This is a courtesy translation. The Ukrainian privacy policy prevails.
Mimiao Privacy Policy
Language notice. This English translation is provided for convenience only. The legally binding original is the current Ukrainian Privacy Policy published at mimiao.online/privacy. If this translation differs from the Ukrainian original, the Ukrainian version prevails.
Version dated 8 September 2026
1. General provisions
1.1. This Policy explains how Individual Entrepreneur (FOP) Illia Vadymovych Pinchuk, Taxpayer Registration Number (RNOKPP) 3770506715, registered and actual place of residence: Apt. 30, 9-A Obolonskyi Avenue, Kyiv, Ukraine, email: mimiaobusiness@gmail.com (hereinafter “Mimiao”, “we”, “us”) collects, uses, stores, transfers and protects personal data when you use:
- the website at https://mimiao.online (the “Website”); and
- the Mimiao cloud CRM platform at https://app.mimiao.online, including its related features, integrations and support channels (the “Service”).
1.2. This Policy has been prepared in accordance with the Constitution of Ukraine, the Laws of Ukraine “On Protection of Personal Data”, “On Information” and “On Electronic Commerce”, and other mandatory laws of Ukraine. Mimiao’s commercial offering is addressed to Customers conducting professional activities in Ukraine.
1.3. The terms “personal data”, “processing”, “controller” and “processor” have the meanings assigned to them by applicable law.
1.4. This Policy was prepared in Ukrainian. Translations into other languages and summaries are provided for convenience only. If there is any discrepancy, the current Ukrainian version published on the Website prevails.
2. Our roles when processing data
2.1. Mimiao as controller. We determine the purposes and means of processing data relating to Website visitors, prospective customers, Customers and account users where this is necessary for registration, entering into and performing a contract, subscription payments, support, security and development of the Service. For development, we use technical telemetry and anonymised aggregates, not the content of School Data, unless the Customer provides a separate documented instruction.
2.2. The school as controller; Mimiao as processor. For data that a Customer or its users enter into the CRM about leads, students, parents, teachers, employees, contractors and other individuals (the “School Data”), the Customer determines the purposes and legal grounds for processing. Mimiao processes that data on the Customer’s behalf to provide the Service and in accordance with the Customer’s documented actions and settings in the Service.
2.3. Requests from data subjects concerning School Data should first be addressed to the relevant school. We will assist the Customer in responding to lawful requests within the features of the Service and our contractual obligations.
2.4. When a payment is made, the bank or payment provider independently determines how payment details are processed under its own rules and applicable law. Mimiao does not receive the full payment-card number, its expiry date or CVV.
3. Data we process
3.1. Depending on how you interact with the Website and the Service, we may process:
- registration and contact data: first and last name, school name, job title, email address, phone number, username, identifiers and messenger contact details;
- account data: user and school identifiers, role, access permissions, settings, language and time preferences, password hash, active-session data and login confirmations;
- contract and payment data: selected Plan, subscription period, invoice and payment history, amount, currency, status and technical payment identifier. Full payment-card details are processed by the payment provider; Mimiao does not receive or store them;
- communications: support requests, demo or trial requests, correspondence and feedback;
- technical data: IP address, request date and time, browser and device type, operating system, login, error, security and administrative-action logs; and
- usage data: sections and features used, interface settings and aggregated Service performance and interaction statistics.
3.2. School Data may include:
- identification and contact data of leads, students, parents, teachers and employees;
- enquiries from the school’s prospective customers received through connected communication channels, including the text of an Instagram Direct message and the sender’s public name or username where the Customer has connected the school’s Instagram account to the Service, as well as the name, contact details and results of visitors completing the school’s public diagnostic tests;
- education information, including language or subject, level, group, schedule, attendance, homework, grades, progress, materials, notes and communications;
- operational financial information, including invoices, payments, refunds, lesson balances, rates and teacher accruals;
- credentials for integrations connected by the Customer to the Service, such as payment-merchant keys or access tokens for connected services. We store them in encrypted form and use them solely to operate the relevant integration; and
- uploaded files and other information that a user knowingly adds to the Service.
