Privacy Policy

Last update: March 2, 2023

This Privacy Policy is meant to help you understand how Mindsmiths collects, uses, and shares Customer Data to operate, improve, develop, and protect Mindsmiths’ Services. This Privacy Policy applies to Customer Data processed as a result of access to or use by our developer customers, (“Developers”, “you”, or “your”) of our Platform (“Platform”), Mindsmiths APIs, websites (“Website”), related tools, and other products or services (collectively, the “Services”) provided by Mindsmiths d.o.o. (“Mindsmiths”, “we”, “us”, or “our”). All capitalized terms not defined in this Privacy Policy will have the meanings set forth in the Mindsmiths’ Terms of Service.


At Mindsmiths, we value customer trust above all else. As such, we strive to help our customers, our customer’s end-users, and our Website visitors maintain control of their information. This Privacy Policy explains our information practices, the kinds of information we may collect, how we intend to use and share that information, and how you can exercise choices you may have in Customer Data.

Mindsmiths processes two broad categories of personal information (known collectively as (“Customer Data”)):

  • As a developer customer (or potential developer customer) of Mindsmiths, you will need to provide us information to create an account and use the Services – we refer to this as “Customer Account Data.”
  • As a developer customer, you may provide us with personal information of your end-users who use or interact with you intelligent agent(s) that you’ve built on Mindsmiths’ Platform – we refer to this information as “Customer End-User Data.”

Mindsmiths distinguishes between these categories of Customer Data because the direct relationship we have with you, our customer, is different than the indirect relationship we have with your end-users. If you are located in the European Economic Area, Mindsmiths is the “controller” of your Customer Account Data and a “processor” of Customer End-User Data.

How Mindsmiths Processes Customer Account Data

We, Mindsmiths, collect and process your Customer Account Data:

  • When you visit a Mindsmiths public-facing Website like, sign up for a Mindsmiths event, or make a request to receive information about Mindsmiths or our products, like a Mindsmiths’ white paper or a newsletter;
  • When you contact Mindsmiths’ Sales Team or customer support team; and
  • When you sign up for a Mindsmiths’ account and use our products and Services.

Broadly speaking, we use Customer Account Data to:

  • Perform our contract with you;
  • Pursue our legitimate interests to:
  1. understand who our customers and potential customers are and their interests in Mindsmiths’ products and Services,
  2. manage our relationship with you and other customers,
  3. provide you with marketing materials,
  4. perform research (including marketing research),
  5. carry out core business operations such as accounting and filing taxes, and
  6. help detect, prevent, or investigate security incidents, fraud and other abuse and/or misuse of our products and services;
  • Comply with any legal obligations we may have; and
  • Carry out other uses which you have consented to.

What Customer Account Data Mindsmiths Processes When You Visit Our Website, Sign Up for a Mindsmiths Event, or Make a Request for Information About Mindsmiths and Why

When you visit our Website, sign up for a Mindsmiths’ event or request more information about Mindsmiths, we will collect information that you submit to us (e.g., through a web form) and we will also collect information automatically using tracking technologies like cookies. We collect this information to fulfill your request, to learn more about who is interested in our products and services, to advertise to you, and to improve our Services.

Information You Share Directly: In some places on Mindsmiths’ Websites, you can fill out web forms to ask to be contacted by our Sales Team, sign up for a marketing or a newsletter, register for a Mindsmiths event, or take a survey. The specific personal information requested on these forms will vary based on the purpose of the form. We will ask you for information necessary for us to provide you with what you request through the form (for example, we will ask you for your email address if you want to sign up for an email newsletter and for your phone number if you want a member of our Sales Team to call you). We may also ask you for additional information to help us understand you better as a customer like your Mindsmiths use case, your company name, or your role at your company. If you sign up to receive marketing communications from Mindsmiths, like a newsletter, you can always choose to opt-out of further communications through a preferences page which will be linked from any marketing email you receive from Mindsmiths. You may also contact us at to communicate your choice to opt-out.

Information We Collect Automatically: When you visit Mindsmiths’ Websites, including our web forms, we and service providers acting on our behalf automatically collect certain information using tracking technologies like cookies, web beacons, and similar technologies. We use this information to understand how visitors to our Websites are using them, which pages and features of the Websites are most popular, and to tailor and deliver advertisements. This helps us understand how we can improve our Websites and track performance of our advertisements.

