All MicHelper legal documents

Privacy Policy

Last updated: June 2026

Planned legal operator: ТОВ "МікХелпер" (TOV "MikHelper"), Lviv, Ukraine.

Registration: being completed — official registration details will be published immediately after registration.

Privacy contact: privacy@michelper.com

Current market: MicHelper is preparing for launch in Ukraine.

Summary

MicHelper is a B2B service for analysing retail service conversations on documented instructions from the customer acting as controller. The audio retention rule is stated in Section 3 and comes from the product facts used by the processing pipeline. This policy explains the relevant processing and data-subject rights without making a compliance guarantee.

On This Page

  • 1. Who We Are
  • 2. Data We Collect
  • 3. Audio & Transcripts
  • 4. Legal Bases for Processing
  • 5. How We Use Your Data
  • 6. Data Sharing & Subprocessors
  • 7. International Data Transfers
  • 8. Data Retention
  • 9. Security Measures
  • 10. Cookies
  • 11. Your Rights
  • 12. Children's Privacy
  • 13. Contact & Complaints
  • 14. Changes to This Policy

1. Who We Are

ТОВ "МікХелпер" (MicHelper LLC), based in Lviv, Ukraine, provides AI-powered sales quality control software for retail networks. Our platform enables businesses to record, transcribe, and analyze sales consultations to improve service quality and sales performance.

MicHelper as Processor (розпорядник)

For conversation data, the business customer — the retail network — is the data controller (володілець персональних даних). It decides whether recording is used, in which locations, whose conversations are recorded, for what purpose, and which authorised users receive access.

  • Controller (володілець): the customer retail network for recordings, transcripts and employee-performance data.
  • Processor (розпорядник): MicHelper processes that data only on the controller's documented instructions and within the written Data Processing Agreement.
  • MicHelper as controller: only for MicHelper's own account administration, billing, website, support and security-log data, where MicHelper determines the relevant purposes and means.

If your conversation was recorded, the relevant retail network is the primary contact for exercising your rights. MicHelper accepts requests at privacy@michelper.com, forwards a verified conversation-data request to the controller within 5 days, tells the requester where it was forwarded, and assists the controller with fulfilment.

2. Data We Collect

2.1 Account Information

When you create an account or your employer creates one for you, we collect:

  • Name, email address, phone number (optional)
  • Company/organization name and role
  • Login credentials (passwords are hashed, never stored in plain text)
  • Language and timezone preferences

2.2 Usage Data

We automatically collect information about how you interact with our service:

  • Login timestamps and session duration
  • Features accessed and actions performed
  • Browser type, operating system, and device information
  • IP address and approximate location (country/region level)

2.3 Device & Technical Data

For our recording devices (microphones) and web application:

  • Device identifiers and status
  • Connection quality metrics
  • Error logs and diagnostic information

2.4 Audio & Transcript Data

This is the core data we process for our service. See Section 3 for detailed information.

2.5 Data from Third-Party Authentication

If you choose to sign in using Google OAuth, we receive and store:

  • Your Google account email address
  • Your display name
  • Your Google account identifier

We do not access your Google contacts, calendar, or any other Google services data. You can disconnect Google authentication at any time through your account settings.

2.6 Push Notifications

If you enable push notifications, we collect and store a device token used solely to deliver notifications to your device. You can disable push notifications at any time through your device settings or the application. Device tokens are deleted when you unsubscribe from notifications or delete your account.

2.7 Telegram Bot Data

If you interact with our Telegram bot, we collect and store:

  • Your Telegram chat ID and username
  • Message history with the bot
  • Your notification preferences

This data is used to provide bot functionality, deliver notifications, and process your requests. You can stop interacting with the bot at any time by blocking it in Telegram, which will cease all data collection. Existing data will be deleted according to our standard retention policies or upon request.

3. Audio Recordings & Transcripts

3.1 What We Record

Our service records audio from designated microphones in retail locations. These recordings capture sales consultations between employees and customers. The recording devices are placed in accordance with local laws and with appropriate signage.