3.3. The Service is not intended to store medical data, biometrics, political opinions, religious beliefs or other data whose processing creates a particular risk. Free-text fields can technically contain such information, so the Customer must not add it without a lawful basis, demonstrated necessity, appropriate notice to the data subject and Mimiao’s prior written agreement where this is required for a security assessment.
3.4. The Service may contain data about students who are minors. The Customer is responsible for establishing a proper legal basis for processing that data, informing parents or legal representatives and obtaining their consent where required by law.
4. Sources of data
4.1. We obtain data:
- directly from you when you register, make a payment, complete a form or contact support;
- from the Customer, school administrators and other users authorised by them;
- automatically from the browser, device and server infrastructure;
- from services connected at your initiative, including payment providers, email and Telegram services, social networks and messengers through which the Customer receives enquiries (for example, Instagram Direct through Meta’s official API), and educational tools such as online whiteboards;
- from visitors to a school’s public diagnostic tests who voluntarily provide their name and contact details before taking a test; and
- from public sources, but only professional contact data made public by the individual where direct business communication can reasonably be expected. At the first contact, and no later than 30 business days after collection, we tell the individual that Mimiao is the controller, identify the source and data categories, purpose and legal ground, recipients or a link to their register, rights under the law and a simple way to object to further messages.
5. Purposes and legal grounds for processing
5.1. For data for which Mimiao is the controller, the following purposes and legal grounds under Article 11 of the Law of Ukraine “On Protection of Personal Data” apply:
| Purpose | Main data | Legal ground |
|---|---|---|
| Responding to an enquiry, providing a demo, negotiations | name, professional contact details, school name, enquiry content | steps taken at the individual’s request before entering into a transaction; consent where requested in the form |
| Customer registration, acceptance and provision of the Service | contact and account data, role, acceptance version and evidence | entering into and performing a transaction |
| Invoicing, monopay/bank transfer and fiscalisation | Plan, amount, status, payment and fiscal identifiers | performing a transaction and complying with a legal obligation |
| Login, access control and abuse prevention | session, IP address, device, login and action logs | performing the contract, protecting rights and information security |
| Support and service messages | contact details, request and technical context | performing the contract or responding to a request |
| Backups, diagnostics, reliability and development | technical logs and aggregated statistics | performing the contract and protecting legitimate interests without disproportionate interference |
| Marketing messages | professional contact details and consent/opt-out history | consent or another ground expressly permitted by law, always with a way to opt out |
| Responding to authorities and defending legal claims | necessary contract, payment and security records | complying with a legal obligation or protecting rights and legitimate interests |
5.2. For School Data, the Customer determines the purpose, categories, retention period and legal ground. Actions taken by the Customer and its authorised users in the Service constitute Mimiao’s documented instructions within the Service’s functionality. Detailed processing terms are set out in the DPA at https://mimiao.online/legal/2026-08-14/dpa.
5.3. If the school owner separately enables AI features, the prompt and the minimum necessary context, filtered according to access permissions, are sent to the model provider named in the register to generate a response. Enabling the feature is an instruction from the Customer to Mimiao, but does not replace the legal ground required in relation to a particular individual. The Customer must not send excessive data, secrets, high-risk information or data about a minor to AI without an appropriate legal ground. Mimiao does not retain AI prompt or response text; a content-free technical log may record the action type, time, user identifier, model, volume and status. AI output requires human review and must not be the sole basis for a decision that significantly affects an individual.
5.4. If a user separately connects Google Calendar, Mimiao uses only the Google Calendar API. We receive the Google account identifier, email address and calendar list needed to authorise the connection and select the destination calendar. To synchronise lessons, Mimiao sends the title, time, status and lesson link from the CRM schedule to the calendar selected by the user. Mimiao does not import Google Calendar events into the CRM and does not use Google Calendar data as a source for AI features. Gmail, Google Drive and Google Photos are not connected.
