Last updated: · Version: privacy-2026-09-26
This policy explains what personal data Mielikkix collects, why, on what legal basis, who we share it with, how long we keep it and what rights you have. It covers the website mielikkix.ai, the dashboard app.mielikkix.ai, our API, the Mielikkix chat widget and our AI agents.
1. Who we are
The data controller is Mielikkix AS, Norway. Mielikkix AS is currently being registered in the Norwegian Register of Business Enterprises (Brønnøysundregistrene); our organization number and registered address will be added here as soon as registration is complete. Contact for all privacy questions: post@mielikkix.no.
2. Our two roles: controller and processor
- Controller for data about our own customers (businesses and their dashboard users), visitors to mielikkix.ai, people who request a demo, and people who chat with the Mielikkix chatbot on our own website.
- Processor for data about our customers' own end users: people who chat with a customer's widget, call a customer's Voice Receptionist number or book through a customer's Booking Assistant. The business you contacted is the controller for that data and its privacy policy applies; we process it only on its instructions under our Data Processing Agreement. Please send requests about that data to the business. If you contact us, we will forward your request.
3. What we collect, why, and our legal basis
| Data | Purpose | Legal basis (GDPR art. 6) |
|---|---|---|
| Name, email, hashed password, business profile, uploaded FAQs/documents/products, plan | Create and run your account and provide the service | Contract (6(1)(b)) |
| Billing and invoicing records | Accounting | Legal obligation (6(1)(c)), Norwegian Bookkeeping Act |
| Demo requests and contact messages (name, email, phone, company, message) | Answer you and arrange a demo | Steps before a contract (6(1)(b)) / legitimate interest (6(1)(f)) |
| Chats with the Mielikkix chatbot on mielikkix.ai, and any lead details you give it | Answer your questions and follow up if you ask us to | Legitimate interest (6(1)(f)) |
| Server and security logs (IP address, timestamps, request data) | Security, abuse prevention, troubleshooting | Legitimate interest (6(1)(f)) |
| Website usage statistics (Google Analytics) | Understand how the website is used and improve it | Consent (6(1)(a)), only if you click "Accept" |
| Product-update emails | Send news and tips | Consent (6(1)(a)), withdraw any time via the unsubscribe link |
| End-user data processed for our customers (see section 2) | Provide the chat, booking and voice services to the customer | Determined by the customer as controller; we act under the DPA |
End-user data we process for customers
- Chat messages sent to a business's chatbot, and the AI's replies, kept as conversation history for that business.
- Lead details a visitor submits (name, email, phone, message), shared with that business.
- Booking details (name, email, phone, requested appointment time) when a visitor books through Booking Assistant.
- For phone calls to a business's Voice Receptionist line: the call audio is transcribed to text by our telephony provider to carry on the conversation; call transcripts are held only in memory for the duration of the call today and are not currently written to a database.
4. AI processing
Our products use large language models from external providers (see Subprocessors) to generate replies, classify support messages, draft review responses and analyse websites. The chatbot and voice assistant are AI systems, not people. They do not make decisions with legal or similarly significant effects about you (GDPR art. 22). We do not use customer or end-user data to train AI models.
5. Google user data (Google API Services)
Google Calendar (Booking Assistant)
Booking Assistant lets a business connect their own Google Calendar so the assistant can check real availability and create real appointments on that business's behalf. This is entirely opt-in: a business only connects if they choose to use Booking Assistant, by signing in with their own Google account through Google's own consent screen.
When a business connects their calendar, we request exactly two Google Calendar scopes:
calendar.freebusy-- read-only access to when the connected calendar is busy or free. We never read the contents, titles, descriptions, or attendees of a business's existing calendar events -- only whether a given time slot is already taken.calendar.events-- lets Mielikkix create new calendar events representing appointments booked through the assistant, with the visitor who booked as an attendee (so Google emails them a calendar invite directly). We do not read, modify, or delete events we did not create.
We also request basic account email (userinfo.email) solely so the business's own dashboard can show them which Google account is connected (e.g. "Connected as: owner@theirbusiness.com").
Google Business Profile (Review & Reputation)
With business.manage, a business that connects its Google Business Profile lets us read the reviews on its own locations and publish the replies that the business has approved. We don't change anything else on the profile.
