Legal

Privacy Policy

Effective July 26, 2026 · Last updated July 26, 2026

1. Scope

This Policy describes how Mizan (“we,” “us”) handles information when an organization uses a Mizan helpdesk instance we operate, and when people use the public site or end-user portal.

2. Roles

Your organization is typically the controller of ticket and attachment content. We act as a service provider for that content when we host Mizan. Do not intentionally submit protected health information (PHI) unless your organization has approved that workflow and required agreements are in place.

3. Information we collect

  • Account data: name, work email, role, authentication sessions
  • Service data: tickets, notes, form answers, email used for ticket sync, encrypted attachments, calendar scheduling metadata if connected
  • Technical data: IP address, user agent, security logs, and diagnostics needed to run the service

We do not sell personal information.

4. How we use information

To provide and secure the service, send notifications, process inbound email into tickets, run SLA/automation features, prevent abuse, and support your organization. We do not use customer ticket content to train public AI models. If your organization connects its own AI provider, that provider’s terms apply.

5. Cookies

We use essential signed session cookies for agent and portal login, plus short-lived cookies for OAuth/security flows. We do not use advertising cookies.

6. Sharing

We share data with infrastructure providers needed to run Mizan (hosting, database, email, DNS) and with identity/calendar providers you connect. We may disclose information if required by law or to protect security and rights.

7. Retention & security

Customer data is kept for the life of the deployment unless deletion is requested or the agreement ends (target deletion window 30–60 days after end of service, subject to legal holds). We use HTTPS, role-based access, and encryption for attachments and selected secrets when configured. No system is perfectly secure.

8. Healthcare / HIPAA

Mizan includes safeguards such as encrypted attachment storage, but using the product does not by itself make a deployment HIPAA compliant. A Business Associate Agreement may be required before PHI is permitted. Until then, avoid placing PHI in tickets.

9. Your choices

Contact your organization’s IT admin to update or remove account access. Organizations may contact us at the address below for instance-level requests.

10. Contact

Ahmad Sheikh Khalil — Mizan
Email: [email protected]
Web: mizan.help

This page summarizes our privacy practices for the live product. A full shareable copy is maintained by the Operator for customer agreements.