Privacy Policy
Last updated: June 19, 2026
Protecting your personal data is important to us. With the following Privacy Policy we inform you, in accordance with Articles 13 and 14 of the General Data Protection Regulation (GDPR), about the type, scope and purpose of the processing of personal data when you use our website at https://www.mira.guide (the “Website”).
When processing your personal data we comply with the applicable data protection laws, in particular the GDPR, the German Federal Data Protection Act (“BDSG”) and the German Telecommunications Digital Services Data Protection Act (“TDDDG”). Where processing is based on Art. 6 (1)(f) GDPR, the purposes stated also represent our legitimate interests.
“Personal data” means any information relating to an identified or identifiable natural person. If our data processing changes, we will update this Privacy Policy; the current version always applies to your next visit.
1. Controller
The controller within the meaning of the GDPR is:
Pragmatic Technologies GmbH, Pappelallee 64, 10437 Berlin, Germany.
Email: [email protected].
2. Data protection officer
We are not legally required to appoint a data protection officer and have therefore not designated one. For any data protection question, or to exercise the rights set out in section 18, you can reach us at [email protected].
3. Informative use of the Website (server log files)
During mere informative use of the Website — i.e. if you do not register or otherwise transmit information to us — your browser automatically sends information to our hosting provider’s server, which is stored temporarily in so-called log files. The following is recorded in particular:
- the IP address of the requesting device
- the date and time of access
- the name and URL of the file retrieved
- the website from which access is made (referrer URL)
- the browser used and the operating system
This processing serves to ensure a smooth connection, the convenient use of the Website and the evaluation of system security and stability. The legal basis is our legitimate interest in the technical provision and security of the Website (Art. 6 (1)(f) GDPR).
4. Hosting and content delivery network (Cloudflare)
The Website is delivered via the infrastructure and content delivery network of Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. On our behalf, Cloudflare processes, among other things, the server log data mentioned above and your IP address in order to deliver the Website’s content, ensure its security (e.g. defending against attacks) and accelerate delivery.
The legal basis is our legitimate interest in the secure and efficient provision of the Website (Art. 6 (1)(f) GDPR). We have concluded a data processing agreement with Cloudflare pursuant to Art. 28 GDPR. As personal data may be transferred to the USA in this context, the transfer is based on Cloudflare’s certification under the EU-U.S. Data Privacy Framework (Art. 45 GDPR) and, additionally, on the European Commission’s Standard Contractual Clauses (Art. 46 GDPR). For more information, see Cloudflare’s privacy policy.
5. Content management and media hosting (Sanity)
The editorial content and images on this Website are managed in the headless content-management system Sanity and delivered via Sanity’s media/asset CDN (cdn.sanity.io). The provider is Sanity AS, Trondheimsveien 2K, 0560 Oslo, Norway. When your browser loads images or other assets from the Website, your IP address is technically processed by Sanity’s CDN in order to deliver those assets.
The legal basis is our legitimate interest in providing the Website with its content efficiently and reliably (Art. 6 (1)(f) GDPR). We have concluded a data processing agreement with Sanity pursuant to Art. 28 GDPR. Sanity AS is established in Norway (within the EEA) and offers EU/EEA data residency; it uses Google Cloud as an infrastructure subprocessor. Insofar as personal data is processed in the USA via subprocessors or Sanity’s US affiliate, this is safeguarded by the European Commission’s Standard Contractual Clauses (Art. 46 GDPR). For more information, see Sanity’s privacy policy.
6. Consent and cookies
Insofar as we use cookies or comparable technologies, or use services that store or read information on your device, we obtain your prior consent for this via a consent banner – unless this is technically necessary. The legal basis is § 25 (1) TDDDG in conjunction with Art. 6 (1)(a) GDPR. Your consent is voluntary and can be withdrawn at any time with effect for the future, for example via the settings of the consent banner. Technically necessary cookies that are required to operate the Website are exempt from consent under § 25 (2) TDDDG; the associated processing is based on our legitimate interest (Art. 6 (1)(f) GDPR). You can adjust or withdraw your choice at any time via the Cookie settings button at the bottom of this page.
