Mermix
  • Features
  • Pricing
  • About
  • Contact
Get started free

Privacy Policy

Last updated:

DRAFT — Subject to legal review before publication.

This Privacy Policy describes how Belesiotis Software & Consulting Services, trading as "Belesio SCS" ("we", "us", or "our"), collects, uses, stores, and protects information when you use Mermix ("the Service"). We are committed to protecting your privacy in compliance with the General Data Protection Regulation (GDPR), the Greek Data Protection Act (Law 4624/2019), and other applicable data protection legislation.

1. Data Controller

Belesiotis Software & Consulting Services Single-Member Private Company (ΙΚΕ), trading as "Belesio SCS" — registered seat Pantanassis 1, 73101 Chania, Crete, Greece; GEMI no. 194842158000; VAT / ΑΦΜ EL803336283 — is the data controller for personal data collected through the Service's account management, marketing, and billing functions.

For Customer Data (Jira project data, resource allocations, worklogs, time-off records): the Customer is the data controller and we act as a data processor on the Customer's behalf. Processing is governed by these Terms and, where applicable, a separate Data Processing Agreement (DPA).

Contact for data protection matters: [email protected]

2. Information We Collect

We collect the following categories of personal data:

Account information (provided by you at registration):

  • Full name, work email address, organisation name.
  • Password (stored as a one-way cryptographic hash — we cannot read your password).

Billing information (provided by you when subscribing):

  • Company name, VAT number, billing address, billing country, billing email.
  • Payment card details are collected and processed exclusively by Stripe — we never see, store, or have access to your card number.

Jira integration data (imported from your Jira instance at your direction):

  • Issue keys, titles, assignees, dates, effort estimates, worklogs, sprint data.
  • Jira user profiles: display name, email, avatar URL, Jira account ID.
  • Atlassian OAuth tokens (issued by Atlassian when you grant access to your Jira instance) — stored encrypted (AES-256-GCM) and never logged. You can revoke these tokens at any time from your Atlassian account settings, which immediately disconnects Mermix from your Jira data.

Usage data (collected automatically):

  • Interactions with the planning calendar, reports, settings, and AI Copilot.
  • AI Copilot queries and responses (for credit metering and quality monitoring).
  • Feature usage patterns (anonymised, for product improvement).

Technical and analytics data (collected automatically):

  • IP address — processed server-side for fraud detection; only the country of origin is stored (not the raw IP address).
  • Country of origin — derived from the Cloudflare CF-IPCountry request header.
  • HTTP referrer — stored for marketing analytics (where visitors come from).
  • Browser user agent — for device/browser analytics (anonymised via hashing).
  • Page views on the marketing website — server-side logging, no client-side tracking scripts.

3. Legal Basis for Processing

We process personal data under the following legal bases (GDPR Article 6):

  • Performance of a contract (Art. 6(1)(b)) — processing necessary to provide the Service: account management, Jira synchronisation, billing, email communications.
  • Legitimate interest (Art. 6(1)(f)) — fraud detection (IP rate limiting, disposable email blocking), server-side web analytics, security monitoring, product improvement based on anonymised usage data.
  • Legal obligation (Art. 6(1)(c)) — retention of billing records for tax and accounting compliance (Greek tax law: 7-year retention for invoices).
  • Consent (Art. 6(1)(a)) — only used if we introduce optional marketing communications in the future. We do not currently process data based on consent.

4. How We Use Your Information

  • To provide and operate the Mermix service, including Jira synchronisation, resource planning, and reporting.
  • To process payments and issue invoices via Stripe and Elorus.
  • To send transactional emails: account verification, password reset, trial warnings, billing receipts, ownership transfer, and account cancellation notifications.
  • To provide AI-powered planning assistance via the AI Copilot (see §8).
  • To detect and prevent fraudulent registrations and abuse.
  • To measure website traffic and marketing effectiveness (server-side analytics only).
  • To improve the product based on anonymised usage patterns.

5. Data Storage and Security

Hosting and location: Your data is stored in PostgreSQL databases hosted by Neon (eu-central-1, Frankfurt, Germany). Application servers are hosted by Render (Frankfurt, Germany). All infrastructure is within the European Union.

