Mizo Named Runner-Up in ConnectWise IT Nation PitchIT Competition 2025 Read the full press release

Privacy Policy

Last updated on July 2nd, 2026

Introduction

This Privacy Policy describes how Mizo Technology Inc., carrying on business as Mizo (“Mizo”, “we”, “us”, or “our”), collects, uses, discloses, and protects personal information when you visit our website (mizo.tech), contact us, request a demo, apply for a job, or otherwise interact with our marketing and sales activities.

Mizo is a company based in Québec, Canada. For the activities described in this Policy, Mizo acts as the data controller (or the organization responsible for personal information, within the meaning of Canadian privacy laws).

A note about our product. Mizo provides an AI-powered service desk platform to business customers. When we process personal data contained in a customer’s tickets, knowledge base, or related systems, we do so as a service provider (processor) on that customer’s behalf, under our Data Processing Agreement — not under this Policy. If your information was submitted to Mizo through one of our customers, please direct privacy requests to that customer; we will assist them in responding as required by law.

This Policy is designed to meet the requirements of, among others: Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and Québec’s Law 25; the EU/EEA General Data Protection Regulation (GDPR) and UK GDPR; and US state privacy laws including the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA).

Personal Information We Collect

Information you provide to us:

  • Contact and demo requests — name, email address, company, phone number, and the content of your message when you fill out a form on our website or email us.
  • Support requests — name, email address, and the details of your request when you submit a support ticket.
  • Job applications — name, contact details, résumé/CV, and any other information you include in your application.
  • Newsletter and marketing — email address and communication preferences when you subscribe to our communications.
  • Business relationships — contact details and correspondence when you or your company evaluates, purchases, or partners with Mizo.

Information we collect automatically when you visit our website:

  • Device and usage data — IP address, browser type, operating system, language, referring pages, pages viewed, time and duration of visits, and interactions with the site.
  • Analytics and session data — collected through cookies and similar technologies (see “Cookies and Similar Technologies” below), including session replay data that records how you interact with our pages (clicks, scrolls, form interactions — excluding fields marked as sensitive).
  • Business visitor identification — we use third-party services that associate the IP address of a visit with a company (not an individual) to help us understand which businesses are interested in Mizo.

Information from other sources:

  • Publicly available business contact information and information from business partners, event organizers, or sales intelligence tools, used for business-to-business marketing.

We do not collect sensitive personal information (such as health, biometric, or financial account data) through our website, and we ask that you not submit it through our forms.

How We Use Personal Information and Legal Bases

We use personal information for the following purposes. Where the GDPR or similar laws apply, the corresponding legal basis is indicated:

  • Provide and operate our website and services — respond to your inquiries, demo requests, and support tickets. Legal basis: performance of a contract or steps prior to entering a contract; legitimate interests.
  • Sales and marketing — send you information about our products, events, and news; measure the effectiveness of campaigns; identify businesses interested in Mizo. Legal basis: consent (where required, e.g., email marketing and non-essential cookies); legitimate interests in promoting our business to professional audiences.
  • Analytics and improvement — understand how our website is used, diagnose issues, and improve content and user experience. Legal basis: consent for non-essential cookies; legitimate interests.
  • Recruitment — evaluate job applications and communicate with candidates. Legal basis: steps prior to entering a contract; legitimate interests.
  • Security, legal, and compliance — protect our website and business, prevent fraud and abuse, comply with legal obligations, and establish, exercise, or defend legal claims. Legal basis: legal obligation; legitimate interests.

We do not use personal information collected through our website to make automated decisions that produce legal or similarly significant effects about you.

Cookies and Similar Technologies

We use cookies and similar technologies on our website:

  • Necessary — required for the website to function (for example, remembering your cookie preferences). These do not require consent.
  • Analytics and performance — Google Analytics and Google Tag Manager (traffic statistics, aggregate demographics, browsing behavior) and LogRocket (session replay, to understand usability issues).
  • Marketing and visitor identification — services such as Leadfeeder, Snitcher, and Lemlist, which help us identify the companies visiting our site and measure outreach.

Where required by law (including in the EU/EEA, UK, Québec, and certain US states), non-essential cookies and trackers are used only with your consent, which you can withdraw at any time. You can also control cookies through your browser settings, and you can opt out of Google Analytics using Google’s opt-out browser add-on.

We honor the Global Privacy Control (GPC) signal where required by applicable law: if your browser sends a GPC signal, we treat it as a request to opt out of the sharing of your personal information for cross-context behavioral advertising.