7. Web analytics (Google Analytics)
This Website uses – exclusively after your consent – Google Analytics, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (Google). Google Analytics uses cookies and similar technologies to analyse the use of the Website (e.g. pages visited, time spent, approximate location, device used). The information generated is generally transferred to and stored on Google servers; this may involve a transfer to Google LLC in the USA.
The legal basis is your consent pursuant to § 25 (1) TDDDG and Art. 6 (1)(a) GDPR. Processing only takes place after you have consented via the consent banner; you can withdraw your consent at any time with effect for the future. For the data transfer to the USA, we rely on Google’s certification under the EU-U.S. Data Privacy Framework and, additionally, on the Standard Contractual Clauses.
For more information, see Google’s privacy policy.
8. Tag management (Google Tag Manager)
To manage the tags used on the Website (such as Google Analytics), we use Google Tag Manager, provided by Google Ireland Limited. Google Tag Manager serves to manage and deploy other services and does not itself set analytics or tracking cookies. However, when it loads, a connection to Google’s servers is established and your IP address is processed. Services triggered via Tag Manager that process personal data are only activated after your consent (§ 25 (1) TDDDG, Art. 6 (1)(a) GDPR).
9. YouTube videos
On individual pages we embed videos from the YouTube platform (provider: Google Ireland Limited). The videos are embedded in extended data protection mode via the youtube-nocookie.com domain. Before you give consent, no data whatsoever is transmitted to YouTube or Google – in particular, no preview image is loaded from Google servers; you initially see a neutral placeholder. A video is only loaded once you accept the External media category via our consent banner or actively click to load the specific video. Only then is a connection to YouTube’s or Google’s servers established and your IP address transmitted.
By activating a video – whether by consenting in the banner or by actively clicking to load it – you consent to the associated data processing by YouTube. The legal basis is your consent pursuant to § 25 (1) TDDDG and Art. 6 (1)(a) GDPR. You can withdraw your consent at any time with effect for the future, for example via the Cookie settings button. Here too, a transfer to the USA may occur, based on the EU-U.S. Data Privacy Framework and, additionally, on the Standard Contractual Clauses. For more information, see Google’s privacy policy.
10. Newsletter and waitlist sign-up (Brevo)
If you sign up for our newsletter or join a waitlist / register your interest via a form on this Website, we process the data you provide (in particular your email address and, where applicable, your name and company) in order to send you the newsletter or the requested information. Registration takes place using the double opt-in procedure: after signing up, you receive an email in which you must confirm your registration. This ensures that the registration was actually made by you.
The legal basis for sending the newsletter / requested communications is your consent pursuant to Art. 6 (1)(a) GDPR. You can unsubscribe and withdraw your consent at any time, for example via the unsubscribe link in every email. To document the registration, we store the time of registration and confirmation as well as your IP address; the legal basis for this is our legitimate interest in being able to demonstrate that consent was duly given (Art. 6 (1)(f) GDPR).
For sending, we use the Brevo service provided by Sendinblue SAS, 17 rue Salneuve, 75017 Paris, France. Brevo processes your data on our behalf within the European Union on the basis of a data processing agreement pursuant to Art. 28 GDPR. For more information, see Brevo’s privacy policy.
11. Appointment booking and demo requests
Via the Website you can arrange an appointment for a product demonstration (demo) or a conversation. For scheduling and conducting the appointment, we use the following services:
- Google Calendar / appointment scheduling – Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
- Microsoft 365 Bookings – Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland
When you make a booking, we process the data you provide, in particular your name, your email address, where applicable your telephone number and company, as well as any details you share about your request and the appointment slot you select. We use this data exclusively to plan, conduct and follow up on the agreed appointment.
