Back to homeMimmo.

Privacy Policy

Last updated: July 2026

1. Data Controller

The AI assistant embedded on this platform is operated by the travel agency that deployed it. For questions about your personal data, contact your travel agency directly.

2. What We Collect

We collect only what is strictly necessary to deliver the service:

  • Organisation code — a pseudonymous code that identifies your company (not your name or email).
  • Conversation messages — what you type and the assistant's replies, used to provide answers.
  • Session identifier — a temporary ID that links your messages within one session.
  • City / timezone — used to show local times in responses; never stored permanently.

We do not store your full name, personal email address, national ID, phone number, or financial data in our database.

3. Legal Basis

Processing is based on performance of a contract (GDPR Art. 6(1)(b)) — the service cannot function without the data listed above. IP addresses are pseudonymised using a one-way hash before storage (Art. 25 — privacy by design).

4. Retention

Conversation records are automatically deleted after 90 days. Account-level codes (organisation code) are deleted after 180 days of inactivity. Audit logs are deleted after 365 days.

5. Third-Party AI Providers

Responses are generated by AI language models. When using self-hosted models, no data leaves our servers. When using cloud AI providers (Groq, AWS Bedrock), your conversation text is transmitted to those providers under their respective data processing agreements. Only the message content is sent — no names, emails, or national IDs are included.

6. Your Rights

Under GDPR you have the right to:

  • Access — request a copy of data held about you.
  • Erasure — request deletion of all your data (Art. 17).
  • Portability — receive your data in a machine-readable format (Art. 20).
  • Objection — object to processing based on legitimate interest.

You can exercise the Right to Erasure directly from the chat widget by typing “delete my data” or by using the Delete My Data button in the chat footer. Alternatively, contact your travel agency administrator. Requests are fulfilled within 30 days.

7. Consent & AI Processing

Before your first message, you will be asked to consent to the processing of your conversation data. You may decline — you can still use the assistant, but your conversation history will not be saved between sessions. Consent can be withdrawn at any time by typing “delete my data.”

Responses are generated by AI language models hosted by Groq and AWS Bedrock. Your message content is transmitted to these providers under data processing agreements. No personal identifiers (name, email, phone) are included in the data sent to AI providers.

8. Security

All data is encrypted in transit (TLS) and at rest (AES-256-GCM for credentials). Access to conversation data is limited to authorised administrators of your organisation.

9. Cookie Policy

The admin dashboard uses an essential session cookie (admin_session) for authentication. This cookie is strictly necessary for the platform to function and does not require consent under the ePrivacy Directive. The chat widget does not use cookies. Analytics cookies are only set with your explicit consent via the cookie banner.

10. Changes to This Policy

Material changes will be communicated via the widget notice. The “Last updated” date above reflects the most recent revision.

Questions about your data?

Contact your travel agency administrator or use the “Delete My Data” button in the chat widget.