Privacy policy
In order to ensure transparency and give you more control over your personal data, this privacy policy (“Privacy Policy”) governs how we, MIND Security Inc. (“MIND”, “we”, “our” or “us”) use, collect and store personal data that we collect or receive from or about you (“you”) in connection with https://mind.io/ (the “Website”), MIND's application (the "Application") and the services provided therein (the “Services”).
We greatly respect your privacy, which is why we make every effort to provide a platform that would live up to the highest user privacy standards. Please read this Privacy Policy carefully, so you can fully understand our practices in relation to personal data. “Important note: Nothing in this Privacy Policy is intended to limit in any way your statutory rights, including your rights to a remedy or other means of enforcement.
This Privacy Policy can be updated from time to time and, therefore, we ask you to check back periodically for the latest version of this Privacy Policy. If we implement material changes in the way we use your information, in a manner that is different from that stated at the time of collection, we will notify you by posting a notice on our Website or by other means and take any additional steps as required by applicable law.
1
What personal data we collect, why we collect it, and how it is used
i. We Process the Following Personal Information:
a. Information provided through the Services. We collect personal data that you voluntarily provide, such as your full name, email address, password, integration details and secret keys, as well as any other information that you decide to provide us. We also collect the contact and billing information of our customers.
b. Information provided through the Website and the Application. When you use the Website and/or the Application, we collect and process full name, email address, IP address and user agent, integration details and secret keys when you interact with the Website and the Application, for example, when you send us a request for a demo or contact us (including, the chat).
c. Information automatically collected. We may automatically collect certain information through your use of MIND’s Website, Application and/or Service, such as cookie, pixels, tracking technologies and similar identifiers (“Technologies”), your Internet protocol (IP) address, and other device identifiers that are automatically assigned to your device, browser type and language, geo-location information, hardware type, operating system, internet service provider and other information about actions taken through the use of the Website and the Application.
d. Information from Other Sources. MIND may also obtain information about you from other sources, including publicly - or commercially- available information, and through third-party data platforms, partners and service providers.
e. Information you provide to us in person. For example, when you visit one of our exhibition booths or attend one of our events and you provide us with your contact details. We will use this information to answer your enquiries or provide additional information to you.
f. Information we collect from online interactions. For example, if you attend a webinar, contact us via social media or otherwise interact with our business, including as a representative of a current / prospective customer, supplier or partner, we track and make a record of those interactions, which may contain your contact details, such as full name, email address, messages and any other information that you decide to provide us with.
ii. We process information for the following purposes:
a. To provide you with the Services. We will use the abovementioned information, including, without limitation, for the following purposes: (i) allow you to create an account; (ii) to provide you the Services and to process your requests; (iii) communicate with you about your use of the Services and for support purposes; (iv) fulfill any instruction and/or request made by you in the context of the Services; (v) send you push notifications and/or emails and notifications regarding your account or certain features of the Services, including, updates pertaining to your subscription, and related to the services we provide you with; (vi) to personalize your experience with our Services; (vii) to allow you to create more users and administrate your users; and (viii) to generally administer and improve the Services.
b. To allow you to make use of our Website or Application. We will use your information to allow you to make use of our Website, including, (i) if you request a demo, we will use your personal data to process and answer your request for a demo; (ii) to answer your questions and to allow you to communicate with us (e.g., by using the Website chat); (iii) to analyze your use of our Website and to improve our Website; and (iv) to customize your experience.
c. For Administrative Purposes. MIND may use your information (i) to respond to your questions, comments, and other requests for customer support, or information, including information about potential or future services; (ii) to provide you with the MIND Services; (iii) for internal quality control purposes; (iv) to establish a business relationship; and (v) to generally administer the Tannin Services.
d. To Market our Website, Application and Services. MIND may use information to market the MIND Services. Such use includes (i) notifying you about offers and services that may be of interest to you; (ii) developing and marketing new products and services, and to measure interest in MIND's services; (v) other purposes disclosed at the time you provide information; and (vi) as you otherwise consent.
