# Trust and security

> Trust and security at MIRA FIVE: made by Cloo GmbH in Germany, analytics data stored in Germany, two named sub-processors, no cookies by default.

URL: https://mirafive.io/security

MIRA FIVE is made by a German company and hosted in Germany.

MIRA FIVE is made by Cloo GmbH in Auerbach, Germany, and your analytics data is stored and processed on servers in Germany. Collection is first-party: the script runs on your own site, and your data is never shared or sold.

## Four facts about your data

Company

Cloo GmbH, a German company in Auerbach

Hosting

Germany; encrypted backups in Finland (EU)

Sub-processors

Hetzner for hosting, Google Workspace for support email

Collection

First-party, on your own site; never shared or sold

Where your data is hosted is one part of compliance. The rest depends on what you collect and why.

[The full fact sheet](https://mirafive.io/about)

1. [Where does my data live?](#where-data-lives)
2. [What does the script collect?](#what-is-collected)
3. [How do I answer a data request?](#data-requests)
4. [Who can see your numbers?](#account-access)
5. [Who else handles the data?](#sub-processors)

## Where does my data live?

Your analytics data is received, stored and processed on Hetzner servers in Germany. Cloo GmbH, a German company, runs MIRA FIVE.

Hosting

Hetzner, Germany; encrypted backups in Finland (EU)

Company

Cloo GmbH, Reumtengrüner Str. 32B, 08209 Auerbach, Germany

Contact

[hello@mirafive.io](mailto:hello@mirafive.io)

## What does the script collect?

The default setup counts visits without cookies or identifiers. Visitors who consent are followed as people across visits.

Default setup

Visits, pages, channels, campaigns, countries, devices and events

With consent

People across visits, their journeys, funnels and A/B tests

IP address

Used to look up country and region; never stored with your analytics data

Opt-outs and bots

Do Not Track and Global Privacy Control honoured; bots filtered

## How do I answer a data request?

Access, erasure and objection are built into the app. Start from the person's page or the privacy page.

Access

Export what is stored about one person

Erasure

Erase one person's data in a project

Objection

Remove a person from every segment flags use and from every experiment result

Record

Every request is kept in the audit log

## Who can see your numbers?

Team sign-in supports two-factor authentication and passkeys. Agents read by default, the API only reads, and every call is logged.

Sign-in

Two-factor authentication and passkeys

Roles

Owner, admin, member

Agents

Setup changes only after you allow them, flag switches behind a second permission; every call logged

API keys

Optional expiry after 30 days, 90 days or 1 year

## Who else handles the data?

Two companies process customer data on our behalf. The public list names them and the place of processing.

Hosting

Hetzner Online GmbH, Germany

Support email

Google Workspace (Google Ireland); a transfer to the US is possible

Error tracking

Self-hosted in Germany

The full list

[Sub-processors](https://mirafive.io/subprocessors)

## Questions about your data

### Does hosting in Germany make my setup compliant?

Not on its own. Where data is hosted is one part; the rest depends on what you collect and why.

### Does MIRA FIVE set cookies?

Not in the default setup. It counts visits, pages and channels, and follows people across visits only after they consent.

### Do you store IP addresses?

Not with your analytics data. The IP address is used to look up country and region; the access logs in front of our servers keep it for security, for at most 14 days.

### Can an agent change or delete my data?

Agents are read-only by default and never delete anything. They can add setup, such as a goal, once you allow it for that connection; switching flags needs a second permission.

## Ask us before you add the script

Write to hello@mirafive.io with questions about hosting, collection or access.

[Write to us](mailto:hello@mirafive.io?subject=MIRA%20FIVE)[Read the docs](https://docs.mirafive.io)
