This policy explains what personal information Mirimera collects through this website, why we collect it, who we share it with, and the control you have over it.
Mirimera is a software development company headquartered in Bangkok, Thailand, with delivery teams in Singapore, Ukraine, and the United States. For personal information collected through this website, Mirimera is the data controller.
You can reach us about anything in this policy at [email protected], or by writing to Mirimera HQ, Bangkok, Thailand 10500.
This policy covers mirimera.com and the forms on it. It does not cover personal data we process on behalf of a client as part of a development engagement. In those cases the client is the data controller and we act as their processor under the signed agreement between us. See client project data below.
We only collect what you type into a form. There are two on this site.
If you email us directly, we hold whatever you choose to put in that email. Please do not send us confidential material before we have a non-disclosure agreement in place.
Like any website, ours is served by infrastructure that records standard technical information in server logs: your IP address, the pages requested, the time of the request, your browser and operating system, and the referring page. We use these logs to keep the site running and to investigate errors and abuse.
We do not run analytics on this site. There is no Google Analytics, no advertising pixel, no session-recording tool, and no behavioural profiling of any kind.
We store one item locally on your device: your light or dark theme preference. It stays in your browser, is never transmitted to us, and is described in full in our Cookie Policy.
We do not sell personal information, we do not share it with advertisers, and we do not use it to build profiles or to make automated decisions about you.
We share personal information only with service providers who help us operate, and only to the extent they need it:
We may also disclose information where we are legally required to, or where it is necessary to establish, exercise, or defend a legal claim.
Separately, some images on this site are served from third-party hosts, which means those hosts receive a standard web request from your browser, including your IP address, when a page loads. They set no cookies for us and receive nothing beyond that request.
We operate from Thailand, Singapore, Ukraine, and the United States, and our service providers may process data in other countries. Where personal information covered by the GDPR leaves the European Economic Area, we rely on appropriate safeguards such as the European Commission's standard contractual clauses. Where it is covered by Thailand's Personal Data Protection Act, we transfer it only in line with the conditions that Act allows.
All traffic to this site is encrypted in transit over HTTPS. Access to systems holding personal information is limited to the people who need it, protected by multi-factor authentication, and reviewed periodically. Our wider engineering practices are described on our Security page.
No system is perfectly secure. If a breach affects your personal information and creates a risk to you, we will notify you and the relevant supervisory authority within the timeframes the law requires.
Depending on where you live, you have some or all of the following rights over your personal information:
To exercise any of these, email [email protected]. We will respond within 30 days. We may ask you to confirm your identity first, and we never charge for a reasonable request.
When we build software for a client, we often work inside their systems and handle data belonging to their users. In that relationship the client decides what is collected and why, and we act strictly on their documented instructions as a processor. Those obligations live in the signed agreement between us, not in this policy, and we will enter into a data processing agreement on request.
If you use a product we built for someone else and want to exercise a right over your data, please contact that company. They are the controller, and we will support them in responding to you.
This site is aimed at businesses and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, email us and we will delete it.
We update this policy when our practices change or the law requires it. If a change is significant, we will say so rather than quietly amending the text.
Questions, requests, and complaints about this policy all go to [email protected]. You can also use the form on our contact page.