Privacy Policy
Last updated: August 30, 2026
This Privacy Policy (this "Policy") explains how Miso Security, Inc. ("Miso", "we", "our" or "us") collects, uses, shares and protects personal data in connection with www.miso.io and its subdomains (the "Site"). It is a notice rather than an agreement: it is here to tell you what we do with personal data and what rights you have in relation to it, and it asks nothing of you. Your use of the Site is governed separately by our Terms of Use, which refer to this Policy.
Who We Are.
Miso Security, Inc. is a corporation organised under the laws of the State of Delaware, United States, with its registered address at 251 Little Falls Drive, Wilmington, DE 19808. For the purposes of the EU General Data Protection Regulation (Regulation (EU) 2016/679) and the UK General Data Protection Regulation (together, the "GDPR"), Miso is the controller of the personal data described in this Policy, meaning that we decide why and how that data is processed. You can reach us at any time at info@miso.io.
What This Policy Covers.
This Policy covers only the personal data we collect through the Site, which currently consists of a small number of informational pages and a single contact form. It does not cover any product or service that Miso may offer separately, nor any personal data that we may process on behalf of a business customer in the capacity of a processor or service provider, which is governed by our agreement with that customer. Where the Site makes an account available and you choose to create one, the personal data you provide in order to do so is covered by this Policy, and we will update this Policy if what we collect for that purpose goes beyond what is described in Section 3 below.
The Personal Data We Collect.
We deliberately collect as little as possible. The contact form is the only place on the Site where you can give us personal data, and the following describes everything we receive when you use it.
Information you give us.
If you choose to use the contact form, we collect your full name, the name of your company, your role, and your email address, all of which are required in order to submit the form, and your phone number, which is optional. The form does not include a free-text message field, and we ask for nothing else.
Information collected automatically when you submit the form.
When the form is submitted, we also receive a small amount of technical information that you did not type: the date and time of submission; the general type of device you used (for example, "iPhone" or "Windows PC"), derived from information your browser sends with every request; an approximate location, being a city and country that our hosting provider estimates from your IP address; the time zone your device reports; and how long the page was open before you pressed Send, which we use to distinguish people from automated submissions. This information is included in the notification email we receive and is retained for as long as that email is retained. Location estimated from an IP address is approximate and frequently wrong, for example where a virtual private network or a corporate network is in use, and we treat it accordingly.
Your IP address.
Your IP address is used in order to limit the number of submissions that may be made from a single address within a rolling ten-minute window, which is how we prevent the form from being abused. It is held only in the temporary working memory of the server handling the request, it ceases to have any effect once that ten-minute window has passed, and it is discarded entirely when that server is recycled, which happens routinely. It is never written to the notification email, is never stored in any database, is not linked to the details you submit, and is not used to identify you. Separately, our hosting provider may record standard server log information, which can include IP addresses, for the purpose of operating and securing the Site. Those logs are kept under that provider's own retention practices rather than ours.
What we do not collect.
The Site sets no cookies and uses no local or session storage. We use no analytics, no advertising technology, no tracking pixels, no session recording and no third-party trackers of any kind. We do not build profiles of visitors, and we do not track you across other websites. Because we set no cookies and perform no tracking, the Site does not ask you for cookie consent, as there is nothing to consent to.
Why We Use Your Personal Data, and Our Legal Basis for Doing So.
Under the GDPR we must have a legal basis for each purpose for which we use your personal data. Ours are as follows.
To respond to your enquiry.
We use the details you submit, and the technical information described above, in order to read, evaluate and reply to your enquiry, and to conduct any resulting correspondence with you. Our legal basis is our legitimate interests under Article 6(1)(f) of the GDPR, namely responding to people who deliberately ask us to contact them and understanding who is approaching us. Where you contact us with a view to entering into a business relationship with Miso, we also rely on Article 6(1)(b), being steps taken at your request prior to entering into a contract.
