If you received an email or call generated through MIMIR and want your details removed, use the unsubscribe link or tell the caller to stop — that is the fastest route and the business that contacted you must honour it. You can also write to us and we will route your request to the customer who holds the data and, where lawful, identify them to you so you can exercise your rights directly. We cannot decide on their behalf whether to erase their records, because we are their processor, not the controller.

11. Children

The Service is for businesses. It is not directed at children and we do not knowingly collect personal data from anyone under 16. If you believe a child's data has reached us, tell us and we will delete it.

12. Changes and contact

We may update this policy; material changes will be posted here with a new version and date and, where the change affects you materially, notified by email. Questions, requests and complaints: hello@mimirdesk.com, or by post to SIA "MIMIR", Stabu iela 26–2A, Riga, LV-1011, Latvia.

HomeTermsAcceptable UseDPASubprocessorsRefund PolicyCopyrightContact