Privacy Policy

1. Privacy at a Glance

General Information

The following notes provide a simple overview of what happens to your personal data when you visit this website. Personal data is any data with which you can be personally identified. Detailed information on the subject of data protection can be found in our privacy policy listed below this text.

2. Responsible Party

The responsible party for data processing on this website is:

Mirox Verwaltungs GmbH
Tempowerkring 6
21079 Hamburg
Germany

Phone: +49 (0) 40 76619191
Email: legal@mirox.de

The responsible party is the natural or legal person who alone or jointly with others determines the purposes and means of processing personal data (e.g., names, email addresses, etc.).

3. Data Collection on This Website

Cookies

Our website uses so-called "cookies". Cookies are small text files and do not cause any damage to your device. They are stored either temporarily for the duration of a session (session cookies) or permanently (permanent cookies) on your device. Session cookies are automatically deleted after your visit. Permanent cookies remain stored on your device until you delete them yourself or an automatic deletion by your web browser occurs.

Server Log Files

The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:

  • Browser type and version
  • Operating system used
  • Referrer URL
  • Host name of the accessing computer
  • Time of server request
  • IP address

This data is not merged with other data sources.

Contact Form

If you send us inquiries via the contact form, your details from the inquiry form, including the contact data you provided there, will be stored by us for the purpose of processing the inquiry and in case of follow-up questions. We do not share this data without your consent.

Web Analytics

To understand how our websites (www.mirox.io and docs.mirox.io) are used and to improve our content, we operate our own privacy-friendly web-analytics system entirely on our own servers in Germany. We do not use any third-party analytics services, and no usage data is shared with third parties for their own purposes. The analysis works without cookies and stores no information on your device. We record aggregated usage data such as the pages viewed, the referring website, your approximate region (derived from your IP address) and the type of device and browser used. Individual visitors are counted using a temporary, irreversible hash value derived from your IP address and browser, which is renewed daily and cannot be traced back to you. We additionally determine the network operator or company associated with your IP address (not your personal identity) — by checking your IP address against public internet registries (RDAP/WHOIS) and via reverse DNS — for aggregated, company-level reach analysis. Your IP address is used solely for this lookup and is not stored. The legal basis is our legitimate interest in the statistical analysis of our reach pursuant to Art. 6(1)(f) GDPR; because no information is stored on or read from your device, no consent under § 25 TDDDG is required. You may object to this processing at any time pursuant to Art. 21 GDPR.

Mirox Mobile App (iOS)

We also provide the Mirox app for iOS, a companion to the web platform that lets you monitor your parks and receive alerts on your device. The following notes describe the personal data the app processes in addition to the data described above. As on our website, the app is built to be data-minimal: we process only the data required to operate the service, and we do not share your data with third parties for their own purposes.

Account Data

To use the app you sign in with your Mirox account. In this context we process your account data — in particular your email address and your name — in order to authenticate you, display your profile and associate your activity in the app (such as tickets and comments) with your account. This data is processed on our own servers and is not shared with third parties. The legal basis is the performance of our contract with you pursuant to Art. 6(1)(b) GDPR.

Push Notifications

If you enable notifications, the app registers with Apple's Push Notification service (APNs) and receives a device push token — a technical identifier that allows notifications to be delivered to your specific device. We store this token on our own servers for the sole purpose of sending you the operational alerts you have requested, for example when a park event or an alarm occurs. The token is used only for this app functionality and never for advertising or tracking. You can disable notifications at any time in your device's system settings; the token is deleted when you turn off notifications or sign out. The legal basis is the performance of our contract with you and your consent pursuant to Art. 6(1)(a) and (b) GDPR.

