Skip to content

Mirari Privacy Notice

Effective date: 20 July 2026

Last updated: 20 July 2026

Version: 1.0

This Privacy Notice explains how Pink Elephant, Unipessoal Lda, NIPC 519056582, operating Mirari, processes personal data in connection with the Mirari Foundation Program and practitioner community.

Mirari is an education and professional-community platform for psychedelic-assisted practice, offering the Foundation Program and a practitioner community for coaches, therapists, integration specialists and related professionals across Europe.

This Privacy Notice applies to prospective students, enrolled students, alumni, community members and subscribers, website visitors, faculty, guest lecturers, contractors, and other identifiable persons whose personal data is included in Mirari records.

1. Controller

The controller responsible for the processing described in this Privacy Notice is:

Pink Elephant, Unipessoal Lda

NIPC 519056582

Edifício Amoreiras Square, Rua Carlos Alberto da Mota Pinto, n.º 17, 2nd floor
1070-313 Lisboa, Portugal

Email: [email protected]

Mirari has assessed that a Data Protection Officer is not required under Article 37 GDPR for the current processing. Privacy questions and data-subject rights requests may be sent to [email protected].

2. Overview of Mirari processing

Mirari processes personal data to operate its educational program and practitioner community. The processing includes application and admissions communications, enrolment and program administration, tuition payment processing, learning-platform account management, live teaching session delivery, progress tracking and assessment, practitioner community operation, marketing communications, and website analytics.

Mirari does not intend to collect special-category data in the ordinary application, enrolment or program delivery processes. The main situation where health-related information may arise is the application process, where an applicant’s motivation statement may include information relating to their own mental health or that of others, given the subject matter of the Foundation Program.

Website analytics are configured with IP anonymization at the point of collection and no User ID tracking, but are not fully anonymous as cookie identifiers and other pseudonymous signals are processed, and this activity is treated as personal-data processing under the GDPR, subject to consent.

3. Applications, admissions and enrolment

If you apply to the Foundation Program, Mirari processes your full name, email address, country of residence, professional background, motivation statement, application status, admission decision, enrolment date and payment status.

This processing is used to assess your application, communicate the admission decision, and enroll you in the Foundation Program where your application is successful.

The legal basis is Article 6(1)(b) GDPR, necessary to take steps at your request before entering into a contract and, where you enroll, to perform that contract, and Article 6(1)(f) GDPR, Mirari’s legitimate interest in evaluating applications against the program’s admissions criteria and maintaining the quality and safety of each cohort.

No Article 9 special-category data is intended to be processed in the application process. Applicants should not include client-identifying information or unnecessary health or other special-category data in the motivation statement. Where an applicant nonetheless includes such information, it is processed on the basis of Article 9(2)(a) GDPR, explicit consent inferred from its voluntary disclosure and used only for the purpose of assessing the application.

The data is accessible to the program director and admissions staff. No external recipients are involved in this activity.

Unsuccessful applications are deleted 12 months after the decision. Enrolled student data is retained for the duration of enrolment plus 3 years from program completion, then deleted.

4. Tuition payments and billing

If you make a payment to Mirari, Mirari processes your transaction reference, payment status, amount, currency, payment date and enrolment reference. Card data is processed exclusively by Stripe or Klarna and is not retained by Mirari.

The legal basis is Article 6(1)(b) GDPR, necessary to perform the contract with you, and Article 6(1)(c) GDPR, Mirari’s legal obligation under Portuguese tax and accounting law (Commercial Code Article 40 and VAT Code Article 52, as implemented by Decree-Law 28/2019).

No Article 9 special-category data is intended to be processed in this activity.

The data is accessible to finance and operations staff. Stripe Payments Europe, Ltd (Ireland) and Klarna Bank AB (Sweden) are used as payment processors. Both are EEA entities, but each belongs to an international group whose standard terms provide for onward transfers to non-EEA affiliates or sub-processors. See section 13.

