Privacy Policy – Digital MIAM
Effective Date: 26th October 2025
Last Updated: 10th August 2026
At Digital MIAM, your privacy and trust are critically important to us. This Privacy Policy outlines how we collect, process, store, and protect your personal data when you use our website and services. We are committed to transparency and complying with the UK General Data Protection Regulation (UK GDPR) and the Privacy and Electronic Communications Regulations 2003 (PECR).
1. Who We Are
Digital MIAM is a UK-based digital platform owned and operated by Cypher 7 Limited (Company Number 13557284), a company registered in England and Wales. We are registered with the UK Information Commissioner's Office (ICO) as a data controller under registration reference ZB990848. We help individuals access the Mediation Information and Assessment Meeting (MIAM) process online, offering intelligent survey tools and mediator matching services.
Cypher 7 Limited (trading as Digital MIAM) is the data controller responsible for your personal data.
2. Data We Collect
2.1 We may collect the following types of personal data:
Identity & Contact Information: Name, email address, and contact details provided when signing up or booking.
Case Information: Answers you provide in our MIAM intake survey, which may include sensitive personal and family-related information.
Technical Data: IP address, browser type, device data, and usage statistics for performance and security monitoring.
2.2 Sensitive Personal Data
The nature of family mediation means we may collect information that constitutes "special category data" under UK GDPR, including information relating to:
Health (physical or mental)
Children and family circumstances
Allegations of domestic abuse or safeguarding concerns
Racial or ethnic origin (where relevant to your case)
We process this data only where:
You have given explicit consent by submitting your MIAM intake form;
Processing is necessary for the establishment, exercise, or defence of legal claims;
Processing is necessary to protect your vital interests or those of another person.
We handle all sensitive data with the highest level of care and confidentiality. We do not use your sensitive personal data, or the information you provide in your MIAM intake survey, for marketing purposes.
3. Use of AI and Anonymised Case Analysis
Digital MIAM uses artificial intelligence (AI) to analyse MIAM survey responses and assist in case preparation. We apply the following strict safeguards:
No personally identifiable information (PII) is ever transmitted to the AI system.
All survey data is anonymised prior to processing to prevent re-identification.
The AI's analysis is used solely to support mediators in preparing for your MIAM and to provide you with a structured case summary.
We ensure that AI outputs are reviewed by qualified mediators and are not used as a substitute for professional judgment.
Our AI tools assist in case preparation by analysing anonymised survey responses. However, no solely automated decisions with legal or significant effects are made about you without human review.
All AI-generated outputs are reviewed by qualified mediators before being used in your case. You have the right to request human intervention, express your point of view, and contest any decision that affects you.
4. How We Use Your Information
We process your personal data to:
Deliver, manage, and improve our digital mediation services
Match you with a suitable and qualified mediator
Communicate with you regarding your booking, case progress, or recommendations
Comply with our legal and regulatory obligations
Ensure the security and integrity of our platform
4.1 Marketing About Our Own and Related Services
From time to time we may contact you about our own products and services, and about closely related or associated products and services offered by Cypher 7 Limited and other companies within our group, where these are relevant to family separation, co-parenting, mediation, or post-MIAM support and are offered as an extension of the Digital MIAM service.
We rely on our legitimate interests as the legal basis for these communications, and (where applicable) on the "soft opt-in" under PECR, on the basis that you are an existing client or have enquired about our services and the products we tell you about are similar or closely connected to those you have used. We do not use the sensitive information from your MIAM intake to target or personalise marketing.
You have the right to opt out of marketing communications at any time. There is no charge to opt out, and doing so will not affect the mediation services you receive. You can opt out by using the "unsubscribe" link included in every marketing email we send, or by emailing contact@digitalmiam.co.uk. We will always provide a simple means to opt out in each marketing message.
4.2 Third-Party Partner Services
From time to time we may work with carefully selected third-party partners who offer services related to divorce, family mediation, or post-MIAM support. We will only share your personal data with such a partner where you have given us your explicit, opt-in consent to do so. We do not share your data with these partners unless and until you have given that consent, and you may withdraw it at any time by emailing contact@digitalmiam.co.uk. Any partner we share your data with is required to comply with UK data protection law and to use your data only for the purpose you have consented to.
5. Confidentiality and When We May Disclose Your Information
We treat the information you share with us — including the details in your MIAM intake survey — as confidential, and we handle it with care. Family mediation is also a confidential and, in most respects, legally privileged ("without prejudice") process, which means that what is discussed in mediation generally cannot be relied upon in later court proceedings. The confidentiality and legal privilege of the mediation itself is a matter between you and your mediator and is addressed in your mediation agreement and our Terms of Service.
There are, however, limited circumstances in which we and/or your mediator may need to disclose information, including personal and special category data, even without your consent. These include:
Where there is a risk of harm to a child or a vulnerable adult, or a serious safeguarding concern;
Where you provide financial information — financial disclosure in mediation is treated as "open" and may be used in later court proceedings;
Where we are required to disclose information by law, by a regulator, or by order of a court or tribunal;
Where we are required to make a report under money laundering, proceeds of crime, or terrorism-financing legislation.
