This Privacy Policy describes how DeusMachina, Inc. dba Mitra ("Mitra," "we", "us," or "our") handles personal information that we collect through our online services that link to this Privacy Policy, including our website and mobile application (collectively, the "Service"), our marketing and social media activities, our communications with you, and the other activities described in this Privacy Policy.
We and our third-party service providers may monitor and record your communications and interactions with us and the Service for the purposes described in this Privacy Policy.
State Law Privacy Rights: See the State Law Privacy Rights section below for important information about rights you may have under applicable U.S. state privacy laws.
If you have any questions or concerns about how we process your personal information, please contact us.
Personal information we collect
The personal information we collect from you, either directly or indirectly, will depend on how you interact with us and with our Service. In general, we collect personal information about you from the following sources:
Information you provide to us. Personal information you may provide to us through the Service, at our events or otherwise includes:
● Contact data. Your name, email address, phone number, and other contact details.
● Account data. Your name, phone number, the password for your account, your preferences, and any other information you choose to add to your account.
● Address book data. The contact details in your device's address book, when you grant the Service access to it through your device's settings.
● User generated data. Information you provide, generate, transmit, or otherwise make available to the Service (including through the Mitra chatbot), such as:
voice or other audio recordings, including those collected from your device's microphone when you choose to grant the Service access to it;
messages drafted or sent through the Service;
images and photos, including those collected from you device's photo app or camera when you choose to grant the Service access to it;
files and documents; and
other media.
● Transaction data. Information about your transactions with us, such as your order history, payment card data associated with the card you use to pay for the Service, information about your payment transactions, and your subscription tier.
● Communications data. Information in your communications with us, including when you communicate with us through the Service, social media, events, our chatbot, or otherwise, including any feedback you provide about the Service and your responses to surveys.
● Marketing data. Information about your preferences for receiving our marketing communications.
If we collect personal information not specifically listed above, we will use it consistent with this Privacy Policy or as otherwise explained at the time of collection.
Information about others. You should never submit personal information of others to the Service if they have not given you permission to do so. When communicating with the Service through your device's microphone, you are responsible for ensuring that only your voice is recorded.
Information automatically collected. As you navigate the Service and our communications, we and our service providers automatically collect identifiable information about you, your computer or device, and your browsing actions and use patterns, such as:
● Device data. Technical information about your computer or mobile device's operating system type and version, manufacturer and model, browser type, screen resolution, RAM and disk size, CPU usage, device type (e.g., phone, tablet), IP address, unique device identification numbers or other identifiers, language settings, mobile device carrier, radio/network information (e.g., Wi-Fi, LTE, 3G), and general location information such as city, state or geographic area.
● Usage data. Page views and searches (including search terms), log-in information, videos and other content that you view, how long you spent on a page or screen, the website you visited before browsing to the Service, your interactions with a page or screen (e.g., if you "like" content), navigation paths between pages or screens, information about your activity on a page or screen, access times and duration of access, metadata about your communications with us (e.g., time sent and whether you have opened our emails or clicked links within them), and other functional information on Service performance (like diagnostics and crash logs).
● Precise geolocation. The GPS location of our device, when you authorize our mobile application to access it in your device's settings.
Cookies and other technologies. Some of the information we and our service providers collect automatically is captured through the following technologies:
● Cookies. These are text files that websites store on a visitor's device to uniquely identify the visitor's browser or to store information or settings in the browser for the purpose of tracking user activity and patterns, helping the visitor navigate between pages efficiently, remembering preferences, improving the visitor's browsing experience, and enabling functionality, and analytics. Cookies used on our site include cookies that we serve as well as cookies served by third parties that we work with to enable the services they provide, such as analytics services that track traffic and usage. You can learn more about cookies and how to control them at www.allaboutcookies.org.
We use Google Analytics to help us understand user activity. You can learn more about Google Analytics and how to opt-out of being tracked by Google Analytics here: https://tools.google.com/dlpage/gaoptout.