Transaction metadata is retained for 10 years from the transaction date under Portuguese tax and accounting law. Payment status records are retained for the duration of enrolment plus 30 days.

5. Learning platform account (Circle)

If you enroll in the Foundation Program, Mirari creates and maintains your account on Circle, the learning management system used to deliver the program. This includes your full name, email address, Circle user ID, account creation date, cohort membership, content access log, completion status and login metadata.

The legal basis is Article 6(1)(b) GDPR, necessary to perform the contract with you and deliver the curriculum.

No Article 9 special-category data is intended to be processed in this activity.

The data is accessible to program staff. Circle Technologies, Inc. is used as the learning management system provider. Circle Technologies, Inc. is established in the United States. Mirari relies on Standard Contractual Clauses under Article 46(2)(c) GDPR and has completed a transfer impact assessment. See section 13.

The data is retained for the duration of enrolment plus 12 months, after which the account is deleted or anonymized.

6. Live teaching sessions (Zoom)

Mirari delivers synchronous teaching, including live group classes and facilitated skills labs, via Zoom. This involves your full name, email address, Zoom display name, session join/leave metadata and participation data. Session recordings are made only where advance notice is given and consent is obtained. Automatic cloud recording is not enabled.

The legal basis for session participation is Article 6(1)(b) GDPR, necessary to perform the contract with you. The legal basis for session recording is Article 6(1)(a) GDPR, consent, which may be withheld without affecting your ability to attend the session.

No Article 9 special-category data is intended to be processed in this activity.

The data is accessible to program staff and faculty. Zoom Video Communications, Inc. is used for session delivery. Zoom is US-headquartered. Mirari has activated EU data residency settings, which keep meeting audio and video on EU servers, although account and session metadata is typically still processed in the United States. See section 13.

Session metadata is retained for 12 months from the session date. Recordings made with consent are deleted within 30 days of the session, or sooner if consent is withdrawn.

7. Progress tracking and assessment

Mirari records your attendance, assignment submission dates and status, reflective practice activity, assessment scores, written submissions, activity logs, completion status and faculty feedback, referenced to your student ID.

The legal basis is Article 6(1)(b) GDPR, necessary to perform the contract with you, including assessment and the award of completion status, and Article 6(1)(f) GDPR, Mirari’s legitimate interest in maintaining the integrity and consistency of its assessment records.

No Article 9 special-category data is intended to be processed in this activity.

The data is accessible to the program director, faculty and academic administrators. Where hosted on the learning management system, the data is processed by Circle Technologies, Inc. on the same basis as section 5.

The data is retained for 3 years from program completion, then deleted.

8. Practitioner community

Mirari operates a practitioner community on Circle for enrolled students and alumni, comprising discussion spaces, resource sharing and professional networking. This may include your full name, professional profile information you choose to provide, community posts and contributions, direct messages, group memberships and engagement metadata.

The legal basis for enrolled students is Article 6(1)(b) GDPR, necessary to perform the contract with you. The legal basis for alumni continued access, and for profile or content information you actively choose to share, is Article 6(1)(a) GDPR, consent, which may be withdrawn at any time.

No Article 9 special-category data is intended to be processed in this activity.

The data is accessible to program staff and community moderators. Circle Technologies, Inc. is used as the community platform, on the same basis as section 5.

For enrolled students, the data is retained for the duration of enrolment plus 12 months. For alumni with continued access, the data is retained until consent is withdrawn or account deletion is requested.

9. Marketing communications

Where you opt in, Mirari sends program information, cohort announcements and educational content to prospective students, website visitors and community subscribers. This includes your email address, first name where provided, subscription status, email engagement metadata and opt-in date and source.

The legal basis is Article 6(1)(a) GDPR, consent. You may withdraw consent at any time by unsubscribing.

No Article 9 special-category data is intended to be processed in this activity.