We may use Google Analytics to collect information regarding visitor behavior and visitor demographics on our Website and Services. For more information about Google Analytics, please visit You can opt out of Google’s collection and processing of data generated by your use of the Services by going to

What Customer Account Data Mindsmiths Processes When You Communicate with Our Sales or Support Teams and Why

If you contact our Sales or support teams, those teams keep a record of that communication, including your contact details and other information you share during the course of the communication. We store this information to help us keep track of the inquiries we receive from you and from customers generally so we can improve our products and Services and provide training to team members. This information also helps our teams manage our ongoing relationships with our customers. Because we store a record of these communications, please be thoughtful about what information you share with our Sales and support teams. We will try to take appropriate measures to protect any sensitive information you share with us, but it is best to avoid sharing any personal or other sensitive information in these communications unless it is necessary for these teams to assist you.

What Customer Account Data Mindsmiths Processes When You Sign Up for and Log into a Mindsmiths Account and Why

When you sign up for a Mindsmiths account, we may ask for certain information like your contact details and billing information so we can communicate with you and so you can pay for our products and Services. We also collect some information automatically, like your IP address, when you login to your account or when an intelligent agent built on Mindsmiths makes requests to our Platform. We use this to understand who is using our Services and how, and to detect, prevent and investigate fraud, abuse, or security incidents.

Information You Share Directly: You can also name your account (or accounts, if you have more than one). We collect this information so we know who you are, we can communicate with you about your account(s), and we can recognize you when you communicate with us through the account portal or otherwise.

We also use your email address to send you information about other Mindsmiths products, services or events in which we think you may be interested in. You can opt out of further marketing communications through your marketing preferences page linked from any marketing email you receive from Mindsmiths. You may also contact us at to communicate your choice to opt-out.

If you upgrade your trial account, we’ll ask you to provide our payment processor with your payment method information like a credit card and/or your billing address. Our payment processor, acting on our behalf, gathers this so we can bill you for your use of our products and Services. Our payment processor will share your billing address with Mindsmiths. Your billing address may also be used by Mindsmiths for tax calculation and audit purposes.

Information We Generate or Collect Automatically

When you sign up for an account with Mindsmiths, we’ll automatically assign each of your Platform intelligent agents unique IDs and we’ll automatically generate API keys for each of your intelligent agents. These are used like a username and password to authenticate end-user accounts onto the Platform. You can use these API keys to retrieve an access token for each end-user account. We keep a record of these access tokens so we know it is you making the requests when your intelligent agent makes requests to our API using these credentials.

In addition, when you use our Platform, we collect your IP address and other information through tracking technologies like cookies, web beacons, and similar technologies. We use this information to understand how customers are using our Platform, who those customers are (if they are a company and the IP address is associated with that company), what country they are logging in from (for analytics and export control purposes), and to help improve the navigation experience.

Note that we also collect the IP address of your devices or servers when you make requests to our Platform. When you use our Platform, we also collect and process the information contained in those interactions.

All information we collect when you sign up for a Mindsmiths’ account and interact with the Mindsmiths’ products and Services may be used to detect, prevent, or investigate security incidents, fraud, or abuse and misuse of our platform and services.

Google API Services User Data Policy

Mindsmiths’ use and transfer of information received from Google APIs to any other app will adhere to Google API Services User Data Policy, including the Limited Use requirements.

Other Customer Account Data We Collect and Why

We may collect information about you from publicly-available sources so we can understand our customer base better. We may also obtain information about your company from third party providers to help us understand our customer base better, such as your industry, the size of your company, and your company’s website URL.

How Long We Retain Your Customer Account Data

Mindsmiths will retain your Customer Account Data as long as needed to provide you with our Services, to operate our business, and comply with applicable laws. If you ask Mindsmiths to delete specific Customer Account Data we will honor this request unless deleting that information prevents us from carrying out necessary business functions, like billing for our services, calculating taxes, or conducting required audits.

How to Make Choices About Your Customer Account Data

Mindsmiths provides you with various choices regarding your Customer Account Data. If you login to your Mindsmiths’ account, you can use the account portal to access, correct, delete Customer Account Data, and/or update your preferences. Please contact for any other requests about your Customer Account Data you cannot make through these self-service tools.