● Pixels. Also known as web beacons or clear GIFs, pixels are embedded in software code or invisibly in image files within webpages or HTML formatted emails and used to demonstrate that a webpage or email was accessed or opened, or that certain content was viewed or clicked, typically to compile statistics about usage of websites and the success of marketing campaigns. We may use pixels to collect information about your interactions with our email messages, such as the links you click on and whether you open or forward a message, the date and time of these interactions and the device you use to read emails.
● SDKs. Software development kits (SDKs) are third-party computer code incorporated into our mobile and web applications to enable functions and tracking similar to those enabled by the other technologies described above, including to enable analytics services and functionality provided by third parties.
● Chatbots. The Service features chat interfaces operated by third parties. These third parties monitor and record your chats, and access and use the data described in the automatic collection section above, for the purposes described in this Privacy Policy. When you use these features, you are not communicating with a human unless we confirm that you are.
Third party sources. We combine personal information we receive from you or collect automatically when you use the Service with personal information we obtain from other sources, such as:
● Public sources. We may collect personal information from social media platforms and other publicly available websites.
● Our business contacts. Our professional contacts share with us contact details about individuals in their networks, including prospective vendors and partners.
How we use your personal information
We use your personal information for the following purposes or as otherwise described in this Privacy Policy or at the time of collection:
Service delivery. We use your personal information to manage and administer your Service account, provide the Service, process your payments, and communicate with you about our Service (including support and administrative messages).
Business operations. We use your personal information to administer and maintain our Service and our IT systems (including monitoring, troubleshooting, data analysis, testing, system maintenance, repair and support, reporting and hosting of data) and to operate our business activities.
Research and development. We use your personal information for research and development purposes, including to analyze and improve the Service and our business in an informed way. We may collect and use your personal information to train the large language models that enable the Service's AI features, but we do not allow large language models developed or operated by third parties to be trained on your personal information. We may also create aggregated, de-identified and/or anonymized data from personal information we collect. We make personal information into aggregated, de-identified or anonymized data by removing information that makes the data personally identifiable to you. We may use this aggregated, de-identified or otherwise anonymized data and share it with third parties for our lawful business purposes, including to analyze, improve and promote the Service and our business and to train our proprietary artificial intelligence models.
Direct marketing. As permitted by applicable law, we may collect and use your personal information to send you marketing emails we think may interest you or contact you by phone about our products, services or events. You may opt-out of our marketing communications as described in the Opt-out of marketing section below.
Compliance and protection. We use your personal information to comply with applicable laws, lawful requests, and legal process, such as to respond to subpoenas or requests from government authorities. We also use your personal information to protect our, your or others' rights, privacy, safety, or property including by making and defending legal claims; conducting internal audits against our policies; enforcing the terms and conditions that govern the Service; and taking steps to prevent, investigate and deter fraud, cyberattacks or other unauthorized, unethical, harmful, dangerous, or illegal activity.
How we share your personal information
We may share your personal information with the following categories of recipients and as otherwise described in this Privacy Policy or at the time of collection.
Affiliates. Our parent company and other corporate affiliates that we control, are controlled by, or with which we are under common control, for purposes consistent with this Privacy Policy.
Service providers. Third parties that provide services on our behalf or help us operate the Service or our business, such as business applications, hosting, content delivery network, other information technology, customer support, email delivery, marketing, payment processing, artificial intelligence (including chatbot, call transcription, voice agent, and voice cloning services), customer research, and analytics.
Payment processors. Third party payment processors, like Apple, that collect your payment card data and other transaction data to process your payment card transactions when you pay for the Service. You can learn about how Apple handles your personal data in its privacy policy available here: https://www.apple.com/legal/privacy/en-ww/.
CAPTCHA providers. To enhance the security of our Service, we use captcha features that require users to complete a task to authenticate to the Service. Third party providers of these CAPTCHA services collect device data and usage data, as described above to enable the CAPTCHA features and as described in their privacy policies. For example, we use the Google reCAPTCHA service. Your use of the Google reCAPTCHA feature is subject to its Terms of Service and Privacy Policy.
Linked third-party services. If you link your Service account to a social media, productivity tool or other third-party service, we may share your personal information with that third-party service. The third party's use of the shared information will be governed by its privacy policy and the settings associated with your account with the third-party service.
