Legal
Your content is yours. Here's exactly what we do with it.
This policy explains what we collect, why, and the rights you have. Questions go to privacy@mindola.ai.
Mindola acts as data controller for customer information and as processor for visitor data. For inquiries, contact security@mindola.ai.
We comply with the GDPR, Dutch UAVG, EU AI Act (Article 50 transparency from 2 Aug 2026), the ePrivacy Directive, the Digital Services Act, the DSM Copyright Directive, the Consumer Rights Directive, and Dutch portrait-rights law.
A standalone consent page records a timestamped receipt and SHA-256 hash. A revoke button in your dashboard deletes the model from ElevenLabs within 24 hours. The original sample is deleted after training; only the model ID is retained.
A non-dismissable "AI version of [Owner]" badge appears in the chat header, an audio cue plays on voice calls, and a deepfake notice appears in the footer when a persona resembles a real person. The platform always discloses its AI nature.
The digital-consent age in the Netherlands is 16. Visitors under 16 are blocked, and we offer no parental-consent flows.
We keep a version-tracked list of subprocessors and give 30 days' advance notice of additions; customers may object on documented grounds.
| Vendor | Purpose | Region |
|---|---|---|
| Vercel Inc. | Application hosting + edge runtime | EU (Frankfurt, Paris) |
| Neon, Inc. | Managed Postgres + pgvector | EU (Frankfurt) |
| OpenAI, L.L.C. | LLM inference (no-training) | US (EU SCC) |
| Anthropic PBC | LLM inference (no-training) | US (EU SCC) |
| ElevenLabs, Inc. | Voice cloning + TTS | US/EU (SCC + UK IDTA) |
| Stripe, Inc. | Payments, billing, VAT | US/EU |
| Google Ireland Ltd. | Analytics 4 (consent-gated) | EU; US transfer under SCC |
| Sentry | Error monitoring | EU (Frankfurt) |
| Resend | Transactional email | EU + US (SCC) |
All model vendors have signed agreements excluding customer content from training.
We respond within 30 days (7-day internal target); submit via /contact or privacy@mindola.ai.
EU hosting (Vercel, Neon). Non-EEA transfers use Standard Contractual Clauses and the UK IDTA where applicable.
First-party (always set): session, CSRF token, theme preference, signed conversation cookie. No cross-site tracking.
Third-party (consent required): Google Analytics 4 (_ga, _ga_*, up to 2 years), loaded under Consent Mode v2 with analytics storage denied by default, IP anonymization enabled, and no pre-checked boxes.
Breaches are reported to the Dutch Autoriteit Persoonsgegevens within 72 hours (Art. 33); affected individuals are notified without undue delay if the risk is high (Art. 34).
Under DSA Art. 16, submit via /report or copyright@mindola.ai. We acknowledge within 24 hours and act within 5 business days.
Material updates bump the "last updated" date and email affected customers. Older versions are retained in git.
You can lodge a complaint with the Dutch Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl) or your local authority.