Privacy Policy
Privacy Policy
Effective date: 18 June 2026
1. About this policy
This privacy policy explains how Miravos handles personal data when people visit the Miravos website, contact us, request access, use the Miravos service, or interact with our support, security, and operational processes.
It also explains the difference between personal data that Miravos controls for its own purposes and customer data that Miravos processes on behalf of customer organisations.
2. Who we are
Miravos is operated by Miravos AI Limited, registered in England and Wales under company number 17275513.
Controller: Miravos AI Limited
Data protection contact: hello@miravos.app
Data Protection Officer: Miravos has not appointed a Data Protection Officer.
3. When Miravos is controller and when it is processor
Miravos is usually the controller for personal data processed for its own website, sales, account administration, security, support, service operations, communications, and legal compliance purposes.
Where a customer organisation uploads, connects, or submits business data into the Miravos service, that customer organisation is usually the controller of any personal data in that customer data. Miravos usually acts as processor for that customer data and processes it on the customer organisation's instructions.
If you are an authorised user of a customer organisation, requests about personal data in your organisation's workspace may need to be handled by that organisation as controller. Miravos will support customer organisations with those requests where required by contract or law.
4. Personal data we collect
The personal data Miravos collects depends on how you interact with us.
Website and contact data
We may collect:
- name, email address, organisation, role, and contact details;
- messages, enquiries, meeting notes, and sales or support communications;
- preferences and consent choices;
- website usage information, such as pages visited, referral source, device/browser information, approximate location derived from IP address, and analytics identifiers.
Account and access data
We may collect:
- user identity details, email address, display name, authentication identifiers, and access records;
- workspace, business, dataset, role, permission, and feature-access information;
- login, session, audit, and security metadata;
- support references, issue reports, feedback, and admin notes.
Service and customer workspace data
Depending on how a customer organisation uses Miravos, the service may process:
- business records, datasets, files, cashflow data, management-information data, and analytics metadata;
- prompts, conversations, AI-assisted outputs, charts, tables, artifacts, exports, and evidence views;
- meeting transcripts, voice dictation inputs, uploaded audio snippets, and extracted questions where these features are used;
- operational telemetry, traces, prompt-capture records, diagnostic data, and usage aggregates.
Some customer data may contain personal data about employees, customers, suppliers, counterparties, or other individuals. The customer organisation is responsible for deciding what customer data is provided to Miravos and for ensuring it has a lawful basis to do so.
5. How we use personal data
Miravos uses personal data to:
- provide, operate, secure, and maintain the website and service;
- respond to enquiries, arrange demos, provide support, and manage customer relationships;
- authenticate users and manage access to workspaces, businesses, datasets, and admin areas;
- run requested analytics, AI-assisted workflows, searches, imports, exports, transcriptions, summaries, and evidence views;
- investigate errors, misuse, security events, feedback, and service-quality issues;
- monitor reliability, usage, performance, and service health;
- improve the product, including through feedback, diagnostics, aggregated usage information, and de-identified analysis;
- meet legal, tax, accounting, audit, regulatory, and contractual obligations;
- enforce agreements and protect Miravos, customers, users, and the service.
6. Lawful bases
Where Miravos is controller, we rely on one or more of the following lawful bases under UK data protection law:
- Contract: to provide the website, service, account access, support, and customer relationship functions requested by you or your organisation.
- Legitimate interests: to operate, secure, improve, troubleshoot, and market Miravos, provided those interests are not overridden by your rights and freedoms.
- Consent: for activities that legally require consent, such as certain non-essential cookies or direct marketing preferences.
- Legal obligation: to comply with laws, regulatory requirements, tax, accounting, and record-keeping duties.
Where Miravos acts as processor for customer data, the customer organisation is responsible for identifying the lawful basis for the processing it instructs Miravos to perform.
7. AI-assisted processing
Miravos uses AI model providers and supporting services to provide requested features. This may involve sending prompts, context, retrieved guidance, files, transcripts, business data, and other selected inputs to configured model providers where needed to generate, classify, transcribe, summarise, or analyse outputs.
Miravos does not use customer data to train third-party foundation models unless the relevant customer organisation expressly agrees in writing.
AI-assisted outputs may contain mistakes or assumptions. Users and customer organisations should review outputs and supporting evidence before relying on them.
8. Cookies and analytics
The Miravos website and service may use cookies and similar technologies.
Some cookies are necessary for authentication, security, session management, and service operation. The public website may also use Google Analytics if the relevant analytics configuration is enabled. Analytics technologies help Miravos understand public website usage, improve content, and monitor performance.
Where required by law, Miravos will ask for consent before setting non-essential cookies or similar technologies. You can usually manage cookies through your browser settings and, where available, through Miravos cookie controls.
9. Who we share personal data with
Miravos may share personal data with:
- hosting, cloud infrastructure, database, storage, authentication, and security providers;
- AI model, transcription, and analytics providers used to deliver requested features;
- search, monitoring, logging, email, support, payment, and business operations providers;
- professional advisers, insurers, auditors, banks, and legal representatives;
- public authorities, regulators, courts, or law enforcement where required by law;
- customer organisations, where the data relates to their authorised users, workspaces, or customer data.
Miravos requires service providers to protect personal data and use it only for permitted purposes.
10. International transfers
Miravos and its service providers may process personal data in the United Kingdom and other countries.
Where personal data is transferred outside the United Kingdom, Miravos will use an appropriate safeguard where required, such as an adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to the EU standard contractual clauses, or another lawful transfer mechanism.
11. How long we keep personal data
Miravos keeps personal data only for as long as reasonably needed for the purposes described in this policy, including to provide the service, comply with law, resolve disputes, enforce agreements, maintain security, and support audit obligations.
Retention periods vary by data type. For example:
- enquiry and sales records are kept while the relationship or opportunity is active and for a reasonable period afterwards;
- account, access, audit, and security records are kept while access is active and for a reasonable period afterwards;
- customer workspace data is kept according to the relevant customer agreement, product settings, retention schedule, or customer instructions;
- operational diagnostics and prompt-capture records may be kept for shorter periods where they are used for troubleshooting and quality review;
- legal, tax, accounting, and contract records may be kept for longer where required.
12. Security
Miravos uses technical and organisational measures designed to protect personal data, including authentication, access controls, server-side tenant checks, audit records, cloud security controls, and operational monitoring.
No online service can be guaranteed to be completely secure. If you believe personal data or a Miravos account has been compromised, contact hello@miravos.app promptly.
13. Your rights
Depending on the circumstances and applicable law, you may have rights to:
- access your personal data;
- correct inaccurate personal data;
- ask for personal data to be erased;
- restrict certain processing;
- object to certain processing;
- receive certain personal data in a portable format;
- withdraw consent where processing is based on consent;
- complain to the Information Commissioner's Office.
To exercise rights for personal data that Miravos controls, contact hello@miravos.app.
For personal data in a customer organisation's workspace, you may need to contact that customer organisation directly because it is usually the controller of that data.
14. Complaints
Please contact Miravos first if you have concerns about how we handle personal data. We will try to resolve the issue.
You may also complain to the UK Information Commissioner's Office:
- Website: https://ico.org.uk/make-a-complaint/
- Phone: 0303 123 1113
15. Changes to this policy
Miravos may update this policy from time to time. Where changes are material, Miravos will take reasonable steps to bring them to affected users' or customers' attention before the new processing begins where required by law.
16. Contact
For privacy questions, contact hello@miravos.app.