Data Governance & Privacy

Privacy Policy & Data Sovereignty

Our transparent standards for protecting proprietary client assets, safeguarding user information, and upholding global privacy compliance across every deployment.

EFFECTIVE: September 13, 2026VERSION: 2026.3STATUS: COMPLIANT & ACTIVE
Monetization
Zero Data Resale

We never sell, broker, or train third-party public models on your proprietary data.

Compliance
GDPR & CCPA Aligned

Built-in data subject rights, exportable records, and rapid DSAR fulfillment.

Isolation
Tenant Sandboxing

Client databases and pipeline telemetry are strictly separated and never commingled.

Offboarding
NIST-Grade Purge

Cryptographically certified data sanitization upon contract completion.

PRV-01

Introduction & Scope

Mindvrix Inc. (“Mindvrix,” “we,” “us,” or “our”) designs and builds custom software, AI-driven automation, video and creative systems, and digital platforms for businesses. This Privacy Policy explains what information we collect through our website and in the course of client engagements, how we use and safeguard it, and the rights available to you.

This Policy applies to visitors of our website, prospective clients who submit discovery enquiries, and individuals whose data we process on behalf of our clients while delivering engineered solutions. By accessing our website or engaging our services, you acknowledge the practices described here.

PRV-02

Information We Collect

Information You Provide Directly

When you submit a project enquiry, architectural RFP, or communicate with our engineers, we collect details you choose to provide — including full name, business email, organization name, estimated budget scope, and technical project parameters.

Telemetry & Automated Diagnostics

When you visit our site, our hosting infrastructure and analytics log non-identifying technical metrics, including client IP address, user-agent string, page interaction timestamps, and referral headers to maintain edge availability and defend against DDoS attacks.

Client Engagement Data Processing

When we build or operate custom pipelines on behalf of a client, we may process end-user records strictly as a Data Processor under documented instructions in a signed Service Agreement. In this context, the client remains the sole Data Controller.

PRV-03

How We Use Information

We process collected data exclusively to:

  • Scope, estimate, and deliver bespoke software engineering and automation architectures;
  • Maintain, monitor, and guarantee uptime for deployed client systems;
  • Enforce infrastructure security, prevent abusive bot traffic, and conduct audit logging;
  • Transmit milestone updates, invoices, and agreed technical documentation;
  • Comply with statutory tax, accounting, and legal requirements.

We strictly do not sell, rent, or monetize personal information or client codebase assets.

PRV-04

Cookies & Storage Technologies

Our website utilizes minimal, privacy-centric cookies and browser storage strictly required for:

Essential Session Cookies

Required for navigation state, security tokens, and responsive layout preferences.

Aggregate Analytics

Anonymous, cookieless or privacy-preserving page counters without cross-site tracking.

PRV-05

How We Share Information

We disclose information only under strictly regulated conditions:

  • Vetted Infrastructure Providers: Cloud hosting (AWS, Cloudflare) operating under verified Data Processing Addendums (DPAs);
  • Statutory Compliance: When mandated by subpoena, court order, or binding government inquiry;
  • Corporate Transactions: In the event of a merger or asset transfer, where the successor entity inherits the commitments of this policy;
  • Explicit Authorization: Where a client explicitly instructs third-party API integration in an agreed statement of work.
PRV-06

Data Retention Standards

Personal records and inquiry metadata are retained only for the duration required to complete the project engagement plus statutory legal/accounting retention windows (typically 7 years for financial and contract records). Client database backups in active hosting contracts adhere to the contracted snapshot retention schedule.

PRV-07

Data Security Architecture

We implement enterprise-grade encryption (TLS 1.3 in transit, AES-256 at rest), role-based access controls, and environment sandboxing. For an exhaustive technical breakdown of our cryptographic and network defense architecture, review our dedicated Security Architecture specification.

PRV-08

Client & Proprietary Project Data

All proprietary source code, algorithms, business logic, and schemas engineered during an engagement are held in strict confidence. Upon project offboarding or contract termination, client data stored in staging or build registries is sanitized and cryptographically purged consistent with NIST SP 800-88 guidelines.

PRV-09

Your Privacy Rights & Controls

Depending on your jurisdiction (such as GDPR in the EU/UK or CCPA/CPRA in California), you hold enforceable rights regarding your personal information:

Right to Access & Portability

Request a full machine-readable export of your personal information held by Mindvrix.

Right to Erasure (“Forget”)

Request total deletion of records where retention is not required by contract or statute.

To exercise your rights, email our Data Governance Officer at privacy@mindvrix.com. We process all verified requests within 30 days.

PRV-10

Cross-Border Data Transfers

Mindvrix operates with a distributed engineering guild and multi-region cloud infrastructure. Where international transfers occur, we utilize standard contractual clauses (SCCs) and equivalent legal mechanisms to guarantee parity in data protection standards.

PRV-11

Children's Privacy Protection

Mindvrix services are exclusively business-to-business (B2B) and are not marketed to or intended for minors under 16 years of age. We do not knowingly harvest information from children.

PRV-12

Policy Revision Protocol

We periodically revise this Privacy Policy to reflect technical advances and legal evolutions. Material modifications will be highlighted on this page along with an incremented revision identifier and date.

PRV-13

Data Governance Contact Desk

For formal privacy inquiries, data subject access requests (DSARs), or DPA execution, contact our compliance team at:

Enterprise Data Processing Addendum

Need a bilateral DPA or Standard Contractual Clauses?

Mindvrix provides pre-executed DPAs with EU Standard Contractual Clauses (SCCs) and UK Addendums for enterprise partners handling regulated end-user datasets.

Request Legal Discovery