Privacy Policy

Last updated: 31 August 2026

This privacy policy applies to the Mentiora product and platform (dba, Hollie) and the website https://hollie.mentiora.ai/ ("Website"), ("Privacy Policy") which are operated by Mentiora AG ("Mentiora", "Hollie", "we", "our" or "us"), a company incorporated in Zurich, Switzerland.

Contact / Controller

Controller: Mentiora AG
Address: Rieterstrasse 6, 8002 Zürich, Switzerland
Optional dedicated privacy contact: [email protected]

In accordance with Art. 27 GDPR we have appointed a representative in the European Union; the contact details are set out under "Your Rights & Supervisory Authorities" below.

Mentiora AG remains the controller for all processing activities related to the Website and the Hollie product and platform and related services.

Scope of this Privacy Policy

This Privacy Policy applies exclusively to interactions with our public Website and our services (the "Services") to the extent that we are considered a data controller. It does not apply to any personal information we process on behalf of our Client(s) through our Services ("Customer Data"). Where we process Customer Data on behalf of a business customer, we act as a processor within the meaning of Art. 28 GDPR (and the corresponding provisions of the Swiss FADP); the applicable terms are set out in a Data Processing Agreement made available to business customers during onboarding or on request.

We may update this Privacy Policy from time to time. Changes will be posted with an updated "Last Updated" date. Therefore, we ask you to check back periodically for the latest version of this Privacy Policy. If we implement material changes in the way we use your personal information, in a manner that is different from that stated at the time of collection, we will notify you by posting a notice on our Website or by other means and take any additional steps as required by applicable law.

This Privacy Policy applies to the use of the Website and all associated services under the Hollie product and platform (including demo platform), operated by Mentiora AG.

Personal Information Collected, Purposes, Retention & Legal Basis

Log Information

Browser type, IP address, operating system, referring URL, timestamp.

Retention: Standard server request logs are retained for up to 30 days; longer only where necessary to investigate a specific security incident or where required by applicable law.

Purpose: To allow us to record certain pieces of information whenever you visit or interact with the Website and Services, including to provide access, maintain and improve performance, prevent fraud and abuse, detect and fix errors, and generate aggregate statistics about the use of our Website and Services.

Legal Basis: Legitimate interest (Art. 6(1)(f) GDPR; proportionality under FADP).

Business Inquiries / Contact Us

If you contact us, we process your name, email, company, and message.

Retention: Until resolved; if relationship arises, for its duration.

Purpose: Mentiora uses your personal information (i) to respond to your questions, comments, and other requests for customer support, or information, including information about potential or future services; (ii) to provide you with the Services; (iii) for internal quality control purposes; (iv) to establish a business relationship; (v) to generally administer the Services; and (vi) to send you service-related communications and, where permitted by law, information about events, news and product updates that may be relevant to you.

Legal Basis: Legitimate interest (Art. 6(1)(f) GDPR) or pre-contractual steps (Art. 6(1)(b) GDPR).

Demo Registration

Email address and full name.

Retention: We retain demo registration data for as long as your registration or account remains active, or longer where required by law or where necessary in connection with an ongoing business relationship.

Purpose: We will use your personal information to process, answer your request for a demo, and to send updates about the demo (including emails to schedule the demo).

Legal Basis: Pre-contractual steps (Art. 6(1)(b) GDPR); Legitimate interest (Art. 6(1)(f) GDPR). For marketing purposes: Consent (Art. 6(1)(a) GDPR).

Customer Accounts & Billing

If you create a Hollie workspace, we will access and process your name, your work email address and, if you sign in with Google, your Google account identity (name, email, profile picture) for login, account administration and service communications. Subscription payments are processed by our payment provider, Stripe; Mentiora does not access or process the full card details, only receives from Stripe payment details and confirmation.

Retention: For the duration of the business relationship, plus any legally required retention periods (e.g. accounting records).

Purpose: Account creation and authentication, providing and administering the Services, billing and invoicing.

Legal Basis: Contract performance (Art. 6(1)(b) GDPR); legal obligation (Art. 6(1)(c) GDPR) for retention of accounting records.

Business Search and Account Setup ("Save your Hollie")

When you set Hollie up from our Website, we process the business you selected (publicly listed details from your Google business listing: name, address, opening hours, phone, website, rating) and the work email you enter. To pre-fill your workspace, we also retrieve and analyse publicly available web content about your business (your business website and, where enabled, a web search via Tavily AI, Inc., United States) using Google Vertex AI to extract business facts such as services, opening hours and prices; you review the results during setup. When reading your business website we read multiple publicly available pages of that site (for example menu, prices, directions, FAQ and team pages), respecting the site's robots.txt. Published names of your staff or practitioners that appear on your own website together with their professional role (for example a named physiotherapist) may be retained as part of your workspace's knowledge base so your assistant can answer questions about your services; private contact details of staff (such as personal email addresses or mobile numbers) are removed before any content is stored or analysed. You can edit or delete any of this content in your dashboard at any time.

