Legal

Privacy Policy

This Privacy Policy describes how Mirvo (Entropian SARL, France) collects, uses, and protects your personal data when you use the Mirvo platform.

Mirvo plays two roles under GDPR: we act as data controller for the personal data of our own users (account holders, subscribers), and as data processor for the contact data that users import into the platform (prospects, email recipients). For questions about the processing of your prospects' data, see our Data Processing Addendum.

Mirvo's supervisory authority under GDPR is the Commission Nationale de l'Informatique et des Libertés (CNIL), France.

1. Definitions

Personal Data: Any information relating to an identified or identifiable natural person.
Data Subject: The individual whose personal data is being processed.
User / Subscriber: An individual or organization that has created a Mirvo account.
Data Controller: The entity that determines the purposes and means of processing.
Data Processor: The entity that processes personal data on behalf of the Data Controller.
Processing: Any operation performed on personal data (collection, storage, use, transmission, deletion, etc.).
Sub-processor: A third party engaged by Mirvo to process personal data on its behalf.
Service: The Mirvo B2B outbound platform, including all features accessible via mirvo.ai.

2. Data we collect about you

Account data

When you create an account, we collect your email address, name, company name, and professional role. This data is used to create and manage your account and to communicate with you about the Service.

Usage data

We collect data about how you use the Service: pages visited, features used, session duration, errors encountered, and in-product interactions. This is used for product improvement and support.

Payment data

Payment processing is handled by our payment processor. Mirvo does not store or have access to your full card details — we only receive a payment confirmation, subscription status, and billing metadata.

Communications data

We retain the content of support messages you send us via email or in-app, as well as automated notifications we send to you, for support and compliance purposes.

Cookie data

See our Cookie Policy for full details on what cookies are set and why.

Google Calendar data

This applies only if you connect a Google account to Mirvo, from Settings, Google Calendar. It describes how Mirvo accesses, uses, stores, shares and deletes the Google user data it receives.

What Mirvo accesses. When you connect, Mirvo asks Google for three permissions: your basic account identity (your Google account identifier and email address), read-only access to the list of your calendars, and access to view and edit the events of your calendars.

How Mirvo uses it. Your account identity is used to show which Google account is connected and to keep the connection tied to that account. Your list of calendars is shown to you so that you can choose which calendars block your availability and which single calendar receives your bookings. Mirvo regularly reads the events of the calendars you chose, over a limited period (from one day in the past to about 120 days ahead), so that your booking page does not offer times when you are busy. When a prospect confirms a meeting through your booking page, Mirvo creates an event at the meeting time in the calendar you chose, titled with the prospect's name and company when they gave them, or with a neutral title otherwise (never their email address). If you later move or cancel that meeting in Mirvo, Mirvo moves or deletes that event in the calendar where it created it. Mirvo does not add guests to these events, does not send Google invitations, and never changes an event it did not create.

What Mirvo stores. An authorization token, encrypted at rest; your Google account identifier, email address and the permissions you granted; the identifier, name and your access level of each of your calendars; and, for the calendars you chose, the start time, end time, busy or free status and technical identifier of each event in the synced period. Each synchronization replaces the previous set. For meetings that Mirvo wrote to your calendar, Mirvo keeps the identifier of the Google event and of the calendar, and the sync status. Mirvo does not store the title, description, location, guests or any other content of your Google Calendar events. This data is stored in Mirvo's database, operated by the sub-processors listed in our Data Processing Addendum.

Sharing. Mirvo does not sell Google user data, does not use it for advertising, does not use it to create, train or improve artificial intelligence models, and does not transfer it to third parties, except to the sub-processors that host and operate the Service, for security purposes, or to comply with the law. Mirvo staff access your Google user data only when you ask us to help you, when it is necessary for security (for example to investigate abuse), or to comply with the law.

Disconnecting and deletion. You can disconnect at any time from Settings, Google Calendar. Mirvo then asks Google to revoke its access and deletes the authorization token, the list of your calendars and all synced busy times. The sync status of meetings already written to your calendar is kept with those meetings in Mirvo, and the events already created stay in your Google Calendar unless you delete them there. When you delete your Mirvo account, Mirvo does the same for the workspaces you own. If you remove Mirvo's access from your Google Account instead, Mirvo can no longer read or write your calendars, and the data above is kept until you disconnect in Mirvo or delete your account. Database backups are kept as described in section 7.

Limited Use. Mirvo's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

3. How we use your data

We use your personal data for the following purposes:

  • Provide and operate the Service: Creating and managing your account, running campaigns, and delivering core product features.
  • Process payments: Managing your subscription, billing, invoicing, and renewal.
  • Communicate with you: Sending transactional emails (receipts, alerts, security notices) and service updates. Not marketing — this is operational communication.
  • Improve the product: Analyzing aggregate usage patterns to identify friction, prioritize features, and fix bugs. No individual profiling for commercial targeting.
  • Security and fraud prevention: Detecting unauthorized access, abuse patterns, and compliance violations.
  • Legal compliance: Meeting our obligations under French law, EU law, and contractual requirements.
  • Marketing communications: Only if you have explicitly opted in. You can withdraw consent at any time.