e. Security purposes. Some of the abovementioned information will be used for detecting, taking steps to prevent and prosecuting fraud or other illegal activity; to identify and repair errors; to conduct audits; and for security purposes. Information may also be used to comply with applicable laws, with investigations performed by the relevant authorities, law enforcement purposes, and/or to exercise or defend legal claims.
f. De-identified and Aggregated Information Use. In certain cases, we may or will anonymize or de-identify your Information and further use it for internal and external purposes, including, without limitation, to analyze and improve MIND services (including through the use of artificial intelligence) and for research purposes. We may use this anonymous or de-identified information and/or disclose it to third parties without restrictions (for example, in order to improve our services and enhance your experience with them and/or to develop new product features and improve existing offerings).
g. Cookies and Similar Technologies. We, as well as third parties that provide content, advertising, or other functionality on the MIND Website, Application and Services, use Technologies to automatically collect information through the Website, Application and Services. We use Technologies that are essentially small data files placed on your device that allow us to record certain pieces of information whenever you visit or interact with the Website, Application and Services. Our Cookies notice provides more details.
(iii) The lawful bases we rely on for processing personal data are (if and when applicable):
a. The data subject has given consent to the processing of his or her personal data;
b. Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract; and/or
c. Processing is necessary for the purposes of the legitimate interest.
2
How we protect and retain your personal data
2.1. Security
We have implemented and maintain reasonable technical, organizational and security measures designed to protect your information. However, please note that we cannot guarantee that the information will not be compromised as a result of unauthorized penetration to our servers. As the security of information depends in part on the security of the computer, device or network you use to communicate with us and the security you use to protect your user IDs and passwords, please make sure to take appropriate measures to protect this information.
2.2. Retention of your information
Your information will be stored until we delete our records, and we proactively delete it, or if you send a valid deletion request. Please note that in some circumstances we may store your information for longer periods of time, for example (i) where we are required to do so in accordance with legal, regulatory, tax or accounting requirements, or (ii) for us to have an accurate record of your dealings with us in the event of any complaints or challenges, and/or (iii) if we reasonably believe there is a prospect of litigation relating to your information or dealings.
4
Your Privacy Rights
4.1. The following rights (which may be subject to certain exemptions or derogations) shall apply to certain individuals (some of which only apply to individuals protected by specific laws):
4.1.1. You have the right to withdraw consent to the processing, where consent is the basis of processing.
4.1.2. You have the right to access the personal data that we hold and request further details about how we process it, under certain conditions.
4.1.3. You have the right to demand rectification of inaccurate personal data about you. We will promptly correct any information found to be incorrect.
4.1.4. You have the right to object to unlawful data processing under certain conditions.
4.1.5. You have the right to the erasure of past data about you (your “right to be forgotten”) under certain conditions.
4.1.6. You have the right to demand that we restrict the processing of your personal data, under certain conditions, if you believe we have exceeded the legitimate basis for processing, the processing is no longer necessary, or if you believe your personal data is inaccurate.
4.1.7. You have the right to data portability of personal data concerning you that you provided us in a structured, commonly used, and machine-readable format, subject to certain conditions.
4.1.8. The personal data we collect is not used for automated decision-making and profiling, except for automated processes in the context of marketing. As stated above, you can opt out of direct marketing by MIND by contacting MIND directly or by following the instructions through the unsubscribe options in our email messages.
4.2. You can exercise your rights by contacting us at privacy@mind.io. You may use an authorized agent to submit a request on your behalf if you provide the authorized agent written permission signed by you. To protect your privacy, we may take steps to verify your identity before fulfilling your request. Subject to legal and other permissible considerations, we will make every reasonable effort to honor your request promptly in accordance with applicable law or inform you if we require further information in order to fulfil your request. When processing your request, we may ask you for additional information to confirm or verify your identity and for security purposes, before processing and/or honoring your request. We reserve the right to charge a fee where permitted by law, for instance if your request is manifestly unfounded or excessive. In the event that your request would adversely affect the rights and freedoms of others (for example, would impact the duty of confidentiality we owe to others) or if we are legally entitled to deal with your request in a different way than initial requested, we will address your request to the maximum extent possible, all in accordance with applicable law.
