Privacy & Security at Myndchat
Protecting the data of everyone who trusts us has always been the priority. The platform is built on security and privacy best practices, and our controls are reviewed independently, to keep your data safe at all times.
Certifications
Myndchat works in line with global security standards. Our controls are reviewed independently and on a regular basis.

Cloud Security Alliance
We follow the Cloud Security Alliance STAR registry as our reference for transparency around cloud controls.
Learn more
ISO/IEC 27001
Our information security management system is designed around the controls described in ISO/IEC 27001.
Learn more
SOC 2 Type II
The SOC 2 trust criteria guide how we handle availability, confidentiality and data integrity.
Learn more
ISO 42001
The management of our artificial intelligence systems follows the framework described in ISO/IEC 42001:2023.
Learn moreOfficial Meta Partner
As an official Meta Business Partner, Myndchat follows the platform's security policies and guidelines, including its data security requirements and data use policy.
TikTok Marketing Partner
As a TikTok Marketing Partner, Myndchat follows the platform's security and data use requirements, with periodic review of access and integrations.
Data privacy
We are committed to a high standard of privacy protection, aligned with international regulatory requirements.
General Data Protection Regulation (GDPR)
GDPR regulates the use of EU residents' personal data.
California Consumer Privacy Act (CCPA)
CCPA secures privacy rights and sets consumer protection practices for California residents.
Privacy Policy
Our Privacy Policy and Data Processing Agreement (DPA) are aligned with GDPR and other privacy regulations.
Our security practices
In transit
All data travelling between your browser and Myndchat goes over strong encryption protocols. We use the latest recommended cipher suites to protect traffic, including TLS 1.2 and AES256 encryption.
At rest
Data stored in Myndchat's production network is encrypted. Keys are managed under controlled access, and every access to them is logged and reviewed.
Security FAQ
We work in line with all three frameworks. To talk about compliance documentation, reach our team through the support channel.
Our card processing integrations follow the PCI DSS requirements that apply to the model we use.
International transfers of personal data are covered by standard contractual clauses, described in our Data Processing Agreement.
Yes. Penetration tests are run periodically by independent specialists, and findings enter our remediation queue with deadlines set by severity.
We keep a channel for responsible vulnerability disclosure. If you found something, talk to us before going public.
Production infrastructure runs on cloud providers with recognised certification, and the storage region is documented in our Data Processing Agreement.
Yes, both. In transit over TLS 1.2 with AES256; at rest, with keys under controlled management.
We do not sell data. Sharing is limited to the subprocessors the service needs to run, all of them publicly listed.
The list lives in our privacy centre and is updated whenever a subprocessor is added or removed.
Data is kept while the account exists. On closure it enters a defined retention window and is then deleted from production systems and backups.
AI systems follow the same access management and logging as the rest of the platform, with additional controls over what goes in and out of the models.
Try Myndchat for free
Transform more conversations into sales, leads, and conversions today
Get started