1. Who we are
"Mitra" is the commercial brand for services supplied by IDEA COM LTD, UIC 202250563, with registered office at 1 Boris Sarafov Street, 2800 Sandanski, Blagoevgrad, Bulgaria.
IDEA COM LTD operates in Greece through its registered branch "ΜΙΤΡΑ ΥΠΟΚΑΤΑΣΤΗΜΑ ΑΛΛΟΔΑΠΗΣ ΜΟΝΟΠΡΟΣΩΠΗ ΕΤΑΙΡΕΙΑ ΠΕΡΙΟΡΙΣΜΕΝΗΣ ΕΥΘΥΝΗΣ", GEMI 170250909001, Greek VAT number 996589360.
"Mitra", "we", "us" and "our" in this Policy refer to the same legal person.
General contact: info@mitra.gr
Privacy requests: privacy@mitra.gr
2. Scope and our role
Mitra provides a business-to-business software platform for customer communications, website chat, WhatsApp Business messaging, business-specific AI assistance, appointments, reservations, service requests, tickets, CRM context, knowledge-based responses, workflows, integrations and authorised staff handoff.
Our data-protection role depends on the context.
When Mitra acts as Controller: We determine the purposes and means of processing relating to Mitra business accounts, subscriptions, billing, website operation, security, fraud prevention, support, legal compliance and our own business communications.
When Mitra acts as Processor: A Mitra business customer normally determines why and how information relating to its own customers, prospects and contacts is processed through the Service. In those circumstances, the business customer is normally the Controller and Mitra processes the information on its behalf.
When you communicate with a business through WhatsApp or a Mitra-powered website chat, that business remains your primary contact regarding the purpose and lawful basis of the communication, appointments or services, marketing consent and its retention decisions.
3. Personal data we process
3.1 Business account and user information
We may process:
- name;
- business email address;
- business telephone number;
- job role;
- company name and business details;
- billing contact and tax information;
- account identifiers;
- authentication and login events;
- user roles and permissions;
- subscription plan;
- invoice and payment status;
- transaction references;
- support requests and communications.
3.2 WhatsApp Business Platform information
When an authorised business connects a WhatsApp Business Account through Meta's supported onboarding process, Mitra may process:
- Meta Business Portfolio identifiers;
- WhatsApp Business Account identifiers;
- connected phone-number identifiers;
- business display and configuration information;
- connection and messaging status;
- access credentials and permissions required to operate the integration;
- webhook events and technical metadata;
- WhatsApp user identifiers or telephone numbers;
- profile names where provided by WhatsApp;
- message timestamps and delivery status;
- message content and conversation context;
- approved message-template information;
- opt-in, opt-out and suppression information.
Mitra does not claim ownership of a customer's WhatsApp Business Account or telephone number.
3.3 Website chat, CRM, appointments and service information
Depending on the customer's configuration, Mitra may process:
- name;
- email address;
- telephone number;
- chat messages and conversation history;
- appointment or reservation information;
- tickets and service requests;
- CRM notes, status and tags;
- assigned staff information;
- follow-up history;
- consent and communication preferences;
- business knowledge and instructions configured by the customer.
Users should not send full payment-card information, passwords, financial credentials, identity-document numbers or other unnecessary highly sensitive information through chat.
4. AI processing
Mitra uses artificial intelligence to assist with business-specific customer service, booking, support and workflow functions.
To generate an answer, draft or action, Mitra may transmit limited conversation context, relevant customer instructions and selected business knowledge to an AI service provider.
Mitra does not use customer or WhatsApp conversation data to train Mitra's own general-purpose AI models.
Where Mitra uses OpenAI's API services, OpenAI states that API inputs and outputs are not used to train its models by default unless the organisation explicitly opts in. Mitra's policy is not to opt customer data into general model training. (OpenAI)
AI-generated information can be incomplete, inaccurate or inappropriate. Mitra is designed to support business-specific workflows and is not intended to make final medical, legal, credit, employment, insurance or similarly significant decisions without appropriate human oversight.
5. Payment information
Subscription payments may be processed by Stripe.
Mitra may receive information such as:
- customer and subscription identifiers;
- payment status;
- amount and currency;
- invoice information;
- transaction references;
- limited payment-method information such as card brand and last four digits;
- fraud or dispute status.
Mitra does not store full payment-card numbers or card security codes.
