Back to Home

Privacy Policy & Data Protection Notice

Last Updated: September 2026 • Mimesis Studios Ltd (Company No. 12768442, Registered in England & Wales) • 27 Old Gloucester St, Holborn, London WC1N 3AX

Data Protection Principles & Privacy Summary

At Mimesis Studios Ltd (Company No. 12768442), we respect your privacy and are committed to protecting your personal data in strict compliance with the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018 ("DPA 2018").

Strictly Essential DataWe only collect data necessary to deliver development and billing services.
Zero Ad TrackingNo marketing cookies, no tracking pixels, and no data sales to third parties.
Enterprise SecurityEncrypted tokens, server-side data isolation, and strict role-based access.

1. Data Controller & Contact Information

Mimesis Studios Ltd ("Mimesis Indie", "we", "us", or "our") is the Data Controller responsible for your personal data collected and processed through indie.mimesis-studios.com.

Data Controller: Mimesis Studios Ltd

Company Registration: Incorporated and registered in England & Wales under Company No. 12768442

Registered Address: 27 Old Gloucester St, Holborn, London WC1N 3AX, United Kingdom

Data Protection Inquiries: support@mimesis-studios.com

Supervisory Authority: Information Commissioner's Office (ICO), United Kingdom

2. Our Data Protection Principles

We adhere strictly to the core principles set out in Article 5 of the UK GDPR. Your personal data is:

  • Processed lawfully, fairly, and in a transparent manner (Lawfulness, Fairness, Transparency).
  • Collected solely for specified, explicit, and legitimate business purposes (Purpose Limitation).
  • Adequate, relevant, and limited to what is necessary for our services (Data Minimisation).
  • Accurate and kept up to date (Accuracy).
  • Kept in a form permitting identification for no longer than necessary (Storage Limitation).
  • Processed securely using appropriate technical and organisational safeguards (Integrity and Confidentiality).

3. Categories of Personal Data We Collect

We collect and process the following categories of personal data:

A. Identity & Account Data

First name, last name, email address, password hash, avatar/profile information, role, and OAuth provider IDs (e.g. GitHub/Google login).

B. Billing, Financial & Transaction Data

Stripe customer ID, Stripe subscription ID, payment intent IDs, invoice history, currency choice (GBP/USD), VAT/tax residency, and development credit ledger balances. (We do not store complete card numbers on our servers; card payments are processed securely via Stripe).

C. Project & Repository Access Data

Game project titles, game engine versions (e.g. Unity LTS), target platforms, git repository URLs, git personal access tokens / deployment keys, branch configurations, and webhook identifiers.

D. Ticket & Technical Communication Data

Feature requests, bug reports, reproduction steps, technical briefs, uploaded screenshots, crash logs, and client approval/rejection notes.

E. Call Bookings & Collaboration Data

Booking dates/times, meeting notes, project onboarding agendas, and Microsoft Teams meeting identifiers.

F. Technical Diagnostic Telemetry & Masked Session Replays

Crash stack traces, client-side runtime errors, browser/device environment, network latency, and privacy-masked diagnostic session replays for bug reproduction. (All text inputs, sensitive form fields, and media elements are strictly obscured and masked on the client before capture; replays are accessed strictly by engineering to diagnose platform crashes and broken interactions).

4. Lawful Bases & Processing Purposes (UK GDPR Article 6)

Processing PurposeData Categories UsedLawful Basis (UK GDPR)
Account creation, authentication & session managementIdentity & Account DataContract Performance (Art 6(1)(b))
Scoping, estimating, and performing game development ticketsProject Data, Ticket Data, Repo CredentialsContract Performance (Art 6(1)(b))
Subscription billing, credit top-ups & ledger calculationsBilling & Financial DataContract Performance (Art 6(1)(b))
UK HMRC statutory accounting, VAT and corporate record-keepingInvoices, Billing Data, Legal Entity DetailsLegal Obligation (Art 6(1)(c))
Infrastructure security, CSRF protection & abuse preventionAccount Metadata, Session TokensLegitimate Interests (Art 6(1)(f))
Platform uptime, real-time error logging & crash diagnostics (Sentry)Diagnostic Telemetry & Masked Session ReplaysLegitimate Interests (Art 6(1)(f))
Customer support live chat & inquiry management (HubSpot)Contact Info, Chat History, Session TokensExplicit Opt-In Consent (Art 6(1)(a)) / Legitimate Interests (Art 6(1)(f))
AI / LLM code scaffolding acceleration (if opted in)Ticket Briefs, Code SnippetsExplicit Consent (Art 6(1)(a))

5. Third-Party Sub-Processors & Data Sharing

We do not sell, rent, or trade your personal data. We share data only with trusted enterprise service providers under strict Data Processing Agreements:

