Privacy Policy
Aims Insights Limited (Mimir App)
Mimir is an application developed by Aims Insights Limited to help sports teams and academies understand and enhance individual and collective performance. Privacy is essential to us, and we are committed to respecting and protecting your data. This privacy policy explains:
- Who we are and what we do
- How we collect, use, and protect your personal information
- Your rights regarding your data
1. Scope of This Privacy Policy
This privacy policy applies to users of the Mimir app. It does not cover third-party services that may be accessible through our platform. Aims Insights Limited is not responsible for how third parties handle your data.
2. Who We Are & Our Role in Data Protection
For the purposes of applicable Data Protection Laws, Aims Insights Limited acts as the Data Controller when processing personal data collected directly through the Mimir app. This means we determine how and why your personal data is processed. However, in cases where we provide Mimir to sports teams, academies, or organisations that use the app for their own team insights, we may also act as a Data Processor on their behalf. When this is the case, we process your data based on their instructions and lawful basis.
3. Lawful Basis for Processing
Aims Insights Limited processes personal data based on:
- Contractual necessity – Providing services via the Mimir app
- Legitimate interests – Enhancing app functionality and user experience
- Consent – In cases where explicit user consent is required
By using the Mimir app, you acknowledge that your data will be processed as outlined in this policy.
Information We Collect
We collect different types of information depending on how you interact with the Mimir app and related services.
Information You Provide to Us
When using the Mimir app, we collect and process the following personal data:
- Personal details: Name, date of birth, email address
- Team information: The team or academy you are affiliated with and your role within it
- Questionnaire responses: Data you submit through Mimir's performance and wellness questionnaires
This information helps us provide insights into team performance and individual wellness.
Information Collected from Your Device
When you install or use Mimir, we may collect information from your device, subject to the permissions you grant. This may include:
- Connection data: IP address, device type, and operating system – used to balance service loads and optimise performance
- Location data: If enabled, this may be collected to ensure secure and efficient access to Mimir services
Cookies & Website Interaction Data
When you visit our website, we use cookies to understand how you interact with our content. This helps us improve the user experience by identifying popular sections and ensuring smooth navigation. 🔹 Key points about cookies:
- We do not collect personally identifiable data through cookies.
- We do not use cookies for targeted advertising or marketing.
- You can control or disable cookies through your browser settings.
How We Use Your Data
We use your personal data for the following purposes:
To Provide You with the Mimir Service (Contractual Necessity)
We process your data to:
- Create, register, and manage your user account, ensuring that your information remains accurate and up to date.
- Enable teams and academies to work together in a safe and secure environment.
- Inform you of any changes, modifications, or updates to our services.
- Review, investigate, and address technical issues that may affect your experience.
To Exercise Our Legitimate Interests
We process your data for:
- Quality assurance – Reviewing and assessing the effectiveness of our service.
- Customer support – Providing a responsive service and assisting users when they contact us.
- Internal operations – Including troubleshooting, fraud detection, data quality checks, functional testing, security measures, audits, and statistical analysis to enhance the service.
- Anonymisation and analysis – We anonymise questionnaire responses to allow us and our customers to analyse trends and interpret results. Once anonymised, this data is no longer considered personal data under UK GDPR.
To Comply with Legal and Regulatory Requirements
We may disclose personal data when required to do so by law, including:
- Regulatory obligations – If requested by a relevant regulatory authority.
- Legal requests – In response to law enforcement, court orders, or legal proceedings.
- Protection of rights – If necessary to protect our legal rights, investigate fraud, or ensure user safety.
How We Share Your Data
We only share your data where necessary to provide the Mimir service and to enhance your experience. We never sell your data or use it for marketing purposes.
Sharing of Your Identifiable Data
We may share the minimum necessary personal data with trusted third parties to support Mimir’s functionality:
- Data storage and backup providers – To securely store and protect the information in your account.
- Push notification providers – To send reminders and updates through the app.
- Your employer, academy, or team – To support your performance and well-being, and to evaluate the effectiveness of our services. (We will only share data with your organisation where this is part of an agreed service and subject to appropriate safeguards.)
- SMS and email messaging services – To facilitate communication with you regarding service updates and support.
We ensure that all third-party providers adhere to strict data protection and confidentiality obligations.
Sharing of Anonymous Data
We may share fully anonymised data with researchers to help interpret questionnaire responses and gain insights into user trends. Once anonymised, this data cannot be linked to you. This allows us and our research partners to better understand team dynamics, well-being trends, and performance insights without compromising individual privacy.
How We Keep Your Information Secure
We take the security of your data seriously and implement industry-standard measures to protect it.
