
Mimecast and GDPR
CertReports found no public GDPR evidence for Mimecast as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 31 Jul 2018
- Expires or valid through
- 10 Jul 2027
- Scope
- COLLECTING PERSONAL DATA We collect information relating to an identified or identifiable natural person (Personal Data) in a variety of ways including: Through web pages on the Site (e.g. when you request a white paper or complete a form for inquiries); Through responses to an online, email or electronic promotion or survey; or over the telephone, through online forums and social networks; through interaction at tradeshows and events; and through user interaction with our Services. Such personal data may include: Your name, job level, email address, postal address or telephone number; Your title, company name and address; Details of the resources you access on the Site and any data you download; Details of other engagements with Mimecast, such as trade show interactions. USING PERSONAL DATA As it is in our legitimate interests to be responsive to you and to ensure the proper functioning of our products and organization, we will use your personal data in the following ways: For business operations purposes relating to human resource and finance; To assist in responding to your product inquiries, including answering your questions on pricing and technical information relating to Mimecast's services; To learn more about your requirements (through surveys and the like) in support of development of our service; To carry out research on our users' demographics; To request your opinion and feedback on areas of the Site or in connection with our services; At your request to register you for a trial of our Services; and At your request to provide you with a quote for our Services. TECHNICAL INFORMATION COLLECTED AUTOMATICALLY When you visit the Site, our systems automatically collect the following information about your visit. We use automatically collected information to assist us in: providing, improving, and administering the Site; providing customer care and support services; providing security and safety to our Site visitors; monitoring activity usage of the Site; and measuring the effectiveness of the content we serve. COOKIES We (or our vendors) may collect your information using cookies, pixel tags, web beacons, embedded web links, and similar technologies. We use cookies and these similar technologies to: Store your preferences and Settings, Detection of abuse or fraud on the Site; Social Media - Our Site includes certain social media features (such as a “share” or “like” button). Those features are provided by the applicable social media platform (such as Twitter or Facebook). Internet-Based Advertising - We also use automatically collected information to target advertising for our service on third party sites; Showing advertising – We use cookies to record how many visitors have clicked on an advertisement and to record which advertisements you have seen so you don’t see the same one. Analytics – We use cookies to gather usage and performance data for the Site. You can choose to reject certain collection technologies (such as cookies) but then you might not be able to take advantage of many of our features. INFORMATION SHARING AND DISCLOSURE We do not sell or rent your personal data to third parties. We do not share personal data, except as expressly provided in our Privacy Statement. We may share your information with the following recipients: Prospective Partners, Reseller Partners, IT Services Providers located in the United States, United Kingdom, South Africa, Europe, and Australia and our Affiliates. We will disclose your personal data if required to do so to comply with any applicable law or regulation or in response to a legal demand, subpoena, warrant or other similar request, and to any regulatory or law enforcement agency if we believe that such action is necessary to protect the rights, property or personal safety of Mimecast, its customers, the public or any third party.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Mimecast North America, Inc.: Active: SW-US Certification, UK Extension Certification, EU-US Certification | Live pagesha256 e521296223 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is Mimecast GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the Security category) whose GDPR row is verified or vendor-stated, ranked by similarity.