Closing Your Account and Deletion. To request closure or deletion of your Mindsmiths’ account, you can contact us at Within 30 days following your request, Mindsmiths will either delete your Customer Account Data or de-identify it such that it can no longer be used to identify you. You should know that closure and/or deletion of your Mindsmiths’ account will result in you permanently losing access to your account and Customer Data in the account. Please note that certain information associated with your account may nonetheless remain on Mindsmiths’ servers in a de-identified or aggregated form that does not identify you or your end-users. Similarly, Customer Account Data, including personal information, we are required to maintain for legal purposes or for necessary business operations (see “How Long We Retain Your Customer Account Data” section above) will be retained after account closure until no longer needed.

Promotional Communications. You can choose not to receive promotional emails from Mindsmiths by following the unsubscribe/opt-out instructions in those emails. You can also opt-out by contacting Please note that even if you opt out of promotional communications, we may still send you non-promotional messages related to things like updates to our Terms of Service or Privacy Policy, security alerts, and other notices relating to your access to or use of our products and Services.

Cookies and Tracking Technologies. You may stop or restrict the placement of cookies and other similar technologies on your device or remove them by adjusting your preferences as your browser or device permits. The online advertising industry also provides websites from which you may opt out of receiving targeted ads from data partners and other advertising partners that participate in self-regulatory programs. You can access these, and also learn more about targeted advertising and consumer choice and privacy, at,,, and Alternatively, for some devices you may use your device’s platform controls in your settings to exercise choice.

Please note you must separately opt out in each browser and on each device.

“Do Not Track”. Do Not Track (“DNT”) is a privacy preference that users can set in certain web browsers. Please note that we do not respond to or honor DNT signals or similar mechanisms transmitted by web browsers.

Other Choices About Your Customer Account Data. In addition, you can exercise other choices about your Customer Account Data (e.g., accessing it, correcting or amending it, deleting it, restricting or objecting to its use, porting it, or withdrawing consent) by contacting We will process such requests in accordance with applicable laws. To protect your privacy, Mindsmiths will take steps to verify your identity before fulfilling your request.

If you are an end-user of an intelligent agent built on Mindsmiths’ Platform and not a direct customer of Mindsmiths, you should direct any requests relating to your personal information to the relevant intelligent agent developer/provider in accordance with the intelligent agent developer/provider’s own privacy policy.

How Mindsmiths Processes Customer End-User Data

For individuals located in the European Economic Area, when Mindsmiths processes Customer End-User Data, it acts as a “processor.” Mindsmiths will only process Customer End-User Data at the instruction of our customers (i.e., the “controller”).

As a customer, your end-users’ personal information (“Customer End-User Data”) typically shows up on Mindsmiths’ Platform in a few different ways:

  • While using your intelligent agent, end-users approve access to their data during an authentication process, and Mindsmiths begins to sync data they have approved access to into the Platform on your (our customer’s) behalf.
  • Your end-users’ personal information may also be contained in the content of communications you (or your end-users) send or receive using Mindsmiths’ products and Services.

What Customer End-User Data Mindsmiths Processes and Why

We use Customer End-User Data to provide Services to you and your end-users and to carry out necessary functions of our business as a platform as a service (PaaS) provider for development of intelligent agents.

The Customer End-User Data Mindsmiths processes when you, our customer, use our products and Services and the reason Mindsmiths processes it depends on which Mindsmiths products and Services you use and how you use those products and Services. For that reason, the API docs for each of our products and Services are the best place to find information about our processing of Customer End-User Data.

Records containing Customer End-User Data may also be used in debugging or troubleshooting or in connection with investigations of security incidents, bugs, as well as for the purposes of detecting and preventing spam or fraudulent activity, and detecting and preventing network exploits and abuse.

How Long Do We Retain Customer End-User Data

Details regarding how long we retain Customer End-User Data and options around Customer End-User Data will depend on which Mindsmiths’ products and Services you are using, how you are using them, the duration for which you use our Services and if we have a separate Data processing agreement signed between you and us.

