Privacy Policy
Mimasa Ai Data Protection Notice
Effective Date: January 1, 2025
Last Updated: January 1, 2025
Mimasa AI ("We", "Us", or "Our") is committed to protecting Your privacy and maintaining the highest standards of data protection. This Privacy Policy explains how We collect, use, process, store, and safeguard Your information when You use our Platform and Services. By using Mimasa AI, You acknowledge that You have read and understood this Privacy Policy.
1. Information We Collect
We collect several categories of information to provide and improve our Services:
Account and Profile Information
- Personal identifiers: Name, email address, username
- Professional information: Job title, company name, department
- Contact details: Phone number, business address
- Billing information: Payment method details, billing address, tax information
- Profile preferences: Dashboard settings, notification preferences, display options
Usage and Activity Data
- Platform interactions: Pages visited, features used, time spent
- Device information: IP address, browser type, operating system, device identifiers
- Log data: Access logs, error logs, performance metrics
- Session data: Login/logout times, session duration, activity patterns
- Analytics data: User engagement metrics, feature usage statistics
User-Generated Content
- Data uploads: Datasets, files, documents You upload to the Platform
- Dashboard content: Charts, reports, visualizations You create
- Queries and prompts: Text inputs for AI-powered analytics
- Comments and annotations: Notes and collaborative content
- Configuration data: Custom settings, saved filters, bookmarks
Third-Party Integration Data
- API connections: Data from connected business systems
- Single sign-on information: Identity provider data (if applicable)
- LLM processing data: Information transmitted to AI providers
- External data sources: Connected databases, cloud storage, SaaS platforms
Communication Data
- Support interactions: Help desk tickets, chat messages, email correspondence
- Marketing communications: Newsletter subscriptions, campaign interactions
- Feedback and surveys: Product feedback, user experience surveys
2. How We Use Your Information
We use the collected information for the following purposes:
Service Provision and Enhancement
- Provide, operate, and maintain the Platform and its features
- Process Your data and generate AI-powered insights and analytics
- Create personalized dashboards and visualizations
- Enable collaboration and sharing features
- Improve Platform performance, reliability, and user experience
Security and Compliance
- Maintain SOC 2 Type II compliance and security standards
- Detect, prevent, and respond to fraud, abuse, or security threats
- Monitor for unauthorized access or suspicious activities
- Ensure compliance with applicable laws and regulations
- Conduct security audits and vulnerability assessments
Communication and Support
- Provide customer support and technical assistance
- service-related notifications and updates
- Process billing and payment transactions
- Deliver marketing communications (with Your consent)
- Respond to inquiries and feedback
Legal and Business Operations
- Comply with legal obligations and regulatory requirements
- Enforce our Terms of Service and other agreements
- Resolve disputes and protect our legal rights
- Support business operations and decision-making
3. Data Processing with Third-Party AI Providers
Third-Party LLM Integration:
- Data You input into AI features may be transmitted to third-party Large Language Model providers including OpenAI, Anthropic (Claude), Mistral AI, Alibaba (Qwen), DeepSeek, and others
- This data transmission is necessary to provide AI-powered analytics, insights, and conversational features
- We select reputable AI providers with strong privacy and security practices
- Data transmission occurs over encrypted connections with appropriate security measures
Important Limitations:
- We do not control how third-party AI providers process, store, or use Your data
- Each AI provider has its own privacy policy and data handling practices
- Some providers may use data for model training or improvement unless specifically opted out
- Data retention periods and deletion policies vary by provider
Your Consent and Responsibility:
- By using AI features, You explicitly consent to data transmission to third-party providers
- You are responsible for reviewing and understanding each provider's privacy policy
- You should not input sensitive personal data unless You understand the privacy implications
- You can disable AI features in Your account settings to prevent data transmission
Current AI Provider Links:
- OpenAI Privacy Policy: https://openai.com/privacy/
- Anthropic Privacy Policy: https://www.anthropic.com/privacy
- Mistral AI Privacy Policy: https://mistral.ai/terms/
4. Data Security and Protection
Security Standards and Compliance:
- SOC 2 Type II compliance with regular third-party audits