The legal basis is the performance of pre-contractual measures at your request and the initiation of a contractual relationship (Art. 6 (1)(b) GDPR), as well as our legitimate interest in efficient appointment organisation (Art. 6 (1)(f) GDPR). The aforementioned providers process the data as processors on the basis of agreements pursuant to Art. 28 GDPR. Insofar as data is transferred to the USA, this is based on the EU-U.S. Data Privacy Framework and, additionally, on the European Commission’s Standard Contractual Clauses. For more information, see the privacy policies of Google and Microsoft.
12. Contacting us by email
If you contact us by email – for example at [email protected] – we process the data you provide (your email address, your name and the content of your message) in order to handle your request. The legal basis is Art. 6 (1)(b) GDPR insofar as your request is aimed at concluding or performing a contract, and otherwise our legitimate interest in responding to your enquiry (Art. 6 (1)(f) GDPR). We delete this data as soon as it is no longer required to achieve the purpose for which it was collected, unless statutory retention obligations prevent this.
13. Web forms (contact form and account deletion request)
We provide web forms through which you can contact us or request the deletion of your account. When you submit a form, we process the information you enter in order to handle your request.
- Contact form. We process the data you provide — in particular your name, your email address, the content of your message, any files you attach and any other information you choose to include. The legal basis is Art. 6 (1)(b) GDPR where your request relates to concluding or performing a contract, and otherwise our legitimate interest in responding to your enquiry (Art. 6 (1)(f) GDPR).
- Account deletion request. We process the information needed to identify you and your account and to act on your request. The legal basis is compliance with our legal obligation to give effect to your right to erasure (Art. 6 (1)(c) in conjunction with Art. 17 GDPR) and our legitimate interest in documenting that the request was handled (Art. 6 (1)(f) GDPR).
Form submissions are stored in object storage provided by Cloudflare (Cloudflare R2) in a bucket located in the European Union; the submitted data therefore remains within the EU. We automatically delete submissions from this storage after 14 days. Cloudflare acts as our processor on the basis of a data processing agreement pursuant to Art. 28 GDPR.
When a new submission arrives, our systems generate an internal notification (via a processing queue and an email sent through our email provider Brevo) so that we know a submission is waiting. These notifications do not contain the data you submitted.
14. Recipients of your data
We use external service providers to process personal data. In part they act as processors on our behalf, on our instructions and under our supervision, exclusively for the purposes described in this Privacy Policy (Art. 28 GDPR). We only pass data to other third parties where we are legally obliged to do so or where this is necessary to assert, exercise or defend legal claims. We do not sell your data. The recipients are:
- Cloudflare, Inc. (101 Townsend Street, San Francisco, CA 94107, USA) — hosting, CDN, security/proxy and object storage (Cloudflare R2; form-submission bucket located in the EU). USA; safeguarded by the EU-U.S. Data Privacy Framework and Standard Contractual Clauses.
- Sanity AS (Trondheimsveien 2K, 0560 Oslo, Norway) — headless CMS and media/asset hosting (CDN). EEA (Norway); any US sub-processing is safeguarded by Standard Contractual Clauses.
- Google Ireland Limited / Google LLC (Gordon House, Barrow Street, Dublin 4, Ireland; 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) — web analytics (Google Analytics), tag management (Google Tag Manager), video embedding (YouTube) and appointment scheduling. EU, with possible transfer to the USA; safeguarded by the EU-U.S. Data Privacy Framework and Standard Contractual Clauses.
- Sendinblue SAS (Brevo) (17 rue Salneuve, 75017 Paris, France) — newsletter and waitlist email (double opt-in). EU.
- Microsoft Ireland Operations Limited (One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland) — appointment booking (Microsoft 365 Bookings). EU, with possible transfer to the USA; safeguarded by the EU-U.S. Data Privacy Framework and Standard Contractual Clauses.
