— LEGAL / 01 OF 04

Privacy Policy

EFFECTIVE 24 AUGUST 2026·VERSION 1.0·DELAWARE, USA·REVIEW ANNUALLY

This Privacy Policy explains how Miaste Stack Inc. collects, uses, and protects personal information when you visit our website or engage us as a client. Read it carefully. If anything is unclear, email privacy@miastestack.com.

— 01 / WHO WE ARE

Who we are.

Miaste Stack Inc. ("Miaste Stack," "we," "us," or "our") is a Delaware corporation providing AI agent engineering services to businesses. This Privacy Policy explains how we collect, use, and protect personal information when you visit miastestack.com or interact with us as a prospective or current client.

For personal information we process on behalf of our clients — for example, transcripts of calls handled by an AI agent we've deployed for one of our clients — we act as a data processor and our clients act as data controllers. Those relationships are governed by our Data Processing Agreement, available on request or attached to our Master Services Agreement.

— 02 / INFORMATION WE COLLECT

What we collect.

Information you give us directly:

  • Contact details (name, email, phone number, company name) when you fill out our intake form or email us
  • Business information you share during discovery calls or written correspondence
  • Payment and billing details, processed by our payment provider — we do not store card numbers on our systems

Information collected automatically when you use our website:

  • IP address, browser type, device information, referring URL
  • Pages viewed, time on site, and general usage patterns
  • Cookies and similar technologies (see Section 09)

Information we do NOT collect through our website:

  • Sensitive categories such as health, biometric, or precise location data
  • Any data about your customers or end users when you are simply browsing our marketing site
— 03 / HOW WE USE INFORMATION

How we use it.

We use the information we collect to:

  • Respond to your inquiries and provide the services you request
  • Send transactional communications such as proposals, invoices, and service updates
  • Improve our website, offerings, and internal operations
  • Comply with legal, tax, and accounting obligations
  • Protect against fraud, abuse, and unauthorized use

We do not sell personal information. We do not use website visitor data to train AI models.

— 04 / HOW WE SHARE INFORMATION

Who we share it with.

We share personal information only with:

  • Service providers who help us operate our business — hosting, email, analytics, payment processing — all bound by written confidentiality and data-protection obligations
  • Legal authorities when required by law or valid legal process, and only to the extent required
  • A successor entity in the event of a merger, acquisition, or asset sale, in which case we will notify affected parties

We do not share your information with third parties for their independent marketing purposes.

— 05 / AI AND MACHINE LEARNING

AI processing.

Our website may use AI-powered tools such as chat widgets or analytics classifiers. When you interact with these tools:

  • Your inputs are processed by our AI providers under contractual controls
  • Inputs are not retained by those providers for training their base models
  • Outputs do not constitute automated decisions producing legal or similarly significant effects on you

For AI agents we deploy on behalf of clients, our client is the data controller and their privacy policy governs end-user data. Our processing obligations to the client are documented in our Data Processing Agreement.

— 06 / DATA RETENTION

How long we keep it.

We retain personal information only as long as necessary for the purposes described in this policy:

  • Contact form submissions and prospect correspondence: 24 months from last contact
  • Active client relationship data: for the duration of engagement, plus 7 years afterward for tax, audit, and legal reasons
  • Website analytics: 14 months
  • Backup copies: purged within 90 days of deletion from primary systems

You may request earlier deletion in accordance with Section 08.

— 07 / SECURITY

How we protect it.

We use industry-standard measures to protect personal information:

  • Encryption in transit (TLS 1.3) and at rest (AES-256) inherited from our cloud infrastructure providers
  • Role-based access controls and audit logging for internal systems
  • Regular security reviews and vendor risk assessments
  • Documented incident response procedures

No system is perfectly secure. If we become aware of a security incident affecting your personal information, we will notify you and any applicable regulators as required by law and within the timeframes mandated by applicable jurisdictions.

— 08 / YOUR RIGHTS

What you can ask us to do.

Depending on your jurisdiction, you may have the following rights regarding your personal information:

  • Access — request a copy of the personal information we hold about you
  • Correction — ask us to fix information that is inaccurate or incomplete
  • Deletion — ask us to delete your information, subject to legal retention requirements
  • Portability — receive your information in a structured, machine-readable format
  • Opt-out — decline marketing communications or specific processing activities
  • Non-discrimination — exercise these rights without adverse consequences

California residents (CCPA and CPRA): you have the right to know what personal information we collect, delete it, correct it, and opt out of any sale or sharing of it. We do not sell personal information.

Residents of the EEA, UK, and Switzerland (GDPR and equivalents): you have the right to lodge a complaint with your local supervisory authority.

To exercise any of these rights, email privacy@miastestack.com. We will respond within 30 days and may request verification of your identity before processing your request.

— 09 / COOKIES AND TRACKING

Cookies.

We use a small number of essential and analytics cookies to make our website work and to understand how it is used. Full details are in our Cookie Policy. You can control cookies through your browser settings or, where applicable, through our cookie preferences interface.

— 10 / INTERNATIONAL TRANSFERS

Where your data goes.

We are based in the United States. If you access our services from outside the US, your personal information may be transferred to, stored, and processed in the United States or other jurisdictions where our service providers operate. For transfers of personal information from the EEA, UK, or other regions requiring specific safeguards, we rely on Standard Contractual Clauses, adequacy decisions, or equivalent mechanisms.

— 11 / CHILDREN

Children.

Our services are directed at businesses and are not intended for individuals under the age of 16. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, contact privacy@miastestack.com and we will delete it promptly.

— 12 / CHANGES TO THIS POLICY

Changes.

We may update this Privacy Policy from time to time. Material changes will be reflected in an updated "Effective" date at the top of this page and, where appropriate, communicated directly to active clients. Continued use of our services after an update constitutes acceptance of the updated policy.

— 13 / CONTACT

How to reach us.

Questions about this Privacy Policy, requests regarding your personal information, or notices under applicable data protection laws should be directed to:

privacy@miastestack.com

Miaste Stack Inc.
Delaware, USA

We respond within 30 days of a verified request.