Privacy Policy

How we collect, use and protect personal data, who we share it with, and the rights you have. This policy applies to the Mizz AI platform operated by AppMind Ltd.

Version 2.0 · Last updated 25 July 2026

1. Who we are and how to contact us

Mizz AI is a trading name of AppMind Ltd, registered in England and Wales (company number 16461561). For the personal data described in this policy as ours, AppMind Ltd is the data controller.

For any privacy question, or to exercise your rights, contact us at support@mizzai.com.

2. Our two different roles — please read

This is the most important thing to understand about how data works on our platform:

  • We are the controller of data about the business owners who register with us — your account details, business information, billing and how you use the dashboard.
  • We are a processor for the data of your own customers — the people who chat with your assistant, book appointments, reserve tables or place orders. That data belongs to your business, which is the controller. We only process it to run the service on your behalf, as set out in our Terms & Conditions.

If you are a customer of a business using Mizz AI and want your data accessed or deleted, please contact that business directly — they control it. We will help them respond.

3. Personal data we collect

From business owners (we are controller)

  • Account data: name, email address, password (stored only in hashed form by our authentication provider), email verification codes.
  • Business data: business name, sector, trading address, phone and WhatsApp numbers, public contact email, website and social links, opening hours, services, products, prices, FAQs, staff names where you add them, and any logo or images you upload.
  • Subscription and billing data: plan, subscription status, billing dates and payment-processor identifiers. We never see or store your full card details — these go directly to Stripe.
  • Usage data: conversation counts, dashboard activity, technical logs, IP address and device/browser information.
  • Communications: emails and support messages you send us.
  • Referral data: if you sign up via a partner code, we record which partner referred you.

From partners in our referral programme (we are controller)

  • Name, email address, phone number, referral code, application status and commission records.

From your customers (we are processor for you)

  • Conversation content: messages exchanged with your AI assistant.
  • Booking and order data: name, email address and/or phone number, chosen service or items, appointment or reservation time, party size, delivery address where relevant, and any notes provided.
  • Technical data: IP address and basic device information for security and abuse prevention.

Please do not ask for, and discourage your customers from sending, special category data (such as health details) through the chat unless you have a lawful basis and appropriate safeguards for it.

4. Why we use it, and our lawful bases

PurposeLawful basis
Creating and running your account, providing the assistant, website and booking featuresPerformance of a contract
Taking payment, managing subscriptions and preventing failed paymentsPerformance of a contract
Sending service emails (verification, confirmations, renewal and trial notices)Performance of a contract
Security, fraud and abuse prevention, enforcing fair usageLegitimate interests — protecting our platform and users
Improving and troubleshooting the service, analytics on how features are usedLegitimate interests — improving a service you pay for
Marketing emails about our own similar services to existing customersLegitimate interests, with an unsubscribe link in every message
Marketing to people who are not yet customersConsent, which you may withdraw at any time
Paying partner commissionsPerformance of a contract
Meeting accounting, tax and other legal dutiesLegal obligation

Where we rely on legitimate interests, we have considered the impact on you and you have the right to object — see section 9.

5. AI processing

To answer your customers' questions, the business information you publish and the content of the conversation are sent to our AI provider (Google) for processing and returned as a generated reply. We use these providers under business terms that do not permit your data to be used to train their public models. No decision producing legal or similarly significant effects about an individual is made solely by automated means.

6. Who we share data with

We do not sell personal data. We share it only with service providers who process it on our behalf under contract, and where the law requires. Our main providers are:

ProviderWhat they do
Google Cloud / FirebaseHosting, database, authentication and file storage
Google (Gemini AI)Generating assistant responses
Google Maps / PlacesAddress lookup during registration and map display
StripeSubscription billing and, where enabled, payments from your customers
Amazon Web Services (SES)Sending transactional email
CloudflareDNS, security, content delivery and custom domains

We may also disclose data to professional advisers, to a buyer if we sell or reorganise our business, and to regulators, law enforcement or courts where we are legally required to.

7. International transfers

Some of our providers process data outside the UK, including in the European Economic Area and the United States. Where data leaves the UK we rely on an adequacy decision where one applies, or on the UK International Data Transfer Agreement or Addendum to the EU Standard Contractual Clauses, together with additional safeguards where appropriate.

8. How long we keep data

  • Account and business data: for as long as your account is active, and up to 12 months after closure so the account can be restored and disputes handled.
  • Billing and tax records: six years, as required by UK tax law.
  • Conversations: retained while your account is active to provide the service; you can ask us to delete them sooner.
  • Bookings and orders: retained while your account is active, subject to your own retention decisions as controller.
  • Marketing preferences and unsubscribe records: kept indefinitely so we continue to honour your choice.
  • Technical logs: typically up to 12 months.

When data is no longer needed we delete it or irreversibly anonymise it.

9. Your rights

Under UK GDPR you have the right to:

  • Be informed about how we use your data — this policy;
  • Access a copy of the personal data we hold about you;
  • Rectification of inaccurate or incomplete data;
  • Erasure of your data in certain circumstances;
  • Restrict our processing in certain circumstances;
  • Data portability — receive your data in a structured, machine-readable format;
  • Object to processing based on legitimate interests, and to direct marketing at any time;
  • Withdraw consent where we rely on it, without affecting earlier processing.

To exercise any right, email support@mizzai.com. We respond within one month and will not charge a fee except where a request is manifestly unfounded or excessive. We may ask you to verify your identity.

10. Security

We apply appropriate technical and organisational measures, including encryption in transit, access controls that restrict business data to its owner, hashed password storage, and infrastructure operated by established cloud providers. No system can be guaranteed completely secure. If a personal data breach occurs that is likely to result in a risk to individuals, we will notify the Information Commissioner's Office within 72 hours where required, and notify affected people where the risk is high.

11. Cookies and similar technologies

We use only what is necessary to run the service — cookies and local storage that keep you signed in, maintain your session and chat state, and protect against abuse. These are strictly necessary and do not require consent. We do not use advertising or third-party tracking cookies. You can block cookies in your browser, but parts of the service will not work.

12. Children

The service is for businesses and is not directed at children. We do not knowingly collect data from children under 13. If you believe a child has provided us with personal data, contact us and we will delete it.

13. If you use Mizz AI for your business

As controller of your customers' data, you are responsible for:

  • Having a lawful basis for collecting and using it;
  • Giving your customers your own privacy notice, and making it available where they can see it;
  • Responding to their data-subject requests — we will assist you;
  • Not using the platform to send unsolicited marketing.

14. Changes to this policy

We may update this policy. The version number and date at the top always show the current version, and we will tell you about material changes by email or in your dashboard.

15. Complaints

If you are unhappy with how we have handled your data, please contact us first at support@mizzai.com. You also have the right to complain to the UK supervisory authority:

Information Commissioner's Office — Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF · Helpline 0303 123 1113 · ico.org.uk