Effective date: 20 July 2026 Last updated: 20 July 2026
Your practice, your data. At Mirari, we take the privacy of our applicants, students, alumni, faculty and community members seriously. We are based in Portugal and comply with the GDPR, one of the strictest data protection frameworks in the world — which means that wherever you’re joining us from, you can trust that your personal data is handled with care.
This policy explains how Mirari collects, uses, shares, retains and protects your personal data across the Foundation Program and the practitioner community.
A quick summary before you dive in:
We only collect what we need. Mirari does not intend to collect special-category data (such as health information) as part of the ordinary application, enrollment or program-delivery process. The one place this can arise is the application form, where an applicant’s motivation statement may touch on their own mental health or someone else’s — given the subject matter of the program. We ask applicants not to include client-identifying or unnecessary sensitive information.
We don’t sell your data. We share personal data only with the service providers who help us run Mirari — payment processors, our learning platform, our video-conferencing provider and similar tools — and only to the extent needed to provide the Services.
You’re in control. You can access, correct, delete or restrict your personal data, object to certain processing, and withdraw consent at any time by emailing [email protected].
You must be 18 or older to apply to the Foundation Program, use the practitioner community, or otherwise use Mirari’s services.
1. Introduction
Mirari is an education and professional-community platform for psychedelic-assisted practice, offering the Foundation Program and a practitioner community for coaches, therapists, integration specialists and related professionals across Europe.
This Privacy Policy is issued by, and describes the processing carried out by:
Pink Elephant, Unipessoal Lda (“Mirari“, “we“, “us“) NIPC 519056582 Edifício Amoreiras Square, Rua Carlos Alberto da Mota Pinto, n.º 17, 2nd floor, 1070-313 Lisboa, Portugal Email: [email protected]
Pink Elephant, Unipessoal Lda is the controller responsible for the personal data described in this policy. We have assessed that a Data Protection Officer is not required under Article 37 GDPR for our current processing; privacy questions and rights requests can still be sent to the email above and will reach the right people.
This policy applies to prospective students, enrolled students, alumni, community members and subscribers, website visitors, faculty, guest lecturers, contractors, and anyone else identifiable in Mirari’s records.
We may update this policy from time to time. If we make material changes — for example, introducing meaningfully different processing, new categories of personal data, new special-category processing, new non-EEA transfers, new processors, or new ways your information is made public — we will update this page and note the new effective date before those changes take effect.
2. Personal data we collect
What we collect depends on how you interact with Mirari. Here’s a breakdown by activity.
Applications, admissions and enrollment. If you apply to the Foundation Program, we process your full name, email address, country of residence, professional background, motivation statement, application status, admission decision, enrolment date and payment status, in order to assess your application, communicate our decision, and enrol you if you’re accepted.
Tuition payments and billing. If you pay us, we process your transaction reference, payment status, amount, currency, payment date and enrollment reference. Your card details are handled exclusively by our payment processors, Stripe and Klarna — we never see or store them.
Learning platform account (Circle). Once enrolled, we create your account on Circle, our learning management system, including your full name, email address, Circle user ID, account creation date, cohort membership, content access log, completion status and login metadata.
Live teaching sessions (Zoom). We deliver live classes and skills labs over Zoom, which involves your full name, email address, Zoom display name, and session join/leave and participation metadata. We only record a session where we’ve given advance notice and obtained consent — automatic cloud recording is switched off.
Progress tracking and assessment. We record your attendance, assignment submission dates and status, reflective practice activity, assessment scores, written submissions, activity logs, completion status and faculty feedback, tied to your student ID.
Practitioner community. If you’re an enrolled student or alumnus with community access, we may process your full name, any professional profile information you choose to add, your posts and contributions, direct messages, group memberships and engagement metadata.
Marketing communications. If you opt in, we process your email address, first name (where given), subscription status, email engagement metadata, and your opt-in date and source, so we can send you program information, cohort announcements and educational content.
