27th September, 2026
MindFull Technologies OÜ
This Privacy Policy explains how MindFull Technologies OÜ ("MindFull", "we", "us", or "our") collects, uses, and shares information across the MindFull platform. It applies to MindFull Backoffice, Kakapo, Sanchari, and the shared MindFull account that signs you in to all of them, together the "Services". It also applies to our website, mindfulltechnologies.com.
A "Workspace" is the account that belongs to one business using the Services. It holds that business's records, its bots, and the people it has invited to work in it. A "bot" is a chat assistant a Workspace builds with Kakapo to answer questions from content the Workspace gives it.
Some of the information we hold is not about you. It is about your customers, and you put it there. Where that is the case you decide what is collected and why, and we process it to run the Services for you. The privacy policy your own customers read is yours to publish, not ours.
We collect information in the following ways:
Where a Workspace has switched on an AI capability, content from that Workspace is sent to the AI providers we use so that an answer or a draft can be generated. Content is sent only for the Workspace it belongs to. A bot answers only from the content given to that bot. It never draws on content given to another bot, even one in the same Workspace, and never on another Workspace's content. We do not use your content to train the general-purpose models of third-party providers.
A visitor chatting with a published bot can remove a conversation from the device they are using. That removes the copy their browser holds and nothing else: the conversation stays in the Workspace's message logs, where the business that runs the bot can read it. A request to remove it from those logs is a request to that business.
You may create or sign in to your MindFull account with a Google account. Google then gives us your name, your email address and whether Google has verified it, and the address of your Google profile picture, which we link to rather than copy. We use them to create your account, to recognise you when you sign in again, and to show your name and picture where the Services show who you are. If an account already exists for the same verified email address, signing in with Google becomes another way into that account rather than creating a second one.
We ask Google for nothing else. Signing in gives us no access to your mail, calendar, contacts, or files; those are reached only through the connections described under Connected accounts below, and only when a Workspace chooses to make one. We keep these details for as long as the account exists. You can withdraw our access at any time from your Google Account's permissions page, and you can ask us to delete the account and the details with it as described under Your rights. Information we receive from Google this way is covered by the Limited Use commitments at the end of Connected accounts.
A Workspace may connect accounts it holds elsewhere so that the Services can work with them. Connecting one is always a choice the Workspace makes, through a sign-in and consent screen that the other provider shows, and it can be undone at any time from the Workspace's settings or from the provider's own account permissions page. When a connection is removed we delete the authorization tokens we held for it.
Mailboxes. A Workspace may connect a Zoho Mail or Gmail mailbox. From the moment it is connected we read the messages that mailbox receives, store them as inquiry conversations in the Workspace, and send the replies the Workspace writes from that same mailbox. A customer's own attachments are not stored; we record only their names and sizes. Files a Workspace member attaches to a reply are stored by us and kept for as long as the inquiry exists. Disconnecting a mailbox deletes the inquiries that arrived through it, except those attached to a booking, which stay with the booking.
Google Calendar. A Workspace may connect a Google account so that bookings show in Google Calendar and busy times in Google Calendar are blocked in Backoffice. With your permission:
Disconnecting Google Calendar removes the busy times we imported from Backoffice and stops us reading or writing your Google account. The Backoffice calendar we created, and the events on it, stay in your account as ordinary events, yours to keep or delete.
MindFull's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
A Workspace may publish a page on customer.mindfulltechnologies.com presenting what it offers, with photos, a video, and a description, where anyone can send the business an inquiry. It shares the address in posts, bios, or flyers, and the page may appear in search results. The business is responsible for what the page says, including where its links lead, and for what it does with the inquiries it receives. If you send one:
Cloudflare describes what it does with these signals in its Turnstile Privacy Addendum.
A request to see or remove an inquiry you sent from a public page is a request to the business you sent it to, as described under Your rights.
Nobody signs in on mindfulltechnologies.com, so what we hold about a visitor is only what they send us:
We share information only where it is needed to provide the Services, comply with the law, or protect our rights. This may include:
We do not sell personal information, and we do not share one Workspace's content with another.
We use cookies only to keep you signed in and to keep signing in secure. The MindFull account and each product you sign in to set their own, and they end when you sign out or the session expires. We do not currently use cookies for analytics or advertising, and our website sets none. A public inquiry page loads Cloudflare's check, described under Public inquiry pages, which is a security measure rather than analytics or advertising. A video on such a page is loaded from YouTube or Vimeo only when you press play, and what that provider then sets is covered by its own policy. If we add analytics, we will name the provider and what it collects here, and ask for your consent before setting any cookie that is not needed to sign you in.
A published bot keeps its conversation in the visitor's browser so that it can be continued, as described under AI processing. You can block cookies and clear browser storage in your browser settings, but you will not be able to sign in while cookies are blocked.
We keep personal information for as long as we need it to provide the Services and to meet our legal obligations. We apply reasonable safeguards to protect it, but no method of transmission or storage is completely secure.
When you delete a bot, its configuration, the content it was given and any files uploaded for it, its API keys, and its conversation history are removed from the platform.
When a Workspace is deleted, access to it ends and it disappears from every product, but its records are archived rather than erased. Nothing deletes them afterwards on a schedule, and we do not promise a period after which they are gone. Bookings, agreements, reviews, and billing history are kept because customers and travelers have an interest in them that outlasts the business that held them, and because the law may require it. A deleted Workspace can be restored by our support team for as long as its records exist. A request to erase records inside a deleted Workspace is handled under Your rights below.
Details a customer gives when accepting a booking agreement, including an identity document number, are kept with the agreement they were given against for as long as the booking record is kept.
Most of what we hold is what you or a Workspace chose to put there. Two kinds of record are made by us, for reasons you did not ask for, and we name them here because they are still about you:
Depending on where you live, you may have the following rights under the GDPR or comparable law:
To make a request, email hello@mindfulltechnologies.com or reach us through the contact page. If your request concerns records held inside a Workspace you do not own, we will pass it to the business that does, because that content is theirs rather than ours. If the Workspace has been deleted, we will handle the request ourselves.
The Services are not intended for children under 13, and we do not knowingly collect personal information from children.
We may update this Privacy Policy from time to time. Where a change is material we will post the updated policy on this page, and the date at the top of it will tell you when it last changed.