Data protection

Mir.IAM Privacy Policy

How OPNS handles personal data in connection with the Mir.IAM website, product trials, marketplace enquiries and technical support.

Version 1.0Effective 3 September 2026Controller: OPNS SA/NV, BelgiumApplies to LARA · MAYA · PAUL · SARA · ZETI

OPNS builds identity and access management software. We keep the amount of personal data we hold about you deliberately small: business contact details so we can answer you, and the technical information we need to support the products. This policy explains what we collect, why, and what you can ask us to do about it.

1Who we are

The controller of the personal data described in this policy is:

Open Products, Networks & Software NV, operating as OPNS
Franklin Rooseveltplaats 12/24, 2060 Antwerp, Belgium
Enterprise / VAT number BE 0438.031.907
E-mail: mir.iam@opns.net

Mir.IAM is OPNS’s product family for OpenText / NetIQ Identity Manager environments. It comprises LARA (Lightweight Access Review Application), MAYA (Manage All Your Applications), PAUL (Protect & Audit Ubiquitous Libraries), SARA (Smart Access Rights Automation) and ZETI (Zero Trust Improvements). This policy applies to all five.

2What this policy covers

This policy covers personal data that OPNS processes as controller when you:

  • visit www.mir-iam.eu or any Mir.IAM product page;
  • request a product trial or download a trial version;
  • submit a technical support request or report a suspected vulnerability;
  • enquire about a Mir.IAM product through a third-party online marketplace, such as the Microsoft commercial marketplace;
  • correspond with us by e-mail, phone or at an event, or subscribe to product updates;
  • are named as a contact by a customer, prospect, reseller or partner organisation.

It does not cover the personal data that a Mir.IAM product processes inside a customer’s own environment — see section 5, which is the part most people are actually asking about.

3The data we collect, and why

We collect only what we need for the purpose in question. The table sets out each purpose, the categories of data involved, and the legal basis we rely on under the GDPR.

Why we process itWhat we collectLegal basis
Providing a product trial
Giving you access to the trial version, sending you the download links, and following up on your evaluation
First and last name, business e-mail, company, country, job title, phone, the directory type you intend to review, your free-text notes, the product requested, and the fact that you accepted the EULAPerformance of a contract, or steps taken at your request prior to a contract (Art. 6(1)(b))
Handling support requests
Diagnosing and resolving product issues
Your contact details, company, product and version, environment type, severity, your description and reproduction steps, licence or contract reference, and any logs, screenshots or configuration extracts you attachPerformance of a contract (Art. 6(1)(b)) where support is contracted; otherwise our legitimate interest in supporting our products (Art. 6(1)(f))
Marketplace enquiries
Following up when you ask for information about a product on a third-party marketplace
The registration and contact details the marketplace passes to us — typically name, business e-mail, company, country, job title, phone, and the offer and plan you looked at. See section 4Our legitimate interest in responding to a business enquiry you initiated (Art. 6(1)(f)), and steps prior to a contract at your request (Art. 6(1)(b))
Answering enquiries and managing our customer relationshipsBusiness contact details, correspondence, meeting notes, and the organisation and role you act forLegitimate interest in running our business (Art. 6(1)(f)); performance of a contract where one exists (Art. 6(1)(b))
Product and licence administration
Issuing, verifying and renewing licences, and licence compliance
Entitlement records, licence key issuance records, order references, and the contact details attached to themPerformance of a contract (Art. 6(1)(b)); legal obligation for accounting records (Art. 6(1)(c)); legitimate interest in protecting our software (Art. 6(1)(f))
Sending product news
Only where you asked for it
Name, business e-mail, and companyConsent (Art. 6(1)(a)), withdrawable at any time; or legitimate interest for existing customers about products they already use (Art. 6(1)(f))
Running and securing the websiteIP address, browser and device information, pages requested, timestamps, referring page, and error information — in server and platform logsLegitimate interest in operating and securing our website (Art. 6(1)(f))
Legal claims and complianceWhatever is relevant to the matter, from the categories aboveLegal obligation (Art. 6(1)(c)); legitimate interest in establishing, exercising or defending legal claims (Art. 6(1)(f))

Please don’t send us data we didn’t ask for

Support attachments are the one place where personal data reaches us unexpectedly. Before you attach logs, screenshots, directory extracts or configuration files, please redact credentials, tokens, private keys, personal data and any regulated data. If you send us special-category or regulated data without a written agreement covering it, we may delete it or ask you to resubmit a redacted version — as set out in EULA §16.

