Privacy Policy
Last updated: 24 June 2026
1. Introduction
MindX Digital Softwares Inc. ("MindX AI," "we," "our," or "us") values and respects your privacy. This Privacy Policy describes how we collect, use, share, and safeguard your personal data when you use our websites, applications, integrations, products and services (collectively, the "Services").
We comply with applicable privacy laws, including:
- General Data Protection Regulation (EU) 2016/679 (GDPR)
- UK GDPR & Data Protection Act 2018
- California Consumer Privacy Act (CCPA) as amended by CPRA
- Brazilian General Data Protection Law (LGPD)
- Canadian Personal Information Protection and Electronic Documents Act (PIPEDA)
- Australian Privacy Act 1988
- Other global privacy regulations where we operate
By using our Services, you agree to the practices described in this Policy.
Two categories of data — and our different roles
This Policy covers two distinct types of data, and MindX AI's responsibilities differ for each:
- Website & Account Data – information about visitors to our websites and about the merchants and businesses that hold a MindX AI account. For this data MindX AI acts as a data controller, as described in Sections 3–7.
- End‑Customer Conversation Data – the messages, and related data, of shoppers and end‑users who interact with an AI chatbot that one of our customers has deployed on their own store or channels. For this data, our customer (the merchant) is the data controller and MindX AI acts solely as a data processor, processing it only on the merchant's documented instructions in order to provide the Services.
Where this Policy describes advertising, marketing, analytics or profiling, those activities relate to Website & Account Data only. We do not use End‑Customer Conversation Data for advertising, and we do not use it to train AI models that serve other customers. The safeguards that apply to End‑Customer Conversation Data are set out in Section 21.
2. Data Privacy Framework (DPF) Compliance
MindX Digital Softwares Inc. complies with the EU‑U.S. Data Privacy Framework (EU‑U.S. DPF), the UK Extension to the EU‑U.S. DPF, and the Swiss‑U.S. Data Privacy Framework (Swiss‑U.S. DPF) as set forth by the U.S. Department of Commerce. MindX Digital Softwares Inc. has certified to the U.S. Department of Commerce that it adheres to the EU‑U.S. DPF Principles with regard to the processing of personal data received from the European Union and the United Kingdom in reliance on the EU‑U.S. DPF and the UK Extension to the EU‑U.S. DPF. MindX Digital Softwares Inc. has certified to the U.S. Department of Commerce that it adheres to the Swiss‑U.S. DPF Principles with regard to the processing of personal data received from Switzerland in reliance on the Swiss‑U.S. DPF. If there is any conflict between the terms in this privacy policy and the EU‑U.S. DPF Principles and/or the Swiss‑U.S. DPF Principles, the Principles shall govern.
To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www.dataprivacyframework.gov/.
3. Information We Collect
Information you provide
- Name, surname, job title and company information
- Email address, phone number and contact preferences
- Billing and payment details (processed by trusted third‑party providers)
- Store addresses and e‑commerce platform data (Shopify, WooCommerce, Magento, etc.)
Information collected automatically
- Log data (IP address, browser, operating system, device identifiers)
- Usage data (clickstream, time spent, pages viewed, referral links)
- Chat transcripts and interaction data. Where these are generated by shoppers interacting with a customer's chatbot, they are End‑Customer Conversation Data that we process as a processor on the customer's behalf (see Sections 1 and 21).
- Approximate geolocation (derived from IP address)
- Advertising identifiers (cookies, pixels, UTM parameters)
Information from third parties
- E‑commerce platforms connected to your account
- Marketing platforms (Google, Meta, LinkedIn, TikTok, etc.)
- Analytics and CRM providers
- Partners and resellers
4. How We Use Your Information
We use data for the following purposes under lawful bases of contract performance, legitimate interest, consent and legal obligation:
- Service provision – to deliver, operate and maintain our Services.
- Account management – to onboard customers, verify identity and provide customer support.