Website analytics. We use Google Analytics 4 to understand how our website is used — cookie identifiers, pages visited, session duration, referral source, device/browser type and approximate geographic region. IP addresses are anonymised at collection and User ID tracking is off, but this is still personal-data processing under the GDPR and only happens with your consent.
Faculty, guest lecturers and contractors. We process full names, professional credentials and biography, contact details, contractual terms, fee and payment details, and session delivery records to manage our working relationship with you.
Where this comes from. In virtually every case, we collect your personal data directly from you — through your application, enrollment, platform use, session participation, or direct communication with us. A small amount comes indirectly, such as payment status reported to us by Stripe or Klarna, or analytics signals generated by your browser. Where we receive data indirectly and the GDPR’s Article 14 applies, we’ll provide you the required information unless an exemption applies.
3. How we use your personal data, and our legal basis
We rely on different legal bases depending on the activity:
| Activity | Legal basis | What this means in practice |
| Assessing your application and, if successful, enrolling you | Art. 6(1)(b) — steps taken at your request before a contract, and contract performance; Art. 6(1)(f) — our legitimate interest in evaluating applications and maintaining cohort quality and safety | We review your application materials to decide whether to admit you, and to run your enrollment once accepted. |
| Processing tuition payments | Art. 6(1)(b) — contract performance; Art. 6(1)(c) — legal obligation under Portuguese tax and accounting law | We collect and record your payment status and transaction details to charge you correctly and meet our bookkeeping duties. |
| Running your learning-platform account | Art. 6(1)(b) — contract performance | We maintain your Circle account so you can access the curriculum you enrolled for. |
| Delivering live sessions | Art. 6(1)(b) — contract performance (attending); Art. 6(1)(a) — consent (recording) | You can always attend a session even if you decline to be recorded. |
| Tracking progress and assessment | Art. 6(1)(b) — contract performance; Art. 6(1)(f) — our legitimate interest in consistent, reliable assessment records | We record attendance, scores and feedback to run the program and award completion status fairly. |
| Operating the practitioner community | Art. 6(1)(b) — contract performance (enrolled students); Art. 6(1)(a) — consent (alumni continued access, and any optional profile/content information you share) | Alumni can withdraw consent at any time to end continued community access. |
| Sending marketing communications | Art. 6(1)(a) — consent | You can unsubscribe whenever you like. |
| Website analytics | Art. 6(1)(a) — consent, given through cookie preferences | Analytics cookies aren’t set until you consent, and you can withdraw that consent at any time. |
| Managing faculty, guest lecturer and contractor relationships | Art. 6(1)(b) — contract performance; Art. 6(1)(c) — legal obligation under Portuguese tax and accounting law | Standard contract administration and statutory recordkeeping. |
Special-category data. We don’t intend to process special-category data (as defined in Article 9 GDPR) in any of our ordinary processing activities. The exception is the application process: if an applicant’s motivation statement voluntarily discloses health-related information about themselves or someone else, we process it under Article 9(2)(a) GDPR (explicit consent inferred from voluntary disclosure), and only for the purpose of assessing that application. We ask applicants not to include client-identifying information or unnecessary sensitive details in their motivation statement.
Who inside Mirari can see your data. Access is limited by role: application and admissions data is seen by the program director and admissions staff; payment data by finance and operations staff; learning-platform, progress and community data by program staff, faculty, academic administrators and community moderators as relevant; marketing data by marketing and communications staff; analytics data by marketing staff; and faculty/contractor records by the program director and finance staff.
4. Your privacy rights
Wherever the GDPR applies to you, you have the following rights over your personal data:
Access. You can ask whether we process your personal data and request a copy of it, along with information about our purposes, the categories of data involved, recipients, retention and the source of the data.