Please note that if you request that we delete your Customer End-User Data, it may take up to 30 days for Customer End-User Data to be completely removed from our systems. In some cases, a copy of those records, including the personal information contained in them, may be retained to carry out necessary functions like billing, invoice reconciliation, troubleshooting, and detecting, preventing, and investigating spam, fraudulent activity, and network exploits and abuse. Sometimes legal matters arise that also require us to preserve records, including those containing personal information. These matters include litigation, law enforcement requests, or government investigations. If we have to do this, we will delete the impacted records when no longer legally obligated to retain them. We may, however, retain Customer End-User Data that has been de-identified or aggregated such that your end-user cannot be identified.

When and Why We Share Customer Data

Below are the different scenarios under which we may share Customer Data with third parties.

  • Third-party service providers, Subprocessors, and
    Mindsmiths engages certain third-party service providers, subprocessors, and consultants to carry out certain data processing functions to provide the Services. These third parties are limited to only accessing or using Customer Data to provide services to us and must provide reasonable assurances they will appropriately safeguard Customer Data. An up-to-date list of our subprocessors is located below.
  • Compliance with Legal Obligations. We may disclose Customer Data to a third party if (i) we reasonably believe that disclosure is compelled by applicable law, regulation, legal process or a government request (including to meet national security or law enforcement requirements), (ii) to enforce our agreements and policies, (iii) to protect the security or integrity of our services and products, (iv) to protect ourselves, our other customers, or the public from harm or illegal activities, or (v) to respond to an emergency which we believe in good faith requires us to disclose information to assist in preventing a death or serious bodily injury. If Mindsmiths is required by law to disclose any personal information of you or your end-user, we will notify you of the disclosure requirement, unless prohibited by law. Further, we may object to requests we do not believe to be valid.
  • Affiliates. We may share Customer Data with an affiliate company, like a subsidiary of Mindsmiths d.o.o. We and our subsidiaries will only use the information as described in this Privacy Policy.
  • Business Transfers. If we go through a corporate sale, merger, reorganization, dissolution or similar event, Customer Data may be part of the assets transferred or shared in connection with the due diligence for any such transaction. Any acquirer or successor of Mindsmiths may continue to process Customer Data consistent with this Privacy Policy.

Aggregated or De-Identified Data. Except as necessary to provide the Services, Mindsmiths does not share any de-identified and/or aggregated Customer End-User Data with third parties. However, Mindsmiths may share de-identified and/or aggregated Customer Account Data with third parties for a number of purposes, including research, internal analysis, analytics, and any other legally permissible purposes.

Subprocessors Mindsmiths uses the following subprocessors to assist in providing the Services:

Sub-processor                                  Purpose                               Location

Amazon Web Services                       Cloud Infrastructure            EU

Microsoft Azure                                  Cloud Infrastructure            EU

Google Cloud Platform                      Cloud Infrastructure            EU

International Data Transfers

All information processed by Mindsmiths may be transferred, processed, and stored anywhere in the world, including but not limited to, the European Union or other countries, which may have data protection laws that are different from the laws where you live. We endeavor to safeguard your information consistent with the requirements of applicable laws.

Security of Customer Data

We take steps to ensure that Customer Data is treated securely and in accordance with this Privacy Policy. Unfortunately, the Internet cannot be guaranteed to be 100% secure, and we cannot ensure or warrant the security of any information you provide to us.

Third Party Websites/Applications

The Services may contain links to other websites/applications and other websites/applications may reference or link to our Website or Services. These other domains and websites are not controlled by us. We encourage our users to read the privacy policies of each website and application with which they interact. We do not endorse, screen or approve, and are not responsible for the privacy practices or content of such other websites or applications. Visiting these other websites or applications is at your own risk.

Supervisory Authority

If you are located in the European Economic Area, Switzerland, or the United Kingdom, you have the right to lodge a complaint with a supervisory authority if you believe our processing of your personal information violates applicable law.

Changes to Our Privacy Policy

We may revise this Privacy Policy from time to time at our sole discretion. If there are any material changes to this Privacy Policy, we will notify you as required by applicable law. You understand and agree that you will be deemed to have accepted the updated Privacy Policy if you continue to use the Services after the new Privacy Policy takes effect.

Contact Us

If you have any questions about our privacy practices or this Privacy Policy, please contact us at:; Mindsmiths d.o.o., Zavrtnica 17, HR-10000 Zagreb, Croatia, EU.