Raw, aggregated, anonymized or derived user data received through Google Workspace APIs, including Google Calendar data, is used only to provide the user-requested integration. It is not sold or transferred to Mistral or another AI provider to train, improve or develop generalized or foundational AI/ML models.
The use of information received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
6. Customer obligations regarding third-party data
6.1. By adding School Data, the Customer confirms that it:
- has a lawful basis to collect, use and transfer the data to Mimiao;
- has given data subjects the necessary information about the processing and the involvement of a cloud provider;
- has obtained consent where consent is required by law;
- has defined appropriate retention periods and does not enter excessive data; and
- gives access only to authorised users and revokes it promptly.
6.2. The Customer is responsible for responding to data-subject requests concerning School Data and for the lawfulness of content added to the Service by the Customer or its users. Mimiao does not transfer to the Customer responsibility for Mimiao’s own breach of its processor or security obligations.
7. Who receives data
7.1. We do not sell personal data.
7.2. To the minimum extent necessary, data may be received by:
- providers of hosting, data storage, backups and technical infrastructure;
- providers of email, Telegram, browser push notifications and other messaging channels, both those activated by the Customer in the Service and those we use to receive and process Website enquiries and requests (in particular, Website form submissions reach us through an operational Telegram bot);
- payment providers and banks for processing and confirming payments;
- third-party services connected by the Customer to the Service, such as online lesson whiteboards, within the integration configured by the Customer and the data required to operate it;
- providers of security monitoring, error diagnostics and analytics;
- the AI model provider, only where the school owner has enabled AI, only to the minimum extent necessary to answer a specific request, and only after we have verified a contractual prohibition on using submitted data to train general models;
- Google LLC, only for the user’s optional Google Calendar integration: Google receives data needed for the authorised calendar connection, while Mimiao sends only the minimum CRM event fields needed to synchronise the selected calendar; Google Calendar data is not sent to AI providers;
- professional advisers and contractors bound by confidentiality;
- public authorities, courts or other persons where disclosure is required by law; and
- a successor in the event of a reorganisation or sale of all or part of the business, provided appropriate data protection is maintained.
7.3. We engage providers under contractual terms, restrict their access to the purpose of the service they provide and require appropriate security measures. The current list of specific providers, their roles, data and processing countries is published at https://mimiao.online/subprocessors.
7.4. Some supporting providers may process limited data outside Ukraine. A transfer is permitted only under Article 29 of the Law of Ukraine “On Protection of Personal Data”: to a country with an adequate level of protection or where another legal ground and appropriate safeguards prescribed by law apply. Before a transfer, we assess the purpose and destination country, minimise the data, and establish contractual restrictions, confidentiality and security measures. The Customer’s connection of its own integration is its documented instruction regarding the recipient, but does not displace mandatory cross-border transfer requirements.
8. Retention and deletion
8.1. We retain data only for as long as necessary for the specified purpose, performance of the contract, mandatory accounting requirements, security and the protection of rights in a dispute.
8.2. Unless the law or a separate agreement requires otherwise, the following guidelines apply:
- a copy of a Website form submission in the operational Telegram channel is retained for no longer than 12 months after submission, or deleted earlier in response to a substantiated request;
- other pre-contract correspondence is retained for up to 24 months after the last meaningful interaction;
- account data is retained for the duration of the relationship with the Customer. A separate, minimum record proving the contract, acceptance, payment, fiscalisation, confirmed termination and completed full deletion is retained until the end of the period required by law for accounting, preventing restored backups from reintroducing deleted data and protecting rights;
- security and technical logs are generally retained for up to 12 months; account action audit logs are retained for up to 3 years. Longer retention applies only where necessary to investigate an incident or comply with the law;
- Mimiao does not retain AI prompt or response text; content-free AI technical audit records follow the audit-log retention period;
- marketing contacts are retained until consent is withdrawn, an objection is made or the purpose is no longer relevant, but generally no longer than 24 months after the last meaningful interaction;
- School Data is retained for the duration of the contract. Following confirmed termination, a 30-day read-and-export-only period applies, after which School Data is deleted from the active database and active file storage;
- disaster-recovery backups containing deleted School Data are automatically rotated out within no more than the following 30 calendar days and are not used for ordinary operations; and
- Mimiao’s own financial, tax, contract and security records are retained only to the minimum extent and for the periods required by law or objectively necessary for a specific dispute. A school’s operational financial history does not become Mimiao’s own tax archive merely because it is stored in the CRM.
