We are Coöperatie Mino.law U.A. (Mino). We respect your privacy and private life, but sometimes we need your Personal Data. We consider Personal Data to be any information relating to an identified or identifiable person, in conformity with the General Data Protection Regulation (the GDPR).
This policy explains which Personal Data we use and why (the Privacy Policy). Furthermore, you will read how we process, store and protect your Personal Data. Finally, we outline what rights you have when we process your Personal Data.
This Privacy Policy applies to our website https://mino.law (the Website), our AI-powered legal tools including Thea and other specialist agents (the Agents), and any other services or products we provide (collectively, the Services). We process your Personal Data in accordance with the GDPR and all other relevant legislation and regulations in the field of protection of Personal Data, including the Dutch Telecommunications Act (Telecommunicatiewet) regarding the use of cookies (the Relevant Legislation).
1. Processing of Personal Data
In order to provide you with our Website and Services, we process your Personal Data.
How do we receive your Personal Data?
We receive Personal Data directly from you when you:
- Create an account
- Subscribe to our Services
- Upload documents to our Agents
- Contact us or subscribe to our newsletter
- Use our Website or Services
Who is the controller of your Personal Data?
We are the controller of your Personal Data within the meaning of the Relevant Legislation. At the end of this Policy, you can find our contact details, including our privacy contact.
What Personal Data do we process, for which purposes, and on which legal basis?
We need some of your Personal Data in order for you to use our Website and Services.
We are allowed to process your Personal Data because we comply with the Relevant Legislation. We lawfully process your Personal Data because we:
- Have legal bases for processing your Personal Data
- Inform you about the processing
- Only process data for specific purposes, and no more than is necessary for that
We shall only use your Personal Data for the following purposes or for compatible purposes. By doing so, we will not use your Personal Data in an unexpected manner.
2. Data Processing Overview
| Category | Data | Purposes | Legal Basis |
|---|---|---|---|
| Account Data | Name, email address, password (encrypted), company name | To create and manage your account, to authenticate you, and to provide our Services | Necessity to perform the contract |
| Contact Data | Name, email address, phone number, company name, address | To contact you, to correspond with you, and to provide customer support | Necessity to perform the contract and legitimate interest |
| Payment Data | Billing address, payment method details, transaction history | To process payments, to send invoices, and to comply with tax obligations | Necessity to perform the contract and legal obligation |
| Content Data | Documents you upload, timelines generated, data extracted by Agents, chat history with Agents | To provide our Services, and to enable our Agents to analyze your documents and generate outputs | Necessity to perform the contract |
| Usage Data | Log data, device information, IP address, browser type, pages visited | To improve our Services, to ensure security, and to analyze usage patterns | Legitimate interest |
| Communication Data | Email address, communication preferences | To send our newsletter and to inform you about updates to our Services | Consent (newsletter) and necessity to perform the contract (service updates) |
3. AI Processing
Our Agents (including Thea and other specialist agents) use artificial intelligence to analyze your documents and generate outputs such as timelines, visualizations, and insights.
How AI processing works
When you upload documents to our Agents:
- Documents that arrive as scans or image-only PDFs are first converted to text. This conversion runs on Microsoft's Azure Document Intelligence service in the EU (West Europe) and necessarily processes the original document.
- The text is then analysed by AI models. Depending on the agent, we use OpenAI models deployed through Microsoft's Azure OpenAI Service in the EU, or Mistral, a French provider. These are enterprise or commercial endpoints, separate from the consumer versions of those products. Where you have enabled pseudonymisation for a matter, the names we detect in your documents are replaced with realistic stand-ins before any text is sent to an AI model, and the real names are restored only when results are shown to you.
- Data extracted from your documents, such as dates, parties, events and keywords, is stored in our database, subject to the access controls described in Section 5.
Your data is not used for AI training
Your data is not used to train AI models. The AI providers we use for our own platform are engaged under terms that prohibit training on customer data. This commitment covers processing on Mino's own provider accounts.
