Privacy Policy
Effective: 9 July 2026
This Policy explains what personal data the operator of the Mira AI booking assistant processes, why and on what legal basis it does so, how long the data is retained, who receives it and what rights data subjects have. It is based on Regulation (EU) 2016/679 (GDPR) and Hungarian Act CXII of 2011 on Informational Self-Determination and Freedom of Information.
1. Data controller
- Controller: Morvai Máté, sole proprietor
- Registered office: 9061 Vámosszabadi, Szabadi utca 7., Hungary
- Tax number: 58070222-1-28
- Registration number: 56698413 (register of sole proprietors)
- E-mail: hello@bookwithmira.com
- Websites: www.bookwithmira.hu, www.bookwithmira.com
No data protection officer has been appointed because Article 37 GDPR does not require one.
2. Our roles as controller and processor
Mira processes personal data in two different roles:
- As controller for visitors to our own websites, prospective customers, and contacts and portal users of contracted Customers.
- As processorwhen the assistant is embedded in a Customer's website. For chats, information entered into them and resulting bookings, the relevant Customer and website operator is the controller. Requests concerning those data should primarily be directed to that Customer. We forward requests received by us and assist the Customer in responding.
3. Data, purposes, legal bases and retention
3.1. Enquiries and leads
| Data | name, e-mail address, optional phone number, optional business type, notes, language, time and source of capture |
|---|---|
| Purpose | responding to the enquiry, preparing an offer and making contact |
| Legal basis | Article 6(1)(b) GDPR — steps taken at the data subject's request before entering into a contract; for business contact data, Article 6(1)(f) — legitimate interests |
| Retention | until the enquiry is closed, but no longer than two years from capture; if a contract is formed, under the contractual retention rules |
We send an automated confirmation to the supplied e-mail address and an internal notification to our customer-service address.
3.2. Demo chat on our websites
| Data | chat messages, conversation identifier and language; the visitor's IP address only for abuse prevention as described in Section 3.6 |
|---|---|
| Purpose | automatically answering questions and demonstrating the Service |
| Legal basis | Article 6(1)(f) GDPR — legitimate interests in operating and demonstrating the Service; Article 6(1)(b) for contact details voluntarily supplied in the chat |
| Retention | chat content is not stored persistently; messages are sent to the AI model provider to produce a response as described in Section 4; captured lead data is retained under Section 3.1 |
Please do not enter special-category data, such as health data, or information that is not needed to answer your question.
3.3. Customer Portal and accounts
| Data | e-mail address, role, login timestamps, hashed session identifiers and hashed magic-link tokens |
|---|---|
| Purpose | operating the Customer Portal, passwordless e-mail magic-link authentication and access management |
| Legal basis | Article 6(1)(b) GDPR — performance of a contract |
| Retention | for the agreement term; magic links remain valid for 15 minutes and sessions for no longer than 30 days |
3.4. Google Calendar connection
| Data | access permissions for the Google account authorised by the Customer, including encrypted OAuth tokens, calendar free/busy data and created calendar events |
|---|---|
| Purpose | retrieving availability and creating bookings in the Customer's calendar |
| Legal basis | Article 6(1)(b) GDPR — performance of a contract; the connection is initiated by the Customer through Google's authorisation interface |
| Retention | until the Customer disconnects the calendar or the agreement ends; tokens are deleted on disconnection |
3.5. Assistant embedded in Customer websites (processing)
| Data | chat messages and conversation identifier; booking data including name, e-mail address, phone number, service and time; lead data; referring website; and usage statistics |
|---|---|
| Controller | the relevant Customer and website operator. We act as processor under that Customer's instructions and the agreed data processing terms. |
| Retention | booking and lead data until the Customer agreement ends or as instructed by the Customer; usage statistics during the agreement |
3.6. Technical data, logs and abuse prevention
| Data | IP address, request time and technical characteristics, and error logs. IP addresses in persistent logs are anonymised by deleting the final IPv4 octet or final 80 IPv6 bits. The full IP address is used only briefly by the rate-limiting system. |
|---|---|
| Purpose | reliability, troubleshooting and preventing overload or automated abuse |
| Legal basis | Article 6(1)(f) GDPR — legitimate interests in Service security |
| Retention | rate-limit counters for no longer than 24 hours; server logs under the hosting provider's rotation schedule, for no longer than 30 days |
3.7. Cookies and local storage
| Name | Type and purpose | Lifetime |
|---|---|---|
| mira-lang | functional — remembers the selected language | 1 year |
| aba_tenant_session | necessary — Customer Portal login session | up to 30 days |
| aba_admin_session | necessary — internal administrator session | 8 hours |
| mira-theme (localStorage) | functional — remembers the light/dark theme | until deleted |
| aba:conversation (sessionStorage) | functional — maintains chat continuity within a session | until the browser tab closes |
We do not use cookies for marketing or profiling. Vercel Analytics measures traffic using aggregated, cookieless data that does not identify individual visitors.
