Back to Home

Privacy Policy & Data Protection Notice

Last Updated: September 2026 • Mimesis Studios Ltd (Company No. 12768442, Registered in England & Wales)

Data Protection Principles & Privacy Summary

At Mimesis Studios Ltd (Company No. 12768442), we respect your privacy and are committed to protecting your personal data in strict compliance with the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018 ("DPA 2018").

Strictly Essential DataWe only collect data necessary to deliver development and billing services.
Zero Ad TrackingNo marketing cookies, no tracking pixels, and no data sales to third parties.
Enterprise SecurityEncrypted tokens, server-side data isolation, and strict role-based access.

1. Data Controller & Contact Information

Mimesis Studios Ltd ("Mimesis Indie", "we", "us", or "our") is the Data Controller responsible for your personal data collected and processed through indie.mimesis-studios.com.

Data Controller: Mimesis Studios Ltd

Company Registration: Incorporated and registered in England & Wales under Company No. 12768442

Data Protection Inquiries: support@mimesis-studios.com

Supervisory Authority: Information Commissioner's Office (ICO), United Kingdom

2. Our Data Protection Principles

We adhere strictly to the core principles set out in Article 5 of the UK GDPR. Your personal data is:

  • Processed lawfully, fairly, and in a transparent manner (Lawfulness, Fairness, Transparency).
  • Collected solely for specified, explicit, and legitimate business purposes (Purpose Limitation).
  • Adequate, relevant, and limited to what is necessary for our services (Data Minimisation).
  • Accurate and kept up to date (Accuracy).
  • Kept in a form permitting identification for no longer than necessary (Storage Limitation).
  • Processed securely using appropriate technical and organisational safeguards (Integrity and Confidentiality).

3. Categories of Personal Data We Collect

We collect and process the following categories of personal data:

A. Identity & Account Data

First name, last name, email address, password hash, avatar/profile information, role, and OAuth provider IDs (e.g. GitHub/Google login).

B. Billing, Financial & Transaction Data

Stripe customer ID, Stripe subscription ID, payment intent IDs, invoice history, currency choice (GBP/USD), VAT/tax residency, and development credit ledger balances. (We do not store complete card numbers on our servers; card payments are processed securely via Stripe).

C. Project & Repository Access Data

Game project titles, game engine versions (e.g. Unity LTS), target platforms, git repository URLs, git personal access tokens / deployment keys, branch configurations, and webhook identifiers.

D. Ticket & Technical Communication Data

Feature requests, bug reports, reproduction steps, technical briefs, uploaded screenshots, crash logs, and client approval/rejection notes.

E. Call Bookings & Collaboration Data

Booking dates/times, meeting notes, project onboarding agendas, and Microsoft Teams meeting identifiers.

4. Lawful Bases & Processing Purposes (UK GDPR Article 6)

Processing PurposeData Categories UsedLawful Basis (UK GDPR)
Account creation, authentication & session managementIdentity & Account DataContract Performance (Art 6(1)(b))
Scoping, estimating, and performing game development ticketsProject Data, Ticket Data, Repo CredentialsContract Performance (Art 6(1)(b))
Subscription billing, credit top-ups & ledger calculationsBilling & Financial DataContract Performance (Art 6(1)(b))
UK HMRC statutory accounting, VAT and corporate record-keepingInvoices, Billing Data, Legal Entity DetailsLegal Obligation (Art 6(1)(c))
Infrastructure security, CSRF protection & abuse preventionAccount Metadata, Session TokensLegitimate Interests (Art 6(1)(f))
Customer support live chat & inquiry management (HubSpot)Contact Info, Chat History, Session TokensExplicit Opt-In Consent (Art 6(1)(a)) / Legitimate Interests (Art 6(1)(f))
AI / LLM code scaffolding acceleration (if opted in)Ticket Briefs, Code SnippetsExplicit Consent (Art 6(1)(a))

5. Third-Party Sub-Processors & Data Sharing

We do not sell, rent, or trade your personal data. We share data only with trusted enterprise service providers under strict Data Processing Agreements:

