Privacy policy
What we collect, why, and what you can ask us to do about it.
Last updated: 26 August 2026
1. Who we are
MIHOS is a service operated by MUUM Sàrl, a limited liability company (société à responsabilité limitée) with registered office at Route de Champ-Colin 12, 1260 Nyon, Switzerland, entered in the Commercial Register of the Canton of Vaud under UID CHE-143.151.748 (register number CH-550.1.241.694-8). Contracts, invoices and data processing agreements are concluded with MUUM Sàrl. MIHOS is the name of the service.
For anything in this policy, write to privacy@mihos.ai.
2. What this policy covers
Two different things, with two different roles.
This website. We decide why and how the data collected here is processed. We are the controller.
The MIHOS application. Our customers deploy MIHOS across their sales teams. They decide what is recorded, analysed and written back. They are the controller and we act as their processor, under a data processing agreement signed before any data reaches us. If you are a sales rep or a client of one of our customers, address your request to that company first. We will help them answer you.
3. What we collect
On this website
- What you type in the contact form: name, company, email address, and the content of your message
- What you enter when you book a demonstration: name, email address, company, time zone, and anything you write in the booking field
- Technical data generated by serving the page: IP address, browser and device information, request logs, kept by our hosting provider
- Essential cookies set by Webflow to serve and secure the page
We ask for a work address but we do not require one, and many people reach us from a personal mailbox. Either way the address is treated the same and covered by this policy.
We run no analytics, no advertising, no session replay and no visitor identification on this website. We do not try to work out who you are from your visit. Bookings are taken through a third party scheduling service, which handles that data on our instructions and on our behalf. We remain responsible for it and this policy covers it.
In the MIHOS application
- Account data: name, email address, company, role, authentication data
- Audio recordings of field sales meetings, and their transcripts
- Consent records: who consented, when, by what means, and the audio segment in which consent was given
- Analyses produced from those recordings: topics, questions, objections, talk-time balance, scores against the customer's playbook, coaching notes, recommended next actions
- Data read from and written to the customer's CRM, calendar and email, limited to the fields their administrator has approved
- Technical and security logs: access, writes performed, errors
Recording requires the explicit and prior consent of every participant in the meeting, including the customer's own client. Consent can be withdrawn at any time. The recording is then deleted, together with its transcript and its analysis, unless a legal retention obligation applies to the customer.
4. Why we process it, and on what basis
| What | Why | Basis |
|---|---|---|
| Contact and booking forms | Answer you, arrange a demonstration | Pre-contractual steps at your request (art. 6.1.b GDPR) |
| Server and security logs | Keep the service available and secure | Legitimate interest (art. 6.1.f) |
| Account data | Provide the service | Performance of the contract (art. 6.1.b) |
| Audio recording | Produce the analysis | Explicit consent of each participant (art. 6.1.a) |
| Consent records | Prove consent was obtained, as Swiss criminal law requires | Legal obligation and legitimate interest (art. 6.1.c, 6.1.f) |
| Transcription and analysis | The purpose of the product | Contract with the customer, plus the consent above |
| CRM, calendar and email writes | Execute what the meeting produced | Contract, within the scope the administrator approved |
Under Swiss law (FADP), the same processing is justified by the contractual relationship, by your consent where it is required, and by our overriding legitimate interest for security.
5. The AI behind MIHOS
MIHOS is built around AI. Without it the product does not function. The AI technology we use is third party and it is not Swiss made. What is Swiss made is the product built around it: the capture application, the consent layer, the scoring engine, the playbook logic and the CRM write-back. That is what the swiss made software + AI label means. See swissmadesoftware.org/en/about/plus-AI.
Speech to text and speaker separation are performed by Gladia, a French provider, consumed as a hosted API and running inside the European Union. Analysis, scoring and coaching text are produced by a large language model consumed as a service and hosted in Switzerland or the European Union. Both are third party, closed source, and used as delivered. We do not train a proprietary model, we do not fine-tune any model, and we do not run models on our own hardware. If any of that changes, this page changes first.
What the AI is not allowed to do
- No emotion inference. MIHOS does not infer, score or label the emotional state of a worker. The sentiment and emotion detection features our providers offer are switched off in our pipeline. Inferring emotions in the workplace is a prohibited practice under art. 5(1)(f) of the EU AI Act, in force since 2 February 2025.
- No voiceprint. MIHOS does not build a template that would let the same voice be recognised from one meeting to the next. See Voice & biometric data.
- No inference of special category data. No health, beliefs, political opinions, union membership or ethnic origin is derived from a voice or a transcript.
- No training. Meeting content is not used to train, fine-tune or improve any model, ours or a provider's.
Scores and recommendations are indicative, and AI output can be wrong. On their own they produce no decision with legal or similarly significant effect on a person. Every decision about a rep involves human judgement, every write into a customer system is logged and reversible, and every score is traceable back to the timestamped passage that produced it. Role play uses a generic synthetic voice, labelled as artificially generated as art. 50 of the EU AI Act requires. No participant's voice is cloned.
Under the EU AI Act, a system used to monitor and evaluate the performance and behaviour of workers falls under Annex III, point 4(b). Regulation (EU) 2026/1744, in force since 27 July 2026, moved the application date of those obligations to 2 December 2027. We are building against that date. The art. 50 transparency obligations, applicable since 2 August 2026, we meet now.
