Effective date: June 10, 2026 · Version 1.1 · Updated: June 2026
MirrorMire (“we”, “us”, “our”) is committed to protecting the privacy of individuals who use our website, platform, and services. This Privacy Policy explains what data we collect, why we collect it, how we use and protect it, and the rights available to you.
This version adds four sections reflecting MirrorMire’s integration landscape:
All other sections are unchanged from v1.0.
MirrorMire operates the AMaze™ AI-native proactive cyber resilience platform. Our registered trading name is MirrorMire; our platform is accessible at mirrormire.ai.
| Product | AMaze™ AI-native proactive cyber resilience platform |
| Website | mirrormire.ai |
| Contact email | privacy@mirrormire.ai |
| DPO contact | dpo@mirrormire.ai |
| Governing law | GDPR (EU/UK) | PDPB (India) | Applicable local law |
This policy applies to:
This policy does not apply to data that our customers process within their own deployments of the AMaze™ platform. Customers are the Data Controllers for that data; MirrorMire acts as Data Processor under a separate Data Processing Agreement (DPA).
New in v1.1 (June 2026)
AMaze™ offers optional connectors to third-party services — including threat enrichment services (e.g. AbuseIPDB, IPQualityScore, VirusTotal), SIEM and SOAR platforms (e.g. Splunk, Microsoft Sentinel, IBM QRadar), notification services (e.g. SendGrid, Slack, Microsoft Teams, PagerDuty), and AI / Large Language Model providers (e.g. OpenAI, Anthropic, Azure OpenAI, Google Vertex AI). Where customers activate these integrations using their own accounts and API keys, MirrorMire acts as a conduit only and does not hold or manage the customer’s credentials or accounts with those third parties. The customer is the Data Controller for any personal data that flows to those third-party services and is responsible for their own contractual and data protection obligations with those providers, including executing any required Data Processing Agreement with the provider. A full list of available integrations and the respective responsibilities is set out in the MirrorMire Integration Catalogue, available on request from privacy@mirrormire.ai.
When you visit mirrormire.ai we collect:
Legal basis: Legitimate interests (analytics, security) and consent (non-essential cookies).
When you contact us, request a demo, or sign up for a trial we collect:
Legal basis: Legitimate interests (responding to enquiries, progressing sales relationships); contract (where a trial agreement is in place).
When authorised users access the AMaze™ platform we collect:
Legal basis: Contract (performance of the subscription agreement); legal obligation (security audit logging).
The AMaze™ platform generates anonymised telemetry (feature usage counts, error rates, latency metrics) to support reliability and product improvement. This telemetry does not include personal data from customer networks and cannot be linked to individual users.
Legal basis: Legitimate interests (product reliability and improvement).
New in v1.1 (June 2026)
Where customers activate the LLM AI Agent integration, AMaze™ constructs and submits prompts to the customer’s chosen LLM provider API. The platform logs the prompt context submitted (including the categories of data included in the prompt, such as attacker IP indicators and attack technique classifications) to the platform audit log store (D2). This log is used solely for security auditing, incident response, and data protection compliance. Prompt logs are retained for 90 days. Personal data of the customer’s end users is never included in prompts by design. The customer’s chosen LLM provider processes prompt data under the customer’s own account and API key; customers are responsible for their LLM provider’s data handling settings.
Legal basis: Legitimate interests (security auditing and compliance). For full details see the MirrorMire LLM Data Handling Policy, available on request from privacy@mirrormire.ai.
MirrorMire does not collect special category data (health, biometric, racial or ethnic origin, political opinion, or similar). We do not collect payment card data — payments are processed by a PCI-DSS-certified third-party processor. We do not knowingly collect data from individuals under the age of 18.
Our website uses the following categories of cookies:
| Category | Purpose | Examples | Consent required? |
|---|---|---|---|
| Strictly necessary | Session management, security, load balancing | Session ID, CSRF token | No |
| Analytics | Aggregate traffic and behaviour analysis | Microsoft Clarity, Google Analytics | Yes |
| Preferences | Storing your cookie consent choice | consent_v1 | No |
You may withdraw consent for analytics cookies at any time via the cookie banner or by emailing privacy@mirrormire.ai. Withdrawing consent does not affect processing carried out before withdrawal.
We use the data described in Section 3 for the following purposes:
We do not sell personal data. We do not share personal data with advertising networks or data brokers. We share data only in the following circumstances:
New in v1.1 (June 2026)
This section has been rewritten to clearly distinguish between MirrorMire’s own sub-processors and customer-configured third-party integrations.
We engage trusted sub-processors to help deliver our services. These are services MirrorMire itself contracts with and uses to operate the AMaze™ platform — including cloud infrastructure providers, identity providers (Azure AD / Entra ID), collaboration tools (Microsoft 365 and OneDrive), source control (GitHub), issue tracking (Jira), and email delivery services. MirrorMire holds Data Processing Agreements with all of these providers. All sub-processors are bound by data processing agreements and are assessed for security compliance before engagement. A current list of sub-processors is available on request from privacy@mirrormire.ai.
