1. Who we are and how to contact us
Mizz AI is a trading name of AppMind Ltd, registered in England and Wales (company number 16461561). For the personal data described in this policy as ours, AppMind Ltd is the data controller.
For any privacy question, or to exercise your rights, contact us at support@mizzai.com.
2. Our two different roles — please read
This is the most important thing to understand about how data works on our platform:
- We are the controller of data about the business owners who register with us — your account details, business information, billing and how you use the dashboard.
- We are a processor for the data of your own customers — the people who chat with your assistant, book appointments, reserve tables or place orders. That data belongs to your business, which is the controller. We only process it to run the service on your behalf, as set out in our Terms & Conditions.
If you are a customer of a business using Mizz AI and want your data accessed or deleted, please contact that business directly — they control it. We will help them respond.
3. Personal data we collect
From business owners (we are controller)
- Account data: name, email address, password (stored only in hashed form by our authentication provider), email verification codes.
- Business data: business name, sector, trading address, phone and WhatsApp numbers, public contact email, website and social links, opening hours, services, products, prices, FAQs, staff names where you add them, and any logo or images you upload.
- Subscription and billing data: plan, subscription status, billing dates and payment-processor identifiers. We never see or store your full card details — these go directly to Stripe.
- Usage data: conversation counts, dashboard activity, technical logs, IP address and device/browser information.
- Communications: emails and support messages you send us.
- Referral data: if you sign up via a partner code, we record which partner referred you.
From partners in our referral programme (we are controller)
- Name, email address, phone number, referral code, application status and commission records.
From your customers (we are processor for you)
- Conversation content: messages exchanged with your AI assistant.
- Booking and order data: name, email address and/or phone number, chosen service or items, appointment or reservation time, party size, delivery address where relevant, and any notes provided.
- Technical data: IP address and basic device information for security and abuse prevention.
Please do not ask for, and discourage your customers from sending, special category data (such as health details) through the chat unless you have a lawful basis and appropriate safeguards for it.
4. Why we use it, and our lawful bases
| Purpose | Lawful basis |
|---|---|
| Creating and running your account, providing the assistant, website and booking features | Performance of a contract |
| Taking payment, managing subscriptions and preventing failed payments | Performance of a contract |
| Sending service emails (verification, confirmations, renewal and trial notices) | Performance of a contract |
| Security, fraud and abuse prevention, enforcing fair usage | Legitimate interests — protecting our platform and users |
| Improving and troubleshooting the service, analytics on how features are used | Legitimate interests — improving a service you pay for |
| Marketing emails about our own similar services to existing customers | Legitimate interests, with an unsubscribe link in every message |
| Marketing to people who are not yet customers | Consent, which you may withdraw at any time |
| Paying partner commissions | Performance of a contract |
| Meeting accounting, tax and other legal duties | Legal obligation |
Where we rely on legitimate interests, we have considered the impact on you and you have the right to object — see section 9.
5. AI processing
To answer your customers' questions, the business information you publish and the content of the conversation are sent to our AI provider (Google) for processing and returned as a generated reply. We use these providers under business terms that do not permit your data to be used to train their public models. No decision producing legal or similarly significant effects about an individual is made solely by automated means.
6. Who we share data with
We do not sell personal data. We share it only with service providers who process it on our behalf under contract, and where the law requires. Our main providers are:
| Provider | What they do |
|---|---|
| Google Cloud / Firebase | Hosting, database, authentication and file storage |
| Google (Gemini AI) | Generating assistant responses |
| Google Maps / Places | Address lookup during registration and map display |
| Stripe | Subscription billing and, where enabled, payments from your customers |
| Amazon Web Services (SES) | Sending transactional email |
| Cloudflare | DNS, security, content delivery and custom domains |
We may also disclose data to professional advisers, to a buyer if we sell or reorganise our business, and to regulators, law enforcement or courts where we are legally required to.
7. International transfers
Some of our providers process data outside the UK, including in the European Economic Area and the United States. Where data leaves the UK we rely on an adequacy decision where one applies, or on the UK International Data Transfer Agreement or Addendum to the EU Standard Contractual Clauses, together with additional safeguards where appropriate.
8. How long we keep data
- Account and business data: for as long as your account is active, and up to 12 months after closure so the account can be restored and disputes handled.
- Billing and tax records: six years, as required by UK tax law.
- Conversations: retained while your account is active to provide the service; you can ask us to delete them sooner.
- Bookings and orders: retained while your account is active, subject to your own retention decisions as controller.
- Marketing preferences and unsubscribe records: kept indefinitely so we continue to honour your choice.
- Technical logs: typically up to 12 months.
When data is no longer needed we delete it or irreversibly anonymise it.
9. Your rights
Under UK GDPR you have the right to:
- Be informed about how we use your data — this policy;
- Access a copy of the personal data we hold about you;
- Rectification of inaccurate or incomplete data;
- Erasure of your data in certain circumstances;
- Restrict our processing in certain circumstances;
- Data portability — receive your data in a structured, machine-readable format;
- Object to processing based on legitimate interests, and to direct marketing at any time;
- Withdraw consent where we rely on it, without affecting earlier processing.
To exercise any right, email support@mizzai.com. We respond within one month and will not charge a fee except where a request is manifestly unfounded or excessive. We may ask you to verify your identity.
10. Security
We apply appropriate technical and organisational measures, including encryption in transit, access controls that restrict business data to its owner, hashed password storage, and infrastructure operated by established cloud providers. No system can be guaranteed completely secure. If a personal data breach occurs that is likely to result in a risk to individuals, we will notify the Information Commissioner's Office within 72 hours where required, and notify affected people where the risk is high.
11. Cookies and similar technologies
We use only what is necessary to run the service — cookies and local storage that keep you signed in, maintain your session and chat state, and protect against abuse. These are strictly necessary and do not require consent. We do not use advertising or third-party tracking cookies. You can block cookies in your browser, but parts of the service will not work.
12. Children
The service is for businesses and is not directed at children. We do not knowingly collect data from children under 13. If you believe a child has provided us with personal data, contact us and we will delete it.
13. If you use Mizz AI for your business
As controller of your customers' data, you are responsible for:
- Having a lawful basis for collecting and using it;
- Giving your customers your own privacy notice, and making it available where they can see it;
- Responding to their data-subject requests — we will assist you;
- Not using the platform to send unsolicited marketing.
14. Changes to this policy
We may update this policy. The version number and date at the top always show the current version, and we will tell you about material changes by email or in your dashboard.
15. Complaints
If you are unhappy with how we have handled your data, please contact us first at support@mizzai.com. You also have the right to complain to the UK supervisory authority:
Information Commissioner's Office — Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF · Helpline 0303 123 1113 · ico.org.uk