- ISO 27001 information security management standards
- GDPR compliance for European users
- Industry-standard encryption for data in transit and at rest
- Multi-factor authentication and access controls
Technical Safeguards:
- AES-256 encryption for stored data
- TLS 1.3 encryption for data transmission
- Network firewalls and intrusion detection systems
- Regular security vulnerability scanning and penetration testing
- Automated security monitoring and incident response
Administrative Controls:
- Role-based access controls with principle of least privilege
- Employee background checks and security training
- Confidentiality agreements for all personnel
- Regular security awareness training and updates
- Incident response procedures and breach notification protocols
Security Limitations:
- No security system can guarantee absolute protection against all threats
- Data shared with third-party AI providers is subject to their security measures
- You are responsible for maintaining the security of Your account credentials
- Security incidents will be reported in accordance with applicable laws
5. Data Retention and Deletion
Retention Principles:
- We retain Your information only as long as necessary to provide Services
- Retention periods vary based on data type and legal requirements
- Active account data is retained for the duration of Your subscription
- Some data may be retained longer for legitimate business purposes
Specific Retention Periods:
- Account information: Retained during active subscription plus 7 years for billing/tax purposes
- Usage logs: Retained for 13 months for security and analytics purposes
- User-generated content: Retained until account deletion or user deletion request
- Support communications: Retained for 3 years for quality assurance
- Marketing data: Retained until consent is withdrawn or opt-out is requested
Data Deletion:
- You may request deletion of Your personal data by contacting privacy@xaigi.tech
- Upon account termination, most data is deleted within 30 days
- Some data may be retained for legal, compliance, or security reasons
- Backup systems may retain data for additional recovery periods
- Data deletion requests are processed within 30 days when feasible
Third-Party Data Retention:
- AI providers have their own data retention policies
- We cannot control deletion of data already processed by third parties
- You should review each provider's data retention and deletion policies
6. Information Sharing and Disclosure
We Do Not Sell Personal Data:
We do not sell, rent, or trade Your personal information to third parties for marketing purposes.
Authorized Sharing:
We may share Your information only in the following circumstances:
Service Providers and Processors
- Cloud hosting providers (AWS, Google Cloud, Microsoft Azure)
- AI and LLM providers for processing Your queries
- Payment processors for billing and subscription management
- Customer support platforms for service delivery
- Analytics providers for platform improvement (anonymized data only)
Legal Requirements
- Compliance with court orders, subpoenas, or legal process
- Response to lawful requests from government authorities
- Protection of our legal rights and interests
- Investigation of fraud, security breaches, or terms violations
- Emergency situations involving immediate harm or danger
Business Transfers
- Mergers, acquisitions, or asset sales (with user notification)
- Bankruptcy or insolvency proceedings
- Corporate restructuring or ownership changes
With Your Consent
- Sharing with specific third parties You authorize
- Public sharing of content You choose to make public
- Integration with third-party services You connect
7. Your Privacy Rights
Depending on Your jurisdiction, You may have various rights regarding Your personal data:
General Rights (Available to All Users)
- Access Your personal data and understand how it's used
- Correct inaccurate or incomplete information
- Delete Your account and associated data
- Export Your data in a portable format
- Opt out of marketing communications
GDPR Rights (EU Residents)
- Right of access to Your personal data
- Right to rectification of inaccurate data
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object to processing
- Right to withdraw consent
- Right to lodge a complaint with supervisory authorities
CCPA Rights (California Residents)
- Right to know what personal information is collected
- Right to delete personal information
- Right to opt out of sale of personal information
- Right to non-discrimination for exercising privacy rights
Exercising Your Rights:
- Contact us at privacy@xaigi.tech to exercise any rights
- Provide sufficient information to verify Your identity
- We will respond to requests within 30 days (or as required by law)
- Some rights may be limited by legal or operational requirements
8. International Data Transfers
Global Operations:
- Your data may be processed in countries outside Your country of residence
- We use cloud providers with global infrastructure (AWS, Google Cloud, etc.)
