Legal & Compliance
Data Processing Agreement
Version 1.0 · Effective June 2026 · Governs processing of personal data under GDPR Art. 28
1. Parties
This Data Processing Agreement ("DPA") is entered into between:
- Controller: the entity that has agreed to Mimr Studio's Terms of Service and whose personal data is processed under this DPA ("Customer"); and
- Processor: Mimr Studio Ltd., the provider of the Mimr Studio platform ("Mimr Studio").
This DPA forms part of, and is subject to, the Terms of Service between the parties. In the event of a conflict, this DPA prevails with respect to data protection matters.
2. Definitions
In this DPA, the following terms have the meanings set out below. Capitalised terms not defined here have the meaning given to them in the GDPR.
- "GDPR" means the General Data Protection Regulation (EU) 2016/679 and, where applicable, the UK GDPR as retained in UK law.
- "Personal Data" means any information relating to an identified or identifiable natural person that is processed by Mimr Studio on behalf of the Customer.
- "Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion.
- "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.
- "Sub-processor" means any third party engaged by Mimr Studio to process Personal Data on the Customer's behalf. Current sub-processors are listed at /subprocessors.
3. Scope and nature of processing
Mimr Studio processes Personal Data solely to provide the Mimr Studio platform and associated services as described in the Terms of Service. The subject matter, duration, nature, and purpose of the processing, together with the types of Personal Data and categories of data subjects, are as follows:
| Subject matter | AI-powered course and content generation platform |
|---|---|
| Duration | For the term of the Customer's subscription, plus any applicable retention period thereafter |
| Purpose | Processing source documents and account data to generate training courses, presentations, and briefings on behalf of the Customer |
| Types of Personal Data | Account holder names and email addresses; personal data incidentally included in source documents uploaded by the Customer |
| Categories of data subjects | Customer employees, contractors, and end-users; individuals mentioned in uploaded documents |
4. Processor obligations
Mimr Studio shall:
- Process Personal Data only on documented instructions from the Customer, including with regard to transfers of Personal Data to a third country or an international organisation;
- Ensure that persons authorised to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
- Implement appropriate technical and organisational security measures as set out in Clause 6;
- Not engage a sub-processor without prior specific or general written authorisation of the Customer, and inform the Customer of intended changes so the Customer has the opportunity to object;
- Take all measures required pursuant to GDPR Article 32 regarding the security of processing;
- Assist the Customer in ensuring compliance with obligations pursuant to GDPR Articles 32–36 (security, breach notification, DPIA, prior consultation), taking into account the nature of processing and information available to Mimr Studio;
- At the Customer's choice, delete or return all Personal Data to the Customer after the end of the provision of services relating to processing, and delete existing copies unless required by law;
- Make available to the Customer all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits and inspections conducted by the Customer or a mandated auditor.
5. Sub-processors
The Customer provides general written authorisation for Mimr Studio to engage sub-processors. Mimr Studio's current sub-processors are listed at /subprocessors. Mimr Studio will notify the Customer of any intended changes to sub-processors at least 30 days in advance by email to the Customer's primary contact address. The Customer has the right to object to such changes.
Mimr Studio shall impose equivalent data protection obligations on sub-processors by way of a contract or other legal act under EU or Member State law and shall remain fully liable to the Customer for the performance of the sub-processor's obligations.
6. Security measures
Mimr Studio implements and maintains the following technical and organisational measures:
- Encryption in transit: TLS 1.2 or higher for all data transferred over public networks
- Encryption at rest: AES-256 encryption for stored job files and database data
- Access controls: Role-based access control (RBAC) with least-privilege principles; MFA available for all accounts
- Audit logging: Immutable audit log of all significant data access and processing events
- Staff training: Annual data protection training for all staff with access to Personal Data
- Vulnerability management: Regular dependency scanning and security patching
- Incident response: Documented Security Incident response procedure with defined notification timelines
7. Security incidents
Mimr Studio shall notify the Customer without undue delay — and in any event within 72 hours of becoming aware — of a Security Incident affecting the Customer's Personal Data. The notification shall, to the extent then known, include:
- A description of the nature of the Security Incident including the categories and approximate number of data subjects and Personal Data records concerned;
- The name and contact details of the data protection officer or other contact point from which more information can be obtained;
- The likely consequences of the Security Incident;
- The measures taken or proposed to be taken to address the Security Incident.
Where information cannot be provided at the same time, it shall be provided in phases without further undue delay. Notification under this clause does not constitute an acknowledgement of fault or liability.
8. International transfers
Where Personal Data is transferred from the European Economic Area (EEA) or the United Kingdom to a country not ensuring an adequate level of data protection, such transfers shall take place on the basis of Standard Contractual Clauses (SCCs) adopted by the European Commission, or the UK International Data Transfer Agreement (IDTA) as applicable.
Mimr Studio's primary sub-processors are located in the United States and rely on SCCs/IDTA or adequacy decisions for international transfer compliance. Details are available upon request at privacy@mimrstudio.com.
9. Data subject rights
Taking into account the nature of the processing, Mimr Studio shall assist the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling the Customer's obligation to respond to requests for exercising data subjects' rights under Chapter III of the GDPR (right of access, rectification, erasure, restriction, portability, and objection).
If Mimr Studio receives a data subject request directly, it shall promptly forward the request to the Customer and shall not otherwise respond unless instructed to do so.
10. Retention and deletion
Personal Data is retained for the duration of the Customer's active subscription. Upon termination or expiry of the subscription, Personal Data is deleted within 90 days unless a longer retention period is required by applicable law.
The Customer may request deletion of specific jobs or account data at any time via the platform or by contacting privacy@mimrstudio.com.
11. Contact and execution
For questions regarding this DPA, to request a countersigned copy, or to report a data protection concern, contact:
Mimr Studio Ltd.
Data Protection Officer
Email: privacy@mimrstudio.com
This DPA is incorporated into and forms part of the Terms of Service by reference. By accepting the Terms of Service, the Customer agrees to this DPA. For enterprise customers requiring a separately executed DPA, please contact the address above.