1.Who we are#
Mitte is a personal AI assistant, currently in an invite-only beta. Mitte, the website at mitte.si and the partner portal at partners.mitte.si are operated by Swfte Limited (“Swfte”, “we”, “us”), 6th Floor, 2 Grand Canal Square, Dublin 2, D02 A342, Ireland.
For the purposes of the EU General Data Protection Regulation (“GDPR”) and the UK GDPR, Swfte is the controller of the personal data described in this policy, except where we explain that we act on behalf of a partner business (see section 3.7).
Email privacy@swfte.com. You can also reach our data protection contact at dpo@swfte.com, or write to us at the address above.
2.What this policy covers#
This policy explains how we handle personal data when you:
- visit mitte.si or partners.mitte.si;
- join the Mitte waitlist or request an invitation, or are invited by someone else;
- apply to become a Mitte partner or developer;
- create and use a partner portal account;
- receive an email from us, or pay a partner business through Mitte-managed checkout.
Processing inside the Mitte app itself (for example, your conversations with your assistant) is described in the privacy information provided with the app. Where the two differ for something that happens in the app, the app’s information applies.
Our Cookie Policy lists every cookie and browser-storage item we use. Use of Mitte is also governed by our Terms of Service.
3.The information we collect#
3.1 When you visit the website
Like every website, our servers receive the technical information your browser sends with each request: your IP address, the page requested, the time, and your browser’s user-agent string. We use it only to deliver the page and keep the service secure. Our reverse proxy does not record request bodies, so the contents of forms are never written to access logs.
The /download link (used by the QR code) reads your user-agent once to send your phone to the right app store. It is not stored. The QR code itself is generated inside your browser.
We do not use analytics, advertising, social-media pixels, session recording or fingerprinting. Our fonts and videos are served from our own servers, so no third party learns that you visited.
3.2 When you join the waitlist or request an invitation
The invitation form asks for your name and email address, plus anything you choose to add in the optional fields, and your agreement to be contacted about Mitte early access. We add a reference number (for example MI-…), the form type and the time of submission.
3.3 When you apply as a partner or developer
Partner applications ask for your name, work email, business or project name, partner category, and optionally your website and a message. Developer applications ask for your name, email, project or team name, the surface you want to build for (for example SMS & WhatsApp, Voice, Wearables, AR & VR or Apps & web), your intended use case and optionally your website. Please don’t include sensitive personal information in the free-text fields.
3.4 Information used to protect the forms
To stop abuse, the forms check that a submission comes from our website, include a hidden field that only automated bots fill in, and limit each connection to ten attempts per hour. The rate limit uses your IP address in the server’s memory only: it is never written to disk or added to your submission, and it is forgotten within an hour.
3.5 When you have a partner portal account
- Account details: your name, email address, company name, whether your email is verified, and when the account was created. Your password is never stored, only a salted one-way hash of it (see section 9).
- Sign-in sessions and one-time links: a random session token (stored only as a hash) and the email verification and password-reset tokens we send you (also stored as hashes, valid for 24 hours and 1 hour respectively, and usable once).
- Your sites and catalog: the sites you connect (name, web address, platform, branding and settings), the domain verification challenge and its result, the product catalog you import or edit (titles, descriptions, prices, availability, product and image links) and your published app.
- API keys: site keys are shown to you once and stored only as a hash plus a short prefix so you can recognise them.
- Activity history: a record of the most recent 200 actions on your account (for example “Site settings updated”) with the time. It does not include your IP address.
- Abuse protection: request counters that limit sign-in, registration, recovery and API attempts. They are keyed by a SHA-256 hash of your IP address, email address or account ID, and are deleted when their time window (at most one hour) ends.
To verify that you control a domain, our servers look up a public DNS TXT record (_mitte-challenge.your-domain). We never fetch arbitrary pages from your website.
3.6 Emails we send
We send partner account emails (to confirm your address or reset your password) through Amazon Simple Email Service in the EU (Ireland) from partners@mitte.si. They contain a one-time link and no tracking pixels. Our mail relay does not log recipients or links. If you joined the waitlist, we use your email address to send your invitation when you are selected, and occasional updates about your place on the waitlist.