- AI providers may process data in various international locations
- Different countries have varying data protection laws
Transfer Safeguards:
- Standard Contractual Clauses (SCCs) for EU data transfers
- Adequacy decisions where applicable
- Binding Corporate Rules for multinational processors
- Additional safeguards for sensitive data transfers
Your Consent:
By using the Platform, You consent to international data transfers as described in this Privacy Policy.
9. Children's Privacy
The Platform is not intended for individuals under 18 years of age:
- We do not knowingly collect personal information from children under 18
- If we become aware of such collection, we will delete the information promptly
- Parents or guardians who believe we have collected information from their child should contact us immediately
- We comply with applicable children's privacy laws (COPPA, GDPR Article 8, etc.)
10. Regulatory Compliance and Data Protection Standards
GDPR Compliance (EU General Data Protection Regulation)
We are fully compliant with the EU General Data Protection Regulation (GDPR) and maintain the following standards:
- Lawful Basis for Processing: We process personal data only when we have a lawful basis under Article 6 GDPR, including consent, contract performance, legal obligation, vital interests, public task, or legitimate interests
- Data Minimization: We collect and process only the personal data that is necessary for the specified purposes
- Purpose Limitation: Personal data is collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes
- Accuracy: We maintain accurate and up-to-date personal data and take reasonable steps to ensure inaccurate data is erased or rectified promptly
- Storage Limitation: Personal data is kept in a form that permits identification for no longer than necessary for the purposes for which it was collected
- Integrity and Confidentiality: We implement appropriate technical and organizational measures to ensure security of personal data
- Accountability: We maintain comprehensive records of processing activities and can demonstrate compliance with GDPR principles
- Privacy by Design: Data protection measures are integrated into our systems and processes from the outset
- Data Protection Impact Assessments (DPIAs): We conduct DPIAs for high-risk processing activities
- Breach Notification: We have procedures to detect, report, and investigate personal data breaches within 72 hours to supervisory authorities and affected individuals when required
- International Transfers: We use Standard Contractual Clauses (SCCs) and other appropriate safeguards for international data transfers
COPPA Compliance (Children's Online Privacy Protection Act)
We are fully compliant with the US Children's Online Privacy Protection Act (COPPA) and implement the following measures:
- Age Verification: We implement robust age verification mechanisms to ensure users are at least 18 years old
- No Collection from Children: We do not knowingly collect personal information from children under 13 years of age
- Parental Notice: If we become aware that we have inadvertently collected information from a child under 13, we immediately notify parents/guardians
- Parental Consent: We do not require parental consent as our services are not directed to children under 13
- Parental Access: Parents have the right to review, delete, and refuse further collection of their child's personal information
- Data Deletion: We promptly delete any personal information inadvertently collected from children under 13
- Safe Harbor: We maintain COPPA Safe Harbor certification through compliance with industry self-regulatory guidelines
- Third-Party Disclosure: We do not disclose children's personal information to third parties except as permitted by COPPA
- Behavioral Advertising: We do not engage in behavioral advertising directed to children under 13
- Regular Audits: We conduct regular compliance audits to ensure ongoing COPPA adherence
DPDP Act Compliance (Indian Digital Personal Data Protection Act, 2023)
We are fully compliant with India's Digital Personal Data Protection Act, 2023 (DPDP Act) and maintain the following standards:
- Lawful Processing: We process personal data only for lawful purposes and with appropriate consent or other legal grounds under the DPDP Act
- Data Principal Rights: We facilitate the exercise of all rights granted to data principals, including access, correction, erasure, and data portability