How We Share Personal Information

We do not sell personal information for money, and we do not use or disclose sensitive personal information for purposes other than those permitted by law. We share personal information only as described below:

  • Service providers — companies that process personal information on our behalf and under our instructions, including: Microsoft Azure (hosting, in Canada), Web3Forms (website form processing), Twilio (email/SMS notifications), Microsoft 365 (business communications), Pipedrive (CRM), Lemlist (email outreach), Google (analytics and tag management), LogRocket (session replay), Leadfeeder and Snitcher (business visitor identification). Our current list of service-related sub-processors is published on our Trust page.
  • Advertising and analytics partners — the use of certain analytics and visitor-identification cookies may constitute “sharing” for cross-context behavioral advertising under California law. You can opt out as described in “Your Privacy Rights” below.
  • Professional advisors and authorities — lawyers, accountants, insurers, auditors, and public authorities where required by law, court order, or to protect our rights.
  • Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality protections and, where required, notice to you.

We never share your personal information with third parties for their own independent marketing purposes without your consent.

International Transfers

Mizo is located in Canada, and our core service infrastructure is hosted in Microsoft Azure data centers in Canada. Some of our service providers (listed above) process personal information in the United States or other countries.

  • For individuals in the EU/EEA and UK: Canada benefits from a European Commission adequacy decision for personal data subject to PIPEDA. Where personal data is transferred to countries without an adequacy decision (such as the United States), we rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum.
  • For individuals in Québec: before communicating personal information outside Québec, we assess the protection the information would receive, consistent with Law 25.

You may request more information about these safeguards using the contact details below.

Data Retention

We retain personal information only as long as necessary for the purposes described in this Policy, and then delete or anonymize it. In general:

  • Inquiries and sales prospects — for the duration of our exchanges and up to 3 years after our last meaningful interaction.
  • Job applications — up to 2 years after the end of the recruitment process, unless you ask us to delete your application sooner or consent to a longer period.
  • Analytics data — retained per the configured retention period of each tool (Google Analytics data is retained for up to 14 months).
  • Contractual and accounting records — for the periods required by applicable tax and commercial law.

Security

We protect personal information using technical and organizational measures aligned with recognized industry standards, including encryption in transit and at rest, access controls with multi-factor authentication, network segmentation, monitoring, and regular security reviews. Our security posture, certifications alignment, and sub-processor list are described on our Trust page.

No method of transmission or storage is completely secure. If a breach of security safeguards creates a real risk of significant harm (or otherwise triggers notification obligations under applicable law), we will notify affected individuals and regulators as required.

Your Privacy Rights

Subject to applicable law, you have the right to:

  • Access the personal information we hold about you and receive a copy;
  • Rectify inaccurate or incomplete information;
  • Delete your personal information;
  • Withdraw consent at any time, where processing is based on consent (including unsubscribing from marketing emails via the link in each message);
  • Object to or restrict certain processing, including direct marketing;
  • Portability — receive certain information in a structured, commonly used format.

If you are in the EU/EEA or UK, you also have the right to lodge a complaint with your local supervisory authority (or the UK Information Commissioner’s Office).

If you are in California or another US state with a comprehensive privacy law, you have the right to know, correct, and delete personal information; to opt out of the sale or sharing of personal information (including via the GPC signal); to limit the use of sensitive personal information; and to not receive discriminatory treatment for exercising your rights. We do not sell personal information; to opt out of sharing for cross-context behavioral advertising, decline non-essential cookies or contact us at [email protected]. If we deny your request, you may appeal by replying to our decision, and we will respond as required by your state’s law. You may also use an authorized agent to submit a request on your behalf.

If you are in Canada, you may access and correct your personal information and withdraw consent, subject to legal and contractual restrictions. Québec residents also benefit from the rights provided by Law 25, including the right to request that dissemination of personal information cease (de-indexing). You may file a complaint with the Office of the Privacy Commissioner of Canada or, in Québec, with the Commission d’accès à l’information.

Exercising your rights. Contact us at [email protected]. We may need to verify your identity before acting on a request. We respond within the time required by applicable law (generally 30 days, or 45 days under US state laws). Exercising your rights is free of charge, except where the law permits a reasonable fee for manifestly excessive requests.

Children’s Privacy

Our website and services are intended for business audiences and are not directed to children under 16 (or under 13 in the United States). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.

Changes to This Privacy Policy

We may update this Policy from time to time to reflect changes in our practices or in the law. The “Last updated” date at the top indicates the most recent revision. For material changes, we will provide reasonable notice on this website (or by email, where appropriate). We encourage you to review this Policy periodically.

Contact Us — Privacy Officer

The person responsible for the protection of personal information at Mizo is:

Mathieu Tougas Privacy Officer, Mizo Technology Inc. (Mizo) Québec, Canada Email: [email protected]

For any questions about this Policy, our privacy practices, or to exercise your rights, please contact us at the address above.