Privacy policy
Last updated: October 6, 2026
1. In short
This policy explains what happens to personal data when you use mivochart, the org chart maker, under the EU General Data Protection Regulation (GDPR). The most important points:
- Your account and your charts are stored in the European Union, in Frankfurt (Germany).
- You can make a chart without an account. It then stays in your browser and is not sent to us.
- The people in your charts are usually your colleagues. For that data your organisation decides and we only process it on its behalf (details in section 3).
- We do not sell personal data, we show no advertising and we run no analytics or tracking today.
- You can export everything and delete your account yourself, at any time, in your account settings.
2. Who is responsible
The controller for the processing described in this policy is MIVO STUDIO S.R.L., Strada Teilor, Nr. 49B, Corp C3, Ap. 2, 407280 Sat Floreşti, Comuna Floreşti, Jud. Cluj, Romania ("we", "us"). You can reach us at hello@mivochart.com.
Data protection officer: none appointed; we are not required to appoint one. Questions about privacy can always be sent to hello@mivochart.com.
3. Two roles: your data and the data in your charts
mivochart is mostly used by HR teams and managers who put information about their colleagues into a chart. The GDPR treats that data differently from your own account data, so we play two different roles:
- We are the controller for the data we need to run your account and our business: your email address, sign-in data, plan and billing data, support emails and technical logs. This policy describes that processing in full.
- We are a processor for the content of your charts (names, job titles, departments, email addresses, photos and so on of the people in them). The organisation that uses mivochart, usually your employer or client, is the controller. It decides what goes into a chart and why, and we process that content only to provide the service, under our data processing agreement (Art. 28 GDPR).
- If you are an employee who appears in a chart: please contact the organisation that made the chart about your data. It is responsible for telling you about the processing and for answering your requests. If you write to us, we will pass your request on to it and help it to answer.
4. Data we process as controller
Depending on how you use mivochart, we process:
- Account data: your email address, your password (stored only as a cryptographic hash by our sign-in provider, never readable by us), the language you chose, and when the account was created and last signed in.
- Sign-in with Google: if you choose it, Google tells us your email address, your name, your profile picture link and your Google account ID. We use the email address for your account; the rest is kept by our sign-in provider as part of the sign-in record. We do not receive your Google password or access to your Google data.
- Plan and billing data, once paid plans are on sale: your plan (Free, Pass or Pro), the Stripe customer and subscription IDs, the price you chose, when your Pass ends or your subscription renews, whether you cancelled, and a record of each Pass purchase (the Stripe checkout and payment references and the number of days). Card details are entered directly at Stripe and never reach us. At checkout Stripe collects your billing name and address and, if you enter one, your VAT ID, to calculate tax and issue the invoice.
- Records of the payment events Stripe sends us (event ID, type and time), so that each one is applied exactly once.
- Share-link settings: whether a link is on, its random token, whether it has a password (the password itself is stored only as a scrypt hash), when it expires, and the date an embedded chart was last loaded (at most once a day), so we can tell you when an embed is paused.
- Emails you send us and our replies.
- Technical data: when you load a page or save a chart, your browser sends your IP address, browser type and the requested address to our hosting provider Vercel, and requests to our database provider Supabase are logged in the same way, for security and to fix errors.
- Rate limiting: when someone enters a share-link password, we count attempts per IP address and link to block password guessing. These counters live only in our server's memory for up to 15 minutes and are not written to a database.
5. Chart content we process for our customers
When you or your organisation use an account, the charts are stored as documents in our database. A chart can contain, for each person: name, job title, department, manager and dotted-line managers, assistant role, work email address, employee number, a photo or a photo link, start date, full-time equivalent (FTE), and any custom fields you add (text, numbers, dates, links, email addresses, phone numbers or choice lists). Charts can also contain open positions, free text on the canvas, and named versions (saved copies of the whole chart).
Photos you upload are made smaller in your browser before upload, which also drops the file's embedded metadata, and are stored in a private storage area. They are only ever shown through links that stop working after one hour.
Files you import (Excel or CSV) are read in your browser; the file itself is not uploaded, only the chart made from it is saved. Exports (PNG, PDF, SVG, PowerPoint, CSV) are also created in your browser.
Please do not put special categories of data into a chart (for example health information, religion or trade union membership) unless your organisation has a legal basis for it. mivochart is not designed for such data.
6. Without an account, and in private mode
You can make a chart without signing up. It is then kept only in your browser's storage on your device (photos in the browser's database) and is not sent to our servers. If you later create an account, the chart is moved into it.
Private mode keeps a chart on your device even when you are signed in: no autosave to our servers, no share links, no versions and no photo uploads, and pasted photo links are not loaded. Clearing your browser data deletes such charts, and we cannot restore them.
7. Share links and embeds: what other people can see
A chart stays private until you turn on its share link. When you do:
- Anyone who has the link can open the chart without an account. They see what the cards show, as you set the chart up: for example names, job titles, departments and, if you chose to show them, email addresses, photos or custom fields. Fields you do not show on the cards, such as employee numbers, hidden email addresses or hidden custom fields, are removed on our server before the chart is sent, so people with the link cannot see them. Only share a chart with people who may see what its cards show.
- People you moved to “Not placed” are left out of the shared chart.
- On paid plans you can protect a link with a password and an expiry date, and embed the chart on another website, such as your intranet. Embeds are shown inside that website; that website's own privacy policy applies to it.
- You can turn a link off at any time, which stops it working immediately.
