Privacy Policy
mindzie Privacy Policy
Last revised: September 10, 2026
1. Overview
mindzie, inc. and mindzie Canada, inc. (together, “mindzie”, “we”, “us” or “our”) provide mindzie studio, a process intelligence platform that helps organizations discover, analyze and improve their business processes. mindzie studio is available as a cloud service hosted by mindzie and as software that customers install and run entirely within their own infrastructure (“on-premises”).
This Privacy Policy explains what personal information we collect, how we use and share it, how long we keep it, and the choices and rights you have. It applies to our website at mindzie.com (the “Website”), our cloud-hosted and on-premises software (the “Service”), and our sales, support, marketing and recruiting activities.
How we handle information depends heavily on how you use mindzie. Sections 3 and 4 explain the difference between the data we control (such as your account details) and the data we process only on a customer’s behalf (such as the process data a customer loads into mindzie studio), and how each deployment model affects what we can and cannot see.
2. Definitions
- Account Data means information about the people who purchase, administer or use the Service, such as name, business email address, job title, company, login credentials, billing information and license details.
- Customer Data means event logs, process data, business records, files, reports, dashboards and any other content that a customer or its users upload to, generate in or connect to the Service. Customer Data may contain personal information about a customer’s employees, customers or other individuals (for example, a user ID recorded in an event log).
- Usage Data means technical and diagnostic information generated by the Website and the Service, such as log files, device and browser information, IP address, feature usage, performance metrics, error reports and license validation events.
- Personal Information means any information that identifies, relates to or could reasonably be linked to an identifiable individual. Depending on where you live it may be called “personal data” or “personally identifiable information”.
- Customer means the organization that has entered into an agreement with mindzie for the Service.
- User means an individual authorized by a Customer to use the Service.
3. Our Role: Controller and Processor
mindzie acts in two distinct roles, and this Policy applies differently to each.
When mindzie is a controller
We decide how and why to process Account Data, Usage Data, Website visitor information, marketing contacts, support communications and job applicant information. This Privacy Policy governs that processing in full.
When mindzie is a processor (or service provider)
Customer Data belongs to and is controlled by our Customer. When a Customer uses the cloud-hosted Service, we process Customer Data only on the Customer’s documented instructions, under the terms of our customer agreement and a Data Processing Agreement (“DPA”), and solely to deliver, secure and support the Service. We do not use Customer Data for our own purposes, do not sell it, and do not use it to train or improve artificial intelligence or machine learning models.
If your personal information is contained in Customer Data (for example, because your employer uses mindzie studio to analyze a business process you participate in), the Customer’s privacy notice governs that use. Please direct any questions or requests about that data to the Customer. If you contact us directly, we will refer your request to the relevant Customer and assist them as required by our DPA.
4. Deployment Models and What mindzie Can Access
Cloud-hosted deployment
On-premises deployment
In an on-premises deployment, the Customer installs and runs mindzie studio within its own data center or private cloud. Customer Data never leaves the Customer’s environment and mindzie has no access to it, unless the Customer expressly chooses to share specific data with us (for example, by attaching a file to a support request). The Customer is solely responsible for the security, hosting, backup and lawful processing of Customer Data in its own environment.
On-premises deployment does not mean mindzie holds no information about you. Even for on-premises Customers, mindzie still collects and controls Account Data (such as administrator and licensed user contact details), license activation and validation data, and any information you share when you contact sales or support. That information is handled as described in this Policy.
5. AI-Assisted Features
mindzie studio includes optional AI-assisted features that help users explore process data, generate summaries and insights, and receive recommendations. These features are designed with the following principles:
- Optional and controllable. AI-assisted features can be enabled or disabled by a Customer administrator, and Users choose when to invoke them. The core Service functions fully without them.
- Customer choice of AI provider. Customers may use AI services arranged by mindzie, connect their own AI service subscription, or connect an AI service running in their own cloud or on-premises environment. Where a Customer connects its own provider, the Customer’s agreement with that provider governs how the data is handled.
- Limited data transmission. When an AI-assisted feature is used, only the information needed to answer the specific request (such as the selected process metrics, a natural-language question or a relevant data excerpt) is transmitted to the AI service, and only for the duration needed to generate a response. mindzie does not retain the inputs or outputs of AI requests beyond what is required to deliver the feature and any history the User chooses to keep within the Service.
- No training on your data. mindzie does not use Customer Data, prompts or outputs to train AI models. Where mindzie arranges the AI service, we contractually require the provider not to use Customer Data to train or improve its models and not to retain it beyond what is needed to process the request.
- Human oversight. AI-generated outputs are provided to assist analysis and decision-making by Users. mindzie does not use AI to make automated decisions that produce legal or similarly significant effects on individuals.
Details of the AI services currently available in a Customer’s deployment, and the regions in which they operate, are available from your mindzie administrator or from mindzie on request.
6. Personal Information We Collect
Information you provide to us
- Contact and account details when you request a demo, register for an account, purchase a subscription, subscribe to communications or create a support ticket: name, business email, phone number, company, job title, country and login credentials.