- Notice and Consent: We provide clear, transparent notices about data processing and obtain valid consent where required
- Purpose Limitation: Personal data is processed only for the specific purposes for which it was collected and consented to
- Data Minimization: We collect and process only the minimum personal data necessary for the stated purposes
- Accuracy and Storage Limitation: We ensure data accuracy and retain personal data only for as long as necessary
- Reasonable Security Safeguards: We implement appropriate technical and organizational measures to protect personal data
- Cross-Border Transfer Compliance: We ensure appropriate safeguards for international data transfers as required by the DPDP Act
- Data Breach Management: We have procedures to promptly notify the Data Protection Board and affected individuals of personal data breaches
- Data Protection Officer: We have appointed a qualified Data Protection Officer to oversee compliance activities
- Children's Data Protection: We implement enhanced protections for processing data of individuals under 18 years of age
- Significant Data Fiduciary Obligations: As applicable, we comply with additional obligations including data audits, impact assessments, and appointing independent data auditors
- Consent Management: We maintain robust consent management platforms allowing users to withdraw consent easily
- Deemed Consent Compliance: Where applicable, we ensure compliance with deemed consent provisions under specific circumstances
- Regular Compliance Reviews: We conduct regular internal assessments to ensure ongoing compliance with the DPDP Act
Additional Regional Compliance
We also maintain compliance with other applicable data protection regulations:
- CCPA/CPRA (California): California Consumer Privacy Act and California Privacy Rights Act compliance
- PIPEDA (Canada): Personal Information Protection and Electronic Documents Act compliance
- LGPD (Brazil): Lei Geral de Proteção de Dados compliance
- PDPA (Singapore): Personal Data Protection Act compliance
- Privacy Act (Australia): Australian Privacy Principles compliance
Compliance Monitoring and Certification
- Regular third-party privacy audits and assessments
- SOC 2 Type II certification with privacy controls
- ISO 27001 information security management certification
- Ongoing legal compliance monitoring and updates
- Privacy impact assessments for new features and processes
- Staff training on data protection regulations and best practices
11. Cookies and Tracking Technologies
Types of Cookies We Use:
- Essential cookies: Required for platform functionality
- Performance cookies: Analytics and platform optimization
- Functional cookies: User preferences and settings
- Marketing cookies: Advertising and remarketing (with consent)
Managing Cookies:
- You can control cookies through Your browser settings
- Essential cookies cannot be disabled without affecting functionality
- We provide cookie consent management tools
- Third-party cookies are subject to their respective privacy policies
Other Tracking Technologies:
- Web beacons and pixel tags for analytics
- Local storage for user preferences
- Session storage for temporary data
- Device fingerprinting for fraud prevention
12. Updates to This Privacy Policy
Policy Changes:
- We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or business operations
- Material changes will be communicated via email or prominent notice on the Platform
- Minor changes may be posted without additional notification
- Continued use of the Platform after updates constitutes acceptance
Version Control:
- We maintain version history of privacy policy changes
- Previous versions are available upon request
- Effective dates are clearly marked for all versions
13. Contact Information and Data Protection Officer
Privacy Inquiries:
For privacy-related questions, data requests, or concerns, contact us:
Privacy Email: privacy@xaigi.tech
Data Protection Officer: dpo@xaigi.tech
General Contact: support@xaigi.tech
Business Address:
Xaigi Technology Pvt Ltd
A-130, Sector 63, Noida, Uttar Pradesh 201301, India
Phone: +91 8951394799
EU Representative (GDPR):
For EU-specific privacy matters, you may also contact our EU representative at eu-privacy@xaigi.tech
Response Times:
- Privacy requests: Within 30 days
- Data breach notifications: Within 72 hours (as required by law)
- General inquiries: Within 5 business days
Last Updated: January 1, 2025
Version: 1.0
© 2025 Mimasa AI by Xaigi Technology Pvt Ltd. All rights reserved.
