Privacy policy
What we collect, why, and what you can ask us to do about it.
Last updated: 26 August 2026
1. Who we are
MIHOS is a service operated by MUUM Sàrl, a limited liability company (société à responsabilité limitée) with registered office at Route de Champ-Colin 12, 1260 Nyon, Switzerland, entered in the Commercial Register of the Canton of Vaud under UID CHE-143.151.748 (register number CH-550.1.241.694-8). Contracts, invoices and data processing agreements are concluded with MUUM Sàrl. MIHOS is the name of the service.
2. What this policy covers
Two different things, with two different roles.
3. What we collect
On this website
- What you type in the contact form: name, company, email address, and the content of your message
- What you enter when you book a demonstration: name, email address, company, time zone, and anything you write in the booking field
- Technical data generated by serving the page: IP address, browser and device information, request logs, kept by our hosting provider
- Essential cookies set by Webflow to serve and secure the page
We ask for a work address but we do not require one, and many people reach us from a personal mailbox. Either way the address is treated the same and covered by this policy.
We run no analytics, no advertising, no session replay and no visitor identification on this website. We do not try to work out who you are from your visit. Bookings are taken through a third party scheduling service, which handles that data on our instructions and on our behalf. We remain responsible for it and this policy covers it.
In the MIHOS application
- Account data: name, email address, company, role, authentication data
- Audio recordings of field sales meetings, and their transcripts
- Consent records: who consented, when, by what means, and the audio segment in which consent was given
- Analyses produced from those recordings: topics, questions, objections, talk-time balance, scores against the customer's playbook, coaching notes, recommended next actions
- Data read from and written to the customer's CRM, calendar and email, limited to the fields their administrator has approved
- Technical and security logs: access, writes performed, errors
Recording requires the explicit and prior consent of every participant in the meeting, including the customer's own client. Consent can be withdrawn at any time. The recording is then deleted, together with its transcript and its analysis, unless a legal retention obligation applies to the customer.
4. Why we process it, and on what basis
Under Swiss law (FADP), the same processing is justified by the contractual relationship, by your consent where it is required, and by our overriding legitimate interest for security.
5. The AI behind MIHOS
Speech to text and speaker separation are performed by Gladia, a French provider, consumed as a hosted API and running inside the European Union. Analysis, scoring and coaching text are produced by a large language model consumed as a service and hosted in Switzerland or the European Union. Both are third party, closed source, and used as delivered. We do not train a proprietary model, we do not fine-tune any model, and we do not run models on our own hardware. If any of that changes, this page changes first.
What the AI is not allowed to do
- No emotion inference.MIHOS does not infer, score or label the emotional state of a worker. The sentiment and emotion detection features our providers offer are switched off in our pipeline. Inferring emotions in the workplace is a prohibited practice under art. 5(1)(f) of the EU AI Act, in force since 2 February 2025.
- No voiceprint.MIHOS does not build a template that would let the same voice be recognised from one meeting to the next. SeeVoice & biometric data.
- No inference of special category data.No health, beliefs, political opinions, union membership or ethnic origin is derived from a voice or a transcript.
- No training.Meeting content is not used to train, fine-tune or improve any model, ours or a provider's.
Scores and recommendations are indicative, and AI output can be wrong. On their own they produce no decision with legal or similarly significant effect on a person. Every decision about a rep involves human judgement, every write into a customer system is logged and reversible, and every score is traceable back to the timestamped passage that produced it. Role play uses a generic synthetic voice, labelled as artificially generated as art. 50 of the EU AI Act requires. No participant's voice is cloned.
Under the EU AI Act, a system used to monitor and evaluate the performance and behaviour of workers falls under Annex III, point 4(b). Regulation (EU) 2026/1744, in force since 27 July 2026, moved the application date of those obligations to 2 December 2027. We are building against that date. The art. 50 transparency obligations, applicable since 2 August 2026, we meet now.