Rectification. If something we hold about you is inaccurate or incomplete, you can ask us to correct it. We may ask for supporting evidence where a correction concerns application-relevant information such as your professional background or credentials. We’re not required to change assessment scores or faculty feedback simply because you disagree with them, but we will record a correction, supplemental statement or dispute note if the underlying facts are shown to be wrong.
Erasure. You can ask us to delete your personal data, and we will do so where a valid ground applies and no exception requires us to keep it.
Restriction of processing. You can ask us to limit how we use your data in certain circumstances — for example, while we look into an accuracy dispute.
Data portability. Where we process your data by automated means on the basis of consent or contract, you can ask for it in a structured, commonly used, machine-readable format.
Objection. You can object to processing we base on our legitimate interests — including admissions evaluation and assessment recordkeeping. We’ll stop unless we can show compelling legitimate grounds that override your rights, or the processing is needed for legal claims.
Withdrawing consent. Where we rely on your consent — recordings, continued alumni community access, optional community profile/content sharing, marketing, and analytics cookies — you can withdraw it at any time. This won’t affect processing we already carried out before you withdrew.
How to exercise these rights. Email [email protected]. We may need to verify your identity before acting on a request, proportionate to the sensitivity of what you’re asking about — a marketing unsubscribe needs less verification than a request touching enrollment, payment, assessment, or Zoom recording data. Where a record includes other people’s personal data — for instance, other participants visible or audible in a Zoom recording, or other members named in a community post — we’ll provide your own data but may redact or withhold anyone else’s.
Timing. We aim to respond within one month of receiving your request, as required by Article 12(3) GDPR. For complex or numerous requests, we may extend this by up to two further months, and we’ll tell you within the first month if we need to do that. If a request affects data we’ve shared with a processor, we’ll take reasonable steps to notify them where required and feasible.
Automated decision-making. We don’t use solely automated decision-making that produces legal or similarly significant effects. Admissions decisions are made manually by our program director and admissions staff.
Complaints. If you have concerns about how we handle your data, email us first at [email protected] — we’d like the chance to sort it out. You also have the right to lodge a complaint with the Portuguese supervisory authority, the Comissão Nacional de Proteção de Dados (CNPD).
5. Who we share your data with
We don’t sell your personal data. We share it only with the internal teams who need it to do their jobs, and with the service providers (“processors”) who help us run Mirari. We’re responsible for these processors and require them to follow our instructions and the law.
| Processor | What they do for us | What they process |
| Stripe Payments Europe, Ltd (Ireland); Klarna Bank AB (Sweden) | Payment processing and, via Klarna, flexible payment plans | Card data directly; we only receive transaction metadata back |
| Circle Technologies, Inc. (United States) | Learning management system and practitioner community platform | Account, cohort, content-access, progress, assessment and community data |
| Zoom Video Communications, Inc. (United States, with EU data residency enabled) | Live teaching sessions | Names, emails, session metadata, and recordings made with consent |
| Klaviyo, Inc. (United States) | Email marketing platform | Email address, subscription status, engagement metadata |
| Google Ireland Ltd (with Google LLC as a limited sub-processor) | Website analytics (Google Analytics 4) | Cookie identifiers, pages visited, device/browser type, approximate location |
We may also disclose personal data where required by law, to respond to legal process, to protect the security or integrity of our services, to establish or defend legal claims, with your authorisation, or in connection with a business transfer or reorganisation.
6. International data transfers
Some of our processors are based, or hold infrastructure, outside the EEA — mainly in the United States. Where that’s the case, we rely on an appropriate safeguard under Chapter V GDPR, such as Standard Contractual Clauses or, where applicable, the EU-U.S. Data Privacy Framework.
- Stripe and Klarna contract with us as EEA entities, but each belongs to an international group whose standard terms allow onward transfers to non-EEA affiliates or sub-processors. Stripe’s onward transfers to Stripe, Inc. and Stripe, LLC in the US are safeguarded by Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework.