Secure Access to Your Data
- You access your information using your personal email and a self-determined password.
- Access to data within the Mimir platform is role-specific, meaning users only have access to the information necessary for their role.
Storage & Encryption
- Your data is securely stored within Amazon Web Services (AWS) in their London region, ensuring compliance with UK and EU data protection laws.
- All data is encrypted both at rest and in transit, using advanced cryptographic protocols to prevent unauthorised access.
Additional Security Measures
We have strict procedures and safeguards in place to minimise unauthorised access or disclosure, including:
- Role-based access controls – Only authorised individuals can access specific data, based on their role.
- Regular security monitoring – We continuously review and update our security practices.
- Incident response – In the event of a security breach, we have processes in place to respond swiftly and mitigate risks.
Important Security Considerations
While we take all reasonable steps to protect your data, no system is 100% secure. If you need to share sensitive information with us, we recommend avoiding email and instead using secure communication channels where available.
How Long We Store Your Information
We retain your personal data for as long as necessary to provide our services or as required by law.
- If you have an active contract, we will retain your data for the duration of the contract.
- If you request data deletion, we will remove your data from our live systems as soon as possible following that request.
- Backup retention: Due to the way our backup systems operate, deleted data may remain in encrypted backups for up to 6 months, after which it is permanently removed. During this period, your data is not actively processed and is only retained for legal or regulatory obligations.
Legal & Regulatory Exceptions
In some cases, we may be required to retain certain information for legal, compliance, or dispute resolution purposes, even after a deletion request.
Your Rights Under UK GDPR
We are committed to upholding your rights regarding your personal data. If you wish to exercise any of these rights, please contact us, and we will respond without undue delay and within regulatory timeframes. Under UK General Data Protection Regulation (UK GDPR), you have the following rights:
Object to Processing
- You can object to us processing your data in certain situations, particularly where we process it based on legitimate interests.
- If you object, we will review our processing and stop unless we have compelling legitimate grounds to continue (e.g., legal obligations).
Restrict Processing
- You can request that we stop processing your data while still allowing us to store it.
- This means we cannot actively use your data but will keep it on record, for example, if you contest its accuracy or object to our use of it.
Be Informed
- You have the right to clear, accessible, and transparent information about how we collect, use, and protect your data.
- This Privacy Policy serves as part of our compliance with this right.
Access Your Information
- You can request access to the personal data we hold about you.
- You can do this by contacting us directly or, if applicable, through your organisation (e.g., coach, academy, or employer).
Correct Your Data (Rectification)
- If any of your information is inaccurate or incomplete, you have the right to request that we correct or update it.
Be Forgotten (Erasure)
- You can request deletion of your data where:
- It is no longer necessary for the purposes we collected it.
- You withdraw consent, and we have no other legal basis for processing.
- You object to processing, and we have no overriding legitimate grounds.
- However, we may be required to retain some data where legally necessary (e.g., compliance, fraud prevention).
Move Your Data (Portability)
- You can request your data in a structured, commonly used, and machine-readable format so you can reuse it elsewhere.
- This applies when we process your data based on consent or contract.
Withdraw Consent
- You can withdraw your consent for processing at any time, and we will stop using your data for the purposes you originally agreed to.
- However, this may mean you will no longer be able to use our services, as we require some data to operate.
- Note: If we process your data based on legal or contractual necessity, we may still need to retain some information.
Complain About Our Use of Your Data
- If you believe we are not handling your data correctly, you can lodge a complaint:
- With us – We will investigate and respond promptly.
- With the UK Information Commissioner’s Office (ICO) – You can report concerns to the ICO at www.ico.org.uk.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, service improvements, or how we handle your data.
- We will notify you of any significant changes via an in-service notification.
- In some cases, we may also notify you via email if required by law or if the changes significantly impact your rights.
- If required, you may need to read and accept the changes before continuing to use our services.
This Privacy Policy should be read in conjunction with our Terms & Conditions, which govern the use of the Mimir app. By activating your user account, you agree to be bound by both.
Contact Us
If you have any questions about this Privacy Policy or how we handle your data, you can contact us at: 📍 Postal Address: Aims Insights Limited 112 Pitmore Road Eastleigh, SO50 4LT 📧 Email: support@aimsinsights.com
🔹 Data Protection Officer (DPO): For data protection enquiries, you can contact our Data Protection Officer (DPO) at: 📧 dpo@aimsinsights.com
If you feel we have not adequately addressed your concerns or wish to escalate a complaint, you can contact the Information Commissioner’s Office (ICO): 📧 Email: casework@ico.org.uk 📞 Phone: 0303 123 1113 🌐 Website: www.gov.uk/data-protection