ProviderService DescriptionData Protection Safeguard
Supabase Inc.Managed cloud database, user authentication, and secure file storageUK/EU Data Residency, SOC 2 Type II, ISO 27001
Stripe Payments Europe / UKPayment gateway, subscription recurring billing, and invoicesPCI-DSS Level 1 Service Provider
Functional Software, Inc. (Sentry)Application performance monitoring, crash telemetry, and privacy-masked diagnostic session replaysEU Ingest Hosting (*.de.sentry.io), SOC 2 Type II, UK GDPR DPA & SCCs
Resend Inc.Transactional email notifications and password reset deliveryUK GDPR DPA & Standard Contractual Clauses (SCCs)
Microsoft Teams / GraphClient video meetings and team webhook task notificationsEnterprise GDPR compliant cloud infrastructure
Asana Inc.Internal studio task management and sprint synchronizationSOC 2 Type II, Enterprise DPA
GitHub / GitLabGit repository synchronization and pull request deliveryEncrypted token storage, restricted server gateways
HubSpot Ireland Ltd.Customer support live chat widget and inbound enquiry managementUK GDPR DPA & EU Data Center Infrastructure
Plausible Insights OÜPrivacy-preserving, cookie-free aggregate website analyticsEU-hosted infrastructure, fully GDPR/ePrivacy compliant without tracking cookies

6. International Data Transfers & Global Personnel

While our primary database and core servers are situated in secure UK and EU data centres, Mimesis Studios Ltd collaborates with qualified international specialists, contractors, and global personnel outside the UK/EEA to deliver multidisciplinary game development services.

Whenever personal data, ticket briefs, or repository credentials are accessed by or transferred to personnel or service providers located outside the United Kingdom or European Economic Area (EEA), we ensure robust safeguards are implemented in strict accordance with Chapter V of the UK GDPR. These safeguards include:

  • UK International Data Transfer Mechanisms: Utilizing the UK International Data Transfer Addendum to the European Commission's Standard Contractual Clauses (SCCs) or the UK International Data Transfer Agreement (IDTA).
  • Strict Role-Based & Least-Privilege Access: Repository credentials, code branches, and ticket assets are provisioned on a strictly needed basis and isolated between clients.
  • Binding Confidentiality & Security Obligations: All international specialists and contractors execute legally binding non-disclosure, IP assignment, and data protection agreements prior to undertaking any client work.
  • Adequacy Decisions: Transferring data to jurisdictions recognized under UK adequacy regulations where applicable.

7. Technical & Organisational Security Safeguards

We implement robust industry-standard technical and organisational security measures to protect personal data:

  • Secure Data Access Controls: All database queries and data mutations are strictly authenticated, authorized, and restricted through secured server-side controls with zero direct client access.
  • Encryption at Rest & In Transit: Sensitive credentials, integration tokens, and all network transmissions are protected using strong, modern cryptographic standards and secure communication protocols.
  • Strict Multi-Tenant Isolation: Robust logical isolation ensures accounts, projects, tickets, and financial data are strictly segmented and accessible only by verified authorized users.
  • Role-Based Access & Least Privilege: Studio personnel and collaborators only access the specific information required to scope, execute, and verify contracted deliverables.

8. Data Retention Schedules & Erasure

  • Active Account Data: Retained for the duration of your registration to provide continuous platform and ticket services.
  • Development Credit & Ticket History: Retained for the 12-month validity period plus active project lifecycle for accounting transparency.
  • Financial & Billing Records: Invoices, payment transaction IDs, and tax ledgers are retained for six (6) full financial years in compliance with UK HMRC statutory corporate tax requirements.
  • Account Deletion: Upon account closure and verified written request, non-statutory personal data, repository access credentials, and profile records are permanently erased within 30 days.

9. Cookies, Tracking & Opt-In Consent Policy

We operate a privacy-first platform with zero advertising, third-party remarketing, or cross-site profiling beacons. The baseline cookies placed automatically on your device are strictly essential for authenticating your account session, maintaining CSRF protection, and facilitating secure Stripe checkout transactions.

Interactive customer support tools (such as our HubSpot chat widget) and related session attribution cookies are loaded exclusively after you provide explicit affirmative opt-in consent via our cookie consent banner.

For a complete technical breakdown and granular cookie inventory, please consult our dedicated Cookie Policy.

10. Your Statutory Data Subject Rights (UK GDPR)

Under Chapter III of the UK GDPR, you have the following rights regarding your personal data:

1. Right of Access (DSAR)

Request confirmation and a copy of the personal data we hold about you.

2. Right to Rectification

Request correction of inaccurate or incomplete personal records.

3. Right to Erasure ("Be Forgotten")

Request deletion of personal data when no longer necessary for legal/contractual duties.

4. Right to Restrict Processing

Request temporary restriction of processing during accuracy disputes.

5. Right to Data Portability

Receive your data in a structured, commonly used machine-readable format.

6. Right to Object

Object to processing based on legitimate interests at any time.

To exercise any of these statutory rights, please contact our data privacy team at support@mimesis-studios.com. We will acknowledge and respond to all verified requests within one (1) calendar month free of charge.

11. Right to Lodge a Complaint with the ICO

If you believe our processing of your personal data infringes UK data protection laws, you have the statutory right to lodge a complaint with the UK supervisory authority:

Information Commissioner's Office (ICO)

Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom

Helpline: 0303 123 1113 • Website: ico.org.uk

12. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect technological updates, operational adjustments, or evolving UK legal requirements. Clients and visitors are advised to check this page regularly for any updates.