Privacy Policy of Mimira P.S.A.

Effective as of: January 26, 2026

§1. Definitions

  1. GDPR – Regulation (EU) 2016/679.

  2. Controller – MIMIRA P.S.A.

  3. Platform – the Mimira website/application available at platform.mimira.eu, enabling the use of the Services.

  4. User – the entity using the Services (in particular a business owner, including sole proprietorships) and individuals acting on their behalf (e.g., employees).

  5. Account – the User's account on the Platform created as a result of registration.

  6. Agreement – the agreement for the provision of services by electronic means (SaaS) concluded between the User and the Service Provider on the terms of the Regulations.

  7. User Data – data, content, and files entered into the Platform by the User or on their behalf.

§2. Controller and Contact

  1. The controller of personal data is MIMIRA P.S.A., ul. Marszałkowska 89, 00-693 Warsaw, KRS 0001155658, NIP 7011246033.

  2. Contact regarding data protection: [email protected].

§3. What Data We Process

Depending on how the Platform is used, we process in particular:

  1. Account and contact data: first and last name, email, phone number, Account identifiers, login details (technical scope), role in the organization.

  2. Company and billing data: company name, VAT ID (NIP), address, data necessary for issuing a VAT invoice, billing history, transaction identifiers.

  3. Payment data: card details are processed by Stripe; the Controller does not store full card details (may store payment/subscription identifiers).

  4. Data about the use of the Platform: technical logs, IP address, device/browser identifiers, events in the application, settings.

  5. Data entered into the Platform: content and files provided by the User (e.g., information regarding proceedings and the User's offer).

  6. Cookies / online identifiers: necessary, analytical, and marketing – depending on settings and consents.

§4. Purposes, Legal Bases, and Standard Categories of Recipients

  1. Conclusion and execution of the Agreement (Art. 6(1)(b) of GDPR): registration of the Account, provision of SaaS Services, handling support requests, Subscription settlements.

  2. Legal obligations (Art. 6(1)(c) of GDPR): bookkeeping, taxes, issuing and storing invoices.

  3. Legitimate interest of the Controller (Art. 6(1)(f) of GDPR): ensuring security, preventing fraud, establishing and defending claims, developing and improving the quality of services (to the extent possible based on aggregated data).

  4. Consent (Art. 6(1)(a) of GDPR): direct marketing by electronic means (if enabled) and analytical/marketing cookies – within the scope of the consent granted; consent can be withdrawn at any time.

  5. Data may be disclosed only to the extent necessary for the above purposes, in particular to:

    1. infrastructure providers for payment processing and recurring billing;

    2. IT infrastructure and hosting providers located in the EEA;

    3. providers of analytical/marketing tools – only if they have been activated and the User has expressed the required consent;

    4. communication and support providers (e.g., ticketing systems) – in the scope of handling contact;

    5. accounting firm, law firm, and public authorities – when resulting from legal provisions.

§5. Transfer of Data Outside the European Economic Area

  1. According to the Controller's current method of providing services, data is not transferred outside the European Economic Area (EEA).

§6. Data Retention Period

  1. Account Data and data related to the Agreement – for the duration of the Agreement, and then as a rule for 12 months after its termination (e.g., for handling potential claims and settlements), unless the data is deleted earlier, provided that law allows it.

  2. Billing data and invoices – for the period required by tax and accounting regulations, as a rule 5 years counting from the end of the year in which the tax obligation arose.

  3. Technical and security logs – as a rule for 12 months, unless longer storage is necessary to resolve an incident or pursue claims.

  4. Consent-based marketing data – until consent is withdrawn, but no longer than 5 years from the last activity or contact, whichever comes first.

  5. After the expiry of the above periods, the data is deleted or anonymized.

§7. Rights of Data Subjects

  1. You are entitled to the right of: access to data, rectification, erasure, restriction of processing, data portability, and the right to object (to processing based on legitimate interest).

  2. In the scope of processing based on consent, you have the right to withdraw it at any time.

  3. You have the right to lodge a complaint with the President of the Personal Data Protection Office (UODO).

  4. Requests should be addressed to [email protected].

§8. Profiling and Automated Decision-Making

  1. The Platform may analyze activity and preference data (e.g., industry, history of tender participation decisions) in order to match tenders and prioritize results. This may constitute profiling within the meaning of the GDPR.

  2. The matchmaking is of a recommendatory nature and as a rule does not produce legal effects or similarly significant effects concerning a natural person – decisions are made by the User.

  3. The data subject has the right to object to profiling based on legitimate interest.

§9. Security

  1. The Controller applies technical and organizational measures adequate to the risks, including access control, transmission encryption, backups, and event logging.

  2. Access to data is restricted to authorized persons and entities acting on behalf of the Controller within the necessary scope.

§10. Cookies and Terminal Equipment

  1. The Platform uses cookies and similar technologies for the following purposes:

    1. necessary (operation of the service, authentication, security),

    2. analytical (statistics and service development),

    3. marketing (measurement and optimization of promotional activities) – if used.

  2. Necessary cookies are always active. Analytical and marketing cookies are used only if the User grants the required consent (e.g., in the cookie banner) and can change or withdraw it at any time.

  3. Approximate maximum cookie storage periods:

    1. necessary - until the end of the session or up to 12 months,

    2. analytical - up to 14 months,

    3. marketing - up to 13 months.

  4. Regardless of the above, the User can also manage cookies in browser settings (deletion, blocking, restriction).

§11. Changes to the Policy

  1. The Policy may be updated in the event of changes in how the Platform operates or legal changes.

  2. The Controller informs about significant changes on the Platform and/or via email.

Privacy Policy of Mimira P.S.A.

