GDPR and your data rights

MimicRadar is built for European use: data minimisation by default, no advertising trackers, and a clear route to every right the GDPR gives you. This page explains those rights and how to use them.

Last updated 16 September 2026

Our two roles

For your account details, billing and support we act as the controller — we decide what is collected and why, as set out in the privacy policy.

For the company data you enter and the findings we store for you, we act largely as your processor: we search on your instructions and keep the results for you. If you need a signed data processing agreement including the Standard Contractual Clauses, request one at privacy@mimicradar.com and we will send it.

Your rights

RightWhat it means here
Access (Art. 15)Get a copy of the data we hold about you — account, companies, locations, findings, billing history and support messages.
Rectification (Art. 16)Correct anything wrong. Company details and locations can be edited directly in your account at any time.
Erasure (Art. 17)Have your account and monitoring data deleted. We keep only billing records that tax law requires us to retain.
Restriction (Art. 18)Ask us to pause processing — for example to stop daily scans while a dispute is resolved.
Portability (Art. 20)Receive your companies, locations and findings in a machine-readable file you can take elsewhere.
Objection (Art. 21)Object to processing we base on legitimate interests, such as security logging.
Automated decisions (Art. 22)Not applicable: name matching flags results for you to review, and no decision with legal effect is made automatically.
Withdraw consent (Art. 7)Where we ever rely on consent, you can withdraw it at any time without affecting what happened before.

How to make a request

Email privacy@mimicradar.com from the address on your account, or open a ticket from the support page once signed in. We answer within one month and will tell you if a complex request needs longer, up to two further months. Requests are free unless they are clearly excessive. We may ask a question to confirm who you are before we release data.

Deleting your account yourself

Cancel the subscription on your billing page to stop payments and monitoring, then ask us to delete the account. Deletion removes your companies, locations, findings, listing records and support history within 90 days.

Transfers outside the EEA

Some providers we rely on operate in the United States. Those transfers use the European Commission's Standard Contractual Clauses or the provider's EU–US Data Privacy Framework certification, plus encryption in transit and at rest. The providers are listed on our subprocessors page and we tell account holders by email before adding a new one.

Data breaches

If a breach is likely to affect your rights we notify the competent supervisory authority within 72 hours of becoming aware of it, and inform affected account holders without undue delay with what happened and what to do.

Complaints

You can complain to the data protection authority in your country of residence or work at any time. We would rather hear from you first at privacy@mimicradar.com so we can try to put it right.

If you are in the United States

State privacy laws in California, Colorado, Connecticut, Texas, Virginia and elsewhere give you rights to know, correct, delete and to opt out of the sale or sharing of personal data and of targeted advertising. We do not sell or share personal data and run no advertising technology, so there is nothing to opt out of. Use the same address above to exercise your right to know, correct or delete, or to appeal a decision we make — we never charge you or reduce the service for asking.