3.7 Partner analytics and managed payments
Partner businesses can send us events about activity that started in Mitte (for example “product viewed” or “order completed”) so they can see reports. Customer, session, product and order identifiers are hashed per site when they arrive, conversation transcripts are never ingested, and groups smaller than five are withheld from reports. For this data we act as a processor on behalf of the partner, who is the controller.
If a partner uses Mitte-managed payments, you pay on a page hosted by Stripe. Card details go only to Stripe; we never see them. After payment, Stripe tells us the result and, so the partner can deliver your order, your name, email address and, where collected, shipping details, together with the items, amounts and currency. We share these order details with the partner that is fulfilling it.
3.8 When someone invites you
Mitte members can invite friends, family or their audience. If someone invites you, they give us the contact details needed to deliver the invitation. We use them only to send that invitation and to connect your access to it. Members should only invite people who would expect to hear from them.
4.How we use it, and our legal bases#
Data protection law requires a legal basis for each use of personal data. Here is ours:
| Purpose | Data | Legal basis |
|---|---|---|
| Managing the waitlist, running invitation rounds and contacting you about early access | Name, email, optional details, reference | Consent (GDPR art. 6(1)(a)), given with the checkbox. You can withdraw it at any time. |
| Reviewing partner and developer applications and replying to you | Application details | Steps you asked for before a contract (art. 6(1)(b)), and your consent to be contacted. |
| Creating and running your partner account, sites, catalog, keys and published apps; sending verification and password-reset emails | Account, site and catalog data | Performance of our contract with you (art. 6(1)(b)). |
| Keeping the service secure: origin checks, bot traps, rate limits, session protection, activity history | IP address (in memory or hashed), account ID, activity history | Legitimate interests (art. 6(1)(f)) in preventing fraud and abuse. |
| Processing managed payments, refunds, disputes and transfers | Order, payment and fulfilment records | Contract (art. 6(1)(b)) and legal obligations such as accounting and tax (art. 6(1)(c)). |
| Partner analytics reports | Hashed identifiers and events | Processed on the partner’s instructions; the partner determines the legal basis. |
| Delivering an invitation from another member | The contact details they provide | Legitimate interests (art. 6(1)(f)) of the member and of Swfte in letting people invite those they know. |
| Complying with the law and defending legal claims | Any relevant data | Legal obligation (art. 6(1)(c)) and legitimate interests (art. 6(1)(f)). |
We do not use your data for advertising, we do not sell it, and we do not share it for cross-context behavioural advertising.
5.The waitlist, invitation rounds and random draws#
Because demand for the beta is high, Mitte grows by invitation. Early members received access first and can invite others; partners and creators can invite their audiences. Everyone else can join the waitlist. Invitations from the waitlist are released in rounds, and places in a round are allocated partly by random draw and partly by operational factors, such as available capacity in a region or on a device platform.
The random draw does not use your personal characteristics, and we do not profile you to decide whether you are invited. Being selected, or not yet selected, for a beta invitation has no legal effect on you and does not similarly significantly affect you, so it is not automated decision-making within the meaning of article 22 GDPR. You can still ask us how a round was run, or ask a person to look at your request.
Joining the waitlist is free and involves no purchase. See section 5 of our Terms of Service for how invitations work.
7.International transfers#
We keep the partner portal and its backups in the EU (AWS Ireland). Some providers, or their parent companies, are based in the United States or process data there, notably Google for the waitlist and application sheet, and Stripe.
When personal data leaves the EEA or UK, we rely on:
- the EU-US Data Privacy Framework (and its UK Extension and the Swiss-US framework) for recipients that are certified under it, such as Google LLC, Amazon.com, Inc. and Stripe, Inc.; and
- the European Commission’s Standard Contractual Clauses (with the UK Addendum where relevant), which are part of these providers’ data processing terms, together with supplementary measures such as encryption in transit and at rest.
You can ask for more information about these safeguards, or a copy of them, by writing to privacy@swfte.com.
