How We Handle Your Data

MIPACE has been designed around one simple idea, your information belongs to you. You choose what goes into your profile, what becomes visible through your device, and whether your profile is active at all.

Designed for user control

MIPACE is not designed as a public directory of people's information. Every public profile is created by its owner, activated by its owner, and populated only with information that the owner chooses to provide.

You decide what information is shared

Every MIPACE profile is individually managed. Some people may only wish to include a first name and emergency contact. Others may choose to include communication preferences, sensory information or medical details. MIPACE does not require everyone to provide the same information.

Owner created

The profile owner creates and manages the information attached to their MIPACE account.

Owner controlled

You decide which information is included and whether your public profile is active.

Not publicly searchable

MIPACE profiles are accessed through an NFC interaction rather than appearing as an open public directory.

Update anytime

You can edit your information whenever your circumstances change and deactivate your profile whenever you choose.

What does “provided by the owner” mean?

Information displayed on an active MIPACE profile has been entered by the profile owner or by the person responsible for managing that profile. MIPACE does not automatically create medical records or independently decide what information should appear.

How a MIPACE NFC tap works

Instead of opening a permanent profile address, every device interaction creates a temporary viewing session. This is one of the privacy controls built directly into the MIPACE platform.

1

The device is tapped

A compatible NFC phone is brought close to the MIPACE device to begin the interaction.

2

A unique temporary URL is created

The visitor is not sent directly to the profile's original URL. A new temporary session link is generated specifically for that viewing session.

3

The public profile opens

Only the information selected by the profile owner is displayed during that temporary session.

4

The session automatically expires

When the temporary viewing period ends, reopening that same link shows that the session has expired rather than displaying the profile again.

Adult and child profiles

MIPACE uses additional privacy-focused controls when a profile is specifically identified as belonging to a child. All accounts are treated as adult profiles unless the child option is deliberately selected.

Additional protection for child profiles

Child accounts are designed with higher privacy defaults and reduced public exposure.

Explore how MIPACE handles your data

The sections below explain the different privacy controls built into the platform.

Rather than exposing a permanent public profile URL every time a device is tapped, MIPACE creates a unique temporary URL for that individual viewing session. Once that session expires, the same link no longer provides access to the profile. This reduces the useful lifetime of an access link and forms part of MIPACE's privacy-by-design approach.

The profile owner can deactivate their public profile at any time. When somebody taps the device while the profile is inactive, MIPACE does not display the owner's public information. Instead, the visitor is shown a message explaining that the profile is not currently active.

MIPACE separates operational administration from personal profile content. Administrative functions are designed around managing devices, accounts, organisations and service operations. Individual public profile content is not presented as a searchable database for administrators to browse. Access permissions are intentionally restricted according to the role being performed.

MIPACE includes measures intended to prevent the normal device screenshot function from capturing the public profile while it is being viewed. Combined with temporary access links, this is intended to reduce the opportunity for profile information to remain available after the viewing session ends. No digital system can guarantee that displayed information can never be recorded by another method, such as photographing a screen using another device.

Because every profile is owner managed, it is important that the profile owner keeps information accurate and up to date. If emergency contacts, communication needs or other personal details change, they should be updated through the owner's MIPACE account. If the profile is no longer required, it can simply be deactivated.

Our privacy principles

Privacy is not simply explained in a policy document. Wherever possible, MIPACE is designed so that privacy controls are built directly into the way the platform behaves.

Data minimisation

People only provide the information they feel is appropriate for their own profile.

Temporary access

You decide which information is included and whether your public profile is active.

Child privacy controls

Child profiles include additional settings designed to reduce unnecessary public exposure.

Restricted administration

Operational administrators manage the service without general browsing access to profile content.

What this means in simple terms

MIPACE is built to give useful information when it is genuinely needed while keeping control in the hands of the profile owner.

This page explains the privacy-focused design and operation of the MIPACE platform. It is intended to help users understand how profile information and temporary public access work alongside the MIPACE Privacy Policy and Terms of Service.