Privacy Policy & Data Protection Notice
Last Updated: September 2026 • Mimesis Studios Ltd (Company No. 12768442, Registered in England & Wales) • 27 Old Gloucester St, Holborn, London WC1N 3AX
Data Protection Principles & Privacy Summary
At Mimesis Studios Ltd (Company No. 12768442), we respect your privacy and are committed to protecting your personal data in strict compliance with the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018 ("DPA 2018").
1. Data Controller & Contact Information
Mimesis Studios Ltd ("Mimesis Indie", "we", "us", or "our") is the Data Controller responsible for your personal data collected and processed through indie.mimesis-studios.com.
Data Controller: Mimesis Studios Ltd
Company Registration: Incorporated and registered in England & Wales under Company No. 12768442
Registered Address: 27 Old Gloucester St, Holborn, London WC1N 3AX, United Kingdom
Data Protection Inquiries: support@mimesis-studios.com
Supervisory Authority: Information Commissioner's Office (ICO), United Kingdom
2. Our Data Protection Principles
We adhere strictly to the core principles set out in Article 5 of the UK GDPR. Your personal data is:
- Processed lawfully, fairly, and in a transparent manner (Lawfulness, Fairness, Transparency).
- Collected solely for specified, explicit, and legitimate business purposes (Purpose Limitation).
- Adequate, relevant, and limited to what is necessary for our services (Data Minimisation).
- Accurate and kept up to date (Accuracy).
- Kept in a form permitting identification for no longer than necessary (Storage Limitation).
- Processed securely using appropriate technical and organisational safeguards (Integrity and Confidentiality).
3. Categories of Personal Data We Collect
We collect and process the following categories of personal data:
A. Identity & Account Data
First name, last name, email address, password hash, avatar/profile information, role, and OAuth provider IDs (e.g. GitHub/Google login).
B. Billing, Financial & Transaction Data
Stripe customer ID, Stripe subscription ID, payment intent IDs, invoice history, currency choice (GBP/USD), VAT/tax residency, and development credit ledger balances. (We do not store complete card numbers on our servers; card payments are processed securely via Stripe).
C. Project & Repository Access Data
Game project titles, game engine versions (e.g. Unity LTS), target platforms, git repository URLs, git personal access tokens / deployment keys, branch configurations, and webhook identifiers.
D. Ticket & Technical Communication Data
Feature requests, bug reports, reproduction steps, technical briefs, uploaded screenshots, crash logs, and client approval/rejection notes.
E. Call Bookings & Collaboration Data
Booking dates/times, meeting notes, project onboarding agendas, and Microsoft Teams meeting identifiers.
F. Technical Diagnostic Telemetry & Masked Session Replays
Crash stack traces, client-side runtime errors, browser/device environment, network latency, and privacy-masked diagnostic session replays for bug reproduction. (All text inputs, sensitive form fields, and media elements are strictly obscured and masked on the client before capture; replays are accessed strictly by engineering to diagnose platform crashes and broken interactions).
4. Lawful Bases & Processing Purposes (UK GDPR Article 6)
| Processing Purpose | Data Categories Used | Lawful Basis (UK GDPR) |
|---|---|---|
| Account creation, authentication & session management | Identity & Account Data | Contract Performance (Art 6(1)(b)) |
| Scoping, estimating, and performing game development tickets | Project Data, Ticket Data, Repo Credentials | Contract Performance (Art 6(1)(b)) |
| Subscription billing, credit top-ups & ledger calculations | Billing & Financial Data | Contract Performance (Art 6(1)(b)) |
| UK HMRC statutory accounting, VAT and corporate record-keeping | Invoices, Billing Data, Legal Entity Details | Legal Obligation (Art 6(1)(c)) |
| Infrastructure security, CSRF protection & abuse prevention | Account Metadata, Session Tokens | Legitimate Interests (Art 6(1)(f)) |
| Platform uptime, real-time error logging & crash diagnostics (Sentry) | Diagnostic Telemetry & Masked Session Replays | Legitimate Interests (Art 6(1)(f)) |
| Customer support live chat & inquiry management (HubSpot) | Contact Info, Chat History, Session Tokens | Explicit Opt-In Consent (Art 6(1)(a)) / Legitimate Interests (Art 6(1)(f)) |
| AI / LLM code scaffolding acceleration (if opted in) | Ticket Briefs, Code Snippets | Explicit Consent (Art 6(1)(a)) |
5. Third-Party Sub-Processors & Data Sharing
We do not sell, rent, or trade your personal data. We share data only with trusted enterprise service providers under strict Data Processing Agreements:
| Provider | Service Description | Data Protection Safeguard |
|---|---|---|
| Supabase Inc. | Managed cloud database, user authentication, and secure file storage | UK/EU Data Residency, SOC 2 Type II, ISO 27001 |
| Stripe Payments Europe / UK | Payment gateway, subscription recurring billing, and invoices | PCI-DSS Level 1 Service Provider |
| Functional Software, Inc. (Sentry) | Application performance monitoring, crash telemetry, and privacy-masked diagnostic session replays | EU Ingest Hosting (*.de.sentry.io), SOC 2 Type II, UK GDPR DPA & SCCs |
| Resend Inc. | Transactional email notifications and password reset delivery | UK GDPR DPA & Standard Contractual Clauses (SCCs) |
| Microsoft Teams / Graph | Client video meetings and team webhook task notifications | Enterprise GDPR compliant cloud infrastructure |
| Asana Inc. | Internal studio task management and sprint synchronization | SOC 2 Type II, Enterprise DPA |
| GitHub / GitLab | Git repository synchronization and pull request delivery | Encrypted token storage, restricted server gateways |
| HubSpot Ireland Ltd. | Customer support live chat widget and inbound enquiry management | UK GDPR DPA & EU Data Center Infrastructure |
| Plausible Insights OÜ | Privacy-preserving, cookie-free aggregate website analytics | EU-hosted infrastructure, fully GDPR/ePrivacy compliant without tracking cookies |
6. International Data Transfers & Global Personnel
While our primary database and core servers are situated in secure UK and EU data centres, Mimesis Studios Ltd collaborates with qualified international specialists, contractors, and global personnel outside the UK/EEA to deliver multidisciplinary game development services.