6. Website, device and cookie information
When you use our website or Service, we may process:
- IP address;
- browser and device type;
- operating system;
- language;
- pages viewed;
- referring page;
- approximate location derived from IP;
- interaction events;
- login and security events;
- error and technical logs;
- cookie preferences and consent information.
Optional analytics and advertising technologies are subject to the choices described in our Cookie Policy.
7. Why we process personal data
When Mitra acts as Controller, we may process information for the following purposes:
- creating and administering business accounts;
- performing contracts and providing the Service;
- securing accounts, infrastructure and communications;
- administering subscriptions, invoices and payments;
- preventing fraud, abuse and unauthorised access;
- providing customer support;
- maintaining and improving service reliability;
- complying with legal obligations;
- establishing, exercising or defending legal claims;
- performing analytics or advertising where the required consent has been obtained.
Depending on the processing activity, the applicable legal basis may include performance of a contract, compliance with a legal obligation, legitimate interests or consent.
Where Mitra acts as Processor, the relevant business customer determines the lawful basis for its processing and provides Mitra with documented instructions.
8. WhatsApp communications
Businesses using Mitra are responsible for complying with applicable Meta and WhatsApp requirements.
Depending on the communication, this may include requirements concerning:
- lawful collection of telephone numbers;
- user permission or opt-in;
- approved message templates;
- customer-service messaging windows;
- opt-out requests;
- appropriate business identification;
- lawful and expected communications.
More information is available at: https://mitra.gr/whatsapp
9. Who receives personal data
Personal data may be made available to:
The relevant Mitra business customer and its authorised users, where they control the relevant workspace.
Service providers and subprocessors, where necessary to provide infrastructure, AI processing or other enabled Service functions.
Meta/WhatsApp, where WhatsApp functionality is used.
Stripe, where payment or subscription functionality is used.
Professional advisers, such as legal, accounting, audit, insurance or security advisers, where reasonably necessary and subject to appropriate confidentiality obligations.
Public authorities, where disclosure is legally required.
Our current Subprocessors information is available at: https://mitra.gr/subprocessors
10. International transfers
Mitra is established in the European Union.
Some service providers or their authorised subprocessors may process personal data outside the European Economic Area.
Where required by applicable law, such transfers are protected using an applicable lawful transfer mechanism, which may include an adequacy decision, European Commission Standard Contractual Clauses or another legally permitted mechanism.
11. Retention
We retain personal data only for as long as reasonably necessary for the relevant purpose, customer instructions, security requirements and legal obligations.
Unless a different lawful or customer-configured period applies, our operational approach is generally:
- business account and configuration information: while the account remains active and until deletion is completed;
- conversation, appointment, ticket and CRM information: customer-configurable where available, otherwise generally subject to a rolling operational retention period;
- WhatsApp connection credentials: while the integration remains authorised and until disconnected or revoked;
- ordinary technical and security logs: generally up to 90 days, unless longer retention is reasonably required for security or legal purposes;
- support records: generally up to 24 months after closure where required for support and dispute management;
- billing and tax information: for applicable statutory retention periods;
- eligible information following a verified deletion request: deletion from active systems targeted within 30 days;
- information contained in rotating backups: removed through normal backup expiry cycles, generally within up to 90 days.
12. Security
Mitra applies technical and organisational measures designed to protect personal data against unauthorised access, disclosure, alteration, loss or misuse.
These measures may include access controls, authentication safeguards, encrypted transmission, infrastructure protections, logging, backup controls, incident management and supplier due diligence.
No internet-based service can guarantee absolute security.
13. Your rights
Subject to applicable law, you may have rights including:
- access to personal data;
- correction of inaccurate data;
- deletion;
- restriction of processing;
- objection to certain processing;
- data portability;
- withdrawal of consent;
- rights relating to certain automated decisions.
Where the relevant information is controlled by a business using Mitra, you should normally contact that business first.
You may also contact privacy@mitra.gr and we will route or assist with the request where appropriate.
You also have the right to lodge a complaint with the competent data-protection supervisory authority.
14. Children
Mitra business accounts are intended for adults acting on behalf of businesses.
Mitra does not offer business accounts to persons under 18.
15. Changes to this Policy
We may update this Privacy Policy when the Service, our providers, applicable law or our processing activities change.
The latest version will always be published on this page together with its effective date.
16. Contact
Privacy: privacy@mitra.gr
General support: info@mitra.gr
Website: https://mitra.gr