Last updated: 2 September 2026
1. Who we are
The controller of your personal data is:
CRAZYSILENCE, LDA
NIPC 514934328
Rua do Alferes Malheiro, 199, 4000-059 Porto, Portugal
Email: admin@mirra.pt
Phone: +351 913 844 969
We operate the spa Mirra Porto SPA and the site mirra.pt.
2. What we collect, and when
When you make a booking — online, by phone, on WhatsApp or at reception
- name
- email address
- phone number
- service, date, time and duration
- therapist preference, where you give one
- any notes you send us about the appointment
When the booking is made on the site, the system also records, at the moment it is created: IP address, browser and device identification, and the date and time. We use this for security and fraud prevention — in particular to detect false bookings.
When you buy a voucher or pay online
- the billing details required by law
- payment details are handled directly by the payment provider; we never receive or store card numbers
When you contact us on WhatsApp
- your phone number and the content of the conversation
- if you reached us from an advert or from a link of ours, a technical code identifying that origin
When you visit the site
- pages visited, where the visit came from, and identifiers associated with cookies and similar technologies — under the terms of section 7
When you leave a review
- what you publish in a Google review is public by your own decision and governed by Google’s terms. We may reply to you publicly.
We do not ask for and do not want health data. If you choose to tell us something about your health that is relevant to a treatment, we use it only to deliver the service safely and we share it with no one.
3. What we use it for, and on what legal basis
| Purpose | Legal basis |
|---|---|
| Managing your booking and delivering the service | performance of a contract |
| Sending confirmations, reminders and changes to the appointment | performance of a contract |
| Invoicing and tax obligations | legal obligation |
| Answering enquiries and complaints | performance of a contract / legitimate interest |
| Site security and prevention of fraudulent bookings | legitimate interest |
| Measuring how the site is used (statistics) | consent |
| Advertising and campaign measurement | consent |
| Invitations to review the service you received | legitimate interest |
Where the basis is consent, you may withdraw it at any time — see section 8. Withdrawing consent does not affect what was done before on the strength of it.
4. Who we share it with
We do not sell your data. We share only what is necessary, with those who provide services to us:
Google — Google Analytics, Google Ads and our Google Business Profile. If you accept measurement and advertising cookies, Google receives information about how the site is used and about completed bookings, so we can tell which adverts work. Where contact details are used for this, they are sent in an irreversible hashed form that cannot be turned back into your number or email.
Meta (Facebook, Instagram, WhatsApp) — on the same terms, if you accept advertising cookies. WhatsApp is also a customer-service channel.
respond.io — the platform where we receive and answer WhatsApp conversations.
Moloni — invoicing.
Viva Wallet — payments. Payment takes place on Viva Wallet’s own pages, under Viva’s privacy policy and terms; card details are entered there and never pass through us. For bookings we send them only the amount and the booking number. For voucher purchases we also send your name and email, which are needed to issue the payment. In both cases, what comes back to us is the confirmation and the transaction reference. Viva Wallet handles this data on our behalf, and is an EU-licensed and supervised institution, registered with Banco de Portugal to operate in Portugal.
Cloudways (on Linode infrastructure) — hosting of the site and the database, in Frankfurt, Germany.
We may also disclose data to authorities where the law requires it.
5. Transfers outside the European Union
Our providers fall into three different situations, each with its own basis. We say where each one is, because that is what decides which basis applies.
Inside the European Union — no international transfer
| Provider | Where | For what |
|---|---|---|
| Moloni | Portugal | invoicing |
| Viva Wallet | European Union | payments |
| Cloudways | European Union — server in Frankfurt, Germany | hosting of the site and the database |
United States — under the European Commission adequacy decision
| Provider | Where | For what |
|---|---|---|
| United States (contracted through the Irish entity) | Analytics, Ads, Business Profile | |
| Meta | United States (contracted through the Irish entity) | Facebook, Instagram, WhatsApp |
These rest on the adequacy decision for the EU-US Data Privacy Framework, provided the receiving entity is certified under that framework.
Outside the European Union — under standard contractual clauses
| Provider | Where | For what |
|---|---|---|
| respond.io | Outside the European Union | WhatsApp conversations |
This provider is established outside the European Union, in a country not covered by a European Commission adequacy decision. The transfer rests on standard contractual clauses approved by the Commission, which bind the provider to a level of protection equivalent to the GDPR.
6. How long we keep it
| Data | Period |
|---|---|
| Bookings and customer history | 3 years after the last contact |
| Invoices and tax documents | 10 years (legal obligation) |
| Technical records of booking creation (IP, device) | 12 months |
| WhatsApp conversations | 3 years after the last contact |
| Advertising-origin contacts that never led to a booking | 90 days, after which they are deleted automatically |
7. Cookies and similar technologies
We use cookies and equivalent technologies for three things: making the site work, measuring how it is used, and measuring the effectiveness of advertising.
Cookies necessary for the site to function are used without consent, because without them the site does not work.
Measurement and advertising cookies are used only if you accept them in the notice we show you on your first visit. Until you choose, they are not used.
You can change your choice at any time under “Manage cookies”, in the footer of any page.
8. Your rights
You have the right to access your data, to correct it, to erase it, to restrict or object to processing, and to data portability. Where processing rests on consent, you have the right to withdraw it — as easily as you gave it.
To exercise any of these rights, write to admin@mirra.pt. We reply within the legal period of one month.
If you believe we have not handled the matter as we should, you may complain to the Portuguese data protection authority, the Comissão Nacional de Proteção de Dados (CNPD) — www.cnpd.pt.
9. Security
We maintain appropriate technical and organisational measures to protect your data, including an encrypted connection to the site, access control, and limiting access to the staff who need it to do their work.
10. Minors
Not all of our services carry the same minimum age:
| Service | Minimum age |
|---|---|
| Massages | 16 |
| Beauty treatments | 16 |
| Sauna and hammam | 18 |
Bookings for under-18s are made and authorised by whoever holds parental responsibility, who accompanies the minor on the day of the service. In those cases, the data we process includes that of the person making the booking.
11. Changes
If we change this policy, we publish the new version on this page with an updated date. If the change is significant, we will say so visibly.