Google Analytics and Search Console (SEO Audit)
With the read-only scopes analytics.readonly and webmasters.readonly, a business that connects them lets us read its own website traffic and search-performance figures to prioritise its SEO audit. We never change its Analytics or Search Console settings.
How Google user data is stored and used
How this data is stored: the OAuth refresh token Google issues is encrypted at rest before it is ever written to our database, using a symmetric key held only on our own servers. It is decrypted only in memory, immediately before making an API call on that business's behalf, and is never logged, emailed, or exposed to any other business.
How this data is used: solely to provide the feature the business connected it for (checking availability and creating bookings, handling its reviews, or its SEO audit). We do not use Google user data for advertising, do not sell it, do not share it with any third party except the Google API itself and the business that owns the connection, and do not use it to train any AI model.
A business can disconnect any Google integration at any time from its own Settings page, which deletes the stored refresh token immediately. Disconnecting Calendar does not delete already-created calendar events (those are removed the normal way, directly in Google Calendar).
Mielikkix's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
6. Who we share data with
We use carefully chosen service providers (subprocessors), each receiving only what it needs for its task. The full, current list, with purpose and location, is on our Subprocessors page. We do not sell personal data. We may also disclose data if the law requires it.
Business transfers. If Mielikkix AS merges, is acquired, or sells all or part of its business, personal data may pass to the new owner as part of that transaction, under a duty of confidentiality and only for the purposes described in this policy (legitimate interest, art. 6(1)(f)). We will tell account holders before their data is transferred or becomes subject to a different privacy policy, so they can first download their data or delete their account.
7. Transfers outside the EEA
Several providers (for example Groq, OpenAI, Anthropic, Google, Twilio and Resend) are based in the USA. When personal data is transferred there, we rely on the EU-US Data Privacy Framework where the provider is certified, or on the EU Standard Contractual Clauses. Each provider's location is listed on our Subprocessors page. You can ask us for a copy of the relevant safeguards.
8. How long we keep data
- Account data: while your account is active. When you delete your account, everything is permanently deleted after a 30-day grace period (during which you can cancel), except what we must keep by law.
- Records of your agreements and consent choices (what you accepted and when, including marketing choices and withdrawals): kept in minimised form for 3 years after account deletion to demonstrate compliance and defend legal claims. Only a keyed hash of your email is kept with them, never your name, business or IP address. They are then deleted.
- Accounting records: 5 years after the end of the financial year (Norwegian Bookkeeping Act).
- Chat conversations (processed for customers): automatically deleted after the retention period the business chooses, counted from the last message: 90 days by default, and never more than 365 days. A business can also delete a single conversation, or all data about one visitor, at any time. Leads (contact details a visitor chose to leave) are kept as the business's customer records until the business deletes them. Everything is deleted with the business's account.
- Voice calls: transcripts are only held in memory during the call and are not stored.
- Demo requests: 12 months after our last contact, unless you become a customer.
- Server logs: 30 days, then deleted automatically.
- Google Analytics data: 2 months (the Google Analytics retention setting).
9. Cookies
mielikkix.ai only uses necessary storage unless you accept analytics in our cookie banner. Google Analytics loads only after you accept, and you can change your choice any time under "Cookie settings" in the footer. Fonts are served from our own server. See the Cookie Policy for every cookie and storage key.
10. Security
Passwords are hashed, never stored in plain text. OAuth refresh tokens are encrypted at rest. Traffic is encrypted with TLS. Dashboard sessions use httpOnly cookies. Each business can only access its own data. More on our Security page.
11. Your rights
Under the GDPR and the Norwegian Personal Data Act you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased ("right to be forgotten");
- restrict processing;
- data portability (receive your data in a machine-readable format);
- object to processing based on legitimate interest;
- withdraw consent at any time, without affecting processing that took place before.
Email post@mielikkix.no to use any of these rights. We answer within one month, and may ask you to verify your identity first. Account holders can also download their data, change their email preferences and delete their account themselves, under Chatbot Settings → Privacy & data in the dashboard.
You can complain to the Norwegian Data Protection Authority, Datatilsynet. In the UK you can complain to the Information Commissioner's Office (ICO).
12. Children
Our services are for businesses and not directed at children. Account holders must be 18 or older.
13. Changes
We will update this policy when our services or the law change. The date and version at the top show the current version. If a change is material, we will tell account holders by email or in the dashboard.