Privacy Policy & Data Protection Notice
Last Updated: September 2026 • Mimesis Studios Ltd (Company No. 12768442, Registered in England & Wales)
Data Protection Principles & Privacy Summary
At Mimesis Studios Ltd (Company No. 12768442), we respect your privacy and are committed to protecting your personal data in strict compliance with the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018 ("DPA 2018").
1. Data Controller & Contact Information
Mimesis Studios Ltd ("Mimesis Indie", "we", "us", or "our") is the Data Controller responsible for your personal data collected and processed through indie.mimesis-studios.com.
Data Controller: Mimesis Studios Ltd
Company Registration: Incorporated and registered in England & Wales under Company No. 12768442
Data Protection Inquiries: support@mimesis-studios.com
Supervisory Authority: Information Commissioner's Office (ICO), United Kingdom
2. Our Data Protection Principles
We adhere strictly to the core principles set out in Article 5 of the UK GDPR. Your personal data is:
- Processed lawfully, fairly, and in a transparent manner (Lawfulness, Fairness, Transparency).
- Collected solely for specified, explicit, and legitimate business purposes (Purpose Limitation).
- Adequate, relevant, and limited to what is necessary for our services (Data Minimisation).
- Accurate and kept up to date (Accuracy).
- Kept in a form permitting identification for no longer than necessary (Storage Limitation).
- Processed securely using appropriate technical and organisational safeguards (Integrity and Confidentiality).
3. Categories of Personal Data We Collect
We collect and process the following categories of personal data:
A. Identity & Account Data
First name, last name, email address, password hash, avatar/profile information, role, and OAuth provider IDs (e.g. GitHub/Google login).
B. Billing, Financial & Transaction Data
Stripe customer ID, Stripe subscription ID, payment intent IDs, invoice history, currency choice (GBP/USD), VAT/tax residency, and development credit ledger balances. (We do not store complete card numbers on our servers; card payments are processed securely via Stripe).
C. Project & Repository Access Data
Game project titles, game engine versions (e.g. Unity LTS), target platforms, git repository URLs, git personal access tokens / deployment keys, branch configurations, and webhook identifiers.
D. Ticket & Technical Communication Data
Feature requests, bug reports, reproduction steps, technical briefs, uploaded screenshots, crash logs, and client approval/rejection notes.
E. Call Bookings & Collaboration Data
Booking dates/times, meeting notes, project onboarding agendas, and Microsoft Teams meeting identifiers.
4. Lawful Bases & Processing Purposes (UK GDPR Article 6)
| Processing Purpose | Data Categories Used | Lawful Basis (UK GDPR) |
|---|---|---|
| Account creation, authentication & session management | Identity & Account Data | Contract Performance (Art 6(1)(b)) |
| Scoping, estimating, and performing game development tickets | Project Data, Ticket Data, Repo Credentials | Contract Performance (Art 6(1)(b)) |
| Subscription billing, credit top-ups & ledger calculations | Billing & Financial Data | Contract Performance (Art 6(1)(b)) |
| UK HMRC statutory accounting, VAT and corporate record-keeping | Invoices, Billing Data, Legal Entity Details | Legal Obligation (Art 6(1)(c)) |
| Infrastructure security, CSRF protection & abuse prevention | Account Metadata, Session Tokens | Legitimate Interests (Art 6(1)(f)) |
| Customer support live chat & inquiry management (HubSpot) | Contact Info, Chat History, Session Tokens | Explicit Opt-In Consent (Art 6(1)(a)) / Legitimate Interests (Art 6(1)(f)) |
| AI / LLM code scaffolding acceleration (if opted in) | Ticket Briefs, Code Snippets | Explicit Consent (Art 6(1)(a)) |
5. Third-Party Sub-Processors & Data Sharing
We do not sell, rent, or trade your personal data. We share data only with trusted enterprise service providers under strict Data Processing Agreements:
| Provider | Service Description | Data Protection Safeguard |
|---|---|---|
| Supabase Inc. | Managed PostgreSQL database, authentication, and file storage | UK/EU Data Residency, SOC 2 Type II, ISO 27001 |
| Stripe Payments Europe / UK | Payment gateway, subscription recurring billing, and invoices | PCI-DSS Level 1 Service Provider |
| Resend Inc. | Transactional email notifications and password reset delivery | UK GDPR DPA & Standard Contractual Clauses (SCCs) |
| Microsoft Teams / Graph | Client video meetings and team webhook task notifications | Enterprise GDPR compliant cloud infrastructure |