ProviderService DescriptionData Protection Safeguard
Supabase Inc.Managed PostgreSQL database, authentication, and file storageUK/EU Data Residency, SOC 2 Type II, ISO 27001
Stripe Payments Europe / UKPayment gateway, subscription recurring billing, and invoicesPCI-DSS Level 1 Service Provider
Resend Inc.Transactional email notifications and password reset deliveryUK GDPR DPA & Standard Contractual Clauses (SCCs)
Microsoft Teams / GraphClient video meetings and team webhook task notificationsEnterprise GDPR compliant cloud infrastructure
Asana Inc.Internal studio task management and sprint synchronizationSOC 2 Type II, Enterprise DPA
GitHub / GitLabGit repository synchronization and pull request deliveryEncrypted token storage, restricted server gateways
HubSpot Ireland Ltd.Customer support live chat widget and inbound enquiry managementUK GDPR DPA & EU Data Center Infrastructure
Plausible Insights OÜPrivacy-preserving, cookie-free aggregate website analyticsEU-hosted infrastructure, fully GDPR/ePrivacy compliant without tracking cookies

6. International Data Transfers

Whenever personal data is transferred outside the United Kingdom or European Economic Area (EEA), we ensure appropriate safeguards are implemented in accordance with Chapter V of the UK GDPR. This includes utilizing the UK International Data Transfer Addendum to the EU Standard Contractual Clauses (SCCs) and working with vendors covered by UK adequacy regulations.

7. Technical & Organisational Security Safeguards

We implement enterprise-grade technical safeguards across our architecture:

  • Strict Server-Side Only Data Access: Browser clients never query the database directly. All mutations and queries pass through strictly authenticated Next.js Server Components and Server Actions.
  • Token Encryption: Sensitive integration tokens (e.g. GitHub/GitLab tokens) are encrypted using industry-standard AES-256 encryption.
  • Row-Level Security & Tenant Isolation: Strict database isolation ensures users can only ever access their own projects, tickets, and billing records.
  • Transport Security: All web traffic is encrypted in transit using TLS 1.3.

8. Data Retention Schedules & Erasure

  • Active Account Data: Retained for the duration of your registration to provide continuous platform and ticket services.
  • Development Credit & Ticket History: Retained for the 12-month validity period plus active project lifecycle for accounting transparency.
  • Financial & Billing Records: Invoices, payment transaction IDs, and tax ledgers are retained for six (6) full financial years in compliance with UK HMRC statutory corporate tax requirements.
  • Account Deletion: Upon account closure and verified written request, non-statutory personal data, repository access credentials, and profile records are permanently erased within 30 days.

9. Cookies, Tracking & Opt-In Consent Policy

We operate a privacy-first platform with zero advertising, third-party remarketing, or cross-site profiling beacons. The baseline cookies placed automatically on your device are strictly essential for authenticating your account session, maintaining CSRF protection, and facilitating secure Stripe checkout transactions.

Interactive customer support tools (such as our HubSpot chat widget) and related session attribution cookies are loaded exclusively after you provide explicit affirmative opt-in consent via our cookie consent banner.

For a complete technical breakdown and granular cookie inventory, please consult our dedicated Cookie Policy.

10. Your Statutory Data Subject Rights (UK GDPR)

Under Chapter III of the UK GDPR, you have the following rights regarding your personal data:

1. Right of Access (DSAR)

Request confirmation and a copy of the personal data we hold about you.

2. Right to Rectification

Request correction of inaccurate or incomplete personal records.

3. Right to Erasure ("Be Forgotten")

Request deletion of personal data when no longer necessary for legal/contractual duties.

4. Right to Restrict Processing

Request temporary restriction of processing during accuracy disputes.

5. Right to Data Portability

Receive your data in a structured, commonly used machine-readable format.

6. Right to Object

Object to processing based on legitimate interests at any time.

To exercise any of these statutory rights, please contact our data privacy team at support@mimesis-studios.com. We will acknowledge and respond to all verified requests within one (1) calendar month free of charge.

11. Right to Lodge a Complaint with the ICO

If you believe our processing of your personal data infringes UK data protection laws, you have the statutory right to lodge a complaint with the UK supervisory authority:

Information Commissioner's Office (ICO)

Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom

Helpline: 0303 123 1113 • Website: ico.org.uk

12. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect technological updates, operational adjustments, or evolving UK legal requirements. Clients and visitors are advised to check this page regularly for any updates.