Customer-configured third-party integrations — such as threat enrichment services (AbuseIPDB, IPQualityScore, VirusTotal), SIEM/SOAR platforms (Splunk, Microsoft Sentinel), notification services (SendGrid, Slack, Teams, PagerDuty), and AI/LLM providers (OpenAI, Anthropic, Azure OpenAI, Google Vertex AI) — are not MirrorMire sub-processors. Customers engage those services directly under their own contractual arrangements. MirrorMire provides the integration connector only and does not hold, manage, or have access to the customer’s credentials or accounts with those services.
We may share data with our lawyers, auditors, and insurers where necessary and under obligations of confidentiality.
We may disclose data where required by law, court order, or regulatory authority, or where necessary to protect our legal rights or the safety of others.
In the event of a merger, acquisition, or sale of assets, personal data may be transferred to the successor entity. We will notify affected individuals in advance where required by law.
MirrorMire operates primarily from the USA and India and serves customers globally. Where personal data is transferred outside the European Economic Area (EEA) or United Kingdom, we ensure an adequate level of protection is in place through one or more of the following mechanisms:
Customers may request a copy of applicable transfer mechanisms by contacting dpo@mirrormire.ai.
New in v1.1 (June 2026)
Where customers activate the LLM AI Agent feature and their chosen LLM provider processes data outside the EEA or UK, any cross-border transfer of data (including attacker IP addresses and other indicators that may constitute personal data under applicable law) is the customer’s responsibility to manage under applicable data protection law. MirrorMire’s Data Processing Agreement (DPA) covers transfers of personal data between MirrorMire and the customer only. Customers must ensure their chosen LLM provider’s DPA covers the relevant data categories and that an appropriate transfer mechanism (adequacy decision, SCCs, or other approved mechanism) is in place between the customer and their LLM provider. MirrorMire provides guidance on this in the LLM Data Handling Policy, available on request from dpo@mirrormire.ai. Azure OpenAI Service is available as a recommended option for customers who require data to remain within a specific geographic region.
We retain personal data only for as long as necessary for the purpose for which it was collected, or as required by law. Our standard retention periods are:
| Data category | Retention period |
|---|---|
| Website visitor logs | 13 months from collection, then aggregated/deleted |
| Prospect and enquiry data | 3 years from last contact, or until opt-out |
| Platform account data | Duration of subscription + 90 days post-termination |
| Platform audit logs | 12 months (configurable by customer up to 7 years) |
| AI Agent prompt logs | 90 days |
| Platform telemetry | 12 months, anonymised thereafter |
| Support case data | 30 days post-case closure |
| Legal / regulatory records | As required by applicable law (typically 6–7 years) |
Upon expiry of the applicable retention period, data is securely deleted or irreversibly anonymised.
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, or destruction. These include:
No system is completely secure. In the event of a personal data breach that is likely to result in high risk to individuals, we will notify affected individuals and relevant supervisory authorities in accordance with applicable law.
Depending on your jurisdiction, you may have the following rights in relation to your personal data:
| Right | What it means |
|---|---|
| Access | Request a copy of the personal data we hold about you. |
| Rectification | Ask us to correct inaccurate or incomplete data. |
| Erasure | Request deletion of your data where there is no overriding legal basis to retain it. |
| Restriction | Ask us to pause processing while a dispute is resolved. |
| Portability | Receive your data in a structured, machine-readable format (where processing is based on consent or contract). |
| Objection | Object to processing based on legitimate interests, including for direct marketing. |
| Withdraw consent | Where processing is based on consent, withdraw it at any time without affecting prior processing. |
| Lodge a complaint | Complain to your local supervisory authority (e.g. the ICO in the UK, or your national DPA in the EU). |
To exercise any of these rights, email privacy@mirrormire.ai with the subject line “Privacy Rights Request”. We will respond within 30 days (or the timeframe required by applicable law). We may ask you to verify your identity before fulfilling a request.
Our platform and services are intended for business use only and are not directed at individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected such data, please contact privacy@mirrormire.ai and we will promptly delete it.
Our website may contain links to third-party websites, documentation, or resources. We are not responsible for the privacy practices of those third parties and encourage you to review their privacy policies before sharing any personal data with them.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will:
Your continued use of our services after the effective date constitutes acceptance of the updated policy. If you do not agree with any changes, you may close your account or stop using our services.
If you have any questions, concerns, or requests relating to this Privacy Policy or our data processing practices, please contact us:
| General privacy enquiries | privacy@mirrormire.ai |
| Data Protection Officer | dpo@mirrormire.ai |
| Postal address | MirrorMire, 262 Chapman Rd, Ste 240, Newark, DE 19702 |
| Website | mirrormire.ai/privacy |
| Integration Catalogue | On request — privacy@mirrormire.ai |
| LLM Data Handling Policy | On request — privacy@mirrormire.ai |
| Sub-processor list | On request — privacy@mirrormire.ai |
We aim to acknowledge all enquiries within 5 business days and resolve them within 30 days. For complex requests or complaints, we will keep you informed of progress.
MirrorMire · Privacy Policy · Version 1.1 · Effective June 10, 2026 · Updated June 2026