Published: August 28, 2025 · Last updated: September 15, 2026
Privacy Policy
At Cognera OÜ (“Cognera”, “Mingleego”, “we”, “our”, or “us”), we operate and provide the Mingleego platform ( https://mingleego.com). This Privacy Policy explains how we collect, use, store, protect, and share your personal data when you access or use our website (https://mingleego.com) and API (collectively, “Services”).
By using our Services, you agree to the practices described in this Privacy Policy. This Policy does not apply to data we process on behalf of our business customers through our API, which is governed by separate customer agreements.
We may update this Privacy Policy to reflect changes in our Services or legal requirements. We will notify you of material changes via email or a notice on our website at least 30 days before they take effect. Your continued use of the Services after such changes constitutes your acceptance of the updated Policy.
1. Data Controller
Cognera OÜ, with its registered office at Harju maakond, Kesklinna linnaosa, Vesivärava tn 50-201, 10152, Tallinn, (17301496) Estonia, is the data controller responsible for the processing of your personal data as described in this Privacy Policy. As an entity established in the European Union, we are fully committed to complying with the General Data Protection Regulation (GDPR) and Estonian data protection laws to ensure the highest standards of privacy and security for your personal data.
We oversee the technical setup, administration, and operation of our website and API, collectively referred to as the Services. We have not appointed a Data Protection Officer (DPO), as this is not required for our operations under GDPR. However, our dedicated team is available to address any inquiries regarding your personal data or to assist you in exercising your privacy rights.
For any questions about this Privacy Policy, the personal data we hold about you, or to exercise your rights under GDPR (such as access, rectification, erasure, or data portability), please contact us at:
Cognera OU
Harju maakond, Kesklinna linnaosa, Vesivärava tn 50-201, 10152,, Tallinn, Estonia
Email: info@cognera.cloud
If you have unresolved concerns, you have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or any other competent supervisory authority in the EU.
2. Personal Data We Collect
We collect personal data relating to you (“Personal Data”) when you interact with our Services, including our website (https://mingleego.com) and API. This data is collected as follows:
Personal Data You Provide
- Account Information: When you create an account, either manually or through social login (see Section 4, Social Login), we collect your name, email address, and account credentials. If you make payments, we collect payment information via Stripe, as described in Section 5 (Payment Service).
- User Content: We collect data you provide as input to our Services, such as prompts or queries sent to AI models provided by OpenAI, Inc., which we may enhance with our own functionality.
- Communication Information: If you contact us via email (Info@cognera.cloud) or other channels, we collect your name, contact details, and the content of your messages.
Personal Data from Other Sources
We may receive personal data from third parties, such as Google and Facebook, when you use social login (see Section 4, Social Login), or from Stripe for payment processing (see Section 5, Payment Service). Additionally, we may receive data from security partners to protect against fraud, abuse, or other threats to our Services. We do not use your personal data for training AI models; however, prompts you provide may be processed by OpenAI, Inc., as described in their privacy policy at https://openai.com/privacy.
Google Gmail and Calendar Integration
If you connect your Google Account, our Services may access Gmail and Google Calendar data through Google API Services to enable AI-powered automation features. This integration is used to create, read, update, and delete emails and calendar events on your behalf, in accordance with the permissions (OAuth scopes) you explicitly grant during connection.
We process the following data, depending on your granted permissions:
- Calendar Events: Event titles, participants, dates, descriptions, and related metadata to automate scheduling and synchronization.
- Gmail Data: Message metadata (sender, subject, timestamps), message content, and attachments if required for the requested automation (e.g., AI-based replies or email classification).
- User Profile Information: Google profile details (name, email address) to personalize your experience and link your account.
All operations are performed programmatically by our AI system under your explicit consent, without manual review or intervention from Mingleego or Cognera OÜ staff.
We do not use Google data for advertising, profiling, or AI model training, and we adhere to the Google API Services User Data Policy, including Limited Use requirements.
We only access data necessary for the integration to function and do not use it for marketing or AI training purposes. You can revoke our access at any time via your Google Account settings at https://myaccount.google.com/permissions. Upon revocation, we will be permanently deleted from our systems within 7 days. We adhere to Google API Services User Data Policy, including its Limited Use requirements, as described in their privacy policy at https://www.google.com/policies/privacy/partners/.
