Privacy Policy
Version of 4 September 2026
This explains what we do with personal data: the data in the conversations you upload, and the data we hold about you as a customer. Those are two different things with two different answers, and the distinction runs through the whole document.
1. Who we are
Mira scores is operated by MiraSoft, a sole proprietorship established in the Plurinational State of Bolivia and based in Santa Cruz, Bolivia. We have no physical offices. You can reach us about anything in this policy at contact@mirascores.com, which is the address for data protection questions as well. This policy covers the Mira scores platform and the mirascores.com website.
2. Controller and processor — which is which
For the conversations you upload and everything derived from them — audio, transcripts, evaluations, coaching notes — you are the controller and we are your processor. We act on your instructions, which in practice means the settings you choose in the product. You decide what is recorded, whose conversations they are, what lawful basis applies and how long you keep them. For the data we hold about your organisation as a customer — your users' names and work email addresses, their role, their sign-in history, what your account was billed — we are the controller. For payment data we are not the controller at all. Purchases are processed by Paddle as merchant of record; Paddle is an independent controller of the transaction data, under its own privacy notice. We never see your card details.
3. The conversations you upload
What this can contain is whatever your customers and agents said, which is why the platform is built the way it is. We process it to transcribe it, to score it against your scorecard, to compute metrics from it, and to produce the dashboards and coaching material you asked for. Nothing else. Before a transcript is stored, scored or shown, a deterministic rule set removes structured identifiers — card numbers validated with the Luhn algorithm, IBANs with the mod-97 check, CVV and PIN, e-mail addresses, phone numbers and long reference codes. This runs on our own servers and it is irreversible: the untouched text is not written to disk, not encrypted for later, and not recoverable by us. We keep a count of what was masked, not what it was. Masking catches structured data. It does not catch a name or an address spoken in ordinary prose, and we would rather tell you that than let you assume the transcripts have been cleaned of everything. We do not use this content to train any model, ours or anyone else's.
4. Account and usage data
We hold the name, work email address, role, team, department and country of the users in your account, because the product cannot scope permissions or write an audit trail without them. We hold sign-in times, the actions users took, and the technical logs a service generates — IP address, browser, timestamps — which we keep for security and troubleshooting. We hold your billing history at the level of what was charged and when. The payment instrument itself is Paddle's. Where you contact us, we keep the correspondence so that the next person who picks it up knows what was already said.
5. The website
The public site sets no advertising cookies and runs no third-party advertising or social tracking. If you fill in the contact form we receive what you typed and use it to answer you. The application stores a small amount of information in your browser to remember your language, your theme and your session; that is functional and is not shared with anyone.
6. Legal bases
Where the GDPR or a similar law applies, we rely on: performance of a contract, for providing the service and billing it; legitimate interests, for securing the platform, preventing abuse and improving the product, balanced against the rights of the people affected; and legal obligation, where a law requires us to keep or produce something. For the conversation content, the legal basis is yours to establish, not ours. See the recording clause in our Terms of Service.
7. Sub-processors and where data goes
We use a small number of providers to run the service, and we tell you who they are: — Google Cloud (Google LLC / Google Cloud EMEA Limited) — AI transcription and scoring through Gemini Enterprise, and hosting. Under enterprise terms that exclude customer data from model training. — Paddle (Paddle.com Market Limited and its group companies) — payment processing as merchant of record. Paddle receives your billing details and the email address of the person who bought; it does not receive your conversation data. — Our email delivery provider, for transactional email: invitations, notifications, password resets. It receives the recipient's email address and the content of the message. Acoustic analysis, conversation metrics and the masking rules run on infrastructure we operate ourselves and involve no third party. We will tell you before adding a sub-processor that processes conversation content, and you may object. Ask us for the current list in writing at any time; the list here is kept up to date.
8. International transfers
We are based in Bolivia and our providers operate globally, so your data will be transferred outside the country where you are. Where data protected by the GDPR or the UK GDPR leaves that area, the transfer relies on the European Commission's Standard Contractual Clauses or the UK Addendum, together with the supplementary measures our providers apply. If your organisation requires processing within a particular region, tell us before you sign. It is sometimes possible, and it is better established in an order form than assumed.
9. How long we keep things
Conversation content is kept while your account is active and for 30 days after termination, during which you may export it. After those 30 days the **recordings are destroyed** — the audio files are deleted — and the remaining records are **retained in de-identified form**: transcripts, evaluations, scores and the audit trail stay, with company names, user email addresses and identifiers rewritten so no individual is named by them. The reason for the split is that the two carry different risk. A recording is a person's voice discussing their own affairs and is the largest thing we hold; a de-identified evaluation record is what lets either party answer a question about the period the account existed, which is sometimes a legal obligation rather than a preference. Where you set a shorter retention period in the product, or agree one in an order form, that period applies instead, and you may ask us in writing to delete the retained records too. Account and billing records are kept for as long as the law requires us to keep them, which is a legal obligation rather than a choice. Security logs are kept for a limited period and then discarded.
10. Security
Data is encrypted in transit and at rest. Every record is scoped to one company at the database level and the scope is enforced on the server, not in the interface. Access inside the product is decided by role, and every route checks it independently of what the menu happens to show. Two-factor authentication is available on every account. Access by our own staff is limited to what is needed to run and support the service and is logged. If a breach affects your data we will tell you without undue delay and in any event within 72 hours of becoming aware of it.
11. Your rights — and the rights of the people on the recordings
Where the law gives you rights over personal data we hold as controller — access, correction, deletion, portability, restriction, objection — write to contact@mirascores.com and we will answer within the period the law allows. If you are in the EEA or the UK you may also complain to your data protection authority. If you are in California or a state with similar law, you may ask what we collect and ask us to delete it; we do not sell or share personal information as those laws define it. For the conversation content, requests belong to you, not to us. If one of your customers or agents asks us directly to access or delete something in a recording, we will not act on it: we will pass it to you and support you in answering it, because you are the controller and only you can judge whether the request is valid.
12. Children
The service is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16 as a user of the product. If a recording you upload contains a child's voice, the lawful basis for that is yours to establish, and the retention and masking controls are there to be used.
13. Changes to this policy
We may update this policy. The date at the top says when it last changed. Where a change materially affects how we handle conversation content, we will tell you before it takes effect rather than after.
14. Contact
Write to contact@mirascores.com with anything about this policy, including a data protection agreement, a security questionnaire, a sub-processor list or a transfer mechanism. We answer these properly rather than pointing at a page.
Questions about any of this?