Autumn Start — 15% off everything, until 31 August. See what's included →

Privacy Policy

Last updated: 9 August 2026

This policy explains what personal data Mira Plus AB collects when you use miraplus.nu, why we collect it, and what rights you have over it. We've tried to write it in plain language rather than legal boilerplate.

Who we are

Mira Plus AB is the data controller for the personal data described here.

  • Mira Plus AB
  • Org. nr. 559392-0944
  • Gamla Norrtäljevägen 103A
  • 187 47 Täby, Sweden
  • info@miraplus.nu
  • +46 72 53 98 795

For any question about your data, or to exercise any of the rights below, email info@miraplus.nu.

What we do not do

It's worth stating clearly, because it shapes everything below:

  • We use no tracking cookies and no analytics of any kind — no Google Analytics, no advertising pixels, no third-party trackers. Only the two essential cookies described under Cookies below.
  • We never sell or rent your personal data, and we don't share it for anyone else's marketing.
  • We do not collect health information through this website.
  • We do not send marketing emails or run a mailing list.
  • We make no automated decisions about you, and we don't profile you.

If any of this changes, we will update this policy before the change goes live.

What we collect, and why

When you create an account

We collect your name, email address, password and, if you provide it, your phone number. Your password is stored in encrypted form and is never visible to us.

Why: so you can log in, see your bookings and check the balance on a prepaid coaching card. Legal basis: performance of a contract (GDPR Art. 6.1.b).

When you book a session

We collect the session you chose, the date and time, your contact details, and a record of your bookings and any prepaid card balance.

Why: to deliver the coaching you've booked, send your confirmation and meeting link, and keep track of the minutes on your card. Legal basis: performance of a contract (Art. 6.1.b).

When you buy something we post to you

Some of what we sell includes physical items — the Zinzino products in a package, or a home test kit. For those orders only, we collect a delivery address: recipient name, street address, any c/o or apartment line, postcode and city. We post within Sweden only.

You can save an address to your account so you don't retype it, but you don't have to — you can enter one at checkout each time. If you're buying as a gift, the address you enter is the recipient's and is not saved to your account unless you tick the box.

We never ask for an address if everything on your order is an online session.

Why: we cannot deliver goods you've bought without somewhere to send them. Legal basis: performance of a contract (Art. 6.1.b).

When you pay

You can pay by card or Klarna, or by Swish.

Card and Klarna payments are handled by Stripe. Your card number is entered directly with Stripe and never reaches our servers — we cannot see or store it. We keep only Stripe's reference for the payment.

From Stripe we receive confirmation that a payment succeeded, the amount, date and payment method, together with the name and email on the payment.

Swish payments are made directly from your bank to ours. You send the amount and write your order number in the Swish message, and we match it to your booking by hand. Through our bank we see what any Swish recipient sees: your name, the amount, and the message you wrote. We deliberately ask for the order number rather than your name, so no more information travels than is needed. If no payment arrives, the order is cancelled automatically after a few days.

In both cases we keep a record of the order itself — what you bought, when, and for how much.

Why: to complete your purchase, confirm your booking, issue a receipt, and meet our bookkeeping obligations. Legal basis: performance of a contract (Art. 6.1.b) and legal obligation (Art. 6.1.c) — Swedish accounting law requires us to keep records of every transaction.

When you contact us

Our contact form collects your name, email address and your message. The same applies to anything you send us by email.

Why: to answer you. Legal basis: legitimate interest in responding to enquiries (Art. 6.1.f), or steps taken at your request before entering a contract (Art. 6.1.b).

When we hold your session

Sessions take place by video using Google Meet. Google processes your name, email address and connection data in order to run the call.

We do not record sessions. Anything you tell us during a session is treated as confidential and is not stored on this website.

Legal basis: performance of a contract (Art. 6.1.b).

Automatically, when you visit the site

Our web server keeps standard access logs containing your IP address, browser type, the pages requested and the time of the request. The server is our own, located in Sweden, and administered by us — these logs are not shared with anyone.

Why: to keep the site running, diagnose faults, and protect it against abuse. Legal basis: legitimate interest in the security and operation of the service (Art. 6.1.f).

Backups

We take regular backups of the site and its database so that nothing is lost to a hardware failure or mistake. Backups are stored in Sweden and are kept private.

Because a backup is a snapshot of a moment in time, data you have asked us to delete may remain inside older backups until they are overwritten in the normal cycle. We never restore backups in order to bring deleted data back into use.

Who else handles your data

We share data only with the suppliers who make the service work. Each of them processes data on our instructions under a data processing agreement, and none of them may use it for their own purposes.

