Privacy Policy

This privacy statement describes how MiblArt collects and uses the personal information you provide on this website: www.miblart.com. It also describes the choices available to you regarding the use of your personal information and how you can access and update this information.

Last updated: 21 September 2026. This policy replaces the version dated 20 September 2021.

1. WHO WE ARE

MiblArt is a trading name of Miblgroup OÜ, a private limited company incorporated in the Republic of Estonia under registry code 16834670, with its registered office in Tallinn, Estonia. In this policy, “we”, “us”, and “MiblArt” mean Miblgroup OÜ.

For most of the processing described in this policy, we are the controller of your personal data. Section 6 explains the one important situation in which we act instead as a processor on your behalf.

For any questions about this policy or about your data, write to [email protected].

We are not required to appoint a Data Protection Officer and have not appointed one. Data protection enquiries are handled by our management team at the email address above.

2. WHAT THIS POLICY COVERS

This policy covers all the personal data MiblArt handles, not only the data we collect through the website. In particular, it covers:

  • the miblart.com website;
  • our client portal;
  • orders for design, illustration, formatting, marketing materials, and editing services, and everything we exchange with you while we carry them out;
  • our newsletters and marketing emails; and
  • applications from designers, illustrators, editors, and other professionals who want to work with us.

MiblArt is part of Mibl Group. Other Mibl Group brands have their own privacy policies, which apply to their own clients.

3. WHAT PERSONAL DATA WE COLLECT

Website visitors. Your IP address, approximate location derived from it, device and browser type, operating system, the pages you view, the site that referred you, and how you interact with the pages. We collect this through cookies and similar technologies – see section 10.

Enquiries and quote requests. Your name, email address, and any telephone number, pen name, book title, genre, word count, budget, deadline, and description of what you need, together with any brief, mock-up, sample, or reference material you send us.

Client accounts and orders. Your account details, order history, project briefs, the files you upload, drafts and deliverables, your comments and approvals, our correspondence with you, invoices, and your bonus points balance.

Manuscripts and creative materials. Where you order editing, formatting, or a cover, you send us a manuscript, a synopsis, a blurb, or similar text. These may contain personal data about you and about other people. Section 6 explains how we handle that.

Payment data. We use PayPal and Stripe to take payment. They collect your card or account details directly; we do not see or store full card numbers. We receive confirmation of payment, the amount, the date, and a transaction reference. Where you choose to pay in instalments, the payment provider stores your payment method so that each instalment can be charged on its due date.

Newsletter and marketing. Your name and email address, the courses or lists you sign up to, and whether you opened or clicked an email.

Testimonials, reviews, and portfolio. Where you agree to it, your name or pen name, book title, cover image, and the words of your review.

Applicants and contractors. If you apply to work with us as a designer, illustrator, editor, or in any other role: your name, contact details, CV, portfolio or sample edits, rates, availability, references, and, once engaged, the details we need to contract with you and pay you.

We do not deliberately collect special category data – such as data about health, religion, ethnic origin, political opinions, or sexual orientation – about our clients. Such data may nevertheless appear inside a manuscript. Section 6 explains how we handle it.

4. WHY WE USE YOUR DATA, AND ON WHAT LEGAL BASIS

Under the GDPR, we must have a legal basis for everything we do with your data. Ours are:

Answering your enquiry and preparing a quote – to take steps at your request before entering into a contract (Article 6(1)(b)). Where you are enquiring on behalf of someone else, our legitimate interest in responding to business enquiries (Article 6(1)(f)).

Carrying out your order and communicating with you about it – performance of our contract with you (Article 6(1)(b)).

Taking payment, including instalments, and chasing unpaid invoices – performance of our contract (Article 6(1)(b)) and our legitimate interest in being paid (Article 6(1)(f)).

Keeping accounting and tax records – compliance with our legal obligations (Article 6(1)(c)), principally under Estonian accounting and tax law.

Sending you our newsletter and marketing emails – your consent (Article 6(1)(a)). You can withdraw it at any time – see section 12.

Showing your book, name, or review in our portfolio or marketing – your consent (Article 6(1)(a)).

Analytics and advertising cookies – your consent (Article 6(1)(a)), given through our cookie banner.

Keeping the website and the client portal secure, and diagnosing faults – our legitimate interest in running a secure service (Article 6(1)(f)).

Improving our services and understanding which of them people want – our legitimate interest in developing our business (Article 6(1)(f)). We use aggregated data for this wherever we can.

Assessing applications from designers, editors, and other professionals – to take steps at your request before entering into a contract (Article 6(1)(b)), and our legitimate interest in building a professional network (Article 6(1)(f)).

Establishing, exercising, or defending legal claims – our legitimate interest in protecting our position (Article 6(1)(f)).

Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights and concluded that it is not. You can ask us to explain that assessment, and you can object – see section 11.