8.How long we keep it#
We keep personal data only for as long as we need it for the purpose we collected it for:
| Information | How long |
|---|---|
| Waitlist and invitation requests | Until you are invited and your access is set up, you ask us to remove you, or 24 months after your most recent request, whichever comes first. |
| Partner and developer applications | 24 months after your most recent application, unless the application leads to a partnership, in which case it is kept for the life of that relationship. |
| Form rate-limit data (IP address) | In memory only; forgotten within an hour or when the server restarts. |
| Partner account, sites, catalog and keys | While your account exists. Deleting your account deletes them immediately, except payment records (below). |
| Sign-in sessions | 7 days, or until you sign out (sign-out everywhere ends all of them). |
| Verification and password-reset links | 24 hours and 1 hour respectively; removed once used or replaced. |
| Activity history | The most recent 200 entries, while your account exists. |
| Portal rate-limit counters | Until their window ends, at most one hour. |
| Partner analytics events | 90 days; order summaries 90 days after their last update. |
| Managed payment and order records | For as long as needed for refunds, disputes and reconciliation, and then as accounting and tax law requires (7 years). A connected payment account blocks deletion of the account until this is settled. |
| Backups of the partner database | Continuous encrypted backups and daily disk snapshots are kept for 7 days on a rolling basis, so deleted data disappears from backups within about 7 days. |
| Technical server logs | Up to 30 days. They never contain form contents or passwords. |
9.How we protect it#
- Encryption in transit: every page and API is served over HTTPS (TLS); plain HTTP is redirected.
- Encryption at rest: server disks, snapshots and backup storage are encrypted (AES-256), and stored form copies use server-side encryption.
- Passwords are hashed with scrypt and a unique random salt. Session tokens, one-time email links and API keys are stored only as SHA-256 hashes.
- Session cookies are host-only, Secure, HttpOnly and SameSite=Lax, and changes require a matching origin.
- Least privilege: each component has only the access it needs (for example, the mail relay can only send our two account email templates to links on our own portal). Secrets are kept in AWS Systems Manager Parameter Store, and servers have no SSH access.
- Minimal logging: request bodies, passwords, form contents, email addresses and email links are not written to logs.
- Abuse controls: origin checks, request size limits, bot traps and rate limits on every form and sign-in route.
No system is perfectly secure. If you believe you have found a vulnerability, please tell us at security@swfte.com. If a breach is likely to put your rights at risk, we will tell you and the supervisory authority as the law requires.
10.Your rights#
If you are in the EEA, the UK or Switzerland, you have the right to:
- access your personal data and receive a copy;
- have inaccurate data corrected;
- have your data erased;
- restrict how we use it;
- receive data you gave us in a portable format (portability);
- object to processing based on legitimate interests;
- withdraw consent at any time, for example to leave the waitlist, without affecting what we did before; and
- not be subject to decisions based solely on automated processing that significantly affect you.
How to exercise them
Email privacy@swfte.com from the address your request relates to, and include your reference number if you have one. Partner account holders can also update their profile, sign out everywhere, and permanently delete their account from Account settings in the portal.
We reply within one month. For complex requests we may extend this by up to two further months, and we will tell you if we do. It is free, unless a request is clearly unfounded or excessive. We may ask you to confirm your identity first. Wherever you live, we will consider any privacy request you make.
12.Children#
Mitte is not directed at children under 16, and you must be 18 or over to join the beta or apply as a partner (see our Terms). We do not knowingly collect personal data from children under 16. If you think a child has given us their details, contact privacy@swfte.com and we will delete them.
13.Changes to this policy#
We will update this policy when our services or the law change. The date at the top shows the latest version. If a change is significant, for example a new purpose or a new kind of recipient, we will tell you by email or in the product before it takes effect, and ask for your consent again where the law requires it.
14.Contact and complaints#
Questions, requests or concerns: privacy@swfte.com, or write to Swfte Limited, 6th Floor, 2 Grand Canal Square, Dublin 2, D02 A342, Ireland.
You also have the right to complain to a data protection supervisory authority, in particular where you live or work or where you think an infringement happened. We would appreciate the chance to resolve your concern first.
- Slovenia: Information Commissioner of the Republic of Slovenia (Informacijski pooblaščenec), Dunajska cesta 22, 1000 Ljubljana, www.ip-rs.si (opens in a new tab).
- Ireland, where Swfte is established: Data Protection Commission, www.dataprotection.ie (opens in a new tab).
- United Kingdom: Information Commissioner’s Office, ico.org.uk (opens in a new tab).
- Elsewhere in the EEA: your national authority, listed by the European Data Protection Board (opens in a new tab).