| Asana Inc. | Internal studio task management and sprint synchronization | SOC 2 Type II, Enterprise DPA |
| GitHub / GitLab | Git repository synchronization and pull request delivery | Encrypted token storage, restricted server gateways |
| HubSpot Ireland Ltd. | Customer support live chat widget and inbound enquiry management | UK GDPR DPA & EU Data Center Infrastructure |
| Plausible Insights OÜ | Privacy-preserving, cookie-free aggregate website analytics | EU-hosted infrastructure, fully GDPR/ePrivacy compliant without tracking cookies |
6. International Data Transfers
Whenever personal data is transferred outside the United Kingdom or European Economic Area (EEA), we ensure appropriate safeguards are implemented in accordance with Chapter V of the UK GDPR. This includes utilizing the UK International Data Transfer Addendum to the EU Standard Contractual Clauses (SCCs) and working with vendors covered by UK adequacy regulations.
7. Technical & Organisational Security Safeguards
We implement enterprise-grade technical safeguards across our architecture:
- Strict Server-Side Only Data Access: Browser clients never query the database directly. All mutations and queries pass through strictly authenticated Next.js Server Components and Server Actions.
- Token Encryption: Sensitive integration tokens (e.g. GitHub/GitLab tokens) are encrypted using industry-standard AES-256 encryption.
- Row-Level Security & Tenant Isolation: Strict database isolation ensures users can only ever access their own projects, tickets, and billing records.
- Transport Security: All web traffic is encrypted in transit using TLS 1.3.
8. Data Retention Schedules & Erasure
- Active Account Data: Retained for the duration of your registration to provide continuous platform and ticket services.
- Development Credit & Ticket History: Retained for the 12-month validity period plus active project lifecycle for accounting transparency.
- Financial & Billing Records: Invoices, payment transaction IDs, and tax ledgers are retained for six (6) full financial years in compliance with UK HMRC statutory corporate tax requirements.
- Account Deletion: Upon account closure and verified written request, non-statutory personal data, repository access credentials, and profile records are permanently erased within 30 days.
9. Cookies, Tracking & Opt-In Consent Policy
We operate a privacy-first platform with zero advertising, third-party remarketing, or cross-site profiling beacons. The baseline cookies placed automatically on your device are strictly essential for authenticating your account session, maintaining CSRF protection, and facilitating secure Stripe checkout transactions.
Interactive customer support tools (such as our HubSpot chat widget) and related session attribution cookies are loaded exclusively after you provide explicit affirmative opt-in consent via our cookie consent banner.
For a complete technical breakdown and granular cookie inventory, please consult our dedicated Cookie Policy.
10. Your Statutory Data Subject Rights (UK GDPR)
Under Chapter III of the UK GDPR, you have the following rights regarding your personal data:
1. Right of Access (DSAR)
Request confirmation and a copy of the personal data we hold about you.
2. Right to Rectification
Request correction of inaccurate or incomplete personal records.
3. Right to Erasure ("Be Forgotten")
Request deletion of personal data when no longer necessary for legal/contractual duties.
4. Right to Restrict Processing
Request temporary restriction of processing during accuracy disputes.
5. Right to Data Portability
Receive your data in a structured, commonly used machine-readable format.
6. Right to Object
Object to processing based on legitimate interests at any time.
To exercise any of these statutory rights, please contact our data privacy team at support@mimesis-studios.com. We will acknowledge and respond to all verified requests within one (1) calendar month free of charge.
11. Right to Lodge a Complaint with the ICO
If you believe our processing of your personal data infringes UK data protection laws, you have the statutory right to lodge a complaint with the UK supervisory authority:
Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom
Helpline: 0303 123 1113 • Website: ico.org.uk
12. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect technological updates, operational adjustments, or evolving UK legal requirements. Clients and visitors are advised to check this page regularly for any updates.