Microsoft Outlook and Calendar Integration
Our Services also integrate with Microsoft Graph API to provide AI-powered automation features for Outlook Mail and Calendar. When you connect your Microsoft account, you explicitly authorize our application to access your mailbox and calendar data through the OAuth 2.0 consent process.
Depending on your granted permissions (OAuth scopes), our Services may perform the following operations on your behalf:
- Mail Access: Read, create, send, update, and delete email messages.
- Calendar Access: View, create, modify, and delete calendar events.
- Profile Information: Access your basic Microsoft account data (name, email address, organization) to personalize your experience.
All operations are executed programmatically by our AI system under your explicit consent. We do not use your Microsoft data for advertising, profiling, or AI model training. We adhere to the Microsoft Privacy Principles and Microsoft Graph API policies, using your data solely to provide the requested automation features.
You may revoke access at any time via your Microsoft Account or Azure App permissions settings: https://account.live.com/consent/Manage. Upon revocation, all Outlook and Calendar data retrieved via the integration will be permanently deleted within 7 days from our systems.
Automated AI Actions Disclaimer (Microsoft Services)
By connecting your Microsoft Account and granting the requested permissions, you acknowledge and consent that Mingleego’s AI may autonomously perform operations — including creating, reading, updating, or deleting emails and calendar events — within the Outlook and Calendar environments, strictly according to the OAuth scopes you authorized.
These operations are performed automatically by the AI without manual review or intervention from Cognera OÜ or Mingleego staff.
While we apply safeguards to prevent misuse or data loss, Cognera OÜ is not liable for unintended or incorrect actions performed by AI integrations, including but not limited to email deletions, mis-sent messages, or scheduling errors.
You are responsible for reviewing and managing your granted permissions and can revoke access at any time through your Microsoft account settings.
Messaging Channels
Our Services let you place an AI assistant on third-party messaging platforms: Telegram, WhatsApp, Instagram, Facebook Messenger, Discord and Slack. When you connect a channel, messages exchanged between your end users and that assistant pass through the platform's own infrastructure before we process them to generate a reply. We process the message content, the platform-specific user identifier and the timestamp, as described in Section 7 (How We Use Personal Data). Each platform is an independent controller of the data it holds and applies its own privacy policy, which we do not control.
Business Integrations
Where you connect them, your assistant may read from or write to third-party business systems on your instruction — including HubSpot and Shopify, alongside the Google and Microsoft services described above. We transmit only what the action you configured requires, such as creating a contact or looking up an order. Data sent to those systems is held under your own agreement with that provider.
Website Analytics
We use Ahrefs Web Analytics on our public marketing pages to measure traffic. It is a cookieless service: it sets no cookies and builds no cross-site profile, which is why no cookie consent banner is shown for it. It processes technical request data such as IP address, user agent, page URL and referrer. It is deliberately not loaded for signed-in users or on the authenticated pages of the dashboard. Their privacy policy is at https://ahrefs.com/privacy.
3. Legal Bases for Processing as required under Article 13.1(c) and Article 6 of the GDPR.
We process your personal data in accordance with the General Data Protection Regulation (GDPR). The table below outlines the purposes for which we process your personal data, the types of data involved, and the legal bases for such processing, as required under Article 13.1(c) GDPR.