Retention: If you do not confirm via the sign-in link, the link expires after 24 hours and the pending setup record (including the email address) is deleted by our daily automated purge. Workspaces created through this flow that are never signed into again are deactivated after 30 days.

Purpose: To create your Hollie workspace and send you a secure sign-in link.

Legal basis: Legitimate interest (Art. 6(1)(f) GDPR) or pre-contractual steps (Art. 6(1)(b) GDPR).

Google Calendar (Business Customers)

If you connect your Google Calendar, Hollie checks availability and creates bookings on your behalf; the applicable processor terms are set out in our Data Processing Agreement. Hollie's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We store only the OAuth refresh token needed to keep the connection working (encrypted with a region-pinned Google Cloud KMS key and stored in our access-controlled database) together with a calendar label; we do not keep copies of your calendar events, and you can disconnect at any time from your dashboard or your Google Account's security settings.

Hollie Voice Assistant and Demo Calls

If you start a Hollie demo call, from our Website or by phoning one of our demo numbers, your call is processed in real time to run the conversation by: LiveKit, Inc. (United States — audio transport; phone-call media is routed via LiveKit's United States infrastructure, while browser-microphone demo audio may be carried via the nearest available edge, which may be outside the EEA); an AI language model (dialogue) — currently Cerebras Systems Inc. (United States) as the primary dialogue model, with Groq, Inc. (United States) serving a share of turns via our capacity router, Google Vertex AI (Gemini) as fallback and Mistral AI SAS (France) as a secondary fallback; and ElevenLabs (speech recognition and voice synthesis, processed in the United States under the EU–US and Swiss–US Data Privacy Frameworks). Calls to our demo phone numbers are carried by Telnyx LLC (United States), our telephony carrier, which processes your caller number and call audio in transit. We do not make a data-residency commitment for demo calls.

If you use the "call me" feature, we process the phone number you enter solely to place that call.

Retention: No audio recording is stored (except limited diagnostic recordings, announced at the start of the call); the durable record of the call is a two-sided text transcript, which we retain for up to 90 days for quality purposes and then delete. You can contact [email protected] for earlier deletion, quoting the call reference shown when your demo call ends.

Purpose: To provide you with the experience of Hollie by calling you or picking up your call at your instruction and request.

Legal basis: Legitimate interest (Art. 6(1)(f) GDPR) or pre-contractual steps (Art. 6(1)(b) GDPR).

Registering Interest (Ad Landing Page)

If you use the "register your interest" form on our public landing page, we process the details you choose to give us — your name, business name, email address and/or phone number, and any message — together with basic campaign attribution captured from the link you arrived on (e.g. UTM tags and a Google click identifier, "gclid"). We use this solely to respond to your enquiry and follow up about Hollie (legal basis: our legitimate interest in responding to and following up on enquiries you initiate, Art. 6(1)(f) GDPR; you can object at any time). At least one of email or phone is required so we can reach you. These enquiries are delivered to our team inbox by our email provider Resend (Resend, Inc., United States; for transfer safeguards see "Third Party Service Providers and International Transfers" below). We also keep a secure, access-controlled record of your enquiry in our own database so we can manage and follow up on it. We keep an enquiry for up to 24 months from when we first record it, unless an active business relationship or a legal duty requires longer retention, and delete it earlier on a valid request where no overriding duty applies. If you give us a separate opt-in consent — by ticking the newsletter box on the form, or by agreeing when Hollie asks you during a demo call — we record that consent (including the wording shown or spoken and when you gave it, as proof of consent) and may send you occasional news and updates about Hollie by email; Resend also acts as our sub-processor for sending those messages. Where you have opted in, we keep your contact details and this consent record for as long as you remain subscribed — beyond the 24 months noted above — so we can send you the updates you asked for. If you unsubscribe, we stop sending and retain a suppression record (your contact details, the consent you gave and your opt-out) so we can honour and evidence your choice, until you ask us to erase your data entirely, which you can do at any time. You can withdraw your consent, unsubscribe, or ask us to erase or export your data at any time — using the email address or phone number you gave us — by contacting [email protected]. We never add you to a newsletter or an unrelated marketing list without that opt-in. We do not sell this information or use it to train AI or machine-learning models.