To keep the Site secure and to prevent abuse.
We use your IP address, the submission timing, and the technical information described above to detect and block automated and abusive submissions. Our legal basis is our legitimate interests under Article 6(1)(f), namely protecting the Site, our systems and our staff from spam, fraud and misuse.
To comply with the law and to establish or defend legal claims.
Where we are required to do so, we use personal data to comply with a legal obligation to which we are subject, our legal basis being Article 6(1)(c), and, where necessary, to establish, exercise or defend legal claims, our legal basis being our legitimate interests under Article 6(1)(f).
Providing Your Personal Data Is Voluntary.
You are under no statutory or contractual obligation to provide us with any personal data. You are free to browse the Site without giving us anything at all. If you choose not to complete the contact form, the only consequence is that we will not be able to reply to you, because we will have no way of doing so.
We Do Not Send You Marketing.
We use the contact details you provide solely to respond to your enquiry and to conduct the correspondence that follows from it. We do not add you to a mailing list, we do not send you newsletters or promotional messages, and we do not pass your details to anyone else for marketing purposes. If this ever changes, we will update this Policy and, where the law requires it, obtain your consent first.
Who We Share Your Personal Data With.
We do not sell your personal data, we do not rent or trade it, and we do not disclose it to advertising networks, data brokers or social media platforms. We share it only with the following categories of recipients, and only to the extent necessary: (i) our website hosting provider, which operates the servers on which the Site runs; (ii) our email delivery provider, which transmits the notification message generated by the contact form; (iii) our email and productivity provider, which hosts the mailbox in which that message is received and stored; (iv) our professional advisers, such as lawyers, auditors and insurers, where they need the information in order to advise us; (v) public authorities, courts and regulators, where we are legally required to disclose it or where disclosure is necessary to establish, exercise or defend legal claims; and (vi) an acquirer or successor, in the event of a merger, acquisition, reorganisation or sale of all or substantially all of our assets, in which case we will require the recipient to honour this Policy. Each of these providers acts as our processor rather than on its own behalf, which means it may use your personal data only in order to provide its service to us, and never for its own purposes. We also give each of them no more than its role requires: our hosting provider necessarily handles the request itself, whereas our email delivery provider and the provider of our mailbox receive only the notification message that the contact form generates, which does not contain your IP address.
International Transfers of Your Personal Data.
Miso is established in the United States, and the service providers described in Section 7 above are established in the United States as well. If you are in the European Economic Area or the United Kingdom, your personal data therefore reaches a country which is not the subject of a general adequacy decision by the European Commission. Where a transfer of personal data out of the European Economic Area or the United Kingdom requires a safeguard under Chapter V of the GDPR, we rely on an appropriate safeguard for that transfer, most commonly the Standard Contractual Clauses adopted by the European Commission. A copy of the Standard Contractual Clauses relied on for a particular transfer is available from us at info@miso.io.
How Long We Keep Your Personal Data.
We keep the personal data you submit through the contact form, together with the correspondence that follows from it, for twenty-four (24) months from our last substantive contact with you, after which it is deleted. Where your enquiry results in a contractual relationship with Miso, we will retain the data for as long as that relationship continues and for such further period as is necessary to comply with our legal obligations or to establish, exercise or defend legal claims. Your IP address is not part of this retained record: as described in Section 3 above, it is used only in the server's working memory and never reaches the notification email. Copies may remain for a limited period in any backups kept by our service providers, and are removed in the ordinary course of those providers' retention cycles.
How We Protect Your Personal Data.
The Site is served over an encrypted (HTTPS) connection, so what you type into the contact form is encrypted in transit. We apply rate limiting to the form, together with automated checks that block abusive and automated submissions, and every field is validated and length-limited before it is processed. We restrict access to the mailbox that receives contact form submissions to those members of the Miso team who need it, and we require our service providers to maintain security measures appropriate to the data they handle for us. The most effective protection we apply, though, is collecting almost nothing to begin with: there is no visitor database, no analytics store and no tracking record to be breached. That said, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Your Rights.