- Service improvement – to analyze interactions and improve the quality, safety and performance of the Services. Each customer's chatbot answers only from that customer's own configured knowledge base and data, which is logically isolated per account; one customer's data is never exposed in another customer's conversations. We do not use End‑Customer Conversation Data to train shared or foundation AI models.
- Analytics and insights – to understand usage patterns, trends and performance.
- Advertising and marketing – to deliver personalized content, email campaigns, retargeting and measure ad effectiveness. These activities use Website & Account Data only and never End‑Customer Conversation Data.
- Compliance and security – to detect fraud, enforce Terms of Service and comply with legal obligations.
- Research and development – to develop new features and enhance user experience.
5. Cookies and Tracking
We use cookies, pixels, tags and similar technologies for:
- Conversion tracking and campaign optimization
- Website performance and session management
- Analytics (Google Analytics, Mixpanel, Amplitude)
- Advertising and retargeting (Google Ads, Meta Pixel, LinkedIn Ads, TikTok Ads)
You can manage cookie settings via your browser or through our Cookie Preferences Tool. For EU/UK users, no non‑essential cookies are deployed without consent.
6. Sharing of Information and Onward Transfer Liability
We do not sell personal data. We share limited data with trusted providers, including:
- Cloud infrastructure: Amazon Web Services (AWS), Google Cloud
- Analytics: Google Analytics, Mixpanel, Amplitude
- Advertising: Meta, Google Ads, LinkedIn, TikTok
- CRM/Marketing: HubSpot, Intercom, Customer.io
- Automation: Zapier, Segment
- Payments: Stripe, PayPal and other processors
- Compliance & Security: Anti‑fraud and security monitoring tools
Each third‑party provider is bound by confidentiality and data processing agreements. When transferring personal data to a third party acting as our agent, MindX Digital Softwares Inc. remains responsible under the DPF Principles if that agent processes such personal data in a manner inconsistent with the Principles, unless we prove that we are not responsible for the event giving rise to the damage.
End‑Customer Conversation Data is treated differently. The advertising, analytics and marketing partners listed above receive Website & Account Data only. We do not share End‑Customer Conversation Data with advertising networks, ad exchanges or data brokers, and we do not use it for cross‑site retargeting or to build advertising profiles. End‑Customer Conversation Data is shared only with the limited infrastructure and AI sub‑processors strictly necessary to deliver the chatbot, each engaged under a data processing agreement and permitted to process the data solely on documented instructions. A current list of sub‑processors is available on request.
7. International Data Transfers
As a U.S.-based company, data may be transferred internationally.
- For EU/EEA/UK customers, transfers are based on Standard Contractual Clauses (SCCs) and UK Addendum where applicable.
- For Swiss customers, transfers follow the Swiss Federal Act on Data Protection (FADP).
- For other jurisdictions, we apply equivalent safeguards.
8. Data Retention
We keep data only as long as necessary for the purposes outlined in this Policy:
- Account and billing data: retained for 7 years (legal obligation).
- Chat logs and End‑Customer Conversation Data: retained for the period configured by the relevant customer (controller) and anonymized or deleted thereafter, unless longer retention is required for security, legal or operational needs. Deletion requests for this data are handled as described in Section 21.
- Marketing data: retained until you opt out or withdraw consent.
9. Data Security
We implement industry‑leading security measures:
- Encryption (in transit and at rest)
- Role‑based access control
- Multi‑factor authentication for internal systems
- Regular audits, monitoring and penetration testing
While no system is 100% secure, we continuously improve safeguards.
10. Your Privacy Rights and Choices
Depending on your jurisdiction, you may have the following rights:
- Right of access – to obtain a copy of your personal data and information about how we process it.
- Right to correction or deletion – to have inaccurate information corrected or deleted when permitted by law.
- Right to restriction – to limit processing under certain circumstances.
- Right to portability – to request a copy of your personal data in a structured, machine‑readable format.
