Last updated July 20, 2026

Privacy policy

This Privacy Policy explains how MiiiSys (“MiiiSys,” “we,” “us,” or “our”) collects, uses, discloses, stores, and protects personal data when you visit our websites, use our products, applications, dashboards, or other online services, or otherwise interact with us (collectively, the “Services”).

This Privacy Policy is intended to provide clear information about our personal data practices and the privacy rights that may be available to you.

1. Our Rule

Depending on the circumstances, MiiiSys may act as:

A data controller when we determine the purposes and means of processing personal data, such as for account administration, service security, analytics, communications, and customer support; or

A data processor or service provider when we process personal data on behalf of a client and in accordance with that client’s documented instructions.

When MiiiSys processes personal data on behalf of a client, that client is generally responsible for determining how and why the personal data is processed. Requests relating to such data should normally be directed to the relevant client. Where required, we may assist the client in responding to those requests.

2. Personal Data We Collect

The personal data we collect depends on how you interact with the Services and may include:

Identification and contact data: Name, business role, email address, phone number, and other business contact information.

Account and organization data: Company name, business domain, account settings, user permissions, access roles, and authentication information.

Transactional and operational data: Case or record identifiers, transaction timestamps, amounts, dispute information, status information, and other metadata required to provide enabled features.

Technical and usage data: IP address, device and browser information, operating system, pages viewed, feature usage, activity logs, diagnostic data, crash data, and cookie, SDK, or application identifiers.

Communications: Emails, support tickets, chat messages, inquiries, feedback, and other communications with us.

Integration data: Information received from payment platforms, e-commerce platforms, CRM systems, fulfillment providers, and other systems that you or our clients choose to connect to the Services.

Derived data and insights: Risk indicators, performance metrics, classifications, recommendations, and other insights generated from data processed through the Services.

Our Services are not designed to collect or store full payment card numbers, card verification codes, or magnetic-stripe data. Where such information is submitted unintentionally, we take reasonable steps to restrict access to and securely delete or redact it, subject to applicable legal and technical requirements.

3. How We Collect Personal Data

We may collect personal data:

Directly from you when you create an account, contact us, submit a request, or use the Services;

Automatically through your use of our websites, applications, and dashboards;

From our clients when they use the Services;

From systems and platforms connected to the Services; and

From service providers, business partners, and other sources where permitted by applicable law.

4. How We Use Personal Data

We may use personal data for the following purposes:

Providing and Maintaining the Services

We process personal data to create and administer accounts, deliver requested features, maintain service availability, process authorized integrations, troubleshoot issues, and provide customer support.

The applicable legal basis may include performance of a contract or our legitimate interests in providing and operating the Services.

Security and Fraud Prevention

We process personal data to authenticate users, manage access, monitor activity, detect and prevent fraud or misuse, investigate suspicious activity, and respond to security incidents.

The applicable legal basis may include our legitimate interests in protecting the Services, our clients, and users, as well as compliance with legal obligations.

Analytics and Service Improvement

We may use personal data to understand how the Services are used, measure performance, conduct research and testing, improve existing functionality, and develop new features.

The applicable legal basis may include our legitimate interests in improving the Services or consent where required by applicable law.

Communications

We use personal data to send service-related messages, respond to inquiries, provide support, and communicate important account, security, or product information.

Where permitted, we may also send marketing communications. You may opt out of marketing communications at any time by using the unsubscribe option provided or contacting us.

The applicable legal basis may include performance of a contract, consent, or our legitimate interests, depending on the nature of the communication and applicable law.

Compliance and Enforcement

We may process personal data to comply with legal, regulatory, accounting, audit, and contractual requirements; respond to lawful requests; enforce our agreements and policies; and establish, exercise, or defend legal claims.

The applicable legal basis may include compliance with legal obligations and our legitimate interests in protecting our rights and operations.

Where we rely on legitimate interests, those interests may include maintaining and improving the Services, protecting systems and users, preventing fraud, supporting business operations, and enforcing our agreements.

5. Automated Processing and Insights

Certain Services may use automated technologies to analyze transactional, operational, or risk-related information and generate indicators, classifications, performance insights, or recommendations.

These outputs are intended to support our clients’ review and decision-making processes. Unless otherwise disclosed, MiiiSys does not use such processing to make final decisions about individuals that produce legal or similarly significant effects without appropriate human involvement.

Where applicable law provides rights relating to automated decision-making, you may contact us or the relevant MiiiSys client for further information.

6. Cookies and Similar Technologies

We use cookies and similar technologies to support security, authentication, session management, website functionality, performance measurement, and service improvement.

Depending on the technologies used, we may deploy:

Strictly necessary cookies;

Functional cookies;

Analytics and performance cookies; and

Advertising or targeting cookies, where applicable and permitted.

You can manage cookies through our cookie preference tools, where available, or through your browser or device settings. Disabling strictly necessary cookies may prevent certain parts of the Services from functioning properly.

We currently do not respond to traditional browser “Do Not Track” signals. Where required by applicable law, we recognize applicable consent choices or opt-out preference signals.

Additional information about the cookies and similar technologies we use will be provided in our separate Cookie Policy.

7. How We Share Personal Data

We may share personal data with the following categories of recipients:

Service providers and subprocessors: Providers of hosting, cloud infrastructure, data storage, backup, analytics, communications, ticketing, security, monitoring, and customer support services.

Clients and authorized users: Where necessary to provide the Services or functionality requested or authorized by the relevant client.