Professional advisors. Professional advisors, such as lawyers, auditors, bankers, and insurers, where necessary in the course of the professional services that they render to us.
Authorities and others. Law enforcement, government authorities, and private parties, as we believe in good faith to be necessary or appropriate for the compliance and protection purposes described above.
Business transferees. Parties (and their advisors) to business transactions (or negotiations of or due diligence for such transactions) involving a corporate divestiture, merger, consolidation, acquisition, reorganization, sale or other disposition of all or any portion of the business or assets of, or equity interests in, Mitra or our affiliates (including, in connection with a bankruptcy or similar proceedings).
Other parties with your consent or at your direction. We may share your personal information for other purposes disclosed to you at the time we collect the information or pursuant to your consent or direction.
Your choices
Access or update your information. You may review and update certain Service account information by logging into your account and visiting the settings page in the app.
Request account deletion. You may request account deletion of your Service account and associated personal information through the settings page in the app or by contacting us.
Opt-out of marketing communications. You may opt-out of marketing emails at any time by following the opt-out or unsubscribe instructions at the bottom of the email, or by contacting us with your request. Please note that if you opt-out of marketing emails, you may continue to receive service related and other non-marketing emails.
Device settings. You can disable our access to your device's precise geolocation, address book, photos, microphone or camera in your mobile device settings.
Cookies. Most browsers let you remove or reject cookies. To do this, follow the instructions in your browser settings. Many browsers accept cookies by default until you change your settings. Please note that if you set your browser to disable cookies, the Service may not work properly. For more information about cookies, including how to see what cookies have been set on your browser and how to manage and delete them, visit www.allaboutcookies.org. You can also configure your device to prevent images from loading to prevent web beacons from functioning.
Do Not Track. Some Internet browsers may be configured to send "Do Not Track" signals to the online services that you visit. We currently do not respond to "Do Not Track" signals. To find out more about "Do Not Track," please visit http://www.allaboutdnt.com.
Linked third-party platforms. If you choose to link your social media, productivity tools other third-party platform account to the Service, you may be able to use your settings in your account with that platform to limit the information we receive from it. If you revoke our ability to access information from a third party platform, that choice will not apply to information that we have already received from that third party.
Mandatory data. If you do not provide information we identify as required or mandatory, we may not be able to provide features or services that require that information.
Other sites and services
The Service may contain links to or integrations of websites and other online services operated by third parties. In addition, our content may be integrated into web pages or other online services that are not associated with us. These links and integrations are not an endorsement of, or representation that we are affiliated with, any third party. We do not control websites or other online services operated by third parties, and we are not responsible for their actions. We encourage you to read the privacy policies of the other websites and online services you use.
Security
We use technical, organizational, and physical safeguards designed to protect the personal information we process. However, security risk is inherent in all internet and information technologies, and we cannot guarantee the security of your personal information.
Retention
We retain personal information for as long as necessary to fulfill the purposes for which we collected it, including for the purposes of satisfying any legal, accounting, or reporting requirements, to establish or defend legal claims, or for the compliance and protection purposes described above. Factors determining the appropriate retention period for personal information include the amount, nature, and sensitivity of the personal information, the potential risk of harm from unauthorized use or disclosure of personal information, the purposes for which we process the personal information, whether we can achieve those purposes through other means, and the applicable legal requirements.
When we no longer require the personal information we have collected about you, we will either delete or anonymize it (so that it is no longer personally identifiable with you) or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will isolate your personal information from any further processing, employing security safeguards designed to protect it, until deletion is possible.
International data transfers
We are headquartered in the United States, and we and our service providers may process personal information from the United States and other countries. These countries may have data protection laws that are not as protective as those where you live.
Children
The Service is not intended for use by anyone under 18 years of age. If you are a parent or guardian of a child from whom you believe we have collected personal information in a manner prohibited by law, please contact us. If we learn that we have collected personal information through the Service from a child without the consent of the child's parent or guardian as required by law, we will comply with applicable legal requirements to delete the information.