3.2 Audio Processing

Audio is retained only until automatic transcription completes and is permanently deleted after successful transcription. This normally takes no more than 5 minutes. If transcription fails, a technical copy may be retained for up to 6 hours for an automatic retry and is then deleted.

3.3 Transcription Process

Audio is transcribed using approved AI speech-recognition technology under MicHelper's privacy and retention controls. Specific model routing, providers and fallbacks are confidential technical information. Customer data is not used for AI model training. Transcripts may include:

  • Text content of the conversation
  • Speaker identification (employee vs. customer)
  • Timestamps and segment boundaries
  • Language detection results

3.4 Transcripts

Text transcripts generated from audio recordings persist during your subscription. Transcripts are a core service feature used for analytics, coaching, and reporting. Transcripts are encrypted at rest with AES-256-GCM field-level encryption.

3.5 Quality Analysis

Transcripts are analyzed against sales scripts and rules configured by the network administrator to generate:

  • Script compliance scores
  • Performance metrics and rankings
  • Violation flags and recommendations

AI analysis is provided for informational purposes only. Accuracy is not guaranteed. AI-generated outputs do not constitute legal advice, official compliance certification, or evidence of employee misconduct. Significant employment decisions should involve qualified human review.

4. Grounds for Processing

We process personal data based on the following legal grounds:

4.1 Contract Performance

Processing necessary to fulfill our service agreement with business customers, including account management, service delivery, and support.

4.2 Legitimate Interests

Processing necessary for our legitimate business interests, such as:

  • Improving and developing our services
  • Preventing fraud and ensuring security
  • Analyzing usage patterns to optimize performance

4.3 Consent

Where required by law, we obtain consent for:

  • Marketing communications
  • Processing beyond what is strictly necessary for service delivery

4.4 Legal Obligations

Processing necessary to comply with applicable laws, such as tax reporting, fraud prevention, and responding to lawful requests from authorities.

5. How We Use Your Data

We use the data we collect for the following purposes:

5.1 Service Delivery

  • Processing and analyzing audio recordings
  • Generating transcripts and quality scores
  • Creating reports, rankings, and analytics
  • Enabling Excel/CSV exports

5.2 Account Management

  • User authentication and authorization
  • Role-based access control (RBAC)
  • Subscription and billing management

5.3 Communication

  • Service notifications and alerts
  • Support responses
  • Product updates (with consent)

5.4 Improvement & Development

  • Analyzing usage patterns to improve features
  • Debugging and troubleshooting

Customer data is NOT used for AI model training. Customer data is NOT shared with AI providers for training.

6. Data Sharing & Subprocessors

6.1 We Do Not Sell Your Data

We do not sell, rent, or trade personal data to third parties for their marketing purposes.

6.2 Subprocessors

We use the following third-party service providers (subprocessors) to operate the Service. Each subprocessor processes data only as necessary for its stated purpose.

Company Purpose Location Data Processed
Cloud infrastructure providerApplication hosting, compute, protected storage and encrypted backupsService hosting environmentApplication data and encrypted backups
Approved AI service providerTranscription and requested analysis under contractual privacy and retention controlsService processing environmentAudio during processing and the minimum text required for the request
Telegram Bot APIOptional customer notifications (Telegram messages)CloudChat IDs, notification content

We maintain this list and will notify customers of changes at least 30 days in advance. To subscribe to subprocessor change notifications, contact privacy@michelper.com. The current disclosed provider list is published on the Subprocessors page.

6.3 Legal Requirements

We may disclose data when required by law, court order, or to protect our rights, property, or safety.

6.4 Business Transfers

In the event of a merger, acquisition, or sale of assets, personal data may be transferred to the acquiring entity.

7. International Data Transfers

MicHelper uses a protected cloud environment for application services, persistent storage and encrypted backups. Approved AI services process requests under contractual privacy and retention controls; their specific routing is confidential technical information.

Information required for a specific customer agreement, including applicable safeguards and provider commitments, is available from legal@michelper.com.

Important: customer content is not used for AI model training, and approved AI services process only the information necessary to complete a request.

