Privacy Policy
- Home
- Privacy Policy
Last updated: August 26, 2026
This Privacy Policy explains how MISTINY ("MISTINY," "we," "us," or "our") collects, uses, discloses, stores, and otherwise processes personal information when you visit our websites, use our products or services, communicate with us, or otherwise interact with us (collectively, the "Services"). It also describes the choices and rights that may be available to you under applicable data protection and privacy laws.
If a local law gives you rights or protections that differ from this Policy, we will apply the requirements of that law to the extent it applies to our processing of your personal information.
1. Scope and Data Controller
This Policy applies to personal information processed by MISTINY through the Services. It does not apply to third-party websites, products, or services that we do not control, even if they are linked from our Services.
Unless otherwise stated in a separate notice or contract, MISTINY is the controller or equivalent responsible entity for personal information covered by this Policy. When we process personal information on behalf of a customer, that customer is generally the controller and its privacy notice governs the processing. Please direct requests concerning customer-controlled data to the relevant customer.
2. Personal Information We Collect
Depending on how you interact with us, we may collect the following categories of personal information:
- Identifiers and contact details: name, username, organization, job title, postal address, email address, telephone number, account identifiers, and similar information.
- Account and transaction information: account credentials, subscription details, orders, invoices, payment status, and records of products or services requested or provided. Payment card information may be processed directly by an authorized payment provider.
- Device, network, and usage information: IP address, browser and device type, operating system, language, approximate location derived from IP address, referring URLs, pages viewed, timestamps, diagnostic data, cookie identifiers, and interactions with the Services.
- Communications: messages, support requests, feedback, survey responses, and other information you provide when communicating with us.
- Security and service data: event logs, alerts, files, hashes, domains, URLs, network or endpoint telemetry, and other data submitted to or generated by cybersecurity Services. Such data may contain personal information depending on its content.
- Marketing and preference information: communication preferences, areas of interest, and responses to campaigns or events.
- Other information: information you choose to provide or that we describe when collecting it.
Please do not provide sensitive personal information unless it is necessary for a requested Service and permitted by applicable law. Where required, we process sensitive personal information only with appropriate consent or another valid legal basis.
3. Sources of Personal Information
We collect personal information directly from you, automatically through the Services, from your organization or an account administrator, from service providers and business partners, from publicly available sources, and from other parties where permitted by law.
4. How We Use Personal Information
We may process personal information to:
- Provide, operate, maintain, support, personalize, and improve the Services;
- Create and administer accounts, authenticate users, and process transactions;
- Detect, investigate, prevent, and respond to fraud, abuse, security incidents, malware, and other harmful or unlawful activity;
- Communicate about accounts, transactions, support, updates, security notices, and administrative matters;
- Send marketing communications where permitted by law and manage communication preferences;
- Analyze performance and usage, conduct research, troubleshoot issues, and develop new features and services;
- Comply with law, enforce agreements, establish or defend legal claims, and protect the rights, safety, and property of MISTINY, our users, and others;
- Carry out a merger, acquisition, financing, reorganization, sale of assets, or similar corporate transaction; and
- Fulfill another purpose disclosed at collection or carried out with your consent.
5. Legal Bases for Processing
Where applicable law requires a legal basis, we rely on one or more of the following: performance of a contract or steps requested before entering a contract; compliance with a legal obligation; our legitimate interests or those of a third party, provided those interests are not overridden by your rights; protection of vital interests; consent; and any other basis authorized by applicable law. You may withdraw consent at any time without affecting processing already carried out lawfully.
6. Cookies and Similar Technologies
We and authorized providers may use cookies, pixels, local storage, and similar technologies to operate and secure the Services, remember preferences, understand usage, measure performance, and, where permitted, support marketing. Where required by law, non-essential technologies are used only after we obtain consent.
You can manage cookies through available consent controls and your browser settings. Blocking some technologies may affect Service functionality. We honor legally recognized opt-out preference signals, such as Global Privacy Control, where required by applicable law.
7. How We Disclose Personal Information
We may disclose personal information to:
- Affiliates and personnel that need the information for the purposes described in this Policy;
- Vendors and service providers that support hosting, infrastructure, security, analytics, communications, customer support, professional services, and payment processing;
- Customers, account administrators, and other users as necessary to provide collaborative or organization-managed Services;
- Business partners when you request an integrated service or authorize the disclosure;
- Government authorities, courts, regulators, law enforcement, or other parties when required or permitted by law or necessary to protect rights, safety, and security;
- Parties involved in an actual or proposed corporate transaction; and
- Other recipients at your direction or with your consent.