| Purpose of Processing | Type of Personal Data Processed | Legal Basis |
|---|---|---|
| To provide, operate, and maintain our Services, including account management, AI-powered responses, Web Chat Widget, Google Calendar integration, and Microsoft Outlook integration | Account Information (name, email, credentials) User Content (prompts, queries) Web Chat Data (chat history, messages, prompts) Google Calendar Data (event data, profile information) Communication Information (name, contact details, message content) Microsoft Outlook Data (emails, calendar events, profile information) | Necessary to perform a contract with you under Article 6(1)(b) GDPR and based on your explicit consent under Article 6(1)(a) GDPR for Google and Microsoft API integrations granted via OAuth authorization. |
| To process payments for our Services | Payment Information (name, email, billing address, payment details, transaction information) | Necessary to perform a contract with you under Article 6(1)(b) GDPR, such as processing payments through Stripe to fulfill your subscription or purchase. |
| To communicate with you, including responding to inquiries and sending updates about our Services | Account Information (name, email) Communication Information (name, contact details, message content) | Necessary for our legitimate interests under Article 6(1)(f) GDPR to provide customer support and service updates, or based on your consent under Article 6(1)(a) GDPR for marketing communications, where applicable. |
| To improve and develop our Services, including analyzing usage patterns and developing new features | Aggregated or anonymized data (usage patterns, analytics data) Data from Other Sources (security partners, Google/Facebook for Social Login) Log Data, Usage Data, Device Information | Necessary for our legitimate interests under Article 6(1)(f) GDPR to enhance and optimize our Services. We do not use personal data to train AI models; however, prompts are processed by OpenAI, Inc., as described in their privacy policy at https://openai.com/privacy. |
| To ensure security and prevent fraud, abuse, or misuse of our Services | Account Information (name, email, credentials) Web Chat Data (chat history, messages) Data from Other Sources (security partners) Log Data, Usage Data, Device Information (IP address, browser type, timestamps) | Necessary for our legitimate interests under Article 6(1)(f) GDPR to protect our Services and users from fraud, abuse, or security threats, such as monitoring login activity or detecting suspicious behavior. |
| To comply with legal obligations and protect the rights, privacy, safety, or property of our users, Mingleego, or third parties. This includes compliance with anti-fraud, financial record-keeping, and data retention obligations under EU and Estonian law. | Account Information (name, email, credentials) User Content (prompts, queries) Communication Information (name, contact details, message content) Payment Information (transaction data) Web Chat Data (chat history, messages) Google Calendar Data (event data, profile information) Data from Other Sources (Google, Facebook, Stripe, security partners) | Necessary to comply with a legal obligation under Article 6(1)(c) GDPR, such as retaining transaction data for tax or accounting purposes, or for our legitimate interests under Article 6(1)(f) GDPR to protect our rights, users, or third parties. |
For more details on the personal data we collect, see Section 2 (Personal Data We Collect). To exercise your data protection rights, see Section 8 (Your Rights) or contact us at Info@cognera.cloud, as described in Section 13 (How to Contact Us).
4. Social Login
You may use Google or Facebook social login services to sign in to our Services instead of creating an account manually. Using social login creates an account that functions identically to one registered directly on our platform, providing the same access, permissions, and user experience.
The Google and Facebook login options are available on our registration or login page at https://mingleego.com. When you select either option, you will be redirected to the respective provider’s website to enter your login credentials.
Upon successful login, Google or Facebook will share limited profile information with us, specifically your name and email address, to identify you and create or access your account in our system. We do not receive your Google or Facebook password. Any additional information you choose to provide will be associated with your Mingleego account.
We use these social login services based on our legitimate interest under Article 6(1)(f) of the General Data Protection Regulation (GDPR) to enhance the convenience of accessing our Services.
To exercise your data protection rights with respect to data processed by Google, visit https://myaccount.google.com/permissions or review their privacy policy at https://www.google.com/policies/privacy/partners/. For Facebook, visit https://www.facebook.com/settings?tab=applications or review their privacy policy at https://www.facebook.com/privacy/policy/.
5. Payment Service
We partner with third-party payment providers to process transactions when you purchase services from Mingleego. This processing is necessary to fulfill our contractual obligations with you, as outlined in Article 6(1)(b) of the General Data Protection Regulation (GDPR). We use Stripe, Inc. (354 Oyster Point Blvd, Suite 201, South San Francisco, CA 94080, United States) to handle payment processing for our Services.
When you make a payment through Stripe, the following personal data may be collected and processed: your name, email address, billing address, payment details (such as credit card number, expiration date, and CVV code), and transaction information by Stripe. This data is used to process your payment, verify your identity, prevent fraud, and comply with applicable legal obligations, including those under GDPR.
We do not store full payment details (such as credit card number, expiration date, and CVV code) and share your payment data with third parties except as required to process your transaction through Stripe. Stripe may share your data with its affiliates or service providers as described in it's privacy policy, available at https://stripe.com/gb/privacy. Stripe employs industry-standard security measures to protect your personal data during transactions, and we implement appropriate safeguards to secure your data within our systems.
You have the right to access, correct, or delete your personal data processed by Stripe. To exercise these rights, please contact Stripe directly. For any questions about our payment processing practices, refer to Section 13 (How to Contact Us).
6. Web Chat Widget
Our Services allow you to create and customize a web chat widget powered by an AI assistant, which you can integrate into your own website to interact with your users. This widget is provided and operated by Cognera OÜ to enhance communication and user engagement.