If you supply your own AI provider key
Users on a paid plan can configure their own API key for an AI provider. Where a user does that, the AI calls for their work are made to that provider under the customer's own contract with it, and the terms of that contract govern, including whether the provider retains data or trains on it. Our own provider commitments do not extend to a key you bring. In a shared workspace, the acting user's key is used for the documents they process. Pseudonymisation runs regardless of whose key is used.
Data isolation
Row-level security restricts access through the application to the workspaces you are a member of, so other customers cannot reach your documents or outputs.
4. Are you obliged to share your Personal Data with us?
In some cases, the processing of your Personal Data is necessary. Without your Personal Data, we cannot provide our Services to you. For example:
- We need your email address to create your account
- We need your payment information to process your subscription
- Our Agents need your documents to generate timelines and other outputs
5. How do we secure your Personal Data?
We make every effort to protect your Personal Data from loss, destruction, use, alteration or dissemination by unauthorized persons. We ensure that those who have nothing to do with your Personal Data cannot access it.
We do this through the following measures:
- Encryption in transit: TLS 1.3 encryption for all data transmitted between your device and our servers
- Encryption at rest: Your documents and database records are stored with Supabase in the EU, whose database and file storage encrypt data at rest, and processed on Microsoft Azure infrastructure in EU regions with the same protection. The re-identification data created by the pseudonymisation feature carries a second layer of encryption that we operate ourselves at the application level, on top of the providers' storage encryption
- Access control: Row-level security restricts access through the application to the workspaces you are a member of, so other customers cannot reach your documents or outputs
- Secure authentication: Session-based authentication with optional two-factor authentication
- EU data residency: Your documents, the text extracted from them, and the AI processing performed on them take place within the European Economic Area
- Staff access: By default nobody at Mino looks at your documents. A small number of authorised personnel can access customer data directly, and we use that access in three situations only. We access data to help you when you have asked for support, to investigate a security incident, or to meet a legal obligation. Where we need to look at a specific matter to help you, we ask you first. Everyone with this access is bound to confidentiality
- Regular security reviews: We continuously monitor and improve our security measures
For more details, see our Security page.
6. How long do we store your Personal Data?
We do not keep your Personal Data longer than we need it for the purposes described above. Most of what we hold is tied to the life of your account and your matters rather than to fixed calendar dates.
| Category | How long we keep it |
|---|---|
| Account Data | For as long as your account exists. Deleting your account removes it. |
| Content Data (documents, extracted text, agent outputs) | For as long as the document, matter or workspace exists. Deleting a document, a matter, or your account removes it from our live systems. |
| Payment Data | Seven years after the transaction, because Dutch tax law requires it. This is the one category we keep after account deletion, and we restrict it to that purpose. |
| Usage Data | Up to 26 months. |
| Communication Data | Until you unsubscribe or ask us to delete it. |
Backups. Deleting something removes it from our live systems immediately. Encrypted database backups, kept only for disaster recovery, rotate on a seven-day cycle, and a copy of deleted database data may persist there for up to seven days. Uploaded files are not included in backups, so deleting a file removes it immediately.
If you are a law firm using Mino to work on client files, you remain the controller of that data and you decide how long it is kept. We act on your instructions. At the end of our contract we delete the data or return it to you.
7. With whom do we share your Personal Data?
Processors
We may share your Personal Data with data "processors" within the meaning of the Relevant Legislation. We conclude a data processing agreement with these parties, which entails that they shall process your Personal Data carefully and that they shall only receive the Personal Data they need to provide their service. These parties shall only use your Personal Data in accordance with our instructions and not for their own purposes.