5. HOW WE PROTECT YOUR DATA

Your personal information is contained behind secured networks and is only accessible by a limited number of persons who have special access rights to such systems and are required to keep the information confidential. Access is granted on a need-to-know basis: the people working on your order can see your files, and other staff cannot.

The measures we apply include encryption of data in transit, access controls and individual accounts for staff and contractors, multi-factor authentication on the systems that support it, written confidentiality undertakings from everyone who handles client files, and regular review of who has access to what.

No system is perfectly secure, and we cannot guarantee that data sent to us over the internet will never be intercepted. If a breach occurs that is likely to result in a high risk to your rights, we will tell you without undue delay, and we will notify the Estonian Data Protection Inspectorate where the law requires it.

6. MANUSCRIPTS AND THE PEOPLE WHO APPEAR IN THEM

This section is the one most likely to matter to you if you have ordered editing, formatting, or a cover, and it is worth reading in full.

Your own data in your manuscript. Anything you write about yourself is yours. We use it only to carry out your order. We do not read manuscripts for any purpose other than doing the work you have asked for.

Other people’s data in your manuscript. A memoir, a biography, a work of narrative non-fiction, a dedication, or an acknowledgements page may name or describe real, identifiable people. It may also reveal sensitive things about them: health, religious or political beliefs, ethnic origin, sexual orientation, or criminal convictions. Fiction can do the same where it draws closely on real events.

Who is responsible for that data. You are. In data protection terms, you are the controller of the personal data you have chosen to include in your manuscript, and we are your processor. We handle that data only on your documented instructions and only to perform your order. We do not decide what goes into your book, and we do not use anything in it for our own purposes.

What that means in practice. We will:

  • process the manuscript only to carry out your order;
  • give access only to the assigned editor, designer, or project manager, and only for as long as they need it;
  • bind every one of them in writing to confidentiality;
  • not disclose the manuscript to anyone else except as set out in section 7;
  • not use it to train, fine-tune, or evaluate any artificial-intelligence or machine-learning system, and not upload it to any service whose terms would permit that;
  • help you respond to requests from people named in the manuscript;
  • tell you promptly if the manuscript is ever caught in a security breach; and
  • delete the manuscript in line with section 9.

If someone in your book contacts us. If a person named or described in a manuscript asks us for access to their data, or asks us to erase or correct it, we will not act on that request ourselves. We will pass it to you as the controller and support you in answering it. The decision is yours, as is the obligation under Article 14 of the GDPR to inform people whose data you have obtained from a source other than themselves.

A formal data processing agreement. The commitments above are contractual, and we will sign a data processing agreement on the terms of Article 28 of the GDPR with any client who asks for one. Publishers, packagers, and agencies should ask for one as a matter of course. Write to [email protected].

What we do not do. We do not read manuscripts to build profiles of authors, we do not sell or share manuscript content with anyone for their own purposes, and we do not quote from a manuscript in our marketing. We will name you or your book publicly only if you have agreed to it.

7. WHO WE SHARE YOUR DATA WITH

We do not sell your personal data, and we do not share it with anyone for their own marketing purposes. We share it with the following recipients. Except where we say otherwise, each acts on our instructions and under a written contract:

  • Designers, illustrators, editors, proofreaders, and project managers. Most of the people who carry out your order are independent contractors rather than employees. They receive only what they need for your project and are bound by written confidentiality obligations. They are prohibited from using your files for any purpose other than your order, and from putting them into generative AI tools.
  • Our client portal provider, which hosts your account, your orders, and the files you upload.
  • HubSpot, our customer relationship management system, which holds enquiries, client records, and our correspondence with you.
  • Dropbox, which we use to store and exchange working files.
  • Google Workspace, which provides our business email.
  • ActiveCampaign, which sends our newsletters and marketing emails.
  • PayPal and Stripe, which process your payments. They act as controllers in their own right, under their own privacy policies.
  • Google (Google Analytics and Google Tag Manager) and Meta, but only where you have consented to analytics or advertising cookies.
  • Stock image, font, and 3D asset vendors, where we buy a licence for your project. We do not send them your personal data beyond what a purchase requires.
  • Our accountants, auditors, bank, and professional advisers.
  • Courts, regulators, and law enforcement, where we are legally required to disclose. Where we are lawfully able to tell you first, we will.
  • A buyer or successor, if we ever sell or reorganise the business. We would tell you before your data moved.

We may change these providers from time to time, and we will update this section when we do.

8. WHERE YOUR DATA GOES

We are based in Estonia, in the European Union. Our team is not. We work with designers, illustrators, editors, and project managers in a number of countries, including Ukraine, and several of the service providers listed in section 7 are based in, or store data in, the United States. Your data therefore travels outside the European Economic Area.