We require service providers to protect personal information and process it only for authorized purposes. We do not sell personal information for monetary consideration. If any processing is considered a "sale," "sharing," or targeted advertising under applicable law, you may exercise the opt-out rights described below.
8. International Data Transfers
Your personal information may be processed in countries other than the country where you live. Those countries may have different data protection laws. Where required, we use lawful transfer mechanisms and safeguards, such as adequacy decisions, standard contractual clauses, contractual protections, security measures, certifications, or consent. You may contact us for additional information about applicable safeguards.
9. Data Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including providing the Services, maintaining security and business records, resolving disputes, enforcing agreements, and satisfying legal, tax, accounting, or regulatory obligations. Retention periods depend on the nature and sensitivity of the information, the processing purpose, risk of harm, contractual requirements, and applicable law. We then delete, anonymize, or securely isolate the information as appropriate.
10. Data Security
We use reasonable administrative, technical, organizational, and physical safeguards designed to protect personal information. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for protecting your credentials and notifying us promptly of suspected unauthorized account access.
11. Your Privacy Rights
Subject to applicable law and relevant exceptions, you may have the right to:
- Know whether we process your personal information and obtain access to it;
- Request correction of inaccurate or incomplete information;
- Request deletion or erasure;
- Restrict or object to processing;
- Receive portable copies of certain information;
- Withdraw consent;
- Opt out of direct marketing, targeted advertising, sale, sharing, or certain profiling;
- Request information about categories of information, sources, purposes, and recipients;
- Not be subject to a decision based solely on automated processing where it produces legal or similarly significant effects;
- Appeal our response to a request; and
- Complain to a competent data protection or privacy authority.
To exercise a right, contact us using the details below and describe your request. We may verify your identity and authority before responding. An authorized agent may submit a request where permitted by law, subject to verification. We will respond within the period required by applicable law and will not unlawfully discriminate against you for exercising a privacy right.
12. Regional Disclosures
European Economic Area, United Kingdom, and Switzerland
You may contact us to exercise your rights or lodge a complaint with your local supervisory authority. Where required, we provide information about our legal bases, international transfer safeguards, and any applicable representative or data protection officer.
United States
Residents of California and other states with comprehensive privacy laws may have rights to know, access, correct, delete, and obtain a portable copy of personal information, and to opt out of sale, sharing, targeted advertising, or certain profiling. The categories collected, sources, purposes, and recipients are described in Sections 2 through 7. We retain each category as described in Section 9. We do not use or disclose sensitive personal information for purposes that require a right to limit under California law unless we provide the required notice and choice.
People's Republic of China
Where the Personal Information Protection Law and related laws apply, we process personal information under an authorized legal basis, provide required notices, obtain separate consent when required, and implement applicable safeguards for sensitive personal information and cross-border transfers. You may exercise rights to know, decide, restrict, refuse, access, copy, correct, or delete personal information as provided by law.
Brazil
Where Brazil's General Data Protection Law applies, you may exercise applicable rights regarding confirmation, access, correction, anonymization, restriction, deletion, portability, disclosure of sharing, consent, review of automated decisions, and complaints to the national authority.
Other Jurisdictions
Residents of Canada, Australia, New Zealand, Japan, South Korea, Singapore, India, South Africa, and other jurisdictions may have additional rights under local law. We will honor applicable rights and mandatory requirements. If this Policy conflicts with a mandatory local requirement, the local requirement controls.
13. Children's Privacy
The Services are not directed to children, and we do not knowingly collect personal information from children below the minimum age established by applicable law without valid parental or guardian authorization. If you believe a child has provided personal information unlawfully, contact us so we can take appropriate action.
14. Third-Party Services
The Services may link to or integrate with third-party services. Those parties process personal information under their own privacy policies, and we are not responsible for their practices. Review their policies before providing personal information.
15. Changes to This Policy
We may update this Policy to reflect changes in our practices, technology, Services, or legal obligations. We will post the updated version and revise the "Last updated" date. Where required, we will provide additional notice or request consent before a material change takes effect.
16. Contact Us
For questions, complaints, or privacy requests, contact:
MISTINY
Room 2376, 26th Floor, No. 65 Kehua North Road
Chengdu, Sichuan, China
Email: contact@mistiny.com
Telephone: +86 184 2800 3550