Integration and business partners: Where required to operate an authorized integration or provide a requested Service.

Professional advisers: Auditors, lawyers, insurers, accountants, and other professional advisers where reasonably necessary.

Legal and regulatory authorities: Where required by law, regulation, legal process, or lawful government request, or where reasonably necessary to protect rights, safety, security, or property.

Parties involved in corporate transactions: In connection with a merger, acquisition, restructuring, financing, sale of assets, or similar transaction, subject to appropriate confidentiality and data-protection safeguards.

Service providers and subprocessors that process personal data on our behalf are subject to appropriate contractual, confidentiality, and data-protection obligations.

MiiiSys does not sell personal data or share personal data for cross-context behavioral advertising as those terms are defined under applicable privacy laws.

8. International Data Transfer

Personal data may be processed outside the country or region in which you or the relevant individual is located, including in locations where MiiiSys, our clients, or our service providers operate.

Where required by applicable law, we use recognized transfer mechanisms and safeguards, which may include:

Adequacy decisions;

Standard Contractual Clauses;

Contractual and organizational safeguards; or

Other legally permitted transfer mechanisms.

You may contact us at privacy@miiisys.com for further information about the safeguards that may apply to your personal data.

9. Data Retention

We retain personal data only for as long as reasonably necessary to:

Provide and maintain the Services;

Fulfil the purposes described in this Privacy Policy;

Follow a client’s documented instructions;

Meet legal, regulatory, accounting, audit, and contractual obligations;

Prevent fraud and maintain security;

Resolve disputes; or

Establish, exercise, or defend legal claims.

As a general guideline, transaction and dispute-related records may be retained for up to five years, while certain technical and usage data may be retained for up to 12 months.

Different retention periods may apply depending on the nature of the data, client instructions, contractual requirements, ongoing disputes, fraud-prevention requirements, and applicable legal obligations.

When personal data is no longer required, it will be securely deleted or anonymized in accordance with our applicable retention and deletion procedures.

10. Data Deletion

You may request deletion of personal data by contacting us at privacy@miiisys.com.

We will acknowledge and respond to verified requests within the period required by applicable law. We may request additional information to verify your identity and may extend the response period where legally permitted. If an extension applies, we will provide notice where required.

Following termination or uninstallation of a MiiiSys application, personal data processed on behalf of a client will be deleted, returned, or anonymized in accordance with:

The client’s documented instructions;

The applicable agreement;

Our retention procedures; and

Applicable legal and regulatory requirements.

Unless otherwise required, account-level personal data is generally scheduled for deletion or irreversible anonymization within 30 days following termination or uninstallation.

Certain information may be retained where necessary for fraud prevention, accounting, security, dispute resolution, legal compliance, or the establishment, exercise, or defense of legal claims.

Residual data stored in backups is generally removed within 90 days through our standard backup-rotation process. Where applicable data is held by subprocessors, we instruct them to delete, return, or anonymize it in accordance with applicable contractual and legal requirements.

11. Data Security

We use appropriate technical and organizational measures designed to protect personal data against unauthorized or unlawful access, use, alteration, disclosure, destruction, or loss.

These measures may include:

Access controls and authentication;

Least-privilege access practices;

Encryption in transit and at rest where appropriate;

Logging and security monitoring;

Vulnerability and patch management;

Incident response procedures; and

Personnel and service-provider confidentiality requirements.

No method of transmission, storage, or processing is completely secure. If a personal data breach occurs, we will investigate and take appropriate response measures and will notify affected clients, individuals, and regulatory authorities where required by applicable law or contract.

12. Your Privacy Rights

Depending on your location and applicable law, you may have the right to:

Request access to the personal data we hold about you;

Request correction of inaccurate or incomplete personal data;

Request deletion of your personal data;

Restrict or object to certain processing;

Receive certain personal data in a portable format;

Withdraw consent where processing is based on consent;

Object to direct marketing;

Request information about certain automated processing; and

Lodge a complaint with an applicable data protection authority.

These rights are not absolute and may be subject to legal conditions, limitations, and exceptions.

To exercise your rights, contact privacy@miiisys.com. We may request information reasonably necessary to verify your identity and process your request.

Where MiiiSys processes personal data solely on behalf of a client, we may direct your request to the relevant client or assist that client in responding.

13. Children’s Privacy

The Services are intended for businesses and authorized business users and are not directed to individuals under the age of 16 or the applicable minimum legal age in their jurisdiction.

We do not knowingly collect personal data directly from children. If you believe that a child has provided personal data to us, please contact privacy@miiisys.com so that we can investigate and take appropriate action.

14. Third-Party Services and Links

The Services may contain links to or integrations with third-party websites, platforms, applications, or services.

The privacy practices of those third parties are governed by their own privacy policies. MiiiSys is not responsible for the privacy, security, or data-processing practices of third parties acting independently from us.

We encourage you to review the relevant third-party privacy policies before providing personal data or enabling an integration.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to our Services, technologies, business practices, or legal requirements.

The revised Privacy Policy will become effective on the date indicated by the updated “Last Updated” date.

Where required by applicable law, we will provide additional notice of material changes and obtain consent before applying changes that require consent.

16. Contact Us

If you have questions about this Privacy Policy, our privacy practices, or the processing of your personal data, or if you wish to exercise an applicable privacy right, please contact:

MiiiSys Privacy Team

Email: privacy@miiisys.com