4.3. Marketing emails – opt-out: You may choose not to receive marketing email of this type by sending a single email with the subject "BLOCK" to []. Please note that the email must come from the email account you wish to block OR if you receive an unwanted email from us, you can use the unsubscribe link found at the bottom of the email to opt out of receiving future emails, and we will process your request within a reasonable time after receipt.
5
International Transfer of Personal Data
a) We store the personal data with the following storing companies: AWS – North Virginia – US and Auth0 – US-4 – US.
b) We transfer personal data to certain countries around the world, including to our affiliates and service providers. Therefore, your personal data may be processed in countries with privacy laws that are different from privacy laws in your country. Whenever we make such transfers, we will use commercially reasonable efforts to implement an appropriate level of protection to your personal data by implementing at least one of the following safeguards:
i. making sure the destination country has been deemed to provide an adequate level of protection for personal data; and/or
ii. by executing implement data onward transfer instruments such as data processing and protection agreements.
6
Use by children
We do not offer our products or services for use by children and, therefore, we do not knowingly collect information from, and/or about children under the age of 18. If you are under the age of 18, do not provide any information to us without the involvement of a parent or a guardian. In the event that we become aware that you provide information in violation of applicable privacy laws, we reserve the right to delete it. If you believe that we might have any such information, please contact us at privacy@mind.io.
7
Interaction of Third Party Products
We enable you to interact with third party websites, mobile software applications and products or services that are not owned, or controlled, by us (each, a “Third Party Service”). We are not responsible for the privacy practices or the content of such Third Party Services. Please be aware that Third Party Services can collect information from you. Accordingly, we encourage you to read the terms and conditions and privacy policies of each Third Party Service.
8
Analytic Tools
Google Analytics
The Website uses a tool called “Google Analytics” to collect information about use of the Website. Google Analytics collects information such as how often users visit this Website, what pages they visit when they do so, and what other websites they used prior to coming to this Website. We use the information we get from Google Analytics to maintain and improve the Website and our products. We do not combine the information collected through the use of Google Analytics with information we collect. Google’s ability to use and share information collected by Google Analytics about your visits to this Website is restricted by the Google Analytics Terms of Service, available at https://marketingplatform.google.com/about/analytics/terms/us/, and the Google Privacy Policy, available at http://www.google.com/policies/privacy/. You may learn more about how Google collects and processes data specifically in connection with Google Analytics at http://www.google.com/policies/privacy/partners/. You may prevent your data from being used by Google Analytics by downloading and installing the Google Analytics Opt-out Browser Add-on, available at https://tools.google.com/dlpage/gaoptout/.
FullStory
The Services use technology services/tools such as FullStory and/or PostHog to understand our users’ needs better and optimize this service and experience. FullStory and PostHog is a technology service that helps us better understand our users’ experience (e.g., how much time they spend on which pages, which links they choose to click, what users do and don’t like, etc.) and this enables us to build and maintain our service with user feedback. FullStory and PostHog use cookies and other technologies to collect data on users’ behavior and devices. This includes a device’s IP address (processed during your session and stored in a de-identified form), device screen size, device type (unique device identifiers), browser information, geographic location (country only), and the preferred language used to display our Service. FullStory stores this information in a pseudonymized user profile. FullStory and PostHog are contractually forbidden to sell any data collected on our behalf. For further details, please see FullStory’s and PostHog's privacy policy at https://www.fullstory.com/legal/privacy-policy/ and posthog.com/privacy. You can opt-out of creating a user profile, FullStory storing data about your usage of our Service, and FullStory’s tracking cookies on other websites on this link https://www.fullstory.com/optout/.
9
Our California do not track notice
Do Not Track (“DNT”) is a privacy preference that users can set in certain web browsers. Please note that we do not respond to or honor DNT signals or similar mechanisms transmitted by web browsers, but we may allow third parties, such as companies that provide us with analytics tools, to collect personally identifiable information about an individual consumer’s online activities over time and across different web sites when a consumer uses the Services.
10
Contact Us
If you have any questions, concerns or complaints regarding our compliance with this notice and the data protection laws, or if you wish to exercise your rights, we encourage you to first contact us at support@mind.io.