mizuiro | 水色
Features Pricing Sign in Get started

Privacy Policy

Last updated: July 2026

Platform: mizuiro (mizuiro.app) · Operator: neoncrayon (Ontario, Canada) · Contact: privacy@mizuiro.app

mizuiro is a people management platform built for organizations that want to take care of their teams. We take privacy seriously. This policy explains what information we collect, how we use it, and what rights you have over it. We've written it to be readable, not to obscure anything.

Our Core Commitments

  • We will never sell your data. Not to anyone, not for any price.
  • We will never sell or share email addresses with third parties for marketing, advertising, or any other commercial purpose.
  • We will never use your data to train AI models - not our own, and not anyone else's.

1. Scope, Eligibility, & Data Protection Roles

1.1 Scope of Application

This policy applies to everyone who interacts with mizuiro, which specifically includes:

  • Account Holders (Managers): The individuals who register an organization account and administer the platform on behalf of their team.
  • Team Members (Supervisors and Employees): The individuals whose workplace information is managed within an organization's active account workspace.
  • Visitors: The individuals who browse the public mizuiro.app website without creating an account or logging into the system.

1.2 Eligibility and Age Limits

You must be at least 18 years old to create an account or use mizuiro. By registering, you confirm that you meet this requirement and are acting on behalf of a legitimate business or organization. mizuiro is not intended for personal or consumer use, and is not designed for use by minors. If we become aware that an account was created by someone under 18, we will terminate that account immediately.

1.3 Data Controller vs. Data Processor Bound

mizuiro is strictly a business-to-business (B2B) tool, meaning that when an organization uses our platform to manage their workforce, the organization acts as the Data Controller for their employees' personal information. In this ecosystem, mizuiro acts exclusively as the Data Processor on the organization's behalf, managing, storing, and hosting records solely on the explicit instructions of the account holder. Employees or team members with questions about how their organization collects, processes, or utilizes their personal data should contact their management team directly.


2. Information We Collect

2.1 Account and Identity Information

When an account holder registers an organization account to administer the platform for their team, we collect their name and professional email address, the name of their organization, a secure account password stored as a one-way cryptographic hash that we cannot read, and an encrypted TOTP authenticator secret used to power mandatory two-factor authentication.

2.2 Platform HR Data (Employee Records)

Managers and supervisors enter information about their team members to run the platform. This information may include:

  • Name, email address, job title, and employment dates.
  • Performance reviews and management notes.
  • Incident records and workplace events.
  • Training records and conference attendance.
  • Expense report parameters.
  • Awards, kudos messages, and recognition records.
  • Leave tracking and attendance logs.
  • Date of birth (optional; used strictly for retirement planning modules).

2.3 Strict Structural Exclusions

mizuiro is not designed or intended to store hard financial or identity data, including government-issued identification numbers (such as Social Insurance Numbers or Social Security Numbers), full credit card numbers, or bank account credentials. Please do not enter this data into the platform.

The platform does support workplace records that touch on sensitive matters, such as incidents and expenses. Where you enter health-related or otherwise sensitive information as part of those records, you are solely responsible for ensuring it complies with the privacy regulations that apply to you.

The prohibited financial and identity data described above is different: it should never be entered. mizuiro does not screen or block what you type, so this rule relies on you. If you enter that data anyway, you do so entirely at your own risk: we accept no responsibility or liability for how it is later accessed, used, exposed, or disclosed, and that responsibility rests with the account holder who allowed it onto the platform. A breach of these terms may also result in termination of your account.

2.4 Usage and Technical Data

When you navigate or log into mizuiro, we automatically collect:

  • IP address and approximate geographic location (restricted to the country level).
  • Browser type, system profile, and version.
  • Login timestamps and session active states.
  • Actions taken within the application, which are written to an immutable audit log for security purposes.

3. How We Use Information & Legal Bases

3.1 Primary Processing Activities

We use the information we collect to:

  • Provide, operate, maintain, and improve the mizuiro platform.
  • Authenticate your identity and keep your account secure via mandatory two-factor authentication.
  • Send critical transactional emails, including account setup links, password resets, and user invitations. We do not send marketing emails.
  • Enforce IP-based and geographic access restrictions configured by your organization.
  • Maintain un-editable audit logs for organizational security and compliance.
  • Respond to and resolve technical customer support requests.
  • Comply with our own legal and financial obligations.

3.2 Workplace Compliance and Electronic Monitoring

Some of mizuiro's features (audit logs, presence tracking, and touchpoints) record workplace activity. How your organization deploys these features may fall under electronic monitoring or employee surveillance laws.

For example, Ontario requires employers with 25 or more employees to maintain a written policy on the electronic monitoring of employees. Meeting this legal obligation and making your team aware of how these features are used is your sole responsibility as the employer, not mizuiro's.

3.3 Legal Basis for European Users

If you access the platform from the European Economic Area (EEA) or the United Kingdom, we process personal data under the following legal bases designated by the GDPR: (1) Performance of a Contract, where processing is necessary to deliver the cloud platform access and administrative services your organization contracted us to provide; (2) Legitimate Interests, to maintain robust system security, verify authentication states, and maintain audit logs to protect against fraud or abuse; and (3) Compliance with Legal Obligations, to satisfy corporate taxation, financial audit trail, or legal reporting mandates.


4. Subprocessors, Data Sharing, & Data Residency

We share data only with a minimal number of trusted sub-service providers (subprocessors) necessary to host and operate the platform. We do not sell your data or share it with advertising networks.

4.1 Data Residency Boundaries

mizuiro's core application servers and primary databases are hosted entirely within a Canadian data centre. Your HR records do not leave Canada in the normal operation of the platform. Our transactional email and billing providers are located in the United States and process only the narrow technical data fields required to execute their specific functions.