Changes to this Privacy Policy
We reserve the right to modify this Privacy Policy at any time. If we make material changes to this Privacy Policy, we will notify you by updating the date of this Privacy Policy and posting it on the Service or other appropriate means. Any modifications to this Privacy Policy will be effective upon our posting the modified version (or as otherwise indicated at the time of posting). In all cases, your use of the Service after the effective date of any modified Privacy Policy indicates your acknowledgment that the modified Privacy Policy applies to your use of the Service and interaction with our business.
How to contact us
If you have questions or concerns about this Privacy Policy or our practices, please email us at support@deusmachina.inc.
State Law Privacy Rights
Scope. Except as otherwise provided, this section applies to residents of U.S. states with privacy laws that grant their residents the rights described below (such laws, "State Privacy Laws"). Mitra is the controller of your personal information for purposes of these laws.
For purposes of this section, "personal information" has the meaning given to "personal data", "personal information," or similar terms under the relevant State Privacy Law.
Please note that the rights listed and disclosures made below may not apply to you if you are not a resident of the state in which these rights are granted or the disclosures are required to be made.
In some cases, we may provide a different privacy notice to certain categories of residents of these states, such as job applicants, in which case that notice will apply with respect to the activities it describes instead of this section.
Your Privacy Rights
● Information/Know. You can request whether we have collected your personal information, and in certain cases, categorical information about the personal information we collect, the purposes for which we use them, the sources from which we collected personal information, the third parties with whom personal information is/was sold, shared or disclosed, and the personal information sold/disclosed. The specific categorical information that may be requested varies depending on your state of residence.
● Access. You can request a copy of certain personal information that we have collected about you in a portable format that can be transmitted to another entity.
● Deletion. You can ask us to delete certain personal information that we maintain about you.
● Correction. You can ask us to correct inaccurate personal information that we have collected about you.
● Opt-out of
Processing/sharing for targeted advertising purposes. You can opt-out of certain sharing and other processing of personal information for the targeted advertising purposes. The Service does not currently use these targeted advertising services.
Sales of personal information. You can opt-out of "sales" of your personal information as defined by State Privacy Laws. We do not currently "sell" personal information as defined in these laws.
Profiling. You can request to opt-out of the processing of personal information for the purposes of "profiling" as defined in State Privacy Laws that will have a legal or similarly significant effect on you. We do not currently engage in such profiling.
● Nondiscrimination. You are entitled to exercise the rights described above free from discrimination or retaliation as prohibited by State Privacy Laws.
● Revoke consent. You may revoke any consent you gave us to the processing of your personal information, but the revocation will not affect activities that occur before your revocation request is processed.
The rights described above are not absolute, and, in certain cases, we may decline your request as permitted by law or where the laws in your state do not afford you these rights. Residents of some states have additional rights described in the state-specific disclosures at the bottom of this Privacy Policy.
How to exercise your rights.
● Information/know, access, correction, and deletion. You may submit requests to exercise these rights described above by submitting a request by emailing us at support@deusmachina.inc. We cannot process your request if you do not provide us with sufficient detail to allow us to understand and respond to it.
● Verification of identity. We may need to verify your identity to process your information/know, access, deletion, and correction requests, and we reserve the right to confirm your state residency. To verify your identity, we may require you to authenticate into your Service account if you have one, verify your email address, provide personal identifiers we can match against information we may have collected from you previously, confirm your request using contact details stated in the request, or provide a declaration under penalty of perjury, where permitted by law.
● Authorized agents. Your authorized agent may make a request on your behalf through the same channels described above. We may ask you and/or your agent to take additional steps permitted by law based on the nature of your request to verify your agent's authority.
● Appeals. If we deny your request to exercise your privacy rights, you can contact us to appeal the denial. You must submit your appeal within 45 days of the denial of our request or within any longer timeframe provided by the relevant State Privacy Law. When sending your appeal, please include your name, contact information, details of the original request, the date of our response, and the reasons you believe the denial should be reconsidered. We will review your appeal and respond in writing within the timeframe required by the relevant State Privacy Law. If we deny your appeal, we will explain why.
● Revoke consent. When we request your consent to process your personal information, you can contact us to revoke your consent.
