1. Scope
This notice applies to the MirrorFoundry product preview and identifies the public-facing brand and European operating region only. It covers mirrorfoundry.ai, messages sent to us, assessment requests, sales and diligence activity, and the invitation process for a customer workspace.
Website assessment requests are used for qualification and response as described below. Customer source data and production processing require separate signed customer and data-processing terms before any such work begins.
Questions can be sent to itops@mirrorfoundry.ai.
2. Information we collect
Information you provide
When you contact us, we may receive your name, work email, company, role, use-case category, region, preferred timing, the description you choose to provide, consent record, and message contents. During diligence and contracting, we may also process meeting notes, commercial requirements, security and legal questions, project scope, and authorised-user details.
Access and technical information
For existing customers, we may process usernames, authentication events, session records, workspace permissions, support communications, and records needed to administer access. Passwords submitted through the sign-in form are used for authentication and are not placed in the session cookie.
Our hosting and security providers may process IP address, browser and device type, requested URL, timestamps, approximate region derived from IP, and operational or security events needed to deliver and protect the site.
3. Purposes and lawful bases
We use personal information to respond to assessment, sales, access, security, legal, privacy, and support requests; evaluate a use case; prepare a proposal or SOW; manage a prospective or active customer relationship; administer invitation-only customer access; operate and secure the website; prevent misuse; and meet legal, tax, accounting, and recordkeeping obligations.
Where the GDPR, UK GDPR, or similar law applies, the lawful basis may be consent, steps requested before entering a contract, performance of a contract, compliance with a legal obligation, or our legitimate interests in operating a secure business-to-business service and responding to professional inquiries. Where we rely on consent, you may withdraw it without affecting prior lawful processing.
4. Service providers and disclosures
We may disclose relevant information to providers supporting website hosting, security, the assessment-form webhook and communications workflow, customer identity, collaboration, professional advice, and business operations. We may also disclose information at a customer's direction, during a corporate transaction, to protect rights or safety, or when required by law. Providers are expected to process information only for the services they supply and subject to applicable contractual restrictions.
We do not sell personal information or share website personal information for cross-context behavioural or targeted advertising.
6. Retention and security
We generally retain prospect and assessment records for up to 24 months after the last meaningful interaction, unless a shorter period is requested or a longer period is needed for an active relationship, legal obligation, dispute, security investigation, or documented business record. Customer, access, and support records follow the applicable agreement and operational retention schedule. Hosting and security logs may have shorter provider-controlled periods.
We use administrative and technical safeguards appropriate to the information and service, including restricted access, server-side form forwarding, controlled customer invitations, signed sessions, and environment boundaries defined during diligence. No transmission or storage method is guaranteed to be completely secure.
7. International transfers
Providers or customer environments may process information outside your country. Where European data-protection law requires safeguards for an international transfer, the applicable agreement may use an adequacy decision, approved standard contractual clauses, the UK International Data Transfer Addendum, or another lawful mechanism, together with supplementary measures where appropriate. Customer data-residency and subprocessor requirements are confirmed during diligence before production use.
8. Your privacy choices and rights
Depending on applicable law, you may have rights to access, correct, delete, restrict, or object to processing; obtain a portable copy; withdraw consent; and complain to the data-protection authority in the country where you live, work, or believe an infringement occurred. Some rights are subject to legal exceptions.
To make a request, email itops@mirrorfoundry.ai with “Privacy request” in the subject and describe your request and relationship with MirrorFoundry. We may verify identity and authority in a proportionate way. We do not make solely automated decisions about website visitors that produce legal or similarly significant effects.
The site and services are intended for business users and are not directed to children. Contact us if you believe a child has provided information.
9. Contact and updates
Privacy questions and requests can be sent to itops@mirrorfoundry.ai. Operating region: Europe.
We may update this notice when the website, services, providers, or legal requirements change. The “Last updated” date shows the latest revision. Material changes will be communicated where required by law.