Where we make such a disclosure, we rely on our legal obligations, the protection of your or another person's vital interests, or the establishment, exercise, or defence of legal claims as our lawful basis under UK GDPR. We will always seek to handle any disclosure sensitively, to share only what is necessary, and to act in accordance with our professional and legal obligations. In some limited cases — for example, certain reports made under anti-money-laundering or proceeds-of-crime legislation — we may be prohibited by law from telling you that a disclosure has been made.
6. Legal Basis for Processing
We process your data under these legal bases:
Performance of a contract (e.g., to deliver MIAM services)
Your consent (e.g., submission of your MIAM intake survey and processing of special category data)
Our legitimate interests (e.g., improving the platform, ensuring security, and marketing our own and closely related products and services)
Compliance with legal obligations
7. Data Retention
We retain personal data only as long as necessary to deliver our services or comply with legal requirements. Survey data may be stored for up to 6 years for audit and compliance.
8. Data Security
We use appropriate technical and organisational measures to protect your data from unauthorised access, loss, or misuse. This includes:
Secure cloud infrastructure
Encrypted data storage
Access controls and internal audits
Anonymisation techniques for AI analysis
9. Your Rights Under UK GDPR
You have the right to:
Access your personal data
Correct inaccurate or incomplete data
Request erasure (where legally permitted)
Object to or restrict processing
Object to direct marketing at any time
Request data portability
Withdraw consent at any time (where processing is based on consent)
To exercise any of your rights, please contact us at: contact@digitalmiam.co.uk. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
10. Third-Party Service Providers (Sub-Processors)
We use trusted third-party service providers to help deliver our services. These providers process personal data on our behalf and are contractually required to protect your data in accordance with UK GDPR.
Our key sub-processors include:
Provider: Supabase Inc. / Purpose: Database hosting and authentication / Location: Data hosted in UK/EU; company headquartered in USA
Provider: OpenAI Inc. / Purpose: Anonymised case analysis / Location: USA
Provider: Stripe Payments UK Limited / Purpose: Payment processing / Location: UK
Provider: Google LLC / Purpose: Communications / Location: USA
Provider: Plus Five Five, Inc. (trading as Resend) / Purpose: Sending transactional and service-related emails to clients (e.g. account, booking and case notifications, and other service communications) / Location: USA
We put Data Processing Agreements (DPAs) in place with our sub-processors. A full list of sub-processors is available on request by emailing contact@digitalmiam.co.uk.
11. Cookies
Our website may use cookies and similar tracking technologies to enhance functionality and user experience. You can manage your cookie preferences via your browser settings. For more details, please refer to our Cookie Policy.
12. Children's Data
Our services are not intended for individuals under the age of 18 without parental or guardian consent. We do not knowingly collect personal data from children without appropriate safeguards.
13. International Data Transfers
Your personal data is primarily stored on servers located within the United Kingdom and European Economic Area.
However, some of our service providers are based in, or have operations in, countries outside the UK, including the United States. Where personal data is transferred outside the UK, we ensure appropriate safeguards are in place, including:
UK International Data Transfer Agreement (IDTA) or Standard Contractual Clauses (SCCs) approved by the UK Government;
Transfers to countries with a UK adequacy decision (including the EU and, for certified companies, the USA under the UK Extension to the EU-US Data Privacy Framework);
Conducting Transfer Impact Assessments where required to evaluate risks.
Our database provider, Supabase Inc., is headquartered in the United States. We have executed a Data Processing Agreement with Supabase that includes Standard Contractual Clauses. Data at rest is stored in UK/EU data centres. We have conducted a Transfer Impact Assessment for this arrangement.
Our email delivery provider, Plus Five Five, Inc. (trading as Resend), and our AI provider, OpenAI, are also based in the United States. Transfers to these providers are protected by appropriate safeguards, including Standard Contractual Clauses and/or the UK Extension to the EU-US Data Privacy Framework.
You may request a copy of the safeguards we use for international transfers by contacting us at contact@digitalmiam.co.uk.
14. Data Security Incidents
In the unlikely event of a personal data breach that poses a risk to your rights and freedoms, we will:
Notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach, where required by law;
Notify you directly without undue delay if the breach is likely to result in a high risk to your rights;
Take immediate steps to contain and remediate the breach.
We maintain incident response procedures and conduct regular security reviews to minimise the risk of breaches.
15. Changes to This Policy
We may update this Privacy Policy from time to time. If material changes are made, we will notify you via our website or by email. Your continued use of the platform constitutes acceptance of the revised policy.
16. Contact Us
If you have questions, concerns, or wish to exercise your rights under this policy, please contact us:
Email: contact@digitalmiam.co.uk
Website: www.digitalmiam.co.uk
Company: Cypher 7 Limited (trading as Digital MIAM), Company Number 13557284
ICO Registration Reference: ZB990848
Company Address: Available upon written request