Legal
Privacy Policy
Last updated: 31 July 2026
1. Who we are
miaHQ is a people-first business-management platform operated by Vivid Vision Designs Ltd, a company registered in England & Wales (company number 16091475), registered office 5 High Street, Husbands Bosworth, Lutterworth, England, LE17 6LJ. In this policy, "miaHQ", "we", "us" mean Vivid Vision Designs Ltd.
For anything in this policy, including any request about your data, contact us at privacy@getmiahq.com (general enquiries: hello@getmiahq.com).
We are registered with the UK Information Commissioner's Office (ICO), registration number ZC203564.
2. The two roles we play
Data-protection law distinguishes the controller (who decides why and how data is used) from the processor (who acts on the controller's instructions). miaHQ is one or the other depending on the data:
- We are a processor for the personal data a customer business puts into miaHQ about its own staff — names, hours, documents, and so on. The customer (the employer) is the controller of that data and decides how it is used. Our handling of it is governed by our Data Processing Agreement (available to business customers on request). If you are an employee of a business that uses miaHQ, your employer's own privacy notice governs that data — this policy does not replace it.
- We are a controller for the data we collect for our own purposes: the people who administer a customer account, visitors to our website, people who ask about the product, and people who contact support.
Sections 4–14 below describe the data we handle as a controller. For staff data we process on a customer's behalf, see your employer and our Data Processing Agreement.
3. If you are an employee using miaHQ
Your employer chose miaHQ and controls your data in it. You can:
- See your data — download a copy of what miaHQ holds about you from Profile → Your data → Download my data.
- Correct your data — edit your own profile details in-app.
- Ask for more — for access, correction, deletion or any other right, contact your employer, who is the controller. We support them in fulfilling those requests.
4. The personal data we handle (as a controller)
| Who | What we collect | Where it comes from |
|---|---|---|
| Account administrators / users | Name, work email, phone, job title, role, sign-in credentials, and (if set) profile photo, two-step-authentication factors | You, or your employer when they set up your account |
| Prospects / enquirers | Name, email, business name, and what you told us | The early-access form, a booking, or an email to us |
| Newsletter subscribers | Name, email, and (optionally) phone, company, role and location | You, when you sign up |
| Website visitors | Strictly necessary cookies and standard server logs | Automatically, when you visit |
| People who contact support | Your name, contact details and the content of your message | You |
| Billing contacts | Billing identity and subscription details; card details are handled by our payment processor, not stored by us | You / our payment processor |
We do not use analytics or advertising trackers, and we do not build advertising profiles. We do not collect location from your device. A weather feature uses only a town or city a company administrator types in settings — never an individual's device location. For the cookies and similar storage we use, see our Cookie Policy.
5. Why we use it, and our legal bases
| Purpose | Legal basis (UK GDPR Art. 6) |
|---|---|
| Providing and securing the service to account holders | Performance of a contract (Art. 6(1)(b)) |
| Keeping the service safe, preventing abuse, and improving the product | Legitimate interests (Art. 6(1)(f)) |
| Billing and taking payment | Performance of a contract; legal obligation for tax records (Art. 6(1)(b), (c)) |
| Responding to enquiries and support | Legitimate interests / steps prior to a contract (Art. 6(1)(f), (b)) |
| Marketing emails to prospects and subscribers | Consent, or legitimate interests where permitted (Art. 6(1)(a)/(f)) — every marketing email carries an unsubscribe link, honoured on receipt |
6. Special category data
Some data a customer stores about its staff (for example a DBS check, a right-to-work document, or an absence that implies health information) can be special category data under Article 9. miaHQ stores this only as a processor, on the customer's behalf and instruction; the customer is responsible for having an Article 9 condition (typically Art. 9(2)(b), employment law). We apply extra safeguards to it — see section 9. We do not use special category data for our own purposes.
7. Who we share it with
We do not sell personal data. We share it with the service providers ("sub-processors") that make miaHQ work, each under a contract that limits them to acting on our instructions. The current list is published on our Trust & security page. In summary: Supabase (database, authentication and file storage; EU/Ireland), Vercel (hosting), Resend and Amazon Web Services (SES) (email), Stripe (billing), Xero (payroll export, only if a customer connects it) and Cal.com (booking a call). Open-Meteo (weather) and Better Stack (uptime monitoring) receive no personal data. We may also disclose data where the law requires it, or to protect our rights, our users, or the public.
8. Sending data outside the UK/EEA
Your core data is stored in the EU (Ireland), and transfers between the UK and the EEA are covered by adequacy. Some providers that help us deliver email, hosting and payments may process limited data outside the UK/EEA. Where they do, we rely on an approved safeguard — the UK Addendum to the EU Standard Contractual Clauses, or equivalent — so the data keeps essentially the same protection it has here.
9. How we protect it
Security measures in the product today include:
- Row-Level Security on every table, so each company's data is isolated at the database, not just in the interface.
- Hashing of secrets — kiosk PINs and two-step recovery codes are stored only as bcrypt hashes; passwords are handled by our authentication provider.
- Encryption of connected-service tokens at the application layer (AES-256-GCM), on top of encryption at rest.
- Short-lived signed links for private documents, with access re-checked on every request.
- Optional two-step sign-in for administrators.
- Controlled staff access. Our own team may access customer accounts to provide support and administration; those internal accounts require two-step sign-in, and support access to an account is recorded with the reason and time.
No system is perfectly secure, but we take these measures seriously and review them. If a personal-data breach occurs, we will notify the ICO and affected people where the law requires.
10. How long we keep it
We keep personal data only as long as we need it for the purposes above, then delete or anonymise it:
- Account data — for as long as your organisation holds an active account with us, and for a limited period afterwards to handle queries, disputes and our own legal obligations.
- Billing and tax records — for as long as tax and accounting law requires (in the UK, generally six years).
- Prospect and marketing data — until you unsubscribe or ask us to stop, after which we keep only a suppression record so we don't contact you again.
For staff data we hold as a processor, retention is the customer's decision; miaHQ provides tools to support it (an opt-in automated retention policy, and a right-to-erasure flow that anonymises a leaver while keeping the anonymised records an employer must retain). Our Data Processing Agreement covers this for business customers.
11. Your rights
Under UK GDPR you have the right to access, correct, delete, restrict, object to, and port your personal data, and to withdraw consent where we rely on it.
- If miaHQ is the controller (your account with us, an enquiry, or support), contact us at privacy@getmiahq.com and we will respond within one month.
- If you are an employee of a business using miaHQ, exercise these rights with your employer (the controller). You can already download your own data in-app from Profile → Your data, and correct your profile details yourself.
You also have the right to complain to the ICO (ico.org.uk), though we'd appreciate the chance to help first.
12. Automated decision-making
miaHQ does not make decisions with legal or similarly significant effects about you by purely automated means, and does not carry out that kind of profiling.
13. Children
miaHQ is a workplace tool and is not directed at children; we do not knowingly collect data from anyone under 16. Where a customer employs workers under 18, that customer, as the controller, is responsible for ensuring an appropriate basis for processing their data.
14. Changes to this policy
We'll update this policy as the product and the law change, and note the "last updated" date at the top. We'll tell administrators about material changes by an in-app notice and/or email.
15. Contact
Vivid Vision Designs Ltd — privacy@getmiahq.com, 5 High Street, Husbands Bosworth, Lutterworth, England, LE17 6LJ. To complain to a regulator: Information Commissioner's Office, ico.org.uk.