GDPR position
No recruited panel. No tracker by default. Submitted personal data is still personal data.
What Mimiq does not collect by default — and what you may still submit
The architectural claim
Mimiq uses simulated personas instead of recruiting a participant panel. A standard test does not install a tracker on your product or observe real end users. Mimiq still processes your account details and the URLs, prompts, uploads, and optional customer rows you choose to submit.
Less data is a useful architectural choice, not a compliance exemption. Under EU guidance, information about an identifiable person — including data that is merely pseudonymised — remains personal data. Do not submit personal data unless you are authorised to process it and it is necessary for the test. European Commission guidance
What data we handle
An honest inventory of every byte that touches our system
- Your account infoEmail, name, billing details, credit balance
Processed to provide the service. Deleted with your account.
Personal data (yours) - URLs you testPublicly reachable website or prototype URLs, screenshots, and other content you submit for testing
Processed to run the test and produce a report. Avoid private URLs or embedded personal data unless you are authorised to submit them.
Confidential; may contain personal data - Prompts you submitYour test questions, goals, audience descriptions
Used to run the test. Prompts may be sent to model providers through AWS Bedrock. Do not include unnecessary personal or sensitive data.
Confidential; may contain personal data - Optional customer importsRows you upload from analytics, CRM, billing, or research tools
You control whether to use this feature and must have a lawful basis. Minimise or remove direct identifiers before upload whenever possible.
May be personal data - Synthetic persona profilesDemographically generated participants (name, age, occupation, traits)
Generated from aggregate priors and model output, not recruited from a participant panel. Do not treat a persona as a real individual.
Designed to be fictional - Simulation resultsWhat synthetic personas 'said' about your test content
Not a real participant voice. Because output can quote or transform your input, handle the report at the same sensitivity as the source material.
Model output; may reflect submitted content - Your end usersThe real people who visit your website or use your product
Mimiq does not install an end-user tracker for a standard test. If you upload customer data or expose it in a tested page, that data enters the processing scope.
Not observed by default
Launch architecture
The AWS production path; final deployment canary still required
GDPR specifics
Article-by-article position
- Art. 4 — Personal data
Persona profiles are designed as fictional statistical constructs, not recruited records. Account data and identifiable information in customer submissions remain personal data.
Scoped - Art. 6 — Lawful basis
Mimiq relies on the appropriate basis for its own account and service operations. Customers remain responsible for a lawful basis covering any personal data they choose to submit.
Shared responsibility - Art. 17 — Right to erasure
Deletion requests are handled at victor@mimiqai.com. Automated account-wide deletion and a documented retention schedule are launch-hardening items.
Manual today - Art. 20 — Data portability
Report exports are available in product where shown; a broader account export is available by request. A share link is not presented as a substitute for a portability export.
Available by request - Art. 28 — Data processors
The current sub-processor list and transfer terms are available on request. Customers submitting personal data should execute the applicable DPA before doing so.
Review before PII - Art. 33 — Breach notification
Incidents will be assessed and notified as required by applicable law and processor terms. A formal, exercised incident-response runbook remains a launch-hardening gate.
Runbook pending - Art. 35 — DPIA
Whether a DPIA is required depends on the customer's purpose, data, and deployment. Mimiq cannot make that legal determination for every use case.
Customer assessment - International transfers
The launch architecture uses AWS US regions and US model inference profiles. Account data and submitted content may therefore be processed in the US; review the current transfer mechanism and DPA before submitting personal data.
US processing disclosed
What the synthetic-participant model changes
No participant recruitment records
A standard Mimiq test does not collect participant names, contact details, consent records, screen recordings, or panel payments because no real panel is recruited.
Customer content still matters
URLs, prompts, uploads, and optional customer imports may be confidential or personal data. They still require minimisation, access controls, retention rules, and an appropriate lawful basis.
Directional evidence, not human research
The smaller participant-data footprint comes with a clear boundary: simulated reactions diagnose likely confusion and disagreement; they do not become human-subject evidence.
Get the docs
For procurement teams, security reviewers, DPOs
Questions?
security@mimiqai.com · victor@mimiqai.com · We aim to reply within two business days