Tenant isolation: Each organisation's data is logically isolated in a dedicated database schema. One organisation cannot access another's data.

Encryption:

  • In transit: all data is transmitted over TLS 1.2+ (HTTPS).
  • At rest: database encryption provided by the hosting provider.
  • Sensitive fields: Atlassian OAuth tokens are encrypted using AES-256-GCM with a per-deployment key before storage.

Access control: Access to production systems is restricted to authorised personnel only. Administrative portals are protected by additional authentication layers.

6. Data Retention

  • Active accounts: Customer Data is retained for the duration of the active Subscription, subject to plan-specific data retention limits (e.g. worklogs and completed tasks may be pruned based on your plan's retention period).
  • Post-cancellation: After Subscription cancellation or trial expiry, Customer Data is preserved in read-only mode for 30 days (grace period). After 30 days, Customer Data is permanently and irreversibly deleted.
  • Account shell: Identity records, billing history, and invoice data are retained after data deletion for legal, accounting, and resubscription purposes.
  • Billing records: Invoices and payment records are retained for 7 years as required by Greek tax law.
  • Fraud signals: Fraud detection records (anonymised IP country, domain patterns, timestamps) are retained for 12 months.
  • Server-side analytics: Page view logs are retained for 24 months, then aggregated and anonymised.

7. Sub-processors and Third-Party Services

We use the following third-party services (sub-processors) to provide the Service:

  • Neon (neon.tech) — PostgreSQL database hosting, Frankfurt, Germany. Stores all Customer Data.
  • Render (render.com) — Application hosting, Frankfurt, Germany. Runs all application servers.
  • Cloudflare (cloudflare.com) — CDN, DNS, DDoS protection, SSL termination. Processes IP addresses for routing and security. Any transfers of personal data outside the EEA are covered by the EU Standard Contractual Clauses (SCCs).
  • Stripe (stripe.com) — Payment processing. Collects and processes payment card details directly. We never handle card data. Stripe is a PCI DSS Level 1 certified provider.
  • Elorus (elorus.com) — Invoice generation and Greek tax compliance (myDATA/AADE). Receives billing details (company name, VAT, address) for invoice creation. EU-based (Greece).
  • Brevo (brevo.com) — Transactional email delivery. Receives recipient email addresses and email content. EU-based (France). GDPR-compliant.
  • Anthropic (anthropic.com) — AI model provider for the AI Copilot feature. Receives planning data context for AI processing (see §8). US-based, and processing takes place on global cloud infrastructure (Anthropic's own sub-processors include Google Cloud, AWS and Microsoft Azure) — transfers outside the EEA are governed by Standard Contractual Clauses (SCCs). Anthropic's commercial API terms prohibit training on customer data. Anthropic publishes its own sub-processor list at trust.anthropic.com/subprocessors.
  • Jira Cloud (Atlassian) (atlassian.com) — Project management platform. We sync data from your Jira instance at your direction using credentials you provide. Your use of Jira is governed by Atlassian's terms.
  • Nager.Date (date.nager.at) — Public API for public holiday data by country. No personal data is sent.

We will notify you before adding new sub-processors that handle personal data, giving you the opportunity to object.

8. AI Data Handling

When you use the AI Copilot feature, the following data flow occurs:

  • Relevant planning data from your workspace (resource allocations, task details, worklogs, time-off, settings) is included as context in your AI request.
  • Team members are pseudonymised before this context is sent — their names, email addresses, and country are replaced with internal identifiers (e.g. R001), so those personal identifiers are not transmitted to the AI provider. Operational text you author (task titles and descriptions, worklog comments, and the messages you type to the copilot) is sent as written.
  • This data is sent securely (TLS) to Anthropic's API for processing.
  • Anthropic processes the data solely to generate your requested response and does not retain it beyond the request duration.
  • Your data is not used to train, fine-tune, or improve AI models. This is guaranteed by Anthropic's commercial API terms.
  • AI interactions are logged on our servers for credit metering (model used, token count). Query content is not stored beyond the active session.

