MIMIR

Subprocessors

Version 1.0 · Last updated: 29 July 2026

This page is the subprocessor list referred to in §7 of the Data Processing Addendum. We give at least 30 days' notice here before adding or replacing a subprocessor. To be notified by email as well, write to hello@mimirdesk.com and ask to join the subprocessor notification list.

TermsAcceptable UsePrivacyDPASubprocessorsRefundCopyright

1. Where the platform runs

MIMIR's servers, database and backups are hosted in Vilnius, Lithuania (European Union). Both the primary server and the encrypted off-site backup are in the EU. Customer Data is at rest in the EU; transfers happen only when an action needs an external provider, as set out below.

2. MIMIR subprocessors

These providers process Customer Data under our accounts. We are responsible for them under the DPA.

ProviderPurposeData it can seeLocation
Hostinger Cloud infrastructure — the server, database and off-site backups All Customer Data, at rest and in transit on our infrastructure Lithuania (EU)
Anthropic (Claude) The AI that drafts, researches, analyses and replies — managed mode only The prompt content an action needs: your instructions plus the relevant lead or client record United States
Google (Gemini API) Media understanding and generation for the video/montage features — managed mode only Media files and prompts you submit to those features United States
ElevenLabs Speech and music generation for voice and media features — managed mode only The text to be spoken and generation parameters United States
Resend Our own transactional email to you — licence key, PIN reset, balance alerts — and inbound parsing of replies to our address Your account email address and the content of those messages United States
Stripe Subscription billing and credit top-ups Your billing identity, email and payment metadata. Card details go to Stripe directly and never reach us. Ireland / United States
Telegram Operational alerts to MIMIR's own operator — for example that a payment succeeded or a job failed Operational metadata. An alert summary line can include a prospect or business name. Outside the EEA

Transfers to providers outside the EEA are made under the Standard Contractual Clauses or the provider's EU–US Data Privacy Framework certification, as described in §12 of the DPA.

3. Providers you connect yourself

These are not our subprocessors. When you connect your own account or key, you contract that provider directly; they are your processor and you are responsible for your relationship with them. We only relay your instruction.

ProviderWhat it does for youWhen it applies
Anthropic or OpenAIRuns the AI on your own key instead of our managed creditYou opt into bring-your-own AI
Your email sending providerDelivers your outreach from your own domain — you are the sender of recordEmail outreach
DIDWW or another SIP providerYour phone number and trunk for outbound callsVoice calling
ElevenLabs / OpenAISpeech synthesis and recognition for the voice agent on your keyVoice calling in bring-your-own mode
Meta (WhatsApp Business, Instagram, Messenger)The messaging channels you connect for yourself or a clientMessaging channels
TelegramA bot you connect for yourself or a clientTelegram channel

4. Other recipients

5. Changes to this list

We publish changes here with a new version and date at least 30 days before they take effect, except where we must replace a provider immediately for security or continuity — in which case we publish as soon as we can and tell you why. Your right to object is in §7.3 of the DPA.

HomeTermsAcceptable UsePrivacyDPARefund PolicyCopyrightContact