Effective as of: January 26, 2026

§1. Definitions

  1. GDPR – Regulation (EU) 2016/679.

  2. Controller – MIMIRA P.S.A.

  3. Platform – the Mimira website/application available at platform.mimira.eu, enabling the use of the Services.

  4. User – the entity using the Services (in particular a business owner, including sole proprietorships) and individuals acting on their behalf (e.g., employees).

  5. Account – the User's account on the Platform created as a result of registration.

  6. Agreement – the agreement for the provision of services by electronic means (SaaS) concluded between the User and the Service Provider on the terms of the Regulations.

  7. User Data – data, content, and files entered into the Platform by the User or on their behalf.

§2. Controller and Contact

  1. The controller of personal data is MIMIRA P.S.A., ul. Marszałkowska 89, 00-693 Warsaw, KRS 0001155658, NIP 7011246033.

  2. Contact regarding data protection: [email protected].

§3. What Data We Process

Depending on how the Platform is used, we process in particular:

  1. Account and contact data: first and last name, email, phone number, Account identifiers, login details (technical scope), role in the organization.

  2. Company and billing data: company name, VAT ID (NIP), address, data necessary for issuing a VAT invoice, billing history, transaction identifiers.

  3. Payment data: card details are processed by Stripe; the Controller does not store full card details (may store payment/subscription identifiers).

  4. Data about the use of the Platform: technical logs, IP address, device/browser identifiers, events in the application, settings.

  5. Data entered into the Platform: content and files provided by the User (e.g., information regarding proceedings and the User's offer).

  6. Cookies / online identifiers: necessary, analytical, and marketing – depending on settings and consents.

§4. Purposes, Legal Bases, and Standard Categories of Recipients

  1. Conclusion and execution of the Agreement (Art. 6(1)(b) of GDPR): registration of the Account, provision of SaaS Services, handling support requests, Subscription settlements.

  2. Legal obligations (Art. 6(1)(c) of GDPR): bookkeeping, taxes, issuing and storing invoices.

  3. Legitimate interest of the Controller (Art. 6(1)(f) of GDPR): ensuring security, preventing fraud, establishing and defending claims, developing and improving the quality of services (to the extent possible based on aggregated data).

  4. Consent (Art. 6(1)(a) of GDPR): direct marketing by electronic means (if enabled) and analytical/marketing cookies – within the scope of the consent granted; consent can be withdrawn at any time.

  5. Data may be disclosed only to the extent necessary for the above purposes, in particular to:

    1. infrastructure providers for payment processing and recurring billing;

    2. IT infrastructure and hosting providers located in the EEA;

    3. providers of analytical/marketing tools – only if they have been activated and the User has expressed the required consent;

    4. communication and support providers (e.g., ticketing systems) – in the scope of handling contact;

    5. accounting firm, law firm, and public authorities – when resulting from legal provisions.

§5. Transfer of Data Outside the European Economic Area

  1. According to the Controller's current method of providing services, data is not transferred outside the European Economic Area (EEA).

§6. Data Retention Period

  1. Account Data and data related to the Agreement – for the duration of the Agreement, and then as a rule for 12 months after its termination (e.g., for handling potential claims and settlements), unless the data is deleted earlier, provided that law allows it.

  2. Billing data and invoices – for the period required by tax and accounting regulations, as a rule 5 years counting from the end of the year in which the tax obligation arose.

  3. Technical and security logs – as a rule for 12 months, unless longer storage is necessary to resolve an incident or pursue claims.

  4. Consent-based marketing data – until consent is withdrawn, but no longer than 5 years from the last activity or contact, whichever comes first.

  5. After the expiry of the above periods, the data is deleted or anonymized.

§7. Rights of Data Subjects

  1. You are entitled to the right of: access to data, rectification, erasure, restriction of processing, data portability, and the right to object (to processing based on legitimate interest).

  2. In the scope of processing based on consent, you have the right to withdraw it at any time.

  3. You have the right to lodge a complaint with the President of the Personal Data Protection Office (UODO).

  4. Requests should be addressed to [email protected].

§8. Profiling and Automated Decision-Making

  1. The Platform may analyze activity and preference data (e.g., industry, history of tender participation decisions) in order to match tenders and prioritize results. This may constitute profiling within the meaning of the GDPR.

  2. The matchmaking is of a recommendatory nature and as a rule does not produce legal effects or similarly significant effects concerning a natural person – decisions are made by the User.

  3. The data subject has the right to object to profiling based on legitimate interest.

§9. Security

  1. The Controller applies technical and organizational measures adequate to the risks, including access control, transmission encryption, backups, and event logging.

  2. Access to data is restricted to authorized persons and entities acting on behalf of the Controller within the necessary scope.

§10. Cookies and Terminal Equipment

  1. The Platform uses cookies and similar technologies for the following purposes:

    1. necessary (operation of the service, authentication, security),

    2. analytical (statistics and service development),

    3. marketing (measurement and optimization of promotional activities) – if used.

  2. Necessary cookies are always active. Analytical and marketing cookies are used only if the User grants the required consent (e.g., in the cookie banner) and can change or withdraw it at any time.

  3. Approximate maximum cookie storage periods:

    1. necessary - until the end of the session or up to 12 months,

    2. analytical - up to 14 months,

    3. marketing - up to 13 months.

  4. Regardless of the above, the User can also manage cookies in browser settings (deletion, blocking, restriction).

§11. Changes to the Policy

  1. The Policy may be updated in the event of changes in how the Platform operates or legal changes.

  2. The Controller informs about significant changes on the Platform and/or via email.