Privacy Policy of MistraAI

Effective Date: 14 September 2025

MistraAI (“Company,” “we,” “our,” or “us”) is committed to protecting your personal information and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform, website, and related services (collectively, the “Services”).

By using the Services, you agree to the terms of this Privacy Policy. If you do not agree, please discontinue use immediately.

1. Information We Collect

We may collect and process the following categories of personal data:

  • Personal Identification Data: Full name, email address, phone number, billing details, company name.

  • Account Data: Login credentials, account preferences, subscription status.

  • Payment Information: Payment method, billing address (processed securely via third-party payment providers such as Stripe or PayPal).

  • Usage Data: IP address, browser type, device information, operating system, pages visited, time and date of visits, referring website.

  • Marketing and Communications Data: Preferences for receiving marketing from us, engagement with our emails or advertisements.

  • Cookies and Tracking Technologies: Session cookies, advertising pixels (e.g., Meta Pixel, Google Ads), analytics tools.

2. How We Use Your Information

We use your information lawfully, fairly, and transparently for the following purposes:

  1. To provide, operate, and maintain the Services.

  2. To manage your account and process subscription payments.

  3. To personalize user experience and improve the Services.

  4. To deliver marketing communications, promotional offers, and targeted advertising (with your consent where required).

  5. To detect, prevent, and address fraud, abuse, or security threats.

  6. To comply with legal and regulatory obligations.

3. Legal Basis for Processing (GDPR)

We process your personal data under one or more of the following legal grounds:

  • Performance of Contract: When necessary to deliver the Services you subscribed to.

  • Legitimate Interests: For analytics, product improvement, and fraud prevention, provided these interests do not override your rights.

  • Consent: For optional marketing emails, cookie tracking, or other non-essential features.

  • Legal Obligation: To comply with applicable laws (e.g., tax or accounting requirements).

4. Sharing of Information

We may share your data with trusted third parties, including:

  • Service Providers: Payment processors, hosting providers, analytics platforms, customer support tools.

  • Advertising Partners: Meta, Google, and other advertising networks (for targeted ads, where lawful).

  • Business Transfers: In the event of a merger, acquisition, or sale of assets.

  • Legal Requirements: Where disclosure is required by law, court order, or government request.

We never sell your personal data.

5. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy:

  • Account data: retained while your account is active and for up to 24 months after closure.

  • Payment data: retained only as long as required for financial and legal compliance.

  • Marketing data: retained until you withdraw consent or unsubscribe.

6. International Data Transfers

If you are located in the European Union or European Economic Area, your information may be transferred outside the EEA. We ensure that such transfers are protected by adequate safeguards, such as Standard Contractual Clauses approved by the European Commission.

7. Your Rights (GDPR and CCPA)

Depending on your jurisdiction, you may have the following rights:

  • Right to access and obtain a copy of your data.

  • Right to rectify inaccurate or incomplete data.

  • Right to erase your data (“right to be forgotten”).

  • Right to restrict or object to processing.

  • Right to data portability.

  • Right to withdraw consent at any time (without affecting prior lawful processing).

  • Right to lodge a complaint with a supervisory authority.

California residents (CCPA) have the right to request disclosure of categories of personal information collected, request deletion, and opt out of the sale of personal data.

8. Security of Your Information

We implement technical and organizational measures designed to protect your personal data against unauthorized access, alteration, disclosure, or destruction. However, no method of transmission or storage is 100% secure.

9. Cookies and Tracking Technologies

We use cookies, pixels, and similar technologies to:

  • Enable essential website functionality.

  • Analyze user behavior and improve performance.

  • Deliver targeted advertising.

You may refuse cookies by adjusting your browser settings. Some features may not function properly if cookies are disabled.

10. Third-Party Links

The Services may contain links to third-party websites. We are not responsible for the privacy practices of those sites and encourage you to review their policies.

11. Children’s Privacy

Our Services are not directed at individuals under 18 years of age. We do not knowingly collect personal information from minors. If we become aware of such data, we will delete it promptly.

12. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. Updates will be posted on this page with a revised “Effective Date.” We encourage you to review it periodically.

13. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy, please contact us at:

📧 Email: info@mistraai.com