You may opt out of AI Features at any time. The core planning, scheduling, and reporting functionality works independently of AI.

9. International Data Transfers

Your data is primarily stored and processed within the European Union (Germany). Where data is transferred to service providers outside the EU (specifically Anthropic in the USA), we ensure appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs) — as adopted by the European Commission, incorporated into our agreements with non-EU sub-processors.
  • Data minimisation — only the data necessary for the specific processing purpose is transferred.

10. Cookies and Local Storage

The Service uses two storage mechanisms — both strictly necessary and exempt from consent under the ePrivacy Directive (Article 5(3)):

  • Planner application (your workspace, e.g. yourcompany.mermix.io) — browser local storage only (no cookies). Stores the JWT authentication token and user interface preferences (theme, calendar zoom level, active portfolio selection).
  • Account portal (myaccount.mermix.io) — a single first-party session cookie (mermix_myaccount, HttpOnly, SameSite=Strict, Secure in production, 24-hour lifetime) required to maintain the login session. No tracking, no third-party.

Our marketing website (portal.mermix.io) uses server-side analytics only. No cookies, no tracking scripts, and no client-side storage are used on the marketing site. No consent banner is required.

We do not use advertising cookies, tracking pixels, or third-party analytics scripts anywhere in the Service or on our website.

11. Your Rights

Under the GDPR, you have the following rights regarding your personal data:

  • Right of access (Art. 15) — request a copy of the personal data we hold about you.
  • Right to rectification (Art. 16) — request correction of inaccurate personal data.
  • Right to erasure (Art. 17) — request deletion of your personal data ("right to be forgotten"), subject to legal retention obligations.
  • Right to restrict processing (Art. 18) — request limitation of processing in certain circumstances.
  • Right to data portability (Art. 20) — receive your personal data in a structured, commonly used, machine-readable format.
  • Right to object (Art. 21) — object to processing based on legitimate interest.
  • Right to withdraw consent (Art. 7(3)) — where processing is based on consent, withdraw at any time.

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. If you are unsatisfied with our response, you have the right to lodge a complaint with your national data protection authority. For Greece, the supervisory authority is the Hellenic Data Protection Authority (HDPA / ΑΠΔΠΧ): www.dpa.gr.

12. Children

The Service is designed for business use and is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 16, we will take steps to delete it promptly.

13. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:

  • Notify the relevant supervisory authority (HDPA) within 72 hours of becoming aware of the breach, as required by GDPR Article 33.
  • Notify affected users without undue delay if the breach is likely to result in a high risk to their rights and freedoms, as required by GDPR Article 34.
  • Document the breach, its effects, and the remedial actions taken.

14. Data Protection Officer

Given the current scale of our operations, we have not appointed a formal Data Protection Officer (DPO). For all data protection matters, please contact us at [email protected]. We will appoint a DPO if and when required by the scale of our processing activities under GDPR Article 37.

15. Automated Decision-Making

The Service does not make automated decisions that produce legal effects or similarly significantly affect you. The AI Copilot provides suggestions and analysis, but all actions require explicit human confirmation. Fraud detection signals may flag registrations for review, but no registration is automatically rejected based solely on automated processing — all flagged registrations are reviewed.

16. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered users of material changes by email at least 30 days in advance. The updated policy will be posted on this page with a revised "Last updated" date. Continued use of the Service after the effective date constitutes acceptance.

17. Contact

For privacy-related questions or to exercise your data protection rights:

  • Email: [email protected]
  • Contact form: mermix.io/contact
  • Data controller: Belesiotis Software & Consulting Services Single-Member Private Company (ΙΚΕ), trading as “Belesio SCS” — GEMI no. 194842158000, VAT / ΑΦΜ EL803336283
  • Postal address: Pantanassis 1, 73101 Chania, Crete, Greece
Mermix

Resource planning for Jira teams.

Product

  • Features
  • Pricing
  • Get started
  • Help
  • Find your workspace

Company

  • About
  • Contact
  • Security

Legal

  • Privacy policy
  • Terms of service
© Belesio SCS. All rights reserved.