- Right to object or withdraw consent – to object to processing based on legitimate interests or withdraw consent at any time where consent is the legal basis.
Rights under the Data Privacy Framework
- Individuals have the right to access their personal data and to correct, amend or delete information where it is inaccurate or processed in violation of the DPF Principles.
- Individuals also have the right to opt out of the disclosure of their personal data to third parties, or the use of their data for purposes materially different from those for which it was originally collected or subsequently authorized.
To exercise any of these rights, please contact us at support@themindx.ai.
11. Complaints and Inquiries
In compliance with the EU‑U.S. DPF, the UK Extension to the EU‑U.S. DPF and the Swiss‑U.S. DPF, MindX Digital Softwares Inc. commits to resolve DPF Principles‑related complaints about our collection and use of your personal information. EU, UK and Swiss individuals with inquiries or complaints should first contact us at:
Email: support@themindx.ai
12. Independent Recourse Mechanism
In compliance with the EU‑U.S. DPF, the UK Extension to the EU‑U.S. DPF and the Swiss‑U.S. DPF, MindX Digital Softwares Inc. commits to cooperate and comply with the advice of the EU data protection authorities (DPAs), the UK Information Commissioner's Office (ICO) and the Swiss Federal Data Protection and Information Commissioner (FDPIC) with regard to unresolved complaints concerning our handling of personal data received in reliance on the DPF. This recourse is provided free of charge to the individual.
13. Investigatory and Enforcement Powers
MindX Digital Softwares Inc. is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission (FTC).
14. Binding Arbitration
Under certain conditions, and after exhausting other available remedies, individuals may invoke binding arbitration for complaints regarding DPF compliance that are not resolved by other DPF mechanisms. MindX Digital Softwares Inc. is obligated to arbitrate claims and follow the terms as set forth in Annex I of the DPF Principles. For more information, please visit https://www.dataprivacyframework.gov/.
15. Legal Compliance and Disclosure to Authorities
We may disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements. We also may disclose data when required by law, regulation, court order or to enforce our Terms of Service.
16. Children's Privacy
Our Services are not intended for individuals under 16. We do not knowingly collect personal data from minors. If we discover such data, we will delete it immediately.
17. Third‑Party Links
Our Services may contain links to external websites. We are not responsible for the privacy practices of third parties.
18. Automated Decision‑Making & Profiling
We may use automated tools, including AI algorithms, to personalize recommendations, trigger marketing campaigns and assess engagement. Significant decisions impacting individuals are subject to human oversight where required by law.
19. Do Not Track & Opt‑Out Mechanisms
We honor Do Not Track (DNT) signals where legally required. You can opt out of targeted advertising via the Network Advertising Initiative (NAI) or Digital Advertising Alliance (DAA) opt‑out pages.
20. Changes to This Policy
We may update this Policy periodically. Major updates will be communicated via email or in‑app notifications.
21. Our Role as a Data Processor & Data Processing Agreement (DPA)
When we provide the chatbot and related Services to a business customer, that customer determines the purposes and means of processing End‑Customer Conversation Data and is the data controller; MindX AI acts as a data processor. In that capacity we commit to:
- Process End‑Customer Conversation Data only on the customer's documented instructions and solely to provide the Services;
- Not use that data for our own purposes, including advertising or training shared or foundation AI models;
- Keep each customer's data logically isolated so it is never exposed in another customer's conversations;
- Impose confidentiality and equivalent data‑protection obligations on every sub‑processor, and make the current sub‑processor list available on request;
- Apply Standard Contractual Clauses (and the UK Addendum) to international transfers, as described in Section 7;
- Assist the customer in responding to data‑subject requests and, on termination, delete or return the data subject to legal retention requirements.
Business customers may enter into a Data Processing Agreement (DPA) with us. To request our DPA, contact support@themindx.ai.
22. Contact Us
MindX Digital Softwares Inc.
1111B S Governors Ave, STE 23511, Dover, DE 19904
Email: support@themindx.ai