PRIVACY POLICY.
Technical compliance protocol governing data processing, cryptographic security, and privacy standards for miidaystudio.
1. INTRODUCTION & PREAMBLE
MIIDAYSTUDIO (“MIIDAYSTUDIO”, “MIIDAY”, “we”, “us”, or “our”) respects your privacy and is committed to protecting personal information that we collect, use, store, and process.
This Privacy Policy explains how we collect, use, disclose, retain, and protect information when you:
- visit our website;
- contact us or submit a project brief;
- request or purchase our engineering services;
- communicate with our design and development team;
- use any products, applications, or APIs provided by us; or
- otherwise interact with MIIDAYSTUDIO.
2. WHO WE ARE & DATA CONTROLLER
MIIDAYSTUDIO is an independent custom software, web design, and AI technology services studio.
3. SCOPE OF THIS POLICY
This Privacy Policy applies to personal information collected through our digital interfaces, contact endpoints, client onboarding channels, and contracted software engineering deliverables.
4. INFORMATION WE COLLECT
4.1 Information You Provide
You may voluntarily provide information such as your name, email address, phone number, company name, project brief details, and budget specifications when initiating a sprint inquiry.
4.2 Technical & Usage Telemetry
We automatically collect technical browser headers, IP address telemetry, operating system details, and interaction metrics to optimize system performance.
5. INFORMATION FROM THIRD PARTIES
We may receive information from verified third-party infrastructure services (Resend, Stripe, Vercel, Cloudflare, GitHub) necessary to execute client contracts and secure application runtimes.
6. HOW WE USE PERSONAL INFORMATION
Develop software & websites, engineer automation systems, deploy custom WebGL graphics, and maintain high-availability runtimes.
Respond to project briefs, issue sprint updates, provide technical support, and process billing invoices.
7. LEGAL BASIS FOR PROCESSING
We process personal information under valid legal bases including contract performance, legitimate commercial interest in running a software agency, compliance with statutory legal obligations, and explicit user consent.
8. AI & ARTIFICIAL INTELLIGENCE PROCESSING
We do NOT submit confidential client information, database contents, or proprietary client source code to public AI systems for public model training.
9. THIRD-PARTY SERVICE PROVIDERS
We engage trusted third-party infrastructure subprocessors (such as Vercel, Resend, AWS, Stripe, and Cloudflare) under strict data protection agreements to ensure data confidentiality and uptime reliability.
10. INTERNATIONAL DATA TRANSFERS
As a global agency, data may be processed across secure edge locations worldwide using Standard Contractual Clauses (SCCs) and compliant data transfer mechanisms.
11. COOKIES AND LOCAL STORAGE
We use minimal essential cookies and browser local storage strictly required for theme preferences, session security, and dynamic UI state navigation.
12. ANALYTICS PROTOCOL
We utilize privacy-focused, anonymized analytics to measure site traffic and performance without selling user profiles or tracking across third-party websites.
13. PAYMENT INFORMATION
Payment transactions are processed securely via PCI-DSS Level 1 certified gateways (Stripe / Razorpay). MIIDAYSTUDIO never stores full credit card numbers or banking passwords on internal servers.
14. DATA SHARING AND DISCLOSURE
We do not sell, rent, or trade your personal data. Disclosure occurs only when mandated by valid legal subpoenas, court orders, or to defend legal rights.
15. CLIENT-PROVIDED DATA RESPONSIBILITY
Clients providing test datasets, user content, or credentials during custom development warrant that they possess all necessary legal authorizations and compliance rights.
16. API KEYS AND CREDENTIALS SECURITY
All client API keys, secrets, and environment credentials provided for integration sprints are encrypted at rest using industry-standard vaults and purged post-offboarding upon client request.
17. TECHNICAL & ORGANIZATIONAL DATA SECURITY
18. DATA BREACHES & INCIDENT RESPONSE
In the event of a confirmed security incident affecting personal data, MIIDAYSTUDIO maintains a rapid incident response protocol to notify impacted parties and regulatory authorities within statutory timelines.
19. DATA RETENTION & PURGING SCHEDULE
We retain personal data only for as long as required to fulfill contract deliverables, resolve disputes, and comply with tax and statutory obligations.
20. YOUR PRIVACY RIGHTS (GDPR / DPDP)
Depending on your location, you hold legal rights including the right to access, rectify, port, erase, or restrict processing of your personal information.
21. HOW TO EXERCISE YOUR RIGHTS
To exercise your statutory privacy rights, submit a written request to [email protected]. Verification of identity may be requested prior to processing.
22. GRIEVANCE REDRESSAL MECHANISM
Under applicable digital data protection laws (including India DPDP Act), grievances can be directed to our designated Grievance Officer at [email protected].
23. CHILDREN'S PRIVACY PROTECTION
MIIDAYSTUDIO services and digital interfaces are intended solely for individuals aged 18 and older. We do not knowingly collect personal data from minors.
24. DO-NOT-TRACK AND PRIVACY SIGNALS
We respect Global Privacy Control (GPC) browser signals and Do-Not-Track (DNT) header preferences transmitted by modern web browsers.
25. THIRD-PARTY WEBSITES & EXTERNAL LINKS
Our site may contain links to third-party domains (e.g., GitHub repositories or client case study websites). MIIDAYSTUDIO is not responsible for external privacy policies.
26. BUSINESS & TRANSACTIONAL COMMUNICATIONS
We may send transactional messages regarding project milestones, invoice receipts, and system alerts. Users can opt out of non-essential communications at any time.
27. SENSITIVE PERSONAL INFORMATION RESTRICTIONS
We do not collect or request sensitive personal data (e.g. biometric data, medical histories, or political affiliations) unless required under a specific signed contract.
28. DATA ACCURACY & RECTIFICATION
We take reasonable steps to ensure that personal information under our control remains accurate, complete, and current for its intended operational purposes.
29. AUTOMATED DECISION-MAKING DISCLAIMER
MIIDAYSTUDIO does not utilize automated profiling or algorithmic decision-making that produces legal or similarly significant effects on users.
30. LEGAL AND REGULATORY COMPLIANCE
We continuously align internal operational procedures with evolving global privacy frameworks including GDPR, CCPA/CPRA, and India Digital Personal Data Protection (DPDP) Act.
31. CHANGES TO THIS PRIVACY POLICY
We reserve the right to update this Privacy Policy to reflect changing technical practices or statutory obligations. Updated versions will feature an updated effective date.
32. OFFICIAL PRIVACY CONTACT INFORMATION
MIIDAYSTUDIO
Privacy Email: [email protected]
Website: https://miidaystudio.com
Location: India // Global Operations
33. GOVERNING INFORMATION & JURISDICTION
This Privacy Policy is governed by the laws of India. Any legal proceedings shall be subject to the exclusive jurisdiction of courts located in India.