Business Onboarding Interview

If you record an onboarding interview so Hollie can learn your business, your voice recording is sensitive (biometric) data and is processed only with your explicit consent, which we log before any recording is kept. We use it to configure your AI receptionist; the recording is transcribed and analysed by the services named above (ElevenLabs for speech, Google Vertex AI for extraction, LiveKit for call audio) — we make no data-residency commitment for interview calls. Draft interview data is deleted after 30 days, or immediately if you choose "Delete interview data"; your published receptionist configuration is kept as your business settings. You can download a copy of your interview data or delete it at any time from the Privacy page in your dashboard.

How We Protect Your Personal Information

We use industry-standard technical, organizational, and security measures to protect your personal information. However, we cannot guarantee against unauthorized access to our servers. Security also depends on your computer, device, network, and the protection of your user IDs and passwords, so please take appropriate precautions.

In addition to the above retention periods, please note that in some circumstances we store your personal information for longer periods of time, for example (i) where we are required to do so in accordance with legal, regulatory, tax or accounting requirements, or (ii) for us to have an accurate record of your dealings with us in the event of any complaints or challenges, and/or (iii) if we reasonably believe there is a prospect of litigation relating to your personal information or dealings.

Third Party Service Providers and International Transfers

We may share your personal information with Third Party Service providers to process your personal information for the purposes outlined above, including, without limitation:

The full, current list of sub-processors — including each one's role, region and transfer safeguard, and your right to object to a new one — is published at /subprocessors.

Transfers may occur to the United States. Safeguards: EU–U.S. Data Privacy Framework (if applicable), adequacy decisions, or Standard Contractual Clauses (SCCs).

Transfers of Personal Information

To provide our Website and Services, we transfer personal information internationally, including to affiliates and service providers outside your jurisdiction. This means your personal information may be processed in countries with different privacy laws. We protect these transfers using Standard Contractual Clauses, data processing agreements, or by ensuring the destination country is recognized as providing adequate protection. According to the Israeli law, by providing your consent to this Privacy Policy, you acknowledge and agree that Personal Information relating to you may be transferred to and stored outside the borders of Israel, in accordance with applicable law and for the purposes described herein.

With Whom We Share Your Data

Your Rights & Supervisory Authorities

You have the rights to access, rectification, erasure, restriction, data portability, object to processing, and withdraw consent where applicable (which may be subject to certain exemptions or derogations). No automated decision-making or profiling takes place.

You can exercise your rights by contacting us at [email protected]. You may use an authorized agent with your signed written permission. To protect your privacy, we may verify your identity before fulfilling your request. We will make reasonable efforts to honor your request promptly as required by law or let you know if more information is needed. We may request additional information for verification or security purposes. Where permitted by law, we may charge a fee if your request is unfounded or excessive. If your request affects others' rights or if the law allows us to handle it differently, we will address it as fully as possible in accordance with applicable law.

Should you ever decide to delete your account, you may do so by emailing [email protected]. If you terminate your account, any association between your account and personal information we store will no longer be accessible through your account. However, given the nature of sharing on certain services, any public activity on your account prior to deletion will remain stored on our servers and will remain accessible to the public.

We have appointed a representative in the EU in accordance with Art. 27 GDPR:
Dr. Christian Szidzek,
THALES Rechtsanwälte,
Prymstraße 1,
97070 Würzburg.

You also have the right to lodge a complaint with a supervisory authority — in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC, https://www.edoeb.admin.ch); in the EU, the supervisory authority of the member state of your habitual residence.

Children's Data

Our Website or Services are intended for adults. Persons under 18 should not provide data without parental consent. We do not knowingly collect such data. If you are under the age of 18 do not provide any information to us without the involvement of a parent or a guardian. In the event that we become aware that you provided personal information in violation of applicable privacy laws, we reserve the right to delete it. If you believe that we might have any such information, please contact us at [email protected].

Interaction with Third Party Products

You may interact with third party websites, apps, and services not controlled by us ("Third Party Services"). We are not responsible for their privacy practices or content. Third Party Services may collect your personal information, so please review their terms and privacy policies.

Cookies & Analytics

On the public Hollie landing page we use Google Tag Manager to load the CookieYes consent platform and Google Analytics 4; analytics and advertising storage is denied by default under Google Consent Mode v2 and is enabled only after you consent. We reserve the right to remove or add new analytic tools, cookies, pixels and other tracking technologies. A full inventory of the cookies and similar technologies we use — including their providers and lifetimes — is published in our Cookie Notice.

Contact Us

For any questions, concerns, or to exercise your privacy rights, please contact us at [email protected].