- Billing information, such as billing address and payment details. Payment card details are handled by our payment processor and are not stored by mindzie.
- Content you submit, such as support requests, survey responses, event and webinar registrations, feedback, and communications with our sales and support teams.
- Job applicant information, such as your résumé, work history and anything else you provide when applying for a position with mindzie.
Information collected automatically
- Website Usage Data collected through cookies and similar technologies: IP address, browser type, device identifiers, pages visited, referring URLs and interaction data (see Section 12).
- Service Usage Data for the cloud-hosted Service: login events, features used, performance and error logs, and security events.
- License and diagnostic data for on-premises deployments: product version, license key status, activation and validation events, and, only if the Customer enables it, anonymized or aggregated usage and diagnostic telemetry. Telemetry never includes Customer Data.
Information from other sources
- Business contact information from our channel partners and resellers, from publicly available professional sources, and from data providers, used for business-to-business marketing and account management in accordance with applicable law.
- Information from third-party sign-in or identity providers when a Customer configures single sign-on for the Service.
7. How We Use Personal Information and Our Legal Bases
We use the personal information we control for the following purposes. Where the GDPR, UK GDPR or similar laws apply, we rely on the legal basis indicated.
- Providing and administering the Service – creating and managing accounts, authenticating Users, delivering licenses, processing payments, and providing updates and support. Legal basis: performance of a contract, or our legitimate interest in serving the Customer organization you work for.
- Operating, securing and improving the Service – monitoring performance, diagnosing problems, preventing fraud and abuse, and understanding how features are used so we can improve them. Legal basis: legitimate interests; for on-premises telemetry, the Customer’s consent or configuration.
- Communicating with you – sending service notices, security alerts, renewal reminders and responses to your enquiries. Legal basis: performance of a contract or legitimate interests.
- Marketing – sending information about mindzie products, events and content that may interest you, in line with your preferences. You can unsubscribe at any time using the link in any marketing email. Legal basis: legitimate interests for existing business contacts, or consent where required by law.
- Recruiting – evaluating job applications and communicating with candidates. Legal basis: steps taken at your request prior to entering a contract, and legitimate interests.
- Compliance and protection – complying with legal obligations, enforcing our agreements, responding to lawful requests, and protecting the rights, property and safety of mindzie, our Customers and others. Legal basis: legal obligation and legitimate interests.
We do not sell personal information, and we do not use personal information for targeted advertising across third-party websites. We do not use personal information for automated decision-making that produces legal or similarly significant effects on you.
8. How We Share Personal Information
We share personal information only as described below and with appropriate safeguards.
- Service providers and sub-processors. We use vetted third parties that process information on our behalf for cloud hosting and storage, AI services (where arranged by mindzie), payment processing, email and communications delivery, customer relationship management, support ticketing, analytics, and security monitoring. Each provider is bound by contractual obligations of confidentiality and data protection and may use the information only to perform services for us. A current list of the sub-processors used for the cloud-hosted Service is available on request from legal@mindzie.com and is incorporated into our DPA.
- Affiliates. mindzie, inc. and mindzie Canada, inc. share information with each other to operate the business, under the same protections described here.
- Channel partners and resellers. If you purchase mindzie through a partner, or a partner refers you to us, we and the partner may exchange account and contact information needed to fulfil the sale, provide support and manage the relationship.
- Legal and safety. We may disclose information when required by law, subpoena or court order, or when we believe in good faith that disclosure is necessary to protect our rights, investigate fraud or security issues, or protect the safety of any person. Where permitted, we will notify the affected Customer before disclosing Customer Data in response to a legal request.
- Business transfers. See Section 15.
- With your direction. We share information with third parties when you ask us to or otherwise consent.
9. International Data Transfers
mindzie is headquartered in the United States with operations in Canada, and our service providers may be located in other countries. For the cloud-hosted Service, Customer Data is stored in the hosting region agreed with the Customer, which may be in the United States, Canada, the European Union, the Middle East or another region. Account Data, Usage Data and support information may be processed in the United States and Canada regardless of the Customer’s hosting region.
Where personal information is transferred out of the European Economic Area, the United Kingdom, Switzerland or another jurisdiction that restricts international transfers, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, adequacy decisions (including the adequacy status of Canada) or other lawful transfer mechanisms. Copies of the relevant safeguards are available on request.
On-premises Customers determine where their Customer Data is stored and are responsible for any transfers within their own environment.
10. Data Retention
We keep personal information only for as long as needed for the purposes described in this Policy, unless a longer period is required or permitted by law. In general:
- Account Data is retained for the life of the Customer relationship and for a limited period afterward to allow for reactivation, resolve disputes and meet legal and accounting obligations.
- Customer Data in the cloud-hosted Service is retained for as long as the Customer’s subscription is active. Following termination, Customer Data is made available for export for a limited period and then deleted from production systems, with encrypted backups expiring on a rolling schedule thereafter, in accordance with our customer agreement and DPA.
- Usage Data and security logs are retained for a limited period for diagnostics, security and compliance, and are then deleted or aggregated.