Where a country has been recognised by the European Commission as providing an adequate level of protection – the United Kingdom, for instance – the transfer needs nothing further. Ukraine has not been the subject of such a decision. For transfers to Ukraine, and to any other country without an adequacy decision, we rely on the European Commission’s standard contractual clauses under Article 46 of the GDPR, combined with an assessment of the conditions in the destination country and additional contractual, technical, and organisational safeguards.

For providers in the United States, we rely on certification under the EU–US Data Privacy Framework where the provider holds it, and on standard contractual clauses where it does not.

You can ask us for a copy of the safeguards we use by writing to [email protected].

9. HOW LONG WE KEEP YOUR DATA

We keep personal data only as long as we need it, and then delete it or make it anonymous. Our normal periods are:

Enquiries that do not become orders – 12 months from the last contact.

Client accounts and order records – for as long as the account is open, and for 3 years after your last order.

Design files – 2 years after the order is completed, so that we can produce further formats, an updated edition, or a matching cover for the next book in a series. You can ask us to delete them sooner or to keep them longer.

Manuscripts and editorial deliverables – 12 months after the order is completed, so that we can support the follow-up round and answer questions about the work. You can ask us to delete them sooner, and we will do so within 30 days.

Invoices and accounting records – 7 years, as Estonian accounting law requires.

Newsletter subscriptions – until you unsubscribe, and then a minimal record of your unsubscribe so that we do not email you again.

Applications from professionals we do not engage – 12 months, so that we can come back to you when a suitable project appears, unless you ask us to delete them sooner.

Website analytics – event-level data in Google Analytics is kept for 2 months. Aggregated reports that do not identify you may be kept longer.

We may keep data longer where we need it for a legal claim that has been made or is reasonably expected. Copies may persist in routine backups for a short period after deletion, and are deleted when those backups expire.

10. COOKIES

Cookies are small files that a site or its service provider transfers to your computer’s hard drive through your Web browser (if you allow) that enables the site’s or service provider’s systems to recognise your browser and capture and remember certain information. We use four kinds:

  • Strictly necessary cookies, which make the site and the client portal work – keeping you logged in, remembering what is in your order, and protecting against fraud. These do not require your consent, and the site will not function without them.
  • Functional cookies, which remember your preferences, such as your language.
  • Analytics cookies, which tell us how many people visit, which pages they read, and where they leave. We use Google Analytics for this.
  • Advertising cookies, which let us show our work to people who have visited the site and measure whether our advertising works. These are set by Google and Meta.

If you are in the European Economic Area or the United Kingdom, we set analytics and advertising cookies only if you consent through our cookie banner. You can change or withdraw your choice at any time through the cookie settings on the site, and you can block or delete cookies in your browser – though blocking the strictly necessary ones will break parts of the site.

11. YOUR RIGHTS

The law gives you the following rights over your personal data. They are yours by right, not by our permission.

Access – to be told whether we hold data about you and to receive a copy of it.

Rectification – to have inaccurate data corrected and incomplete data completed.

Erasure – to have your data deleted where we no longer need it, where you withdraw consent we were relying on, or where we have no lawful reason to keep it.

Restriction – to have us pause our use of your data while a dispute about it is resolved.

Portability – to receive the data you gave us in a structured, machine-readable format, and to have it sent to another provider where technically feasible.

Objection – to object to processing we base on legitimate interests. Where you object to direct marketing, we will stop, without exception.

Withdrawal of consent – to withdraw consent at any time, without affecting anything we did lawfully before you withdrew it.

Complaint – to complain to a supervisory authority.

To exercise any of these rights, write to [email protected]. We will reply within one month. If your request is complicated, we may take up to two further months, and we will tell you if so. We may ask you to confirm your identity before we act, so that we do not disclose your data to someone else. There is no charge unless a request is manifestly unfounded or excessive.

Our supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee). If you live in another EU or EEA country, you may also complain to the authority there, or go to the courts of the country where you live.

12. MARKETING

We send newsletters, email courses, and occasional offers only to people who have asked for them. Every email has an unsubscribe link, which works immediately and permanently. You can also write to us, and we will remove you.

Unsubscribing from marketing does not stop the emails we have to send you about an order you have placed – delivery notices, drafts, invoices, instalment reminders, and the like.

13. CHILDREN

Our services are sold to adults and are not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has given us their data, write to [email protected], and we will delete it.

14. AUTOMATED DECISIONS

We do not make decisions about you by automated means alone, and we do not profile you in any way that produces legal effects or similarly significant effects. Quotes, briefs, and editorial assessments are prepared by people.

15. CHANGES TO THIS POLICY

We update this policy when what we do with data changes. The date at the top shows when it was last revised. Where a change materially affects you – a new purpose, or a new category of recipient – we will tell you by email or through the client portal before it takes effect. Earlier versions are available on request.

16. HOW TO CONTACT US

Miblgroup OÜ, trading as MiblArt

Registry code 16834670, Tallinn, Estonia

Email: [email protected]