8.3. Data may be anonymised instead of deleted. Anonymised, aggregated data that no longer makes it possible to identify an individual is not personal data.
9. Cookies and Google Analytics 4
9.1. Necessary cookies support authentication, security and preferences. Optional analytics is not required for registration, CRM use or payment.
9.2. Only after permission through the banner do we load Google Analytics 4 (GA4) to understand Website visits and registration steps on app.mimiao.online. A first-party cookie shares the choice across both hosts. The Google tag does not load beforehand. Advertising attribution is separately described in section 9.7; publishing this revision does not activate it. Payment uploads remain disabled until separate activation and a new banner choice. Ad personalisation and Google Signals stay off; ad-measurement consent is sent only after permission.
9.3. GA4 receives page views, public button/form interactions without form contents, registration start/completion, timestamps, pseudonymous cookie identifiers and technical browser/device information. Google also receives network information needed to deliver requests. Page context excludes URL queries/fragments; referral context contains only the origin. We do not add names, emails, phone numbers, passwords, payment credentials, learning records or Google Calendar data to events. Pseudonymous identifiers are not anonymous.
9.4. Choice and consent-time cookies last up to 365 days. GA4 _ga and ga* cookies are configured for up to 2 years, renewable by new activity; browsers may impose shorter limits. GA4 event-data retention is 2 months and user-data retention is 14 months, with the user identifier’s period reset on new activity. These settings do not limit standard aggregated reports. Cookie expiry does not mean simultaneous deletion of all data held by Google.
9.5. Use the analytics/cookie settings on the Website or registration pages to change your choice. Only necessary stops further measurement in this browser and removes accessible analytics cookies. It does not automatically erase data already sent to Google. Contact mimiaobusiness@gmail.com for access, correction or deletion; we handle requests under applicable law and Google’s available mechanisms. Withdrawal does not affect the lawfulness of previous processing. Other browsers/devices have their own choice.
9.6. Google, including Google Ireland Limited and Google LLC, receives data through GA4 and its global infrastructure. Mimiao controls this analytics processing; Google provides processing under the Google Ads Data Processing Terms, which also cover GA4 despite their name. Processing may occur outside Ukraine, including in the United States, for the measurement described above. See the recipient register and section 7.4 for recipients and safeguards. Analytics permission is not permission for marketing messages or advertising use of School Data.
9.7. Google Ads measurement
After a new choice in the banner, Mimiao measures advertising results across mimiao.online and app.mimiao.online. Previous GA4-only permission does not enable advertising attribution. Refusal does not restrict registration, CRM use or payment.
With permission, we retain the Google click identifier (gclid, gbraid or
wbraid), UTM campaign labels, landing-page path and consent time. First-party
cookies connect the Website and application; registration links this information
to the created school for advertising measurement. These are pseudonymous, not
anonymous data. Do not place contact details or other personal data in campaign labels.
Google Ads receives the click identifier, conversion type and time, consent state and a stable technical event identifier used to prevent duplicates. The first paid subscription also includes the actual amount in UAH and plan code. Activation means verified owner registration, at least two teachers and the first student added; teacher/student names and records are not transmitted. We do not add names, emails, phone numbers, school names, form contents, passwords, payment credentials, learning records or Google Calendar data. Ad personalisation and Google Signals remain disabled.