The data is accessible to marketing and communications staff. Klaviyo, Inc., a US-based email service provider, is the platform used for this processing. See section 13 for the applicable transfer safeguard.

The data is retained until unsubscribed or withdrawal of consent, plus 30 days for suppression-list maintenance.

10. Website analytics and cookies

Mirari uses Google Analytics 4 to understand website usage, including cookie identifiers, pages visited, session duration, referral source, device/browser type and approximate geographic region. IP addresses are anonymized at collection, no User ID tracking is enabled, and advertising features are disabled.

The legal basis is Article 6(1)(a) GDPR, consent, given through cookie preferences. Analytics cookies are not set until consent is given, and consent may be withdrawn at any time through cookie preferences.

No Article 9 special-category data is intended to be processed in this activity.

The data is accessible to marketing staff. Google Ireland Ltd processes the data within the EEA. Google LLC in the United States may act as a sub-processor for limited purposes. See section 13.

Analytics data is retained for 14 months from collection. Cookie consent records are retained for 3 years.

11. Faculty, guest lecturers and contractors

Mirari processes personal data of teaching faculty, guest lecturers and contractors to manage the working relationship, including full name, professional credentials and biography, contact details, contractual terms, fee and payment details and session delivery records.

The legal basis is Article 6(1)(b) GDPR, necessary to perform the contract with you, and Article 6(1)(c) GDPR, Mirari’s legal obligation under Portuguese tax and accounting law, on the same basis as section 4.

No Article 9 special-category data is intended to be processed in this activity.

The data is accessible to the program director and finance staff. No external recipients are involved in this activity.

The data is retained for the duration of engagement plus 10 years, under the Portuguese tax and accounting retention obligation described in section 4.

12. Recipients and processors

Mirari may disclose or make available personal data to authorized internal personnel and to processors used to operate the service.

Internal recipients include the program director, admissions staff, finance and operations staff, program staff, faculty, academic administrators, community moderators, and marketing and communications staff, each only where access is necessary for their role.

External processors include Stripe Payments Europe, Ltd and Klarna Bank AB for payment processing; Circle Technologies, Inc. for the learning management system and practitioner community; Zoom Video Communications, Inc. for live teaching sessions; Klaviyo, Inc. for marketing communications; and Google Ireland Ltd for website analytics.

Processor arrangements are governed by data processing agreements or equivalent processor terms.

13. International transfers

Several processors used by Mirari are established, or maintain infrastructure, outside the EEA, principally in the United States. Where this occurs, Mirari relies on an appropriate transfer mechanism under Chapter V GDPR such as an adequacy decision, Standard Contractual Clauses, or another lawful safeguard, as applicable.

Stripe Payments Europe, Ltd (Ireland) and Klarna Bank AB (Sweden) are EEA entities and the primary relationship with each does not itself constitute a third-country transfer. Both belong to international groups whose standard terms provide for onward transfers to non-EEA affiliates or sub-processors. Stripe discloses onward transfers to Stripe, Inc. and Stripe, LLC in the United States, safeguarded by Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework.

Circle Technologies, Inc. is established in the United States. Mirari relies on Standard Contractual Clauses under Article 46(2)(c) GDPR and has completed a transfer impact assessment.

Zoom Video Communications, Inc. is US-headquartered. Mirari has activated EU data residency settings, which keep meeting audio and video on EU servers. Account and session metadata is typically still processed in the United States, safeguarded by Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework.

Google Ireland Ltd processes website analytics data within the EEA. Google LLC in the United States may act as a sub-processor for limited purposes, safeguarded by Standard Contractual Clauses and Google’s EU Data Processing Terms.

Klaviyo, Inc., Mirari’s email marketing platform, is US-based. This transfer is safeguarded by the EU-U.S. Data Privacy Framework, with Standard Contractual Clauses available as a fallback.