4. Processors and recipients
We use the following processors to provide the Service:
| Processor | Service | Data location and safeguards |
|---|---|---|
| Vercel Inc. (USA) | hosting and application operation, cookieless analytics, AI gateway | EU-region serving; certified under the EU–US Data Privacy Framework |
| Anthropic PBC (USA) | large language model generating chat responses | USA; EU–US Data Privacy Framework or Standard Contractual Clauses |
| Neon Inc. (USA) | customer and operational database | EU (Frankfurt); EU–US Data Privacy Framework or Standard Contractual Clauses |
| Upstash Inc. (USA) | short-lived technical rate-limiting counters | EU (Frankfurt); EU–US Data Privacy Framework or Standard Contractual Clauses |
| Proton AG (Switzerland) | e-mail delivery, including confirmations, magic links and notifications | Switzerland, covered by an EU adequacy decision |
| Google LLC (USA) | Google Calendar API for Customers using that integration | certified under the EU–US Data Privacy Framework |
| [Accountant / invoicing provider] | invoicing and compliance with legal obligations | [Hungary] |
Data may be disclosed to a competent authority or court where required by law. Accounting records are retained for eight years under Section 169 of Hungarian Act C of 2000 on Accounting; the legal basis is Article 6(1)(c) GDPR.
5. Transfers outside the EEA
Some processors operate outside the European Economic Area, primarily in the United States. Transfers are protected by certification under the EU–US Data Privacy Framework or, where unavailable, the European Commission's Standard Contractual Clauses and any necessary supplementary measures. Switzerland is covered by a European Commission adequacy decision.
6. Security
- all communications use encrypted HTTPS/TLS connections;
- calendar access tokens are encrypted at rest using AES-256-GCM;
- magic links and sessions are stored only as SHA-256 hashes and are single-use or time-limited;
- administrative interfaces require authorisation and access is logged;
- rate limiting and Content Security Policy controls protect against abuse; and
- IP addresses are anonymised in persistent logs.
7. Automated decision-making and profiling
Chat responses are generated automatically by artificial intelligence, but the assistant does not make decisions producing legal effects or similarly significant effects for data subjects. No automated decision-making within Article 22 GDPR or profiling takes place. We do not use processed data to train AI models.
8. Data subject rights
- Access (Article 15 GDPR): obtain information about personal data we process.
- Rectification (Article 16): correct inaccurate data.
- Erasure (Article 17): request deletion where no further legal basis applies.
- Restriction (Article 18): request restriction of processing.
- Data portability (Article 20): receive data processed automatically on the basis of contract or consent in machine-readable form.
- Objection (Article 21): object to processing based on legitimate interests.
- Withdrawal of consent (Article 7): withdrawal does not affect the lawfulness of processing before withdrawal.
Requests may be sent to hello@bookwithmira.com. We will respond within one month, extendable by up to two further months where necessary. If a request concerns data processed through an assistant on a Customer's website under Section 3.5, we will forward it to that Customer as controller and assist with the response.
9. Complaints and remedies
- Supervisory authority: Hungarian National Authority for Data Protection and Freedom of Information (NAIH), 1055 Budapest, Falk Miksa utca 9–11., Hungary; postal address: 1363 Budapest, Pf. 9.; telephone: +36 (1) 391-1400; e-mail: ugyfelszolgalat@naih.hu; website: naih.hu.
- Judicial remedy: a data subject may also bring proceedings before the competent court for their residence or place of stay.
10. Changes to this Policy
We review and may update this Policy from time to time. The current version is available on our websites. Contracted Customers will be informed of material changes by e-mail or through the Customer Portal.