4.2 Authorized Subprocessors

Provider Purpose Data Handled Location
DigitalOcean Cloud hosting and managed databases. Core platform infrastructure. Structured application text data and platform databases. mizuiro is not a file storage platform and does not host uploaded documents or attachments. Canada
Mailgun Transactional email delivery. Relays operational account updates, notifications, and setup links. Recipient email addresses and specific transactional message contents. United States
Stripe Secure payment processing. Manages subscription billing. Payment methods, billing addresses, and card details. This data goes directly to Stripe and is never stored on mizuiro servers. United States
MaxMind GeoIP location reference data. Powers country-based access restrictions. No data is sent. Lookups run locally on our own servers against a downloaded copy of the MaxMind database; your IP is never transmitted externally. Local Lookup

We may also disclose information if required to do so by law, court order, or to protect the safety and rights of our users or the general public.


5. Security & Cookies

5.1 System Security Framework

We use multi-layered technical controls to keep your organization's data safe:

  • Passwords are encrypted using one-way cryptographic hashes; they cannot be recovered, only reset.
  • Sensitive data fields are encrypted at rest using AES-256. This includes account credentials (email addresses, TOTP secrets, backup codes) and the text content of sensitive HR records (tasks, training logs, expense text, incident records, awards, and kudos messages). These are decrypted only when requested by an authorized user.
  • All data connections are encrypted using HTTPS (TLS 1.2+).
  • Two-factor authentication (TOTP) is strictly mandatory for all accounts.
  • Session tokens are stored exclusively as cryptographic digests; the raw token is never persisted.
  • Account holders have access to custom IP and geographic location restriction controls.
  • Immutable security audit logs track all administration-relevant changes.

5.2 Cookie Policy

mizuiro uses first-party cookies strictly for essential functions - specifically, to securely keep you signed in between page loads. We do not use advertising cookies, tracking beacons, or third-party analytics scripts. Because we do not deploy tracking technologies that profile users, no cookie consent banner is required on our platform. Disabling cookies in your browser settings will prevent you from logging into or using the platform.


6. Data Retention Lifecycle

We retain your data for as long as your organization's account remains active. If your subscription is cancelled, your trial expires, or a payment fails, your data cycles through these three explicit lifecycle stages before permanent removal:

  • 30-Day Grace Period: The account switches to read-only mode. Administrators can log in, view records, and export data, but cannot add new entries. You can resubscribe during this window to restore full account functions.
  • Locked Phase: You can no longer log into the platform, but your data is safely retained on our servers for one year from the start of the lapse. Resubscribing through support during this window fully restores your data.
  • Purged Status: After one year of inactivity, all HR records - including employee files, reviews, incident text, touchpoints, training logs, expense entries, and account identities - are permanently and irreversibly deleted.

If you actively click to delete your account (rather than letting a subscription lapse naturally), your HR data is removed from our live databases immediately. We cannot recover data deleted by users or purged after the one-year lifecycle.

6.1 Security Log Retention Exceptions

The only data retained after an account purge is a separate set of system security logs (login events, access attempts, and administrative deletions). These are operational metadata logs, not your HR data, and they do not contain the content of employee records. We retain these security logs for up to three years for fraud prevention, legal compliance, and system safety, after which they are destroyed.

6.2 Employer Retention Obligations

Many jurisdictions - including Ontario under the Employment Standards Act - require employers to retain employment records for a minimum duration (typically three years) regardless of whether they close their account with a specific software provider. This is your legal obligation as an employer. Please ensure you export all data before your account reaches the final purge status.


7. Individual Data Rights & Erasure

7.1 Canadian Users (PIPEDA & Provincial Privacy Laws)

Under the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial frameworks (such as BC's PIPA, Alberta's PIPA, and Quebec's Law 25), individuals have the right to access personal information held about them, request corrections to inaccuracies, and withdraw consent to data use (subject to legal or contractual constraints).

Quebec Law 25 Note: Quebec law requires explicit consent before deploying profiling or cross-site tracking scripts. Because mizuiro does not track, profile, or use third-party analytics, there are no tracking scripts to consent to.

7.2 European Economic Area Users (GDPR)

If you are located in the EEA or UK, you maintain the following rights under the GDPR:

  • Right of Access: To request a machine-readable copy of the personal data processed.
  • Right to Rectification: To request the correction of inaccurate or incomplete personal data.
  • Right to Erasure ("Right to be Forgotten"): To request data deletion, subject to overriding legal obligations.
  • Right to Restriction: To limit how data is processed in specific scenarios.
  • Right to Portability: To receive your structured data in a reusable format.
  • Right to Object: To object to processing based purely on our legitimate interests.

7.3 How to Exercise Rights

Because your employer acts as the Data Controller over your workplace records, individual team members seeking to access, correct, or erase their files must submit their requests to their employer first.

If an authorized account holder contacts us at privacy@mizuiro.app to execute an erasure or correction command to fulfill their legal obligations, we will process the instruction within 30 business days.


8. Updates, Attributions, & Contact

8.1 Policy Changes

We may update this policy as our features and global compliance rules evolve. We will notify account holders via email at least 14 days before material changes take effect.

8.2 MaxMind Attribution

This product includes GeoLite2 data created by MaxMind, available from maxmind.com.

8.3 Privacy Inquiries

Questions, erasure requests, or compliance concerns: privacy@mizuiro.app

neoncrayon, Ontario, Canada

← Back to home Terms of Service →

© 2026 mizuiro | 水色. Built with ♥ in Canada by neoncrayon.

Features Pricing Terms of Service