The attribution cookie lasts up to 90 days; the choice, consent-time and random withdrawal-key cookies last up to 365 days. Server advertising profiles and queued conversions become ineligible 90 days after capture or upon confirmed withdrawal. Expired advertising copies are removed in bounded background batches; technical failures may delay deletion but do not make expired records eligible for new uploads. A withdrawal-key hash is kept for up to 91 days to prevent recapture. This does not change mandatory financial retention or existing immutable operational events. Backup and Google retention are not the same as active advertising-table retention.
Choose Only necessary in analytics/cookie settings to withdraw. The browser stops measurement and requests removal of the linked server advertising profile and queue. Once the server confirms, no new upload for that key can begin. If the request awaits connectivity, the interface says so; a pending cookie lasts up to 91 days and retries on reconnection or a later visit. Keep that cookie until confirmation. For another device, a lost key or data already sent to Google, contact mimiaobusiness@gmail.com. Withdrawal does not automatically recall completed Google requests or erase payments.
Google receives conversions through Google Ads/Data Manager and its global infrastructure, including Google Ireland Limited and Google LLC, to measure advertising-driven registration, activation and first subscription payment—not to send marketing messages or use learning records for advertising. Processing may occur outside Ukraine, including the United States. See the recipient register and section 7.4 for processing terms and transfer safeguards. GA4 retention remains separately disclosed; Google Ads retention must not be inferred from GA4 settings or Mimiao cookie lifetimes.
10. Security and incidents
10.1. We use reasonable technical and organisational measures appropriate to the nature of the data and the risks, including access controls, transmission over secure channels (TLS), isolation of school data, encryption of integration credentials and other secrets (AES-256-GCM), logging of significant actions, backups and secrets protection.
10.2. No method of data transmission or storage can guarantee absolute security. This does not remove our obligation to take appropriate measures, but means that we cannot promise that no incident will ever occur.
10.3. If we discover a personal-data security incident affecting School Data, we will notify the Customer’s contact person without undue delay after we have enough information to give notice. The initial notice may be supplemented later; we do not wait for final confirmation of every consequence.
10.4. Users are responsible for keeping their credentials confidential, using strong passwords, keeping roles current and reporting suspected compromise immediately.
11. Data-subject rights
11.1. In the cases and to the extent established by law, you have the right to:
- know the sources, location, purpose and conditions of processing of your data;
- access your personal data;
- request correction of inaccurate or incomplete data;
- object to processing and request that it stop;
- request deletion where data is processed unlawfully or is no longer needed, except where retention is mandatory;
- withdraw consent without affecting the lawfulness of processing carried out before withdrawal;
- lodge a complaint with the Ukrainian Parliament Commissioner for Human Rights or a court; and
- exercise other rights under Article 8 of the Law of Ukraine “On Protection of Personal Data”.
11.2. To exercise a right, email mimiaobusiness@gmail.com. We may request enough information to verify your identity and locate the data. We respond within the period required by applicable law.
11.3. To opt out of marketing messages, use the “Unsubscribe” link in the email or contact us. Service messages concerning security, payments and material changes to the Service are a necessary part of the contract.
12. Changes to this Policy
12.1. We may update this Policy in response to changes in law, the Service or our processing. The current version and its date are published at the permanent address https://mimiao.online/privacy.
12.2. We will notify you of material changes through the Service or by contact email before they take effect, unless the law requires an immediate change.
13. Contact details
- Controller / processor: Individual Entrepreneur (FOP) Illia Vadymovych Pinchuk
- Taxpayer Registration Number (RNOKPP): 3770506715
- Registered and actual place of residence: Apt. 30, 9-A Obolonskyi Avenue, Kyiv, Ukraine
- Privacy email: mimiaobusiness@gmail.com
- General email: mimiaobusiness@gmail.com
- Website: https://mimiao.online
A complaint about personal-data processing may also be submitted to the Ukrainian Parliament Commissioner for Human Rights at https://ombudsman.gov.ua/.