We share your Personal Data with the following processors:
| Processor | Purpose | Location |
|---|---|---|
| Microsoft Azure | AI text generation (Azure OpenAI Service), application hosting | EU |
| OpenAI | AI text generation in one internal agent used only by Mino administrators for our own market and prospect research. It does not process the documents in your matters | US, with safeguards |
| Microsoft Azure Document Intelligence | Converting scanned documents to text. Processes the original document before any pseudonymisation is possible | EU (West Europe) |
| Mistral AI | AI text generation and automatic document classification | EU (France) |
| Voyage AI | Search embeddings and reranking for Feitlijn case-law search | See our sub-processor notices for changes to this provider |
| orq.ai | Routing AI requests to the providers above | EU |
| Supabase | Database hosting, file storage, user authentication | EU |
| Vercel | Website and application hosting | EU |
| Railway | Application hosting for agents and background workers | EU |
| Resend | Transactional email. Receives recipient addresses and account-lifecycle messages, not the content of your matters | EU/US, with safeguards |
| Mollie | Payment processing | Netherlands |
| Pirsch | Website and product analytics | EU |
| Slack | Internal notifications of sign-ups and enquiries | US, with safeguards |
| Formspree | Handling enquiry and agent-request forms | US, with safeguards |
Where a user configures their own AI provider key, that provider is engaged under the customer's own contract and is not a Mino processor for those requests. We keep this list current and will publish changes here.
Legal obligations
If we have a legal obligation to share your Personal Data, we will do so. This is the case, for example, if a public authority legally requires us to share your Personal Data.
8. Cookies
A cookie is a small text file that can be sent via the server of a website to the browser. The browser saves this file to your computer. Your computer is tagged with a unique number, which enables our site to recognize that computer in the future.
We use cookies to:
- Improve the user experience on our Website
- Ensure that the Website works properly
- Enable secure authentication
- Track and solve errors on our Website
You can always delete or disable cookies yourself via the browser settings. No more cookies will be stored when you visit our Website. However, please note that without cookies, our Website may not function as well as it should, and you may not be able to log in to your account.
9. Other provisions
Transfer
Your documents, the text extracted from them, and the AI processing performed on them take place within the European Economic Area.
Some supporting services we use (email delivery, payment processing, website analytics, internal notifications, enquiry forms, and the internal research agent described in Section 7) are provided by companies established outside the EEA or with infrastructure outside it. Where personal data reaches those services we rely on an adequacy decision or on Standard Contractual Clauses with supplementary measures. The categories of data involved are limited to what each service needs, and they are listed in Section 7.
We do not share your Personal Data with recipients other than those listed in Section 7, except where we are legally required to do so.
Websites of third parties
Our Website may contain links to other websites. We are not responsible for the content or the privacy protection on these websites. Therefore, we advise you to always read the privacy policy of those websites.
10. Your rights
You have the following rights under the GDPR:
| Right | Description |
|---|---|
| Right of access | You can request access to your Personal Data and receive a copy |
| Right to rectification | You can request us to correct inaccurate Personal Data |
| Right to erasure | You can request us to delete your Personal Data |
| Right to restriction | You can request us to limit the processing of your Personal Data |
| Right to data portability | You can request a copy of your Personal Data in a structured, commonly used format, and we can provide this copy to third parties at your request |
| Right to object | You can object to the processing of your Personal Data based on legitimate interests |
| Right to withdraw consent | You can withdraw your consent at any time. From the moment of withdrawal, we will stop processing based on that consent |
| Right to file a complaint | You can file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) if you believe we process your data unlawfully |
To exercise any of these rights, contact us using the details below.
11. Modifications to the Privacy Policy
We may modify this Privacy Policy. If we substantially modify the Privacy Policy, we shall place a notification on our Website together with the new Privacy Policy. We shall notify registered users by email in case of a substantial modification.
12. Contact
In the event that you wish to exercise your rights, or in the event of other questions or remarks regarding our Privacy Policy, you can contact us via the following details.
Coöperatie Mino.law U.A.
Koningin Wilhelminaplein 1
1062 HG Amsterdam
The Netherlands
KvK: 42103359
Email: privacy@mino.law
General inquiries: hello@mino.law
Privacy contact:
privacy@mino.law