Crash and Diagnostics Data

To detect and fix problems and to keep the app stable, the app collects crash and diagnostics data — such as the type of error, an anonymised stack trace, the app and operating-system version, and the state of the app at the time of the error. This data is processed by a crash-reporting system that we operate entirely on our own servers using open-source software. This system is GlitchTip, self-hosted entirely on our own infrastructure — no external, third-party crash-reporting cloud service is used. It is not shared with Apple or with any third-party crash-reporting or analytics provider. We use this diagnostic data solely to diagnose and fix problems in the app; it is not used for advertising or tracking. The legal basis is our legitimate interest in the security and stability of our app pursuant to Art. 6(1)(f) GDPR.

Device Identifiers

Aside from the push token described above, the app does not access your device's advertising identifier (IDFA) and does not assign you an advertising profile. Where a device or installation reference is processed — for example to link your push token to your session or to include basic technical device information in a crash report — it serves only to operate the app. We do not track you across other apps or websites, and the app contains no third-party advertising or tracking technologies.

Session and Device Data

When you sign in, we record session metadata to help keep your account secure — including the IP address used, an approximate location derived from it, information about your device and operating system, and a technical identifier generated for your app installation. You can review your active sessions in the app under Settings ▸ Devices and revoke them at any time. The legal basis is our legitimate interest in the security of your account pursuant to Art. 6(1)(f) GDPR. We retain this data for the duration of the session and delete it once you revoke the session or sign out.

Content You Provide

Tickets, comments, support messages, chat messages, and any photos or files you attach to them are stored on our own servers so that we can provide these features to you. This content is visible to the other members of your organization according to their assigned permissions. The legal basis is the performance of our contract with you pursuant to Art. 6(1)(b) GDPR.

AI Assistant

The app includes an AI assistant that can answer questions about your parks and data. Messages you send to the assistant — including any personal data they may contain — are processed on our own servers by a self-hosted language model that we operate ourselves; they are not shared with a third-party AI provider. Your conversations with the assistant are stored in your account and can be deleted by you at any time in the app. Responses from the assistant are always clearly marked as AI-generated. The legal basis is the performance of our contract with you pursuant to Art. 6(1)(b) GDPR and, where you choose to share additional personal information in your messages, your consent pursuant to Art. 6(1)(a) GDPR.

Data Retention

We retain personal data only for as long as it is necessary for the purposes described in this policy or as required by law. Your account data is kept for the duration of your account and is deleted when you delete your account. Your push token is deleted when you disable notifications or sign out. Session and device data is retained for the duration of the session and is deleted once you revoke the session in Settings ▸ Devices or sign out. Crash and diagnostics data is stored on our own servers only for as long as needed to investigate and resolve the underlying problem and is then deleted or aggregated. Content you provide in the app — such as tickets, comments, support messages, chat messages and attached files — is retained for as long as it is needed to provide the service to you and your organization. Conversations with the AI assistant are stored in your account until you delete them. Where statutory retention obligations apply, we restrict processing of the affected data until those periods have expired.

4. Your Rights

You have the right at any time to:

  • Information about your personal data stored by us
  • Correction of incorrect or incomplete personal data stored by us
  • Deletion of your personal data stored by us
  • Restriction of the processing of your personal data
  • Object to the processing of your personal data
  • Data portability

5. Right to Object

If your personal data is processed on the basis of legitimate interests pursuant to Art. 6 para. 1 sentence 1 lit. f GDPR, you have the right to object to the processing of your personal data pursuant to Art. 21 GDPR, provided there are reasons for this arising from your particular situation.

6. Right to Lodge a Complaint with a Supervisory Authority

In the event of data protection violations, the data subject has a right of complaint to the competent supervisory authority. The competent supervisory authority for data protection issues is the state data protection officer of the federal state in which our company is headquartered.

7. SSL/TLS Encryption

This site uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content, such as orders or inquiries that you send to us as the site operator. You can recognize an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line.

8. Changes to This Privacy Policy

We reserve the right to adapt this privacy policy so that it always complies with current legal requirements or to implement changes to our services in the privacy policy, e.g., when introducing new services. The new privacy policy will then apply to your next visit.

Last updated: July 2026