Miiwa
HomePrivacyTermsLogin

Miiwa OS

Privacy Policy

How we process personal data, integration data and security information across the Miiwa platform.

Last updated: July 2026

On this page

  1. 01Who we are
  2. 02What this policy covers
  3. 03What information we process
  4. 04Data by product area
  5. 05Zero-Trace™ and session data
  6. 06Purpose of the processing
  7. 07Legal basis
  8. 08Cookies and analytics
  9. 09Sub-processors
  10. 10Integrations you connect
  11. 11International transfers
  12. 12Storage and deletion
  13. 13Your rights
  14. 14Security
  15. 15Changes to this policy
  16. 16Contact
01

Who we are

Miiwa Ltd, a company registered in Cyprus (company registration number HE 492913; registered office: Tagmatarchi D. Pouliou and K. Pantelidi, Melina Court, Floor 2, 8011 Paphos, Cyprus), is the data controller for the processing of personal data in connection with the Miiwa platform, our website and our commercial relationships.

If you have questions about this privacy policy or how we process personal data, you can contact us at info@miiwa.ai.

02

What this policy covers

This policy applies to the Miiwa platform, our public website and the public surfaces we host on behalf of customers, such as careers sites, partner portals and the demo-booking form.

03

What information we process

We process the information needed to deliver, secure and operate the Platform.

  • account information, such as name, email address, organisation and login-related details
  • agreement and billing information when you enter into a commercial relationship with us
  • technical and security information, such as log data, device and session details, and integration metadata
  • content you choose to store in features such as Miiwa Vault or through connected systems
04

Data by product area

Some product areas process personal data beyond ordinary account information. Depending on how the Platform is used, this can include:

  • Recruitment: candidate details such as name, contact information, CV, applications and interview notes, including data submitted through public careers sites and the candidate portal
  • Tourism: partner and destination contacts, portal access, and analytics sourced from connected tourism data services
  • Annual planning (Year Wheel): activities, plans and calendar data, including optional Google Calendar synchronisation
  • Decisions: the decision records and rationale you capture
  • Assistants and agents: the messages, prompts and content you exchange with an assistant or agent during a session
  • Demo bookings: name, email, organisation and scheduling details submitted through the public booking form
  • Support and triggers: emails and content sent to support mailboxes, or to an agent's email, webhook, browser-extension or MCP trigger
05

Zero-Trace™ and session data

Miiwa is designed around a Zero-Trace™ principle for ordinary agent sessions.

As a general rule we do not keep the input and output of standard runs as a persistent history, and we do not use customer data to train models for other customers.

If you actively use features where storage is part of the product, such as Miiwa Vault or integrations, the data you choose to store or sync is processed as part of that feature.

06

Purpose of the processing

We process personal data in order to:

  • create and administer user access
  • deliver the Platform's features, onboarding and support
  • protect the Platform against misuse, errors and security incidents
  • deliver the integrations you choose to connect
  • meet accounting, contractual and legal requirements
07

Legal basis

We process personal data on one or more relevant legal bases, including performance of a contract, our legitimate interest in operating and securing the Platform, your consent where it applies, and compliance with legal obligations.

08

Cookies and analytics

We keep cookies and similar technologies to a functional minimum.

  • a signed session cookie that enforces session lifetime and security
  • authentication cookies set by our identity provider so you stay signed in
  • a preference cookie that remembers your chosen language
  • privacy-conscious analytics and performance monitoring that help us understand usage and keep the Platform reliable

Our error and performance monitoring is configured to strip personal data before it leaves the Platform.

09

Sub-processors

We use a set of trusted sub-processors to run the Platform:

Sub-processors that support the Miiwa platform.
ProviderPurposeDataRegion
SupabaseDatabase, authentication and file storageApplication data and encrypted secretsEU
VercelApplication hosting and edge networkRequest metadata and runtime logsGlobal edge
StripeSubscription billingBilling contact and subscription state (card data held by Stripe)EU / US
ResendTransactional and inbound agent emailEmail addresses and message contentEU / US
SentryError and performance monitoringError events with personal data removedEU / US
Google AnalyticsWebsite analyticsAnonymous usage dataGoogle
Vercel Speed InsightsPerformance monitoringAnonymous performance metricsVercel
AI providers (Anthropic, OpenAI, Google, Perplexity)AI model inferencePrompt and response content for the runProvider regions
FirecrawlManaged web scrapingTarget URLs and fetched contentProvider region
DepositphotosStock media search and licensingSearch queries and licence recordsEU / US
VistaCreateEmbedded design editorDesign content you createEU / US
VisitDataTourism analyticsTourism metricsProvider region
Google Workspace and GmailEmail delivery and calendar syncEmail addresses and message or event dataGoogle

AI providers do not train on your content through Miiwa, and bring-your-own-key setups keep provider usage on your own account. Services you connect yourself, such as CRM, advertising or productivity tools, are not Miiwa sub-processors: you control those credentials, and Miiwa passes data through only to deliver the integration you enabled.

10

Integrations you connect

When you connect a third-party service to Miiwa, this happens on your initiative and with your approval through OAuth or a similar authorisation flow.

We use only the tokens and data needed to deliver the integration you chose, into your own account or workspace.

Integrations are isolated per user or workspace and are not shared across customers.

11

International transfers

Some of the sub-processors above may process data outside the EU or EEA.

Where that happens, we rely on appropriate safeguards, such as EU Standard Contractual Clauses or an adequacy decision, to protect your data.

12

Storage and deletion

We keep personal data for as long as it is needed for the purposes it was collected for, or for as long as required by law or the agreement in place.

Account, agreement and security information may be kept longer than ordinary session content where this is necessary for operations, documentation or legal obligations. Workspace administrators can also configure how long run data is retained.

13

Your rights

Subject to applicable law, you have:

  • the right to access the personal data we hold about you
  • the right to have inaccurate information corrected
  • the right to erasure where the conditions are met
  • the right to restrict processing
  • the right to object to certain processing
  • the right to data portability

You can also lodge a complaint with the Office of the Commissioner for Personal Data Protection in Cyprus, or with the supervisory authority in your own EU or EEA country.

14

Security

We apply technical and organisational security measures matched to the risk, including access control, encryption, isolation of integration data, multi-tenant separation between workspaces and ongoing security monitoring. Enterprise controls such as single sign-on, automated user provisioning and audit logging are available.

We operate an information security program aligned with SOC 2 and ISO 27001 practices. This is a program of controls and evidence, not a substitute for a completed certification. No solution is entirely free of risk, so you should always avoid sharing unnecessary personal data in systems and documents.

15

Changes to this policy

We may update this privacy policy as the Platform and our legal requirements evolve. We will update the date at the top of this page when we do, and we will surface material changes where appropriate.

16

Contact

If you want to exercise your rights or have questions about how we process personal data, you can contact us at info@miiwa.ai.

© Miiwa Ltd

HomePrivacyTermsLogin