Sensitive data. With the exception of the username and password you use to access your Service account and the contents of your messages sent and received through the Service, we do not require you to provide us with data classified as "sensitive" under State Privacy Laws to use the Service. However, certain features require use of sensitive data, such when you ask the Service to perform a task that requires your precise geolocation or when you use our voice cloning feature, which creates a clone of your voice that may be classified as biometric in some states. Do not provide us with this sensitive data if you do not consent to our handling of it as described in this Privacy Policy. By providing this sensitive data you affirmatively confirm that you freely give your informed, unambiguous agreement to our use and disclosure of it for the purposes explained or apparent at the time of collection or otherwise as described in this Privacy Policy. You can contact us to revoke this consent at any time but we will not be able to provide services or grant requests that require it.
Additional information for California residents. While you should read this Privacy Policy in its entirety, the following summarizes our practices currently and during the past 12 months regarding the categories of personal information that we collect and how we use them.
● Collection and disclosure. The list below describes the personal information we collect by reference to the categories of personal information specified in the California Consumer Privacy Act ("CCPA") and the categories of external parties to whom we disclose it. The terms in the list refer to the categories of information detailed above in the Personal information we collect section and the external parties described above in the How we share your personal information section of this Privacy Policy. Information you voluntarily provide to us, such as in emails or free form webforms, may contain other categories of personal information (including sensitive personal information) not described below. We may also disclose personal information to professional advisors, law enforcement and government authorities, and business transferees as described above in the How we share your personal information section of this Privacy Policy.
Identifiers
Categories containing this data: All categories
External parties to which we disclose for a business purpose: Affiliates, Service providers, Payment processors, CAPTCHA providers, Linked third-party services
California Customer Records (as defined in Cal. Civ. Code §1798.80)
Categories containing this data: All categories
External parties to which we disclose for a business purpose: Affiliates, Service providers, Payment processors, CAPTCHA providers, Linked third-party services
Commercial Information
Categories containing this data: Account data, transaction data
External parties to which we disclose for a business purpose: Affiliates, Service providers, Payment processors, CAPTCHA providers, Linked third-party services
Audio/visual data
Categories containing this data: User generated data, communications data
External parties to which we disclose for a business purpose: Affiliates, Service providers
Internet or Network Information
Categories containing this data: Device data, usage data
External parties to which we disclose for a business purpose: Affiliates, Service providers, Payment processors, CAPTCHA providers, Linked third-party services
Geolocation data
Categories containing this data: Device data, precise geolocation
External parties to which we disclose for a business purpose: Affiliates, Service providers
Sensitive personal information
Categories containing this data: Service username/password; payment card details; precise geolocation of your device when you grant us access to it; information derived from your voice recording to the extent it constitutes biometric information; contents of messages sent and received through the Service
External parties to which we disclose for a business purpose: Affiliates, Payment processors, Service providers
Inferences
May be derived from all of the categories above.
External parties to which we disclose for a business purpose: Affiliates, Service providers
● Sources and purposes. We collect all categories of personal information from the sources and use them for the business/commercial purposes described above in the Privacy Policy.
● Children. Although our Service is not intended for children under 18 years of age, we are required to inform you that we do not have actual knowledge that we have sold the personal information of California residents under the age of 16.
● Sensitive personal information. We do not use or disclose sensitive personal information for restricted purposes that California residents have a right to limit under the CCPA.
● Retention. We retain personal information as described in the Retention section above.
Additional information for Minnesota and Oregon residents. You can request a list of specific third parties, other than natural persons, to which we have disclosed your personal information or if we do not maintain one, a list of the third parties to which we have disclosed personal information of any resident of your state. You can submit this request by following the instructions in the how to exercise your rights section above.
Additional information for Connecticut residents. You have the right to request a list of specific third parties to which a business has sold your personal information or, if the business does not maintain one, a list of third parties to which the business has sold personal information of any Connecticut resident. We do not sell personal information as defined in the Connecticut privacy law.
Nevada opt-out rights. Nevada residents have the right request to opt-out of the sale of certain personal information regulated by Nevada privacy law. We do not sell personal information as defined in the Nevada privacy law.