8. Data Retention

Audio Recordings

Audio is retained only until automatic transcription completes and is permanently deleted after successful transcription. This normally takes no more than 5 minutes. If transcription fails, a technical copy may be retained for up to 6 hours for an automatic retry and is then deleted.

Transcripts

Text transcripts persist during your subscription. Transcripts are a core service feature that enables analytics, coaching, and reporting. They are retained for the duration of your active subscription.

Analytics, Scores & Performance Data

QA scores, coaching notes, event timelines, and metadata persist during your subscription plus 30 days after termination, to allow for data export.

Account & Configuration Data

User accounts, network configurations, scripts, and system settings are retained for the subscription term plus 30 days following account termination to allow for data export.

Audit Logs

Security and access logs are retained for 90 days.

Summary

Data Type Retention
Raw audio recordingsDeleted after successful transcription; failed-transcription retry copy retained for no more than 6 hours
TranscriptsPersist during subscription
Analytics & QA scoresPersist during subscription + 30 days after termination
Account dataSubscription term + 30 days
Audit logs90 days

9. Security Measures

We implement technical and organizational measures to protect your data:

9.1 Technical Measures

  • Encryption in Transit: All data transmitted using TLS 1.2 or higher
  • Encryption at Rest: Encrypted data at rest
  • Access Controls: Role-based access control (RBAC) with principle of least privilege
  • Authentication: Secure password hashing (bcrypt), session management
  • Rate Limiting: Protection against abuse and brute-force attacks
  • CSRF Protection: Cross-site request forgery prevention

9.2 Organizational Measures

  • Audit Logging: All data access and modifications are logged (retained 90 days)
  • Incident Response: Documented procedures for security incidents
  • Regular Reviews: Periodic security assessments and updates

9.3 Incident Notification

In the event of a data breach affecting your personal data, we will notify you and relevant authorities as required by applicable law, within 72 hours of becoming aware of the breach.

10. Cookies

We use essential cookies only. We do not use tracking, analytics, or marketing cookies.

Cookie Name Purpose Type
csrf_tokenSecurity (CSRF protection)Essential
connect.sidSession authenticationEssential
michelper_consentConsent preference (canonical key; legacy key oct_consent is read for backward compatibility)Essential

11. Your Rights

Depending on your location and applicable law, you may have the following rights:

11.1 Rights under applicable law

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate or incomplete data
  • Erasure: Request deletion of your data ("right to be forgotten")
  • Restriction: Limit how we process your data
  • Portability: Receive your data in a structured, machine-readable format
  • Objection: Object to processing based on legitimate interests
  • Withdraw Consent: Withdraw previously given consent at any time

11.2 Exercising Your Rights

To exercise any of these rights:

  • Contact privacy@michelper.com; MicHelper will forward conversation-data requests to the relevant controller and assist with fulfilment
  • Use the Privacy Requests feature in your MicHelper account
  • If you are an employee, contact your employer (the Data Controller)

For conversation data, MicHelper will forward a verified request to the relevant controller within 5 days and notify the requester of the recipient. The controller remains responsible for the substantive response within the period required by applicable law.

12. Children's Privacy

MicHelper is a business-to-business service and is not intended for use by individuals under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected data from a child under 16, we will take steps to delete it promptly.

13. Contact & Complaints

13.1 Contact Us

The official contact channel for all MicHelper support, privacy, sales, billing, security, legal and data subject requests is:

  • Privacy: privacy@michelper.com
  • Support: support@michelper.com

13.2 Supervisory Authority

If you are in the EEA or UK and believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection supervisory authority.

For data subjects in Ukraine, complaints may also be addressed to the Ukrainian Parliament Commissioner for Human Rights (the authorised personal data protection authority in Ukraine) in accordance with applicable Ukrainian law.

14. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes:

  • We will update the "Last updated" date at the top of this page
  • For significant changes, we will provide notice through our service or via email
  • Continued use of our service after changes become effective constitutes acceptance

We encourage you to review this policy periodically.

Last updated: June 2026

Planned legal operator: ТОВ "МікХелпер" (TOV "MikHelper"), Lviv, Ukraine.

Questions about this policy? privacy@michelper.com

© 2026 MicHelper. All rights reserved.