Last updated: 2 September 2026

1. Who we are

The controller of your personal data is:

CRAZYSILENCE, LDA
NIPC 514934328
Rua do Alferes Malheiro, 199, 4000-059 Porto, Portugal
Email: admin@mirra.pt
Phone: +351 913 844 969

We operate the spa Mirra Porto SPA and the site mirra.pt.

2. What we collect, and when

When you make a booking — online, by phone, on WhatsApp or at reception

  • name
  • email address
  • phone number
  • service, date, time and duration
  • therapist preference, where you give one
  • any notes you send us about the appointment

When the booking is made on the site, the system also records, at the moment it is created: IP address, browser and device identification, and the date and time. We use this for security and fraud prevention — in particular to detect false bookings.

When you buy a voucher or pay online

  • the billing details required by law
  • payment details are handled directly by the payment provider; we never receive or store card numbers

When you contact us on WhatsApp

  • your phone number and the content of the conversation
  • if you reached us from an advert or from a link of ours, a technical code identifying that origin

When you visit the site

  • pages visited, where the visit came from, and identifiers associated with cookies and similar technologies — under the terms of section 7

When you leave a review

  • what you publish in a Google review is public by your own decision and governed by Google’s terms. We may reply to you publicly.

We do not ask for and do not want health data. If you choose to tell us something about your health that is relevant to a treatment, we use it only to deliver the service safely and we share it with no one.

3. What we use it for, and on what legal basis

Purpose Legal basis
Managing your booking and delivering the service performance of a contract
Sending confirmations, reminders and changes to the appointment performance of a contract
Invoicing and tax obligations legal obligation
Answering enquiries and complaints performance of a contract / legitimate interest
Site security and prevention of fraudulent bookings legitimate interest
Measuring how the site is used (statistics) consent
Advertising and campaign measurement consent
Invitations to review the service you received legitimate interest

Where the basis is consent, you may withdraw it at any time — see section 8. Withdrawing consent does not affect what was done before on the strength of it.

4. Who we share it with

We do not sell your data. We share only what is necessary, with those who provide services to us:

Google — Google Analytics, Google Ads and our Google Business Profile. If you accept measurement and advertising cookies, Google receives information about how the site is used and about completed bookings, so we can tell which adverts work. Where contact details are used for this, they are sent in an irreversible hashed form that cannot be turned back into your number or email.

Meta (Facebook, Instagram, WhatsApp) — on the same terms, if you accept advertising cookies. WhatsApp is also a customer-service channel.

respond.io — the platform where we receive and answer WhatsApp conversations.

Moloni — invoicing.

Viva Wallet — payments. Payment takes place on Viva Wallet’s own pages, under Viva’s privacy policy and terms; card details are entered there and never pass through us. For bookings we send them only the amount and the booking number. For voucher purchases we also send your name and email, which are needed to issue the payment. In both cases, what comes back to us is the confirmation and the transaction reference. Viva Wallet handles this data on our behalf, and is an EU-licensed and supervised institution, registered with Banco de Portugal to operate in Portugal.

Cloudways (on Linode infrastructure) — hosting of the site and the database, in Frankfurt, Germany.

We may also disclose data to authorities where the law requires it.

5. Transfers outside the European Union

Our providers fall into three different situations, each with its own basis. We say where each one is, because that is what decides which basis applies.

Inside the European Union — no international transfer

Provider Where For what
Moloni Portugal invoicing
Viva Wallet European Union payments
Cloudways European Union — server in Frankfurt, Germany hosting of the site and the database

United States — under the European Commission adequacy decision

Provider Where For what
Google United States (contracted through the Irish entity) Analytics, Ads, Business Profile
Meta United States (contracted through the Irish entity) Facebook, Instagram, WhatsApp

These rest on the adequacy decision for the EU-US Data Privacy Framework, provided the receiving entity is certified under that framework.

Outside the European Union — under standard contractual clauses

Provider Where For what
respond.io Outside the European Union WhatsApp conversations

This provider is established outside the European Union, in a country not covered by a European Commission adequacy decision. The transfer rests on standard contractual clauses approved by the Commission, which bind the provider to a level of protection equivalent to the GDPR.

6. How long we keep it

Data Period
Bookings and customer history 3 years after the last contact
Invoices and tax documents 10 years (legal obligation)
Technical records of booking creation (IP, device) 12 months
WhatsApp conversations 3 years after the last contact
Advertising-origin contacts that never led to a booking 90 days, after which they are deleted automatically

7. Cookies and similar technologies

We use cookies and equivalent technologies for three things: making the site work, measuring how it is used, and measuring the effectiveness of advertising.

Cookies necessary for the site to function are used without consent, because without them the site does not work.

Measurement and advertising cookies are used only if you accept them in the notice we show you on your first visit. Until you choose, they are not used.

You can change your choice at any time under “Manage cookies”, in the footer of any page.

8. Your rights

You have the right to access your data, to correct it, to erase it, to restrict or object to processing, and to data portability. Where processing rests on consent, you have the right to withdraw it — as easily as you gave it.

To exercise any of these rights, write to admin@mirra.pt. We reply within the legal period of one month.

If you believe we have not handled the matter as we should, you may complain to the Portuguese data protection authority, the Comissão Nacional de Proteção de Dados (CNPD)www.cnpd.pt.

9. Security

We maintain appropriate technical and organisational measures to protect your data, including an encrypted connection to the site, access control, and limiting access to the staff who need it to do their work.

10. Minors

Not all of our services carry the same minimum age:

Service Minimum age
Massages 16
Beauty treatments 16
Sauna and hammam 18

Bookings for under-18s are made and authorised by whoever holds parental responsibility, who accompanies the minor on the day of the service. In those cases, the data we process includes that of the person making the booking.

11. Changes

If we change this policy, we publish the new version on this page with an updated date. If the change is significant, we will say so visibly.