Effective June 8, 2026
Account data (name, email, role, firm), authentication data (hashed credentials, OTP records, session metadata) and the operational data your firm uploads or syncs through ERP bridges.
Strictly to operate the MIZAN platform for you and your clients, including AI-assisted reporting and operations you initiate. We do not train models on your data.
Today our database and file storage run in a Singapore data center and our accounting-engine workspaces run in a Frankfurt (EU) data center — neither is in the Middle East yet. We're planning a move to a UAE/Middle East region as we scale to larger client volumes; until then, data is protected in transit and at rest under the same security controls described in our Security page regardless of region.
Never sold. Shared with sub-processors only as required to operate the platform — see the full list below and in our Data Processing Addendum.
Access, correction, deletion and export — at any time from Settings → Privacy, or by emailing privacy@mizan.team.
privacy@mizan.team · DIFC, Dubai
We use a small set of vetted sub-processors to run MIZAN: Supabase (database, authentication, file storage), Anthropic (AI-assisted analysis and drafting), our Odoo accounting-engine host (AWS, Frankfurt), Resend (transactional email), and Vercel (web hosting). Each is bound by its own data-processing terms; see our Data Processing Addendum for the complete, current list.