If you are in the European Economic Area or the United Kingdom, you have the following rights in relation to your personal data. These rights are not absolute, and each is subject to the conditions and exemptions set out in the GDPR.
Access.
You may ask us to confirm whether we hold personal data about you and, if so, to provide you with a copy of it, together with information about how we use it and who we share it with.
Rectification.
You may ask us to correct personal data about you that is inaccurate, and to complete personal data that is incomplete.
Erasure.
You may ask us to delete personal data about you, for example where it is no longer necessary for the purpose for which we collected it, or where you have successfully objected to our use of it.
Restriction.
You may ask us to suspend the use of personal data about you in certain circumstances, for example while we verify its accuracy or consider an objection you have raised.
Portability.
Where we process personal data by automated means on the basis of a contract or your consent, you may ask us to provide it to you, or to another controller, in a structured, commonly used and machine-readable format.
Objection.
You may object at any time, on grounds relating to your particular situation, to our use of personal data about you where we rely on our legitimate interests, which is the basis we rely on for most of what is described in this Policy. If you object, we will stop unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or unless we need the data to establish, exercise or defend legal claims. Because we do not use your personal data for direct marketing, no separate marketing objection is necessary.
Withdrawal of consent.
We do not currently rely on consent as a legal basis for any of the processing described in this Policy. Where we ever do, you will be able to withdraw that consent at any time, without affecting the lawfulness of processing carried out before you withdrew it.
How to Exercise Your Rights.
Write to us at info@miso.io. We will respond without undue delay and in any event within one month of receiving your request, though we may extend that period by up to two further months where the request is complex or where we have received a number of requests, in which case we will tell you within the first month and explain why. Exercising your rights is free of charge, unless your request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline to act. We may need to ask you for information to confirm your identity before we act, in order to make sure we do not disclose your personal data to someone else.
Complaints.
We would prefer to resolve any concern with you directly, so please raise it with us first at info@miso.io. You nevertheless have the right to lodge a complaint with a supervisory authority, in particular in the European Union or European Economic Area member state of your habitual residence, your place of work, or the place where you believe an infringement occurred. If you are in the United Kingdom, the relevant authority is the Information Commissioner's Office.
No Automated Decision-Making.
We do not take decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing, and we do not carry out profiling of the kind described in Article 22 of the GDPR. The automated checks we apply to the contact form are limited to distinguishing genuine submissions from automated ones; they assess the submission, not you, and they evaluate no personal characteristic of yours.
Children.
Consistent with our Terms of Use, the Site is intended for individuals aged thirteen (13) years or older, and if you are between 13 and 18 years of age you should review this Policy with your parent or guardian. The Site is not directed at children, and we do not knowingly collect personal data from anyone under 13. If you believe that a child has provided us with personal data, please contact us at info@miso.io and we will delete it.
Residents of California and Other Jurisdictions.
If you are a resident of California, or of another state or country with comparable privacy legislation, please note in particular that we do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not process it for targeted advertising of any kind; the rights described in Section 11 above, and the contact route described in Section 12, are available to you on the same terms.
Changes to This Policy.
We may update this Policy from time to time, for example to reflect a change in what the Site does or in the law that applies to it. When we do, we will post the revised Policy on the Site and update the "Last updated" date at the top of it. Where a change is material, we will take reasonable steps to bring it to your attention before it takes effect. Because this Policy is a notice rather than an agreement, it does not require your acceptance; the legal bases on which we rely are set out in Section 4 above, and your right to object to them is described in Section 11.
Contact Us.
If you have any question about this Policy or about how we handle your personal data, please write to us at info@miso.io, or by post to Miso Security, Inc., 251 Little Falls Drive, Wilmington, DE 19808, United States.