The EU-U.S. Data Privacy Framework is currently valid but subject to a pending legal challenge before the Court of Justice of the European Union, with a ruling not expected before late 2026. Mirari does not rely on the Framework alone. Standard Contractual Clauses are maintained as a fallback safeguard by the relevant processors, and this notice will be updated if the Framework’s status changes.

14. Data security

Mirari applies technical and organizational measures to protect personal data.

Access to the Circle platform and administrative systems is controlled through role-based access and the least-privilege principle. MFA is required for admin accounts. Access rights are reviewed on staff change.

TLS 1.2 or higher is enforced across platform endpoints. Data at rest is encrypted by Mirari’s platform providers in accordance with their published security standards. No plaintext credentials are stored.

Mirari does not process or store card data. Payment processing is handled exclusively by Stripe and Klarna within their respective PCI DSS compliance frameworks. Mirari retains only transaction metadata.

Personnel with data access are subject to Mirari’s internal privacy procedures.

15. Retention

Mirari retains personal data only for the periods necessary for the purposes described in this notice, unless a longer period is required for legal, dispute or compliance reasons.

Unsuccessful applications are deleted 12 months after the decision. Enrolled student application data is retained for the duration of enrolment plus 3 years from program completion.

Transaction metadata is retained for 10 years from the transaction date. Payment status records are retained for the duration of enrolment plus 30 days.

Learning platform account data is retained for the duration of enrolment plus 12 months. Progress and assessment data is retained for 3 years from program completion.

Session metadata is retained for 12 months from the session date. Recordings made with consent are deleted within 30 days of the session, or sooner if consent is withdrawn.

Community data for enrolled students is retained for the duration of enrolment plus 12 months. For alumni with continued access, it is retained until consent is withdrawn or account deletion is requested.

Marketing data is retained until unsubscribe or withdrawal of consent, plus 30 days. Analytics data is retained for 14 months from collection. Cookie consent records are retained for 3 years.

Faculty and contractor data is retained for the duration of engagement plus 10 years.

16. Your rights

Where the GDPR applies, you may have the right to request access to your personal data, rectification of inaccurate personal data, erasure of personal data, restriction of processing, data portability where applicable, and objection to processing based on legitimate interests.

Where processing is based on consent, you may withdraw consent at any time. Withdrawal does not affect processing carried out before withdrawal.

You may object to processing based on Article 6(1)(f), including admissions evaluation and assessment record-keeping, where applicable. Mirari may continue processing where it demonstrates compelling legitimate grounds or where processing is required for legal claims.

You may exercise your rights by contacting [email protected]. Mirari may need to verify your identity before responding to a request. Mirari will respond within one month of receiving a request under Article 12(3) GDPR, extendable by a further two months for complex or numerous requests, with notice of any extension given within the first month.

If a request affects data shared with processors, Mirari will take reasonable steps to notify them where required and feasible.

17. Source of information

Mirari collects personal data directly from you in virtually all cases described in this notice: through application, enrolment, platform use, session participation and direct communication with Mirari. A limited amount of information is received indirectly, such as payment status reported by Stripe or Klarna following a transaction, or analytics signals generated by your browser. Where Mirari receives personal data indirectly, it will provide the information required by Article 14 GDPR to the relevant data subject, unless an exemption applies.

18. Automated decision-making

Mirari does not use solely automated decision-making producing legal or similarly significant effects. Admissions decisions are made manually by the program director and admissions staff.

19. Complaints

You may contact Mirari at [email protected] if you have questions or concerns about the processing of your personal data.

You also have the right to lodge a complaint with the Portuguese supervisory authority, the Comissão Nacional de Proteção de Dados.

20. Changes to this Privacy Notice

Mirari may update this Privacy Notice from time to time. If material changes are made, Mirari will provide notice in an appropriate manner.

Mirari will update this Privacy Notice before introducing materially different processing, new categories of personal data, new special-category processing, non-EEA transfers, new processors, or new public disclosure models.