15. International data transfers
Some services we use are provided by providers based or with servers in the USA (in particular Cloudflare, Google and Microsoft). Our content-management provider Sanity AS is based in Norway (EEA); a transfer to the USA only occurs at the subprocessor level. Insofar as personal data is transferred to the USA or other third countries, this takes place on the basis of an adequacy decision (EU-U.S. Data Privacy Framework, Art. 45 GDPR) for correspondingly certified providers and/or the European Commission’s Standard Contractual Clauses (Art. 46 GDPR):
- Cloudflare, Inc. — USA — EU-U.S. Data Privacy Framework (Art. 45) and SCC (Art. 46).
- Google LLC — USA — EU-U.S. Data Privacy Framework (Art. 45) and SCC (Art. 46).
- Microsoft Corporation — USA — EU-U.S. Data Privacy Framework (Art. 45) and SCC (Art. 46).
- Sanity (via US sub-processors) — USA, where applicable — Standard Contractual Clauses (Art. 46).
You can request a copy of the Standard Contractual Clauses at [email protected]. Our newsletter/waitlist provider Brevo (Sendinblue SAS) processes your data within the European Union.
16. Retention period
We process and store personal data only for as long as is necessary to fulfil the respective purposes or as required by statutory retention periods (e.g. commercial and tax law obligations). Once the respective purpose ceases to apply or these periods expire, the data is deleted.
17. Data security
We take appropriate technical and organisational measures to protect your data against loss, destruction, manipulation and unauthorised access. This Website uses TLS/SSL encryption, recognisable by the padlock symbol in your browser and the address bar beginning with https://. Our fonts are served locally from our own server; external font services (e.g. Google Fonts) are not used.
18. Your rights as a data subject
With regard to the personal data concerning you, you are entitled to the following rights free of charge:
- Right of access (Art. 15 GDPR). You can obtain information as to whether and what personal data we process about you, including the purposes, the storage period, the origin of the data and the recipients, and you can request a copy of that data.
- Right to rectification (Art. 16 GDPR). You can request that we correct inaccurate data without undue delay and complete incomplete data.
- Right to erasure (Art. 17 GDPR). You can request erasure of your data, in particular where it is no longer necessary for the purposes for which it was collected, where you withdraw your consent and there is no other legal basis, or where it has been processed unlawfully. Statutory retention obligations remain unaffected.
- Right to restriction of processing (Art. 18 GDPR). You can request that we restrict processing, for example while the accuracy of your data is being verified.
- Right to data portability (Art. 20 GDPR). You can receive the data you provided to us in a structured, commonly used and machine-readable format, or have it transmitted to a third party.
- Right to object (Art. 21 GDPR). Where we process personal data on the basis of legitimate interests (Art. 6 (1)(f) GDPR), you may object at any time on grounds relating to your particular situation. We will then no longer process the data concerned unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims. You may object to processing for direct marketing purposes at any time.
- Right to withdraw consent (Art. 7 (3) GDPR). You can withdraw any consent you have given us at any time with effect for the future. The lawfulness of processing carried out up to that point remains unaffected.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority competent for us is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit), Alt-Moabit 59–61, 10555 Berlin, Germany. You may also lodge a complaint with the supervisory authority at your place of residence.
19. Obligation to provide personal data
The provision of your personal data is neither legally nor contractually required; you are not obliged to provide us with data. However, without the respective necessary data we cannot handle certain requests – for example an appointment booking, the sending of the newsletter or responding to an enquiry.
20. Automated decision-making
No automated decision-making, including profiling within the meaning of Art. 22 GDPR, takes place.
21. Changes to this Privacy Policy
We reserve the right to amend this Privacy Policy so that it always complies with current legal requirements or in order to reflect changes to our services. The current version then applies to your next visit.
This English text is a non-binding convenience translation. In the event of any discrepancy, the German version shall prevail.