Providing the data marked required on our forms is necessary for us to act on your request. If you leave it out we may not be able to give you access to a trial version or handle a support case. Everything else is optional.

4Marketplace enquiries

Mir.IAM products are listed on third-party online marketplaces, including the Microsoft commercial marketplace. If you click for more information, request a trial, or otherwise express interest in one of our offers there, the marketplace operator passes your enquiry to us so that we can respond.

That transfer is made by the marketplace operator under its own privacy terms, as its own controller. Once we receive the enquiry, OPNS is the controller of that data and this policy applies to it. We use it only to respond to your enquiry, issue a trial where you asked for one, and keep a record of the enquiry. We do not buy contact lists and we do not enrich these records with data bought from third parties.

For how the marketplace operator itself handles your data, please see that operator’s privacy statement — for the Microsoft commercial marketplace, the Microsoft Privacy Statement.

If you would rather we did not contact you after a marketplace enquiry, e-mail mir.iam@opns.net and we will close the record.

5Data inside the products themselves

Mir.IAM products run in your environment, not ours

Mir.IAM products are deployed inside the customer’s own infrastructure. LARA, for example, is a single virtual machine in the customer’s environment that reads users and their entitlements straight from the customer’s own LDAP directory. The identity data stays in the customer’s environment. OPNS does not host it, does not receive a copy of it, and has no access to it.

Because of that, for the identity data processed by a Mir.IAM product in a customer’s environment:

  • the customer is the controller and decides what data is in scope, who reviews it, how long it is kept, and on what legal basis it is processed;
  • OPNS is not a processor of that data merely by supplying the software, because it never receives it;
  • OPNS becomes a processor only where the customer actually sends us personal data — typically in support attachments, or during professional services. Where that happens, we process it on the customer’s documented instructions under the applicable order and EULA §16.

Mir.IAM products may generate technical, diagnostic and usage information about the software itself. Where OPNS receives such information it is used for support, security, licence administration and product improvement, and OPNS uses it in aggregated or de-identified form only for other purposes, as set out in EULA §16.

6Cookies and how visits are measured

This website sets no cookies. Besides the forms described above, it counts visits and measures page performance using the audience and performance measurement built into the platform that hosts it — see section 7. Neither sets a cookie and neither builds a profile of you, so there is no consent banner because there is nothing to consent to.

A visit is counted from a hash derived from the incoming request, including your IP address. That hash is discarded after 24 hours and cannot be used to recognise you on a later visit or on any other website. OPNS sees the result only in aggregate:

  • the page visited and the site that referred you, if any;
  • approximate location, no more precise than country, region and city;
  • browser, operating system and device type;
  • page-speed readings, such as how quickly the main content appeared.

We do not use advertising, remarketing or cross-site tracking technology on this website, and we do not combine the measurement above with the contact details you give us on a form.

If you change the site’s light or dark theme, that choice is stored in your own browser so the page looks the same on your next visit. It is not a cookie, it is never sent to us, and clearing your browser storage removes it.

7Who we share data with

We do not sell personal data, and we do not share it for third-party advertising or profiling. We share it only with the following categories of recipient, and only as far as necessary.

RecipientWhat forRole
Website and application hosting provider (Vercel)Hosting www.mir-iam.eu, serving the pages, receiving form and webhook submissions, and the audience and performance measurement described in section 6Processor
AirtableRecording trial requests, support requests and marketplace enquiries so we can track and follow them upProcessor
E-mail and productivity providerDelivering and storing the notification e-mails our forms and webhook generate, and our correspondence with youProcessor
Third-party marketplace operators, including MicrosoftPassing us the enquiries you make on their marketplace — see section 4Independent controller (as source)
Authorised resellers and implementation partnersWhere you were introduced by, bought through, or asked to be supported by a partner, so that they can serve youIndependent controller or joint recipient, depending on the arrangement
Professional advisers, auditors and insurersLegal, accounting, audit and insurance purposes, where relevantIndependent controller or processor
Public authoritiesWhere we are legally required to disclose, or to establish, exercise or defend legal claimsIndependent controller

8Transfers outside the EEA

OPNS is based in Belgium and we prefer to keep data in the European Economic Area. Some of the providers listed above are established in, or have infrastructure in, the United States or other countries outside the EEA, so some of the data described in this policy may be transferred there.