6. How long we keep it
- Contact form and booking submissions: 24 months from our last exchange
- Account data: for the duration of the contract, then 12 months. Invoicing and accounting records are kept 10 years, as art. 958f of the Swiss Code of Obligations requires
- Audio recordings: 90 days by default
- Transcripts: 12 months by default
- Analyses, scores and coaching notes: 24 months by default
- Consent records: as long as the recording they relate to, plus 12 months
- Security logs: 12 months
A customer can shorten any of these. Extension beyond the default is possible only where the customer documents a regulatory obligation that requires it, and it is written into the order form. Where MIHOS is used to evidence a regulatory duty, that data is kept separate from coaching data and follows its own schedule.
At the end of the contract, customer data is exportable for 30 days and deleted within 60 days, unless a legal obligation requires otherwise. Deletion is permanent in production systems. Encrypted backups are rotated out within 35 days, after which no copy remains.
7. Who else touches the data
Providers that handle meeting content
These are the ones that matter most, so we name them.
Everything else
Beyond those, we rely on established providers for the hosting of this website and its form submissions, for demonstration bookings, for the technical connection to a customer's CRM, calendar and email, and for our own business email. They are established in the European Union and in the United States. None of them receives audio, transcripts or analyses.
We do not sell or rent personal data. We do not use meeting content to train or improve models. Our speech and language providers are engaged on contractual terms that prohibit training on our customers' audio and hold retention to what a single request requires. We share data only with the providers described above, with the customer company you work for, and where a competent authority legally requires it.
8. Where the data sits, and what that does and does not mean
Recordings, transcripts and analyses are stored in Switzerland, in the Zurich region. Transcription is carried out inside the European Union. No meeting content is stored outside Switzerland.
We would rather be precise than flattering about what that guarantees. The Zurich infrastructure is operated by Supabase, Inc. on Amazon Web Services, both United States companies. Physical residency in Switzerland is not the same thing as legal sovereignty: a US-controlled provider can in principle be reached by a US production order wherever the disks are. We therefore rely, in addition to the location itself, on the European Commission's Standard Contractual Clauses together with the Swiss addendum recognised by the FDPIC, on encryption in transit and at rest, on contractual limits on provider access, and on an assessment of the destination country.
Customers who require a provider chain with no US parent can ask us. We will tell them honestly what that would take and what it would cost.
9. Security
Encryption in transit and at rest. Access restricted to the people who need it and reviewed regularly. Every write the product performs into a customer system is logged. Every access by our staff to meeting content is logged and visible to the customer. Customer environments are separated. We do not claim certifications we have not obtained.
Where we act as processor and become aware of a breach affecting customer data, we notify the customer without undue delay, as art. 33(2) GDPR requires, and give them what they need to meet their own 72 hour deadline. Where we act as controller, we notify the FDPIC as soon as possible under art. 24 FADP, and the competent supervisory authority within 72 hours where the GDPR applies.
10. Your rights
You can ask for access to your data, its correction, its deletion, a restriction of processing, a copy in a portable format, and you can object to processing based on legitimate interest. Where processing rests on consent, you can withdraw it at any time, without affecting what was done before.
If our answer does not satisfy you, you can complain to the Federal Data Protection and Information Commissioner (FDPIC) in Switzerland, or to the supervisory authority of your country of residence in the EEA.
11. Recording people at work
Where MIHOS is deployed over a sales team, the employer must inform its employees before any recording, issue a written internal policy covering the system, its retention periods and its consequences, and consult employee representatives where local law requires it. That obligation sits with the customer company. We provide the documentation needed to meet it, including a data protection impact assessment template.
In Switzerland, art. 26 of Ordinance 3 to the Labour Act prohibits surveillance systems intended to monitor employee behaviour. MIHOS is built so that it cannot be operated as one: recording is started by the rep, session by session, the product does not listen between sessions, and there is no continuous or scheduled capture mode to enable.
12. Minors
MIHOS is a business tool. We do not knowingly collect data about anyone under 16. Anything collected by mistake is deleted.
13. Cookies
This website sets only the cookies Webflow needs to serve and secure the page. There is no analytics cookie, no advertising cookie and no tracking pixel, so no consent banner is required. If that ever changes, this page changes first and a banner appears before the first cookie is set.
14. Changes
If this policy changes materially, we update the date above and notify customers at least 30 days in advance.
15. Contact
If there is any discrepancy between the French and the English version of this document, the English version prevails.