  • Hostup AB (Sweden) — server infrastructure and backups, and the mail relay that sends your booking confirmations. The server is located in Sweden and is administered by us.
  • Loopia AB (Sweden) — our mailboxes and domain. Email you send to info@miraplus.nu is delivered here.
  • Stripe Technology Europe Ltd (Ireland) — card payments.
  • Klarna Bank AB (Sweden) — pay-later payments, offered through Stripe.
  • Google Ireland Ltd (Ireland) — Google Meet, for holding sessions.

Swish payments go directly between your bank and ours; no third party processes them on our behalf.

We may also disclose data to our accountant, or to an authority where the law requires it.

Transfers outside the EU/EEA

Your data is stored in Sweden.

Two of our suppliers — Stripe and Google — may transfer limited data to the United States as part of their global operations. Where they do, the transfer is protected by the European Commission's Standard Contractual Clauses and, where applicable, the suppliers' certification under the EU–US Data Privacy Framework.

How long we keep your data

  • Account details — while your account is active. If you don't use it, we delete it 24 months after your last activity. You can ask us to delete it sooner.
  • Booking history — while your account is active, and as part of the accounting record below.
  • A delivery address saved to your account — until you change or clear it, or your account is deleted. The address an individual order was sent to stays on that order, as part of the record of what we sold and sent, for the seven years below.
  • Payment and accounting recordsseven years after the end of the financial year they belong to. This is required by the Swedish Bookkeeping Act (bokföringslagen) and we cannot delete these earlier, even on request.
  • Contact form messages and email correspondence — 12 months, unless the message forms part of an accounting record.
  • Web server access logs — 14 days, after which they are deleted automatically.
  • Backups — we back up the site and its database daily, and no backup copy is kept longer than 30 days. Because a backup is a snapshot of a moment in time, data you have asked us to delete may remain in an older backup until it rotates out within that period. We never restore a backup in order to bring deleted data back into use.

Cookies

We use only essential cookies — the ones needed to make the site work. They set no advertising identifiers, they build no profile, and they follow you nowhere.

The cookies this site sets are:

  • sessionid — keeps you logged in and remembers your booking in progress. Deleted when your session ends or you log out.
  • csrftoken — a security token that protects forms against cross-site request forgery. Without it, forms cannot be submitted safely.

We use no analytics cookies, no advertising cookies and no third-party trackers.

Because we set no cookies beyond those strictly necessary to provide the service you asked for, this site shows no cookie banner. Swedish law does not require consent for strictly necessary cookies. Should we ever add analytics or any other non-essential cookie, we will ask for your consent first, and this section will be updated before that happens.

On the payment step, Stripe sets its own cookies for fraud prevention when you enter card details. Those are Stripe's, not ours, and are described in Stripe's privacy policy.

You can block or delete cookies in your browser settings. Blocking the two cookies above will prevent you from logging in or completing a booking.

How we protect your data

The site is served over an encrypted connection (HTTPS), passwords are stored hashed, and access to client information is limited to those at Mira Plus who need it to do their work. Our servers are located in Sweden.

No system is perfectly secure, but we take this seriously — and if a breach ever put your rights at risk, we would notify both the supervisory authority and you, as the law requires.

Your rights

Under the GDPR you have the right to:

  • Access — get a copy of the personal data we hold about you.
  • Rectification — have inaccurate or incomplete data corrected.
  • Erasure — have your data deleted, where we have no legal obligation to keep it. Accounting records are the main exception.
  • Restriction — ask us to pause processing while a dispute is resolved.
  • Portability — receive the data you gave us in a machine-readable format.
  • Objection — object to processing we base on legitimate interest.
  • Withdraw consent — at any time, where we rely on consent. This does not affect anything done before you withdrew it.

To use any of these, email info@miraplus.nu. We will reply within one month. We may need to confirm your identity first, so that we don't hand your data to someone else.

Exercising these rights is free, and we will never treat you differently for it.

If you're not happy

Please tell us first — most things are quickest to fix directly.

You also have the right to complain to the Swedish supervisory authority:

Children

Our services are intended for adults. We do not knowingly collect personal data from children under 13 without the consent of a parent or guardian. If you believe a child has given us personal data, contact us and we will delete it.

Changes to this policy

If we change how we handle personal data, we will update this page and change the date at the top. Significant changes — such as introducing analytics, a newsletter, or the collection of health information — will be published here before they take effect.

Contact

  • info@miraplus.nu
  • Mira Plus AB, Gamla Norrtäljevägen 103A, 187 47 Täby, Sweden
  • +46 72 53 98 795