Legal
Privacy Policy
Last updated: May 2026
Mimr Studio Ltd ("Mimr", "we", "our", or "us") is the data controller for personal data processed through this platform. We provide tools for generating, editing, hosting, and delivering structured learning content from uploaded source material. This policy explains what data we collect, why we collect it, how long we keep it, and your rights.
Information We Collect
- Account information
- Name, email address, username, company and workspace assignment, role, and account status. Passwords are stored as one-way cryptographic hashes — plain-text passwords are never stored or accessible.
- Uploaded content
- Documents, PDFs, and other source material you upload to the platform. You retain ownership of all content you upload and all outputs generated from it within your workspace. Generated outputs — lessons, assessments, narration, and media — are stored within your workspace alongside the source material and are not shared with other workspaces.
- Technical & usage information
- IP address, session activity, browser type, and platform usage events. This information is used to operate, secure, and maintain the platform and is recorded in our security audit log.
- Support communications
- Messages, descriptions, and any content you include when submitting a support request through the platform.
Lawful Basis for Processing
We process personal data on the following legal bases under UK and EU GDPR:
- Contract performance
- Processing your account information and uploaded content is necessary to provide the platform services you have engaged us to deliver.
- Legitimate interests
- Security logging, fraud prevention, abuse detection, and platform reliability monitoring. We balance these interests against your privacy rights and process only what is necessary.
- Legal obligation
- Retaining audit records and incident logs to meet our obligations under applicable law, including security and data protection legislation.
How We Use Information
We use data to:
- Generate learning content and presentations from uploaded source material
- Provide hosted delivery, exports, and workspace functionality
- Authenticate users and manage access controls
- Maintain security, detect abuse, and investigate incidents
- Respond to support requests
- Meet our legal and regulatory obligations
We do not use personal data for advertising, profiling, or any purpose unrelated to operating the platform.
Third-Party Processors
Certain platform features pass uploaded content to third-party providers to deliver specific functionality. All providers are contracted as data processors under Data Processing Agreements (DPAs) and are not permitted to use your data for their own purposes.
Mimr does not use customer-uploaded content to train public AI models. Processors operate under the same restriction.
- OpenAI
- Used for AI-assisted course structure and content generation, lesson writing, and assessment creation. Data is transmitted over encrypted connections and subject to OpenAI's enterprise data processing terms.
- ElevenLabs
- Used for text-to-speech narration generation on courses where audio is enabled. Text content from lessons is processed to produce audio files stored in your workspace.
- HeyGen
- Used for AI avatar video generation when the avatar feature is enabled on a workspace. Lesson script content is transmitted for video rendering.
- SendGrid (Twilio)
- Used to deliver transactional email notifications, including account invitations, password resets, and support correspondence. Email addresses are transmitted solely for delivery purposes.
- Render
- Cloud infrastructure provider hosting the platform and storing workspace data. All data is encrypted in transit and at rest.
International Data Transfers
All third-party processors listed above are headquartered in the United States. Where personal data is transferred from the UK or European Economic Area to processors in the US, we rely on appropriate safeguards including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- International Data Transfer Agreements (IDTAs) under UK GDPR where applicable
Copies of applicable transfer mechanisms are available on request at privacy@mimrstudio.com.
Data Retention
We retain data only for as long as necessary for the purpose it was collected or as required by law:
- Account & profile data
- Retained for the duration of the account. Following a verified erasure request, personal identifiers are anonymised within 30 days.
- Uploaded content & generated outputs
- Retained within the workspace until deleted by the workspace owner or administrator. Deleted content is removed from active storage immediately; it may persist in operational backups for up to 90 days.
- Audit & security logs
- Retained for 2 years from the date of creation to support security review, incident investigation, and legal compliance. Log entries are anonymised at the point of account erasure.
- Operational backups
- Rolling 90-day retention. Backups are used solely for disaster recovery and are not used to restore deleted content on request.
- Support records
- Retained for 3 years from the date a ticket is closed, to support ongoing service quality and dispute resolution.
Security
Mimr applies a range of technical and operational controls to protect personal data, including encrypted transport (HTTPS with HSTS), HTTP security headers, CSRF protection, bcrypt password hashing, session security controls, rate limiting on authentication endpoints, append-only audit logging, and workspace-scoped access controls.
In the event of a personal data breach that is likely to result in risk to individuals, we will notify the relevant supervisory authority within 72 hours of becoming aware and, where required, notify affected individuals without undue delay.
Your Rights
Under UK and EU GDPR, you have the following rights in relation to your personal data:
- Access
- Request a copy of the personal data we hold about you. Email privacy@mimrstudio.com and we will respond within 30 days.
- Rectification
- Request correction of inaccurate or incomplete personal data. You can update your name and email address in your account settings.
- Erasure
- Request deletion of your personal data. Contact us at privacy@mimrstudio.com. Requests are processed within 30 days.
- Portability
- Request your data in a structured, machine-readable format. Use the data download feature in your account settings to export a JSON file of your personal data.
- Restriction
- Request that we restrict processing of your data in certain circumstances, for example while a correction request is being assessed.
- Objection
- Object to processing based on legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.
To exercise any of these rights, contact us at privacy@mimrstudio.com. We will respond within one month. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or your local supervisory authority.
Cookies & Sessions
Mimr uses only essential session cookies required for authentication, security, and platform functionality. These cookies are set with HttpOnly, Secure, and SameSite=Lax flags. No third-party advertising, analytics, or tracking cookies are used.
Because we use only strictly necessary cookies, we do not present a cookie consent banner. If this changes, this policy will be updated.
Changes to This Policy
We may update this policy from time to time. Material changes will be communicated to workspace administrators by email. The date at the top of this page reflects the most recent revision. Continued use of the platform after changes are posted constitutes acceptance of the updated policy.
Contact
Privacy and data protection enquiries: privacy@mimrstudio.com