5. AI usage at Mirvo

Mirvo uses AI to help sales teams work more effectively. This section explains exactly how AI is used and what our commitments are.

What AI is used for

  • Email content generation based on prospect context you provide
  • Sentiment analysis on incoming email replies (to classify response intent)
  • AI-powered help and guidance within the product

Anti-fabrication commitment

Mirvo's AI does not invent prospect information beyond what is provided in your imported data. We do not generate fictitious job titles, fictitious company details, or fabricate prospect signals not present in your source data. AI output is grounded in the information you supply.

No training on customer data

Customer data processed through Mirvo is not used to train AI models. We work exclusively with enterprise-grade AI providers who provide contractual no-training-on-customer-data guarantees. Your campaigns, prospects, and email content are yours and are not used to improve AI models.

EU AI Act transparency

Mirvo qualifies as a Limited Risk AI system under the EU AI Act (Regulation (EU) 2024/1689) and complies with the applicable transparency obligations. Users are informed when they are interacting with AI-generated content or AI-powered features within the product.

Human oversight

AI is decision-support, not autonomous. All AI-generated email drafts can be reviewed and edited by you before sending. No email is sent without your explicit action. The final sending decision is always yours.

AI provider transparency

Mirvo works with enterprise-grade AI providers under the EU-US Data Privacy Framework (DPF) and Standard Contractual Clauses (SCCs). A full list of AI sub-processors is available in our Data Processing Addendum.

6. Sharing your data

We do not sell your personal data to third parties under any circumstances.

We share data only with the sub-processors necessary to deliver the Service. These fall into the following categories:

  • Hosting & CDN
  • Database & Authentication
  • Payment processing
  • AI processing
  • Email infrastructure
  • Product analytics
  • Rate limiting & abuse protection
  • Bot protection
  • Error monitoring

A complete list of sub-processors with full names, locations, and data transfer mechanisms (DPF/SCCs) is available in our Data Processing Addendum or by contacting privacy@mirvo.ai.

Cross-border transfers to US-based providers are covered by the EU-US Data Privacy Framework (DPF) and Standard Contractual Clauses (SCCs) where applicable.

7. Data retention

We retain data for as long as necessary for the purpose it was collected, or as required by law.

Data typeRetention period
Active account dataDuration of subscription
Deleted account data30-day soft-delete grace period, then hard deletion
Prospect data (imported contacts)Duration of subscription + 30-day grace period after cancellation
Inbox messages90 days
Admin action logs90 days minimum
Payment records10 years (French accounting obligation)
Analytics events12 months
Google Calendar connection and synced busy timesUntil you disconnect Google Calendar or delete your account
Database backups7 days rolling

8. Your rights

Under GDPR, you have the following rights regarding your personal data. To exercise any of them, email privacy@mirvo.ai. We will respond within 30 days as required by law.

Right to be informed (Art. 13-14): To know what data we process and why — which is the purpose of this policy.
Right of access (Art. 15): To request a copy of the personal data we hold about you.
Right to rectification (Art. 16): To correct inaccurate or incomplete personal data.
Right to erasure (Art. 17): To request deletion of your data ("right to be forgotten"), subject to legal retention obligations.
Right to restriction (Art. 18): To restrict how we use your data while a dispute is being resolved.
Right to data portability (Art. 20): To receive your data in a machine-readable format for transfer to another service.
Right to object (Art. 21): To object to processing based on legitimate interest or for direct marketing.
Automated decision-making (Art. 22): Mirvo does not make solely automated decisions with legal or similarly significant effects. AI features are decision-support tools; humans make final decisions.

You also have the right to lodge a complaint with the CNIL: www.cnil.fr.

9. International data transfers

Mirvo applies a hybrid data residency approach:

  • EU-resident: Your account data, product analytics, rate limiting and error monitoring are handled by sub-processors whose data is stored in the EU.
  • Providers outside the EU, with safeguards: Hosting and CDN, payment processing, AI processing, email delivery and bot protection involve providers incorporated outside the EU. Transfers are covered by the EU-US Data Privacy Framework (DPF) and Standard Contractual Clauses (SCCs) under Commission Implementing Decision (EU) 2021/914.

Full details including a Transfer Impact Assessment are available in our Data Processing Addendum.

10. Security

Mirvo implements technical and organizational security measures including TLS 1.3 encryption in transit, AES-256 encryption at rest for the primary database and file storage, Row-Level Security multi-tenant isolation, hardened HTTP security headers, and automated security review on every code change.

For a complete description of our security measures, see our Security page.

11. Changes to this policy

We will notify you of material changes to this Privacy Policy at least 30 days before they take effect, via email and in-app notice. The updated policy will be published at this URL with the version date updated.

Continued use of the Service after a material change takes effect constitutes acceptance of the updated policy. If you do not accept the changes, you may terminate your subscription before the effective date.

12. Contact

Privacy and data protection inquiries: privacy@mirvo.ai

Postal: Entropian SARL, France

CNIL (supervisory authority): www.cnil.fr

Privacy Policy — Mirvo