Privacy Notice

1. Current Data Collection
The contact form and newsletter subscription function on mitico.tech have been temporarilydisabled, pending appointment of a GDPR Article 27 EU representative (see Section 6). As a result, thiswebsite does not currently collect personal data submitted directly by visitors through forms.The website may still process limited technical data automatically as visitors browse the site — seeSection 2 (Cookies and Automated Data).

2. Cookies and Automated Data
This website may use cookies and similar technologies to enable core site functionality, and, where applicable, to understand how visitors use the site. Cookies are small text files stored on your device. We categorise cookies as follows:
- Strictly necessary — required for the website to function (e.g. security, load balancing); these cannot be switched off.
- Functional — remember preferences (e.g. language, region).
- Analytics — help us understand visitor behaviour in aggregate.
- Marketing — used to track visitors for advertising purposes.
[Placeholder: a full cookie audit is in progress to confirm which categories above are actually in use, and which specific third-party tools (e.g. analytics or advertising providers) are active on the site. This section will be updated with the confirmed list, including cookie names, purposes, and retention periods, once that audit is complete.]
For visitors in the European Union, Switzerland, and the United Kingdom, cookies other than strictly necessary cookies will only be set with your consent, obtained via a cookie banner presented on your first visit. You can withdraw or change your consent at any time via [placeholder: cookie settings link/mechanism].For visitors elsewhere, applicable local law governing cookies and tracking technologies will be reflected here once confirmed alongside the audit above.
[Open item: confirm what, if any, cookies/analytics tools are currently live on the site (e.g. Google Analytics, hosting logs). If analytics are active, a geo-aware consent banner is required for EU/CH visitors and this section should be expanded accordingly. If no cookies are set beyond strictly necessary ones, this section should say so explicitly.]

3. Who Is Responsible for Your Data (Controller Table)

This table is included for transparency and will apply once data-collection functions are reactivated. It identifies which Mitico group entity is the data controller depending on your location:

[Note: row for Abtikar (UAE) intentionally omitted. They will be added only if it begins collecting personal data directly through the website or a dedicated data-collection channel (e.g. its own branded contact point, or conference lead-capture identifying Abtikar by name).]

4. Why We Would Process Your Data

[To be completed once forms are reactivated: e.g. responding to enquiries, providing requested information, marketing communications following consent.]

5. Legal Bases and Applicable Regimes

  • General Data Protection Regulation (GDPR) — EU visitors
  • Swiss Federal Act on Data Protection (FADP) — Swiss visitors
  • Personal Information Protection and Electronic Documents Act (PIPEDA), and Canada's Anti-Spam Legislation (CASL) if marketing communications are reactivated — Canadian visitors
  • ADGM Data Protection Regulations 2021 — if Abtikar becomes a controller for specific data (see Section 3)
  • CCPA/CPRA (California Consumer Privacy Act, as amended by the California Privacy Rights Act) — notice-and-opt-out model; no GDPR-style "legal basis" requirement — United States visitors, subject to statutory thresholds
  • Other regimes to be added if a controller entry is added for a new region

6. EU Representative

Mitico, Inc. is in the process of appointing a representative in the European Union under Article 27 GDPR. This appointment is required given the nature and extent of Mitico's activities directed at the EU market, and the contact form and newsletter subscription will remain disabled until it is complete. Contact details for the appointed representative will be added to this notice once confirmed.

7. Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, as set out in this notice, and to comply with our legal, regulatory, accounting, or reporting obligations.

[Placeholder: specific retention periods to be confirmed once the contact form and newsletter subscription are reactivated, and aligned with the retention periods already established under the group's intercompany data transfer arrangements. Anticipated categories to be addressed:

  • Contact form enquiries — [placeholder: e.g. retained for the duration of the business relationship plus a defined period thereafter, or deleted after a defined period if no relationship results]
  • Newsletter subscriptions — [placeholder: retained until you unsubscribe, plus a short period to process the unsubscribe request]
  • Cookies and analytics data — [placeholder: to be confirmed alongside the cookie audit referenced in Section 2]

Where personal data is processed by more than one Mitico group entity (see Section 3), each entity applies the retention period applicable to its own processing activity, which may differ by data category and jurisdiction.

At the end of the applicable retention period, personal data is securely deleted or anonymised, unless a longer retention period is required or permitted by law.

8. Your Rights

Depending on your location, you may have rights to access, correct, delete, or restrict the use of your personal data, and to object to certain processing or lodge a complaint with your local data protection authority. Because this website does not currently collect personal data via forms, these rights are described here for transparency and will apply in full once data-collection functions are reactivated.

9. International Transfers

Because the Mitico group operates across multiple jurisdictions through separate, arm's-length entities, personal data collected through this website may be transferred to, and processed by, other Mitico group entities as described in Section 3 above — for example, where an enquiry originating in one region is handled or followed up by the group entity responsible for that territory.

These transfers are governed by an intercompany data transfer agreement between Mitico, Inc., Mitico International Sàrl and Mitico Canada Ltd, which sets out the safeguards, purpose limitations, and security obligations applicable to personal data shared between these entities, reflecting their status as separate, arm's-length group companies rather than a single combined operator.

Where a receiving entity is located outside the European Economic Area, the United Kingdom, or Switzerland, and that jurisdiction has not been recognised as providing an adequate level of data protection, the intercompany agreement incorporates Standard Contractual Clauses (or an equivalent recognised transfer mechanism) to protect the transferred data.

Further information about the safeguards applied to a specific transfer is available on request — see Section 10 (Contact).

10. Contact

Questions about this notice can be directed to: [privacy contact email]

11. Updates to this Notice

This notice will be updated when the contact form and newsletter subscription are reactivated, when an EU representative is appointed, and as the group's data processing activities evolve.