Mia Labs, Inc. Privacy Policy
Last Updated - December 20, 2023
Introduction
Mia Labs, Inc. (“Mia Labs” or “we” or “us”) has created this Privacy Policy in order to disclose its collection, use and disclosure of personal information and other data about you by Mia Labs, its employees, affiliates, and successors and assigns, in connection with its website, applications, software, services, mobile apps, social networking sites, and other Mia Labs properties or technology displaying or referencing this Privacy Policy (collectively, the “Sites”). Any questions regarding this policy should be directed by email to privacy@mia.inc. You may also contact Mia Labs at 450 Century Pkwy, Ste 250, Allen, Texas 75013.
When you visit a Site, we may automatically collect certain information, including information about your device such as your web browser, IP address, time zone, and other information on your device in connection with our site. Additionally, we collect information as you browse the website, including the web pages you view, the referral source (such as the page, website or search terms that brought you to the site), and other information about your interactions with our Sites. Such information may or may not be considered personal information.
We may obtain information about you from other sources, including, but not limited to, our affiliates, organizations with a relationship with Mia Labs (such as customers, prospects, vendors, and suppliers), social media sites, organizations providing marketing contacts, publicly available databases, and through other third-party services and organizations to supplement information provided by you.
Mia Labs does not require you to include sensitive information (e.g., racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union memberships, genetic data, biometric data, data concerning health or data concerning sexual orientation). In the event that you provide such sensitive information without an express agreement authorizing it, you acknowledge that you have provided Mia Labs explicit consent concerning the collection, use and disclosure of such information in accordance with this Privacy Policy or as otherwise described to you at the time of collection. If the jurisdiction where you reside requires affirmative, separate, opt-in consent, this paragraph does not apply to you and you are required to provide consent at or before the time of collection, or if not, do not provide the sensitive information to Mia Labs.
Lawful Basis for Processing
Certain jurisdictions require a lawful basis for processing of personal data, and we will only collect and process your personal data there where we have lawful basis. Our lawful basis include consent (where you have given it), where processing is necessary for the performance of a contract with you, and for the purposes of our legitimate interests or the legitimate interests of our third parties, provided that such interest does not outweigh your rights and freedoms. Examples of legitimate interest include but are not limited to: (i) complying with applicable law, (ii) protecting against security or other threats, (iii) administration of our business interests, including improvements and enhancements of our business, and (iv) customer relationship issues.
Sale of Personal Information
Mia Labs does not sell personal information to third parties for valuable consideration, as “sell” is defined under applicable US privacy laws.
Whenever applicable, Mia Labs identifies the purposes for which the information is being collected before or at the time of collection. The collection of your personal information will be limited to that which is needed for the purposes identified by Mia Labs. Unless you consent, or we are required or permitted by law, we will only use the personal information for the purposes for which it was collected or another purposed described to you at that time. If Mia Labs will be processing your personal information for another purpose later on, our Mia Labs will seek your further legal permission or consent; except where the other purpose is compatible with the original purpose.
We will only retain your personal information for as long as reasonably necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your personal information for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.
To determine the appropriate retention period for personal information, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure of your personal data, the purposes for which we process your personal information and whether we can achieve those purposes through other means, and the applicable legal, regulatory and tax, accounting or other requirements.
In some circumstances you can ask us to delete your personal information (see Your Privacy Rights below).
In some circumstances we will anonymise your personal data (so that it can no longer be associated with you) for research, statistical or other permitted purposes, in which case we may use this information indefinitely without further notice to you.
Your Privacy Rights
Depending on where you reside, you may have the right to exercise additional rights available to you under applicable laws and receive additional disclosures, including:
In certain states in the United States:
• Access. You may have the right to access your personal data or the categories of personal data that our Company processes.
• Correct/Update. You may have the right to correct and/or update your personal data.
• Erasure. You may have a broader right to erasure of personal data that we hold about you. For example, if it is no longer necessary in relation to the purposes for which it was originally collected. Please note, however, that we may need to retain certain information for record keeping purposes, to complete transactions or to comply with our legal obligations, among other things.
• Data portability. In certain circumstances, you may have the right to be provided with your personal data in a structured, machine readable and commonly used format and to request that we transfer the personal data to another data controller without hindrance.
• Confirm processing. You may have the right to confirm our processing of your personal data.
