Legal
Your content is yours. Here's exactly what we do with it.
This policy explains what we collect, why, and the rights you have. Questions go to privacy@mindola.ai.
Mindola acts as data controller for customer information and as processor for visitor data. For inquiries, contact security@mindola.ai.
We comply with the GDPR, Dutch UAVG, EU AI Act (Article 50 transparency from 2 Aug 2026), the ePrivacy Directive, the Digital Services Act, the DSM Copyright Directive, the Consumer Rights Directive, and Dutch portrait-rights law.
A standalone consent page records a timestamped receipt and SHA-256 hash. A revoke button in your dashboard deletes the model from ElevenLabs within 24 hours. The original sample is deleted after training; only the model ID is retained.
A non-dismissable "AI version of [Owner]" badge appears in the chat header, an audio cue plays on voice calls, and a deepfake notice appears in the footer when a persona resembles a real person. The platform always discloses its AI nature.
The digital-consent age in the Netherlands is 16. Visitors under 16 are blocked, and we offer no parental-consent flows.
We keep a version-tracked list of subprocessors and give 30 days' advance notice of additions; customers may object on documented grounds.
| Vendor | Purpose | Region |
|---|---|---|
| Vercel Inc. | Application hosting + edge runtime | EU (Frankfurt, Paris) |
| Neon, Inc. | Managed Postgres + pgvector | EU (Frankfurt) |
| OpenAI, L.L.C. | LLM inference (no-training) | US (EU SCC) |
| Anthropic PBC | LLM inference (no-training) | US (EU SCC) |
| ElevenLabs, Inc. | Voice cloning + TTS | US/EU (SCC + UK IDTA) |
| Stripe, Inc. | Payments, billing, VAT | US/EU |
| Google Ireland Ltd. | Analytics 4 (consent-gated) | EU; US transfer under SCC |
| Sentry | Error monitoring | EU (Frankfurt) |
| Resend | Transactional email | EU + US (SCC) |
All model vendors have signed agreements excluding customer content from training.
We respond within 30 days (7-day internal target); submit via /contact or privacy@mindola.ai.
EU hosting (Vercel, Neon). Non-EEA transfers use Standard Contractual Clauses and the UK IDTA where applicable.
First-party (always set): session, CSRF token, theme preference, language preference (mindola_lang, up to 1 year), cookie choice (mindola_consent, up to 6 months), signed conversation cookie. No cross-site tracking.
Third-party (consent required): Google Analytics 4 (_ga, _ga_*, up to 2 years), loaded under Consent Mode v2 with analytics storage denied by default, IP anonymization enabled, and no pre-checked boxes.
Breaches are reported to the Dutch Autoriteit Persoonsgegevens within 72 hours (Art. 33); affected individuals are notified without undue delay if the risk is high (Art. 34).
Under DSA Art. 16, submit via /report or copyright@mindola.ai. We acknowledge within 24 hours and act within 5 business days.
Material updates bump the "last updated" date and email affected customers. Older versions are retained in git.
You can lodge a complaint with the Dutch Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl) or your local authority.
Cookies
We'd like to use Google Analytics to understand how the site is used. It sets cookies, so we only load it if you agree. Nothing is loaded if you decline. See our privacy policy.