- Circle Technologies, Inc. is US-based. We rely on Standard Contractual Clauses under Article 46(2)(c) GDPR and have completed a transfer impact assessment.
- Zoom is US-headquartered. We’ve activated EU data residency settings, which keep meeting audio and video on EU servers, though account and session metadata is typically still processed in the US, safeguarded by Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework.
- Google Ireland Ltd processes analytics data within the EEA; Google LLC in the US may act as a limited sub-processor, safeguarded by Standard Contractual Clauses and Google’s EU Data Processing Terms.
- Klaviyo, Inc., our email marketing platform, is US-based. This transfer is safeguarded by the EU-U.S. Data Privacy Framework, with Standard Contractual Clauses available as a fallback.
The EU-U.S. Data Privacy Framework is currently valid but subject to an ongoing legal challenge before the Court of Justice of the European Union, with a ruling not expected before late 2026. We don’t rely on the Framework alone — Standard Contractual Clauses are maintained as a fallback safeguard by our processors, and we’ll update this policy if the Framework’s status changes.
7. How long we keep your data
We keep personal data only for as long as it’s needed for the purposes described in this policy, unless a longer period is required for legal, dispute or compliance reasons.
- Unsuccessful applications: deleted 12 months after the decision.
- Enrolled student application data: duration of enrolment + 3 years from program completion.
- Transaction metadata: 10 years from the transaction date (Portuguese tax and accounting law).
- Payment status records: duration of enrollment + 30 days.
- Learning-platform account data: duration of enrolment + 12 months, then deleted or anonymised.
- Progress and assessment data: 3 years from program completion.
- Session metadata: 12 months from the session date.
- Session recordings (made with consent): deleted within 30 days of the session, or sooner if consent is withdrawn.
- Community data — enrolled students: duration of enrollment + 12 months. Alumni with continued access: until consent is withdrawn or deletion is requested.
- Marketing data: until you unsubscribe or withdraw consent, plus 30 days for suppression-list maintenance.
- Analytics data: 14 months from collection. Cookie consent records: 3 years.
- Faculty and contractor records: duration of engagement + 10 years (Portuguese tax and accounting law).
8. Security of your personal data
We apply technical and organisational measures designed to protect your personal data:
- Access control: role-based access and least-privilege principles across the Circle platform and administrative systems, multi-factor authentication required for admin accounts, and access rights reviewed whenever staff change.
- Encryption and transport security: TLS 1.2 or higher enforced across our platform endpoints; data at rest is encrypted by our platform providers under their published security standards; no plaintext credentials are stored.
- Payment security: we don’t process or store card data ourselves — Stripe and Klarna handle it exclusively within their PCI DSS compliance frameworks, and we retain only transaction metadata.
- People: everyone with access to Mirari data follows our internal privacy procedures.
If a personal data breach occurs and it’s likely to pose a risk to your rights and freedoms, we’ll notify the CNPD without undue delay (and within 72 hours where feasible), and where the risk to you is high, we’ll let you know directly.
9. Eligibility and children’s privacy
You must be at least 18 years old to use the Mirari website, apply to the Foundation Program, or join the practitioner community. Mirari’s services aren’t directed at, or intended for, anyone under 18, and we don’t knowingly collect personal data from minors.
10. Complaints and how to reach us
If you have questions, concerns, or want to exercise any of the rights described above, contact us at:
Pink Elephant, Unipessoal Lda Edifício Amoreiras Square, Rua Carlos Alberto da Mota Pinto, n.º 17, 2nd floor, 1070-313 Lisboa, Portugal Email: [email protected]
You also have the right to lodge a complaint with the Portuguese supervisory authority, the Comissão Nacional de Proteção de Dados.
11. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we’ll post the updated policy here with a new effective date, and will provide notice in an appropriate manner before introducing materially different processing, new categories of personal data, new special-category processing, non-EEA transfers, new processors, or new public disclosure models.