GDPR position

No recruited panel. No tracker by default. Submitted personal data is still personal data.

What Mimiq does not collect by default — and what you may still submit

The architectural claim

Mimiq uses simulated personas instead of recruiting a participant panel. A standard test does not install a tracker on your product or observe real end users. Mimiq still processes your account details and the URLs, prompts, uploads, and optional customer rows you choose to submit.

Less data is a useful architectural choice, not a compliance exemption. Under EU guidance, information about an identifiable person — including data that is merely pseudonymised — remains personal data. Do not submit personal data unless you are authorised to process it and it is necessary for the test. European Commission guidance

What data we handle

An honest inventory of every byte that touches our system

  • Your account infoEmail, name, billing details, credit balance

    Processed to provide the service. Deleted with your account.

    Personal data (yours)
  • URLs you testPublicly reachable website or prototype URLs, screenshots, and other content you submit for testing

    Processed to run the test and produce a report. Avoid private URLs or embedded personal data unless you are authorised to submit them.

    Confidential; may contain personal data
  • Prompts you submitYour test questions, goals, audience descriptions

    Used to run the test. Prompts may be sent to model providers through AWS Bedrock. Do not include unnecessary personal or sensitive data.

    Confidential; may contain personal data
  • Optional customer importsRows you upload from analytics, CRM, billing, or research tools

    You control whether to use this feature and must have a lawful basis. Minimise or remove direct identifiers before upload whenever possible.

    May be personal data
  • Synthetic persona profilesDemographically generated participants (name, age, occupation, traits)

    Generated from aggregate priors and model output, not recruited from a participant panel. Do not treat a persona as a real individual.

    Designed to be fictional
  • Simulation resultsWhat synthetic personas 'said' about your test content

    Not a real participant voice. Because output can quote or transform your input, handle the report at the same sensitivity as the source material.

    Model output; may reflect submitted content
  • Your end usersThe real people who visit your website or use your product

    Mimiq does not install an end-user tracker for a standard test. If you upload customer data or expose it in a tested page, that data enters the processing scope.

    Not observed by default

Launch architecture

The AWS production path; final deployment canary still required

You (browser)
HTTPS/TLS
CloudFrontS3 + same-origin API
HTTP origin hopCloudFront prefix list+ secret origin header
ALB → ECS API+ SQS worker
AWS Bedrockmodel inference
DynamoDBretained records
Stripe + Cognitobilling + auth
Plainly: one CloudFront distribution fronts separate S3 and API origins. TLS terminates at CloudFront. The documented CloudFront-to-ALB origin connection uses HTTP, while ALB ingress is restricted to the AWS-managed CloudFront prefix list and requests must carry a secret origin header. ECS runs the API and browser worker, DynamoDB stores records, and AWS Bedrock US inference profiles run model calls. Stripe handles card entry and Amazon Cognito handles accounts. This diagram is the deployment contract, not proof of a completed audit: the final public Page, Ask, Flow, share, and failure-path canaries must pass before production traffic is invited.

GDPR specifics

Article-by-article position

  • Art. 4 — Personal data

    Persona profiles are designed as fictional statistical constructs, not recruited records. Account data and identifiable information in customer submissions remain personal data.

    Scoped
  • Art. 6 — Lawful basis

    Mimiq relies on the appropriate basis for its own account and service operations. Customers remain responsible for a lawful basis covering any personal data they choose to submit.

    Shared responsibility
  • Art. 17 — Right to erasure

    Deletion requests are handled at victor@mimiqai.com. Automated account-wide deletion and a documented retention schedule are launch-hardening items.

    Manual today
  • Art. 20 — Data portability

    Report exports are available in product where shown; a broader account export is available by request. A share link is not presented as a substitute for a portability export.

    Available by request
  • Art. 28 — Data processors

    The current sub-processor list and transfer terms are available on request. Customers submitting personal data should execute the applicable DPA before doing so.

    Review before PII
  • Art. 33 — Breach notification

    Incidents will be assessed and notified as required by applicable law and processor terms. A formal, exercised incident-response runbook remains a launch-hardening gate.

    Runbook pending
  • Art. 35 — DPIA

    Whether a DPIA is required depends on the customer's purpose, data, and deployment. Mimiq cannot make that legal determination for every use case.

    Customer assessment
  • International transfers

    The launch architecture uses AWS US regions and US model inference profiles. Account data and submitted content may therefore be processed in the US; review the current transfer mechanism and DPA before submitting personal data.

    US processing disclosed

What the synthetic-participant model changes

No participant recruitment records

A standard Mimiq test does not collect participant names, contact details, consent records, screen recordings, or panel payments because no real panel is recruited.

Customer content still matters

URLs, prompts, uploads, and optional customer imports may be confidential or personal data. They still require minimisation, access controls, retention rules, and an appropriate lawful basis.

Directional evidence, not human research

The smaller participant-data footprint comes with a clear boundary: simulated reactions diagnose likely confusion and disagreement; they do not become human-subject evidence.

Get the docs

For procurement teams, security reviewers, DPOs

Questions?

Start free