GDPR Compliant ยท EU Hosted

GDPR-compliant website testing, built in Europe

AI testing can expose site content, screenshots, and user-journey data to the testing vendor. When that processing uses US infrastructure or external AI providers, European teams must assess the transfer and its safeguards.

Mira reduces that transfer surface: product-data processing stays in the EU, with AI running on our own EU infrastructure.

What GDPR-compliant website testing actually requires

A testing tool touches real pages, forms, and sometimes personal data. EU hosting helps, but it does not establish compliance on its own. A vendor review should cover:

  • Processing locations and transfers

    Know where product data is processed and which safeguards apply to any third-country transfer.

  • Model-training policy

    Confirm whether site content, screenshots, and test data can feed model-training pipelines.

  • AI subprocessors

    Identify every AI provider that can receive product data and the terms governing that processing.

  • Data-processing terms

    Review the vendor's processing terms, security measures, and responsibilities before approval.

  • Data minimisation and retention

    Limit collection to what the tests need and establish how long each data category is retained.

How Mira meets European requirements

Mira reduces the transfer surface for website testing by keeping product-data processing and AI execution on its own EU infrastructure. These product-design choices support a GDPR review; your organisation remains responsible for assessing its own use case and obligations.

Hosted in Europe

Your data is processed on our own servers in the EU and never leaves our infrastructure.

Designed for European requirements

Product-data location and AI processing were considered in the architecture instead of added as an afterthought.

No training on customer data

Your site content and test data are never used to train AI models. Not yours, not anyone else's.

AI on our own servers

Mira runs AI on its own hardware in the EU. Your data never leaves our infrastructure and is never used for training.

Published privacy information

Review the published handling of personal information, transfers, safeguards, and retention periods in our Privacy Policy.

What the vendors state about data location

Data residency and contractual safeguards are separate questions. This comparison reports what each vendor publishes; it is not a legal-compliance rating.

On narrow screens, scroll the table horizontally to compare transfer terms.

Published product-data locations and transfer documentation for Mira Checks, mabl, and testRigor
Vendor Published product-data location Published transfer / DPA position
Mira Checks Product data and AI processing on Mira-operated infrastructure in the EU Privacy Policy describes published handling of personal information, transfers, safeguards, and retention periods
mabl All customer data stored in the United States Works with customers to review and sign a DPA
testRigor Primary processing facilities in the United States Publishes a DPA with EU Standard Contractual Clauses

Checked 25 August 2026. Sources: mabl data security and privacy and testRigor Data Processing Addendum. For feature differences, see Mira vs mabl and Mira vs testRigor.

Who this matters for

For some teams, EU/GDPR compliance in the QA stack is the first question in every vendor evaluation. Not an afterthought.

Agencies serving EU clients

When you run QA for EU clients, you need to understand where test data goes and which vendors can access it. EU-hosted product processing can reduce cross-border transfer complexity.

Teams with formal privacy review

Procurement and privacy teams need clear answers about processing locations, providers, safeguards, and retention. Use the published information as a starting point for your own review.

Regulated industries

Finance, healthcare, and public-sector teams often face additional contractual, security, or regulatory requirements. Their review must cover the specific data and workflow being tested.

Frequently asked questions

How does Mira support a GDPR review?
Mira keeps product-data processing and AI execution on its own EU infrastructure and does not train models on customer data. Your organisation must still assess its configuration, lawful basis, contracts, and obligations.
Where is my data processed?
On our own servers in the EU. Your site content, screenshots, and test data never leave our infrastructure.
Do you train AI on our website or test data?
No. Your data is never used to train AI models.
Does Mira use third-party AI providers?
No. Mira runs AI on its own servers in the EU. Your data never leaves our infrastructure and is not used to train any models.
Hosted in EU

Try Mira

Mira is live with self-service onboarding. Also see how Mira compares to other AI website testing tools and GDPR-compliant website monitoring for ongoing checks.

Try Mira