8. Purposes and legal bases
We only process personal data where the GDPR allows it:
| Purpose | Data | Legal basis |
|---|---|---|
| Creating and running your account, saving and sharing your charts | Account data, chart content, share settings | Contract (Art. 6(1)(b) GDPR). For chart content we act on our customer's instructions (Art. 28 GDPR). |
| Sign-in with Google | Google account data listed in section 4 | Contract (Art. 6(1)(b) GDPR), at your request |
| Selling and billing paid plans, issuing invoices, handling refunds | Plan and billing data | Contract (Art. 6(1)(b) GDPR); keeping accounting records: legal obligation (Art. 6(1)(c) GDPR) |
| Answering your emails | Your message and contact details | Contract or pre-contractual steps (Art. 6(1)(b) GDPR); otherwise our legitimate interest in answering (Art. 6(1)(f) GDPR) |
| Keeping the service secure, preventing abuse and password guessing, fixing errors | Technical data, rate-limit counters | Legitimate interest (Art. 6(1)(f) GDPR) in a secure, working service |
| Storing information on your device that the service needs (sign-in, language, drafts) | Browser storage listed in the cookie notice | Strictly necessary (Art. 5(3) ePrivacy Directive and national law); the further processing: contract (Art. 6(1)(b) GDPR) |
| Product analytics (not active today) | Usage data | Only with your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time |
| Defending or enforcing legal claims | As needed for the case | Legitimate interest (Art. 6(1)(f) GDPR) |
9. Your right to object
Where we rely on legitimate interest (Art. 6(1)(f) GDPR), you can object at any time for reasons arising from your particular situation (Art. 21 GDPR). We then stop, unless we have compelling legitimate grounds or need the data for legal claims. Write to hello@mivochart.com.
10. Who receives data
We use a small number of service providers who process data on our behalf under data processing agreements. They are listed, with what they do and where, on our sub-processors page:
- Supabase: database, sign-in and photo storage, in Frankfurt (Germany).
- Vercel: hosting and delivery of the website and our server functions (region: [OWNER: Vercel function region]).
- Stripe: payments, subscriptions, tax calculation and invoices for paid plans.
- Google: only if you choose sign-in with Google. Google remains responsible for your Google account itself under its own privacy policy.
- Sign-up confirmation and password-reset emails are sent by [OWNER: sender of sign-in emails].
11. Transfers outside the EU
Your account data and charts are stored in the EU (Frankfurt). Some of our providers are companies based in the United States (Supabase, Vercel, Stripe's parent company and Google), so access from outside the EU, for example for support or operations, cannot be ruled out. Where data is transferred to a country without an EU adequacy decision, we rely on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) and, where the provider is certified, on the EU-U.S. Data Privacy Framework (Art. 45 GDPR).
You can ask for a copy of these safeguards at hello@mivochart.com.
12. How long we keep data
We keep your account data and charts for as long as your account exists. When you delete a chart or your account, the data is removed from the live service at once; copies in backups disappear within [OWNER: backup window]. Billing records that the law requires us to keep are kept for 10 years. The retention page has the details for each kind of data.
13. Security
Connections are encrypted, every database table has access rules so that one account cannot read another's charts, photos are stored privately and shared only through links that expire after an hour, and share-link passwords are stored as hashes. The security page describes our measures in plain language, including what we do not (yet) do.
14. Cookies, browser storage and analytics
We only store on your device what the service needs to work: your sign-in session, your language and theme, your browser drafts and backups of unsaved changes, and your cookie choice. This needs no consent. Every item is listed in the cookie notice, and you can review your choice at any time under “Cookie settings” at the bottom of each page.
We do not use analytics, advertising or tracking tools today. We plan to use PostHog (EU cloud) for product analytics; if we switch it on, it will only run after you have agreed in the cookie banner, and we will update this policy and the cookie notice first.
Pasted photo links: if a chart uses a link to a photo hosted elsewhere, your browser loads that photo from the other website, which can see your IP address. Private mode does not load such links.
15. No automated decisions, no selling
We do not make decisions about you based solely on automated processing, including profiling (Art. 22 GDPR). We do not sell or rent personal data, and we do not use your charts for advertising or to train AI models.
16. Your rights
Under the GDPR you have the right to:
- access your personal data (Art. 15 GDPR) and receive a copy; the account export in your settings gives you a ZIP file with your account details, every chart (as JSON and CSV), its versions, share settings and photos;
- have incorrect data corrected (Art. 16 GDPR);
- have your data erased (Art. 17 GDPR); you can delete charts and your whole account yourself;
- restrict processing (Art. 18 GDPR);
- data portability (Art. 20 GDPR);
- object to processing based on legitimate interest (Art. 21 GDPR, see section 9);
- withdraw any consent at any time, without affecting what happened before (Art. 7(3) GDPR).
17. How to exercise your rights, and complaints
Write to hello@mivochart.com. We answer within one month and tell you if we need longer (Art. 12(3) GDPR). We may ask you to confirm your identity first.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the EU country where you live or work. The authority responsible for us is: the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 Bucharest, Romania, anspdcp@dataprotection.ro, www.dataprotection.ro.
18. Do you have to provide data?
An email address is needed to create an account; without it we cannot provide the account features. Everything else is up to you. You can use the editor without giving us any data at all.
19. Children
mivochart is a work tool for adults and is not directed at children. We do not knowingly process personal data of children under 16. If you believe a child has given us personal data, write to hello@mivochart.com and we will delete it.
20. Changes to this policy
We update this policy when the service or the law changes. The date at the top shows the current version. If a change affects how we use your data in a significant way, we will tell you before it takes effect.