6. How long we keep it
- Contact form and booking submissions: 24 months from our last exchange
- Account data: for the duration of the contract, then 12 months. Invoicing and accounting records are kept 10 years, as art. 958f of the Swiss Code of Obligations requires
- Audio recordings: 90 days by default
- Transcripts: 12 months by default
- Analyses, scores and coaching notes: 24 months by default
- Consent records: as long as the recording they relate to, plus 12 months
- Security logs: 12 months
A customer can shorten any of these. Extension beyond the default is possible only where the customer documents a regulatory obligation that requires it, and it is written into the order form. Where MIHOS is used to evidence a regulatory duty, that data is kept separate from coaching data and follows its own schedule.
At the end of the contract, customer data is exportable for 30 days and deleted within 60 days, unless a legal obligation requires otherwise. Deletion is permanent in production systems. Encrypted backups are rotated out within 35 days, after which no copy remains.
7. Who else touches the data
Providers that handle meeting content
These are the ones that matter most, so we name them.
| Provider | What it does | Where the data sits |
|---|---|---|
| Supabase, Inc. (United States), running on Amazon Web Services | Application, database and file storage: audio, transcripts, analyses and account data | Switzerland, Zurich region |
| Gladia (France) | Speech to text and separation of speakers within one recording | European Union |
| Analysis model provider | Summaries, scores against the playbook, coaching text and CRM field suggestions | Switzerland or the European Union |
Everything else
Beyond those, we rely on established providers for the hosting of this website and its form submissions, for demonstration bookings, for the technical connection to a customer's CRM, calendar and email, and for our own business email. They are established in the European Union and in the United States. None of them receives audio, transcripts or analyses.
Each of them is named individually, with the data it processes and the region it processes it in, in the sub-processor annex to our data processing agreement. That annex is the complete and authoritative list, and we send it to anyone who asks at privacy@mihos.ai, customer or not. Customers are notified by email at least 30 days before a new sub-processor starts processing their data, and may object on reasonable data protection grounds.
We do not sell or rent personal data. We do not use meeting content to train or improve models. Our speech and language providers are engaged on contractual terms that prohibit training on our customers' audio and hold retention to what a single request requires. We share data only with the providers described above, with the customer company you work for, and where a competent authority legally requires it.
8. Where the data sits, and what that does and does not mean
Recordings, transcripts and analyses are stored in Switzerland, in the Zurich region. Transcription is carried out inside the European Union. No meeting content is stored outside Switzerland.
We would rather be precise than flattering about what that guarantees. The Zurich infrastructure is operated by Supabase, Inc. on Amazon Web Services, both United States companies. Physical residency in Switzerland is not the same thing as legal sovereignty: a US-controlled provider can in principle be reached by a US production order wherever the disks are. We therefore rely, in addition to the location itself, on the European Commission's Standard Contractual Clauses together with the Swiss addendum recognised by the FDPIC, on encryption in transit and at rest, on contractual limits on provider access, and on an assessment of the destination country.
Customers who require a provider chain with no US parent can ask us. We will tell them honestly what that would take and what it would cost.
9. Security
Encryption in transit and at rest. Access restricted to the people who need it and reviewed regularly. Every write the product performs into a customer system is logged. Every access by our staff to meeting content is logged and visible to the customer. Customer environments are separated. We do not claim certifications we have not obtained.
Where we act as processor and become aware of a breach affecting customer data, we notify the customer without undue delay, as art. 33(2) GDPR requires, and give them what they need to meet their own 72 hour deadline. Where we act as controller, we notify the FDPIC as soon as possible under art. 24 FADP, and the competent supervisory authority within 72 hours where the GDPR applies.
10. Your rights
You can ask for access to your data, its correction, its deletion, a restriction of processing, a copy in a portable format, and you can object to processing based on legitimate interest. Where processing rests on consent, you can withdraw it at any time, without affecting what was done before.
Write to privacy@mihos.ai. We answer within 30 days. Where a request is complex, or where you have sent us several, we may extend that by two months and will tell you why within the first 30 days.
If our answer does not satisfy you, you can complain to the Federal Data Protection and Information Commissioner (FDPIC) in Switzerland, or to the supervisory authority of your country of residence in the EEA.
11. Recording people at work
Where MIHOS is deployed over a sales team, the employer must inform its employees before any recording, issue a written internal policy covering the system, its retention periods and its consequences, and consult employee representatives where local law requires it. That obligation sits with the customer company. We provide the documentation needed to meet it, including a data protection impact assessment template.
In Switzerland, art. 26 of Ordinance 3 to the Labour Act prohibits surveillance systems intended to monitor employee behaviour. MIHOS is built so that it cannot be operated as one: recording is started by the rep, session by session, the product does not listen between sessions, and there is no continuous or scheduled capture mode to enable.
12. Minors
MIHOS is a business tool. We do not knowingly collect data about anyone under 16. Anything collected by mistake is deleted.
13. Cookies
This website sets only the cookies Webflow needs to serve and secure the page. There is no analytics cookie, no advertising cookie and no tracking pixel, so no consent banner is required. If that ever changes, this page changes first and a banner appears before the first cookie is set.
14. Changes
If this policy changes materially, we update the date above and notify customers at least 30 days in advance.
15. Contact
MUUM Sàrl, Route de Champ-Colin 12, 1260 Nyon, Switzerland. Data protection: privacy@mihos.ai. Anything else: hello@mihos.ai.


