Legal
Privacy Policy
Effective July 26, 2026 · Last updated July 26, 2026
1. Scope
This Policy describes how Mizan (“we,” “us”) handles information when an organization uses a Mizan helpdesk instance we operate, and when people use the public site or end-user portal.
2. Roles
Your organization is typically the controller of ticket and attachment content. We act as a service provider for that content when we host Mizan. Do not intentionally submit protected health information (PHI) unless your organization has approved that workflow and required agreements are in place.
3. Information we collect
- Account data: name, work email, role, authentication sessions
- Service data: tickets, notes, form answers, email used for ticket sync, encrypted attachments, calendar scheduling metadata if connected
- Technical data: IP address, user agent, security logs, and diagnostics needed to run the service
We do not sell personal information.
4. How we use information
To provide and secure the service, send notifications, process inbound email into tickets, run SLA/automation features, prevent abuse, and support your organization. We do not use customer ticket content to train public AI models. If your organization connects its own AI provider, that provider’s terms apply.
5. Cookies
We use essential signed session cookies for agent and portal login, plus short-lived cookies for OAuth/security flows. We do not use advertising cookies.
6. Sharing
We share data with infrastructure providers needed to run Mizan (hosting, database, email, DNS) and with identity/calendar providers you connect. We may disclose information if required by law or to protect security and rights.
7. Retention & security
Customer data is kept for the life of the deployment unless deletion is requested or the agreement ends (target deletion window 30–60 days after end of service, subject to legal holds). We use HTTPS, role-based access, and encryption for attachments and selected secrets when configured. No system is perfectly secure.
8. Healthcare / HIPAA
Mizan includes safeguards such as encrypted attachment storage, but using the product does not by itself make a deployment HIPAA compliant. A Business Associate Agreement may be required before PHI is permitted. Until then, avoid placing PHI in tickets.
9. Your choices
Contact your organization’s IT admin to update or remove account access. Organizations may contact us at the address below for instance-level requests.
10. Contact
Ahmad Sheikh Khalil — Mizan
Email: [email protected]
Web: mizan.help
This page summarizes our privacy practices for the live product. A full shareable copy is maintained by the Operator for customer agreements.