- Marketing contact information is retained until you unsubscribe or we determine it is no longer current.
- Job applicant information is retained for the duration of the recruiting process and for a limited period afterward, unless you ask us to delete it sooner or consent to being considered for future roles.
When information is no longer needed we securely delete or anonymize it. Where immediate deletion is not practical (for example, data in backup archives), we isolate the information from further use until deletion is possible.
11. Security
mindzie maintains a security program with administrative, technical and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration and loss. These include:
- Encryption of data in transit using Transport Layer Security (TLS) and encryption of data at rest.
- Role-based access control, multi-factor authentication for administrative access, and the principle of least privilege.
- Logical separation of Customer environments in the cloud-hosted Service.
- Logging and monitoring of production systems and access to Customer Data.
- Secure software development practices, vulnerability management and regular security testing.
- Security and privacy training for personnel, and confidentiality obligations for all employees and contractors.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Customers are responsible for managing their own User accounts and credentials, for configuring the Service appropriately, and, for on-premises deployments, for securing the environment in which the Service runs. Additional details about our security practices are available on request.
12. Cookies and Tracking Technologies
Our Website uses cookies and similar technologies (such as pixels and local storage) to keep the site working, remember your preferences, measure how the site is used and, where you agree, support our marketing. We group these as strictly necessary, functional, analytics and marketing cookies. Where required by law, we ask for your consent through a cookie banner before setting non-essential cookies, and you can change your choices at any time through the banner or your browser settings.
The cloud-hosted Service uses only the cookies and similar technologies necessary to authenticate Users, maintain sessions, preserve settings and keep the Service secure and performing well. We honor Global Privacy Control signals where applicable law requires it. Disabling necessary cookies may prevent parts of the Website or Service from working.
13. Your Privacy Rights
Depending on where you live, you may have some or all of the following rights regarding personal information that mindzie controls:
- To access the personal information we hold about you and receive a copy of it.
- To correct inaccurate or incomplete information.
- To request deletion of your personal information.
- To restrict or object to certain processing, including processing based on legitimate interests and direct marketing.
- To receive your information in a portable, machine-readable format.
- To withdraw consent at any time where processing is based on consent, without affecting processing carried out before withdrawal.
- To not be discriminated against for exercising any of these rights.
- To lodge a complaint with a supervisory or data protection authority.
To exercise these rights, email legal@mindzie.com. We will verify your identity, which may involve confirming the email address associated with your account, and respond within the time required by applicable law. You may designate an authorized agent to make a request on your behalf where the law allows; we may require proof of that authorization. If we decline all or part of a request we will explain why, and you may appeal by replying to our response.
If your personal information is contained in Customer Data, please contact the Customer, who controls that information. We will support Customers in responding to such requests as required by our DPA.
European Economic Area, United Kingdom and Switzerland
If you are in the EEA, UK or Switzerland, the rights above apply under the GDPR, UK GDPR and Swiss Federal Act on Data Protection. You have the right to lodge a complaint with your local data protection authority. Contact details for EEA authorities are available at edpb.europa.eu, and for the UK at ico.org.uk.
Canada
mindzie Canada, inc. complies with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws, including Quebec’s Law 25. You may request access to and correction of your personal information and may withdraw consent subject to legal and contractual restrictions. Our designated privacy officer can be reached at legal@mindzie.com. You may also contact the Office of the Privacy Commissioner of Canada.
United States
14. Children
The Website and Service are intended for business use by adults. We do not knowingly collect personal information from anyone under the age of 16 (or the age of majority in your jurisdiction, if higher). If you believe a child has provided us with personal information, contact us at legal@mindzie.com and we will delete it.
15. Business Transfers
If mindzie is involved in a merger, acquisition, financing, reorganization, or sale of all or part of its business or assets, personal information may be transferred as part of that transaction. Any successor will be bound to honor the commitments in this Privacy Policy, or we will notify you before your information becomes subject to a different privacy policy and give you any choices required by law.
16. Security Incident Notification
We maintain an incident response program to identify, contain, investigate and remediate security incidents. If a security incident affects Customer Data in the cloud-hosted Service, we will notify the affected Customer without undue delay and within the time frame set out in our DPA, and provide the information the Customer needs to meet its own notification obligations. If an incident affects personal information that mindzie controls, we will notify affected individuals and regulators as required by applicable law.
17. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices, technology or the law. The revision date at the top of this page indicates when it was last updated. If we make material changes, we will provide notice through the Website, by email to the account administrators of affected Customers, or within the Service before the changes take effect. Continued use of the Website or Service after the effective date means the updated Policy applies, but it does not by itself constitute consent to any processing that requires consent under applicable law.
18. Contact Us
If you have questions about this Privacy Policy or our privacy practices, or wish to exercise your rights, please contact us:
mindzie, inc.
2600 E Southlake Blvd, Suite 120 PMB 378
Southlake, Texas 76092, United States
Email: legal@mindzie.com
Customers who require a Data Processing Agreement, our current sub-processor list, or a summary of our security practices can request them at the same address.