Whenever personal data, ticket briefs, or repository credentials are accessed by or transferred to personnel or service providers located outside the United Kingdom or European Economic Area (EEA), we ensure robust safeguards are implemented in strict accordance with Chapter V of the UK GDPR. These safeguards include:
- UK International Data Transfer Mechanisms: Utilizing the UK International Data Transfer Addendum to the European Commission's Standard Contractual Clauses (SCCs) or the UK International Data Transfer Agreement (IDTA).
- Strict Role-Based & Least-Privilege Access: Repository credentials, code branches, and ticket assets are provisioned on a strictly needed basis and isolated between clients.
- Binding Confidentiality & Security Obligations: All international specialists and contractors execute legally binding non-disclosure, IP assignment, and data protection agreements prior to undertaking any client work.
- Adequacy Decisions: Transferring data to jurisdictions recognized under UK adequacy regulations where applicable.
7. Technical & Organisational Security Safeguards
We implement robust industry-standard technical and organisational security measures to protect personal data:
- Secure Data Access Controls: All database queries and data mutations are strictly authenticated, authorized, and restricted through secured server-side controls with zero direct client access.
- Encryption at Rest & In Transit: Sensitive credentials, integration tokens, and all network transmissions are protected using strong, modern cryptographic standards and secure communication protocols.
- Strict Multi-Tenant Isolation: Robust logical isolation ensures accounts, projects, tickets, and financial data are strictly segmented and accessible only by verified authorized users.
- Role-Based Access & Least Privilege: Studio personnel and collaborators only access the specific information required to scope, execute, and verify contracted deliverables.
8. Data Retention Schedules & Erasure
- Active Account Data: Retained for the duration of your registration to provide continuous platform and ticket services.
- Development Credit & Ticket History: Retained for the 12-month validity period plus active project lifecycle for accounting transparency.
- Financial & Billing Records: Invoices, payment transaction IDs, and tax ledgers are retained for six (6) full financial years in compliance with UK HMRC statutory corporate tax requirements.
- Account Deletion: Upon account closure and verified written request, non-statutory personal data, repository access credentials, and profile records are permanently erased within 30 days.
9. Cookies, Tracking & Opt-In Consent Policy
We operate a privacy-first platform with zero advertising, third-party remarketing, or cross-site profiling beacons. The baseline cookies placed automatically on your device are strictly essential for authenticating your account session, maintaining CSRF protection, and facilitating secure Stripe checkout transactions.
Interactive customer support tools (such as our HubSpot chat widget) and related session attribution cookies are loaded exclusively after you provide explicit affirmative opt-in consent via our cookie consent banner.
For a complete technical breakdown and granular cookie inventory, please consult our dedicated Cookie Policy.
10. Your Statutory Data Subject Rights (UK GDPR)
Under Chapter III of the UK GDPR, you have the following rights regarding your personal data:
1. Right of Access (DSAR)
Request confirmation and a copy of the personal data we hold about you.
2. Right to Rectification
Request correction of inaccurate or incomplete personal records.
3. Right to Erasure ("Be Forgotten")
Request deletion of personal data when no longer necessary for legal/contractual duties.
4. Right to Restrict Processing
Request temporary restriction of processing during accuracy disputes.
5. Right to Data Portability
Receive your data in a structured, commonly used machine-readable format.
6. Right to Object
Object to processing based on legitimate interests at any time.
To exercise any of these statutory rights, please contact our data privacy team at support@mimesis-studios.com. We will acknowledge and respond to all verified requests within one (1) calendar month free of charge.
11. Right to Lodge a Complaint with the ICO
If you believe our processing of your personal data infringes UK data protection laws, you have the statutory right to lodge a complaint with the UK supervisory authority:
Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom
Helpline: 0303 123 1113 • Website: ico.org.uk
12. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect technological updates, operational adjustments, or evolving UK legal requirements. Clients and visitors are advised to check this page regularly for any updates.