• Transparency. You may have the right to request additional information not contained in this Privacy Policy. Note: if your US state requires specific privacy disclosures, please see our disclosures above concerning our collection, use and disclosure of personal information as well as the information contained in the California privacy rights section below.
• Sale of Personal Data. You may have the right to opt out of the sale of personal data.
• Cross-contextual behavioral advertising. You may have the right to opt out of the “sharing” of personal data in connection with cross-contextual behavioral advertising.
• Restrict processing. You may have the right to request that we restrict processing of your personal data in certain circumstances. For example, where you believe that the personal data we hold about you is inaccurate or unlawfully held. You may also be able to opt-out of targeted advertising, processing of sensitive data, and profiling in furtherance of decisions that produce legal or similarly significant effects as required by an applicable law.
• Accessibility: You may have the right to additional assistance with your privacy rights. If you are unable to reasonably access this Privacy Policy due to a disability, please contact us via the contact information below so that we may determine how to provide you with alternate notice.
If you would like to exercise any of the above rights, please contact us by email (see our contact details in the “Contacts” Section below). We will consider your request in accordance with applicable laws. To protect your privacy and security, we may take steps to verify your identity before complying with the request.
Mia Labs will not discriminate against a data subject for exercising any of its data protection rights.
For reconsideration of our response to your request under any applicable law that provides for an appeal, please request an appeal within the time frame for the appeal notice set forth in the applicable law (or in the event no time frame is provided, then fifteen days) by utilizing the contact information published below.
If you need further assistance regarding your rights, please contact us using the contact information provided below and we will consider your request in accordance with applicable law. There may be exceptions to the foregoing rights and some or all of the above rights may not apply to you. Where a privacy law permits an organization to continue to maintain and/or use personal information for a particular purpose, despite receiving your request, we reserve the right to utilize your personal information for such purpose. In some cases, our ability to uphold these rights for you may depend upon our obligations to process personal data for security, safety, fraud prevention reasons, compliance with regulatory or legal requirements, or because processing is necessary to deliver the services you have requested. Where this is the case, we will inform you of specific details in response to your request.
How We Store and Process Your Information
The information collected by Mia Labs may be processed and/or stored in the United States, European Union Member Nations, Canada, or any other country in which Mia Labs or its affiliates or service providers maintain operations. Mia Labs may transfer information that we collect, including personal information, to affiliated entities, or to other third parties across borders and from your country or jurisdiction of domicile to other countries or jurisdictions. If you are located in the European Union or other regions with laws restricting transferring of data, please note that we will comply with laws applicable to us.
Mia Labs may act as a Processor or Subprocessor, and not a Controller, with respect to personal information collected on behalf of customers. If we are a Processor or Subprocessor with respect to your data, the processing of your data will be set by the Controller and there may be additional or different terms with respect to your data. If you are a customer who uses our services and you collect personal information on citizens within the European Economic Area or United Kingdom, we ask that you contact privacy@mia.inc to request a Data Processing Addendum (“DPA”).
International Transfer of your Personal Information to the United States
Below is a list of categories of personal data (from the California Consumer Privacy Act) we have collected and disclosed about consumers for a business purpose in the past 12 months:
• Category A: Identifiers;
• Category B: Personal Data categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e));
• Category C: Protected classification characteristics under California or federal law;
• Category D: Commercial information;
• Category F: Internet or other electronic network activity;Category I: Professional or employment-related information;
• Category K: Inferences drawn from other Personal Data to create a profile about a consumer.
The above list does not include information about personal information collected and disclosed while operating as a service provider to our customers.
Personal information may be used and disclosed for business purposes such as ensuring the security of the Sites, performing services on our behalf, short-term transient use, providing advertising and marketing services, technological research and development, and other business purposes.
Service providers and other categories of third parties that may receive personal information under a business purpose include advertising networks, affiliates, data analytics providers, email providers, government entities, internet and other technology service providers, lenders or other financing, payment processors, and social networks.
If the California Consumer Privacy Act, as amended (“CCPA”) applies to your personal information, please also see the section titled “Your Privacy Rights” above.
Amendments
Mia Labs may amend this policy at any time. If Mia Labs is going to use personal information collected in a manner materially different from that stated at the time of collection, Mia Labs will notify users via email and/or by posting a notice on the Mia Labs site for thirty (30) days prior to such use. This Privacy Policy may not be otherwise amended except in a writing that specifically refers to this Privacy Policy and is physically signed by both parties.