Privacy Notice
Last updated: July 2, 2026
What we collect
When you create a Mizan workspace, we collect account information: the workspace administrator's name, work email address, brokerage firm name, country, and the license number you optionally provide for RFP and audit use. We also collect billing contact details and correspondence related to your subscription.
As you use the platform, we store workspace content: deal records, company and contact profiles, uploaded documents (policy schedules, census files, RFP submissions), commission records, renewal dates, and any notes or tasks your team creates. This content is generated by your firm and remains your firm's property; we process it only to deliver the service.
We collect usage metadata — server-side logs of actions taken within the platform (page views, feature interactions, API calls) — to operate, secure, and improve the service. This metadata is tied to your workspace and user ID, not to personal identifiers beyond what is needed for audit and troubleshooting purposes. We do not use third-party behavioural tracking cookies within the authenticated application.
Why we process your data
We process account and billing information to manage your subscription, authenticate users, issue invoices, and communicate important service notices — including changes to these terms or pricing. The legal basis for this processing is contract performance.
We process workspace content to deliver the core functionality of Mizan: parsing uploaded documents, generating RFP drafts, scoring renewal opportunities, and presenting your pipeline and commission data. You control what content enters the platform; we process it on your instructions as your data processor. We do not use your workspace content to train AI models.
We process usage metadata to ensure the security, reliability, and performance of the platform; to investigate potential security incidents; and to understand aggregate feature usage in order to prioritise product improvements. Where any of this processing involves personal data, our legal basis is our legitimate interest in operating a secure and functional service.
Where your data lives
Every Mizan workspace is provisioned as a logically isolated tenant enforced through Postgres row-level security policies. No query issued by one workspace can return rows belonging to another. Enterprise customers additionally benefit from per-tenant key management, where your workspace's encryption keys are held separately from other tenants.
Data at rest is encrypted using AES-256. Data in transit between your browser or API client and Mizan's infrastructure is protected by TLS 1.2 or higher. Append-only audit logs are maintained for all data-access and administrative events within your workspace, and these logs are not modifiable by workspace administrators or Mizan support staff.
By default, data is stored in our primary region (MENA). Enterprise subscribers may choose a preferred residency region — MENA, EU, or US — at the time of account setup. If your regulatory environment requires data to remain within a specific jurisdiction, please contact us before provisioning your workspace so we can configure the appropriate region.
Who can see your data
Mizan does not sell your data or your clients' data to any third party, and we do not share workspace content with advertisers or data brokers. Access to your workspace data by Mizan personnel is limited to authorised support and engineering staff, and only when necessary to respond to a support request you have raised, to investigate a security incident, or to maintain the platform. All such access is logged in the append-only audit trail.
We engage a small number of sub-processors — infrastructure providers, payment processors, and transactional email services — who may handle limited categories of data as part of delivering the platform. All sub-processors are bound by data processing agreements that restrict their use of your data to the purposes for which it was shared. A current list of sub-processors is available on request at hello@mizan.io.
If Mizan receives a lawful request from a government authority to disclose data, we will — to the extent permitted by law — notify the relevant workspace administrator before complying, and we will limit disclosure to what is strictly required by the request.
Your rights
As a workspace administrator or as an individual whose personal data is processed by Mizan, you have the right to access the personal data we hold about you, to correct inaccuracies, to export a copy of your data in a machine-readable format, and to request erasure of your personal data subject to any legal retention obligations. These rights apply under Egypt's Personal Data Protection Law (PDPL) and, where applicable, under the GDPR.
Mizan provides built-in Data Subject Access Request (DSAR) tooling within the workspace settings. Workspace administrators can initiate an export or erasure request for any individual whose data is stored in the workspace. We aim to fulfil verified DSAR requests within 30 days of receipt; where a request is complex or involves a large volume of data, we will notify you of an extension before the deadline passes.
If you believe we have processed your data unlawfully or failed to honour a rights request, you may contact us at hello@mizan.io. You also have the right to lodge a complaint with the relevant supervisory authority in your jurisdiction — in Egypt, that is the Personal Data Protection Centre (PDPC); in EU member states, the competent national data protection authority.
Retention and contact
We retain workspace content for as long as your subscription is active. Following cancellation or termination, content is held in a recoverable state for 30 days to allow for re-activation or final export, after which it is permanently and irreversibly deleted. Usage logs and audit records are retained for a period of 12 months from the date of the event, after which they are deleted or anonymised. Billing and transactional records are retained for 7 years to comply with financial record-keeping requirements.
You may request early deletion of your workspace content at any time by submitting a request via hello@mizan.io or through the DSAR tooling in workspace settings. We will action deletion requests within 30 days, subject to any mandatory retention obligations under applicable law. Deletion is permanent: Mizan has no ability to recover data following confirmed erasure.
For all privacy enquiries, data subject requests, or questions about this notice, please contact us at hello@mizan.io. We aim to respond to all privacy enquiries within 5 business days. This notice was last updated on 2 July 2026 and supersedes all prior versions.