Privacy Policy
Version 1.0 · Effective 29 June 2026 · Last updated 29 June 2026. This explains how AVI Verifide India Private Limited (“MIKA”, “we”) handles personal data. MIKA is a marketing platform for businesses, so we handle data in two different roles — please read section 1 first, because it shapes everything else. This policy describes MIKA’s full service; some features — and the vendors and safeguards tied to them — activate as you use them.
1. Our two roles: controller and processor
We are the “controller” of your account data — what you give us to use MIKA (your name, email, billing, and how you use the product).
We are a “processor”, acting on your instructions, for the data youcollect through MIKA about your customers — most importantly the leads captured by forms on a site MIKA builds. For that data you are the controller and MIKA has no direct relationship with those individuals; their requests come to you and we help you fulfill them. A separate Data Processing Agreement (DPA) governs this relationship.
2. Definitions
- Personal data — information relating to an identified or identifiable person.
- Controller / Processor — who decides the purposes of processing (controller) vs. who processes on the controller’s instructions (processor).
- Lead / End user — a person who submits their details through a site or form you operate with MIKA.
- Subprocessor — a third party we engage to help process data.
- Service data — data we generate about how you use MIKA (logs, usage).
3. What we collect
- Account — name and email from Google sign-in; billing details for paid plans.
- Your business profile & content — what you tell MIKA about your business, your brand voice, the content you create, and your byline author details.
- Leads (as your processor) — contact details people submit through your MIKA-built site (name, email, phone, message).
- Connected-account tokens — when you link a service (Google Search Console / Analytics / Business Profile), the access tokens needed to provide that feature.
- Usage & technical data — logs, device/IP, and security signals needed to run and protect the service.
4. How we use data, and our legal bases
Where the GDPR/UK GDPR applies, we rely on these legal bases (Art. 6):
- To provide the service (run your account, build/host your site, generate content you request) — performance of a contract.
- To secure the platform and prevent abuse, and to improve the service using aggregated data — our legitimate interests.
- To send you product or marketing messages where required — your consent (withdrawable at any time).
- To meet legal obligations (tax, security, lawful requests) — legal obligation.
- Lead data we process on your instructions as your processor; your own legal basis as controller applies.
5. AI — we never train on your data
We use data to generate content you request. We do not sell your data, and we do not train AI models on your data, content, or leads. When we use AI providers:
- Anthropic (our primary AI) does not train its models on our customers’ API content, per its commercial terms.
- OpenAI (fallback) does not use data submitted via its API to train its models by default.
- We never put a lead’s personal details into an AI prompt unless a task genuinely requires it, and connected-account tokens are never sent to an AI provider.
6. Google user data (Limited Use)
If you connect Google services, MIKA’s use of Google user data complies with the Google API Services User Data Policy, including Limited Use: we use that data only to provide features you see in MIKA, we don’t sell it, we don’t use it for advertising, and we don’t let humans read it except as that policy allows.
7. Cookies and tracking
We use only strictly necessary cookies to sign you in and keep your session secure; these don’t require consent. We do not currently use analytics or advertising cookies. If we add non-essential cookies in future, we’ll list them here and obtain consent where required.
8. How we share data (subprocessors)
We share data with vetted vendors under contracts requiring them to protect it. Each vendor processes data only for the feature it supports — so a vendor receives data only once you use that feature. Our current list is on our subprocessors page. We do not sell personal data.
9. International transfers
Your data is primarily processed in India (Mumbai). Some subprocessors — for example our AI providers — process data in the United States. Where personal data crosses borders we rely on contractual data-protection terms with those vendors, and on Standard Contractual Clauses where EU/UK personal data is involved.
10. Your rights and how to exercise them
Subject to local law, you can access, correct, export (portability), delete, object to, or restrict processing of your personal data, and withdraw consent. Exercise these by emailing team@mikahq.com or via your account settings; we respond within 30 days and may verify your identity first. You also have the right to lodge a complaint with your data-protection supervisory authority. For lead data, the individual contacts you as controller and we assist you in locating, exporting, or deleting it.
11. US state privacy rights (CCPA/CPRA and similar)
Where US state laws apply, you have rights to know, access, delete, correct, and to opt out of the “sale” or “sharing” of personal information, and to limit the use of sensitive personal information.
- Categories collected — identifiers (name, email), commercial information (plan/billing), internet/usage activity, and content you provide.
- “Do not sell or share” — we do not sell personal information, and we do not share it for cross-context behavioral advertising.
- Sensitive personal information — we don’t use it for purposes requiring a “limit” right.
- Authorized agents may submit requests with proof of authorization.
- Non-discrimination — we won’t discriminate against you for exercising these rights.
12. India (Digital Personal Data Protection Act, 2023)
MIKA is operated by AVI Verifide India Private Limited (Gurugram, India). Under India’s DPDP Act, 2023, we act as a Data Fiduciary for your account data and as a Data Processor for the lead data you collect. We process personal data on a lawful basis (your consent, or as necessary to provide the service you request).
- Your rights as a Data Principal — access, correction, completion, updating, erasure, grievance redressal, and nomination.
- Grievance Officer — contact team@mikahq.com; we respond within the timeline the law requires.
- Escalation — you may approach the Data Protection Board of India if your grievance isn’t resolved.
13. Automated decision-making
MIKA does not make decisions producing legal or similarly significant effects about you based solely on automated processing. AI assists with drafting and suggestions, and you review and approve actions before they take effect (publishing and outbound sends always require your approval).
14. How long we keep data, and deletion
Deletion is first-class at MIKA:
- Delete a project → we hard-delete its data — leads, brand voice, audits, imports, and connected-account tokens are removed (cascade).
- Per-person deletion/export — on request, we delete or export an individual’s data.
- Retention — leads are kept until you delete the project or request deletion; operational logs/telemetry are pruned on a rolling window (messages up to 12 months, activity logs up to 24 months, API/telemetry logs up to 180 days); connected-account tokens are deleted when you disconnect.
15. How we protect data
Each business’s data is isolated from every other (tenant isolation). We don’t log raw lead details or AI prompt/response bodies. When you connect a third-party account, the access tokens are encrypted at rest and decrypted only in memory at the point of use — never logged, never returned to your browser, never sent to an AI provider. We will notify affected users and regulators of a qualifying personal-data breach without undue delay (and within 72 hours where required).
16. Children
MIKA isn’t intended for anyone under 16, and we don’t knowingly collect their personal data; if we learn we have, we delete it.
17. Changes to this policy
We may update this policy; we’ll post the new version, change the “last updated” date, and for material changes give prominent notice (e.g. in-product or by email) before they take effect.
18. Contact
Privacy questions or requests: team@mikahq.com · AVI Verifide India Private Limited, Plot 94, Sector 44, Gurugram, Haryana, India. No Data Protection Officer or EU/UK Article 27 representative is currently appointed; we will appoint one if and when our processing requires it.