Mirro Security & GDPR FAQs
Learn how Mirro handles personal data, privacy, and platform security.
A. GDPR Compliance
1. Where is the data stored, on which server, and for what period?
Your data is securely stored on the Google Cloud Platform (GCP), with servers located in Western Europe. The application ensures high availability through cloud infrastructure and architectural redundancy:- High-availability infrastructure - Deployed across multiple availability zones to
minimize downtime risks. - Auto-scaling: Database and application resources scale automatically to manage traffic spikes.
- Redundant components:Critical services are configured redundantly to eliminate single points of failure.
For more details, visit our Privacy & Security Policy.
2. What happens to employee data upon departure, and how is the "right
to be forgotten" applied?
- When an employee leaves the company, the platform administrator must deactivate their Mirro account.
- Upon deactivation, the employee loses access, but their history and employment documents remain available to the platform administrators.
- The right to be forgotten is managed between the Data Subject (employee) and the Data Controller (employer).
- Mirro acts strictly as a Data Processor. If the Employer requests complete deletion of an employee's data, our system can fully support and execute this operation.
3. How is GDPR consent obtained?
- Under GDPR, Mirro is the Data Processor acting on behalf of the company (Data Controller).
- Explicit employee consent is not required to use the platform if its usage is stipulated within the employer's internal GDPR policies.
- Optionally, the platform can be configured to display a specific, explicit GDPR policy regarding the application's purpose when inviting a new employee.
4. How are security breach notifications handled?
- ZITEC's information security incident management aims to prevent and minimize data compromises.
- Our processes strictly accord with SR ISO/IEC 27001:2022, IEC/FDIS 31010:2009, and ISO/IEC 27005:2008 standards.
- We rely on dedicated IT Operations and Security Operations teams.
- The IT team manages the infrastructure, while the Security team monitors and responds to threats, ensuring continuous information security governance.
B. Technical Aspects, Backup, and Incident Response
- What is the backup policy and how is data integrity ensured? Data integrity is safeguarded at both the application and database levels:
- Transactional consistency: Operations follow ACID properties to prevent data corruption.
- Data validation: Strict schema-level constraints guarantee data accuracy before storage.
- Backups & replication: Data is backed up periodically and replicated across multiple availability zones.
- What security and encryption mechanisms does Mirro use? Mirro leverages advanced GCP encryption mechanisms to protect data:
- Data in transit: Encrypted using TLS 1.2/1.3 protocols.
- Data at rest: Automatically encrypted using the industry-standard AES-256 algorithm with keys managed by Google.
- What is the incident response and data recovery procedure?
- We perform professional Penetration Tests at least once a year.
- Additionally, automated security checks (such as static code analysis and dependency vulnerability scans) are integrated into our CI/CD pipelines to mitigate OWASP Top 10 risks.
- The service is backed by a High Availability architecture with a guaranteed SLA of at least 99.9%.
- For major incidents, our technical configuration supports a Recovery Point Objective (RPO) of under 15 minutes and a Recovery Time Objective (RTO) of a few hours.