Where that happens, we rely on one of the transfer mechanisms permitted by Chapter V of the GDPR — an adequacy decision of the European Commission (including, where applicable, the EU–US Data Privacy Framework for certified recipients), or the European Commission’s Standard Contractual Clauses together with any additional safeguards the transfer requires.

You can ask us for information about the transfers relevant to you, and for a copy of the relevant safeguards, at mir.iam@opns.net.

9How long we keep data

We keep personal data only as long as we need it for the purpose we collected it for, and then delete it or anonymise it.

  • Newsletter subscriptions are kept until you unsubscribe, plus a suppression record so we do not re-add you.

Where a longer period is required by law, or where data is relevant to an actual or anticipated legal claim, we keep it until that need ends.

10How we protect data

We apply technical and organisational measures appropriate to the risk, including transport encryption for our websites and forms, access control on a need-to-know basis, authentication controls on the systems that hold this data, logging, and the confidentiality obligations we place on our staff and subcontractors.

Identity and access management is our own field, and we hold ourselves to it: access to the systems that hold trial, support and enquiry records is limited to the people who need it for their role and is reviewed periodically.

No system is perfectly secure. If a personal data breach affecting your data occurs and it is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority and, where required, you, in line with GDPR Articles 33 and 34.

11Your rights

Subject to the conditions and exceptions in the GDPR, you have the right to:

  • access the personal data we hold about you, and receive a copy of it;
  • rectify data that is inaccurate or incomplete;
  • erase data, where we no longer have a valid reason to keep it;
  • restrict our processing while a dispute about accuracy or lawfulness is resolved;
  • object to processing based on our legitimate interests, and to object at any time to direct marketing — if you object to direct marketing we will stop, without needing a reason;
  • data portability — receive data you gave us in a structured, commonly used, machine-readable format, where we process it by automated means on the basis of consent or a contract;
  • withdraw consent at any time, where we rely on consent. Withdrawal does not affect processing already carried out;
  • not be subject to a decision based solely on automated processing that has legal or similarly significant effects for you. We do not make such decisions.

To exercise a right, e-mail mir.iam@opns.net. We answer within one month, and will tell you if we need longer because the request is complex. We may ask for information to confirm your identity — we will not use it for anything else.

If your request concerns identity data held inside a customer’s Mir.IAM deployment, please contact that organisation: they are the controller of that data and we have no access to it. See section 5. If you contact us instead, we will tell you so, and will assist the customer as required by EULA §16.

12Children

Mir.IAM is enterprise software sold to organisations. Our website and forms are not directed at children and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, contact us and we will delete it.

13Changes to this policy

We may update this policy as our products, providers or legal obligations change. The version number and effective date at the top of the page always tell you which version applies. Where a change materially affects how we use data you have already given us, we will tell you directly — by e-mail, or by a notice on the website — before it takes effect.

14Contact and complaints

For anything in this policy, including requests to exercise your rights:
OPNS — Mir.IAM, Franklin Rooseveltplaats 12/24, 2060 Antwerp, Belgium
mir.iam@opns.net

We would rather hear from you first, but you also have the right to lodge a complaint with a supervisory authority — either the authority in the EU country where you live or work, or the one where the issue arose. Our lead authority is the Belgian Data Protection Authority:

Gegevensbeschermingsautoriteit / Autorité de protection des données
Drukpersstraat 35, 1000 Brussels, Belgium
www.dataprotectionauthority.be

This policy describes OPNS’s processing as a controller. It is informational and does not amend the Mir.IAM End User License Agreement or any data processing terms agreed in an order — see EULA §16.