When you or your website users interact with the web chat widget, we process the following personal data:
- Customer Data: For customers who create and manage the web chat widget, we collect your user ID and email address, as described in Section 2 (Personal Data We Collect) and Section 4 (Social Login).
- Chat User Data: For end users interacting with the widget on your website, we may collect chat history, including messages and prompts sent to the AI assistant.
The processing of this data is necessary to provide the web chat functionality and is based on our legitimate interest under Article 6(1)(f) of the GDPR to support efficient communication and service delivery, or on contractual obligations under Article 6(1)(b) GDPR for customers using our Services.
We do not share chat user data with third parties without your explicit consent, except as required to operate the AI assistant, which relies on OpenAI, Inc. models, as described in their privacy policy at https://openai.com/privacy.
You can manage or delete your data related to the web chat widget through your Mingleego account settings or by contacting us at Info@cognera.cloud, as described in Section 13 (How to Contact Us). End users of the widget should contact the website owner (our customer) to exercise their data protection rights.
7. How We Use Personal Data
We use your personal data for the following purposes, in compliance with the General Data Protection Regulation (GDPR):
- To Provide and Maintain Our Services: We use your personal data, such as account information and user content, to deliver and operate our Services, including processing your prompts through AI models provided by OpenAI, Inc., managing your account, and enabling features like the Web Chat Widget (see Section 13) and Google Calendar integration (see Section 2).
- To Process Payments: We use payment information collected via Stripe to process transactions for our Services, as described in Section 5 (Payment Service).
- To Communicate with You: We use your contact details to respond to your inquiries, provide customer support, and send you updates about our Services, such as changes to features or policies, based on our legitimate interest under Article 6(1)(f) GDPR or your consent under Article 6(1)(a) GDPR.
- To Improve and Develop Our Services: We use aggregated or anonymized data, such as usage patterns, to analyze how our Services are used, enhance functionality, and develop new features. We do not use your personal data to train AI models; however, prompts you provide may be processed by OpenAI, Inc., as described in their privacy policy at https://openai.com/privacy.
- To Comply with Legal Obligations: We use your personal data to comply with applicable laws, such as tax, accounting, or data protection regulations, as required under Article 6(1)(c) GDPR, and to protect the rights, privacy, safety, or property of our users, Mingleego, or third parties.
We may aggregate or anonymize personal data so that it no longer identifies you. Such data may be used for analytics, research, or to improve our Services, and we will not attempt to re-identify it unless required by law. For details on how we collect these data, see Section 2 (Personal Data We Collect).
8. Your Rights
Under the General Data Protection Regulation (GDPR), you have the following rights regarding your personal data:
- Access (Article 15 GDPR): You can request access to your personal data and information about how we process it.
- Rectification (Article 16 GDPR): You can request correction or updating of inaccurate or incomplete personal data.
- Erasure (Article 17 GDPR): You can request deletion of your personal data from our systems, also known as the "right to be forgotten."
- Restriction of Processing (Article 18 GDPR): You can request that we restrict the processing of your personal data in certain circumstances.
- Data Portability (Article 20 GDPR): You can request a copy of your personal data in a structured, commonly used, and machine-readable format to transfer to another provider.
- Object (Article 21 GDPR): You can object to the processing of your personal data for direct marketing or when processing is based on our legitimate interests.
- Withdraw Consent (Article 7(3) GDPR): Where we rely on your consent for processing, you can withdraw it at any time, without affecting the lawfulness of processing before withdrawal.
- Lodge a Complaint: You can lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or another competent supervisory authority in the European Union if you have concerns about our data practices.
You can exercise some of these rights, such as updating or deleting your account information, directly through your Mingleego account settings. For other requests, please contact us at Info@cognera.cloud, as described in Section 13 (How to Contact Us). We will respond to your request within 30 days, as required by GDPR.
A Note About AI Accuracy: Our Services utilize AI models provided by OpenAI, Inc. (1850 Greenwich St, San Francisco, CA 94123, United States) to generate responses based on your input. We may enhance these models with our own functionality, which could influence the output. These AI-generated responses may not always be factually accurate due to the predictive nature of the models. If you believe our Services have generated inaccurate personal data about you, you can request correction or deletion by contacting us at Info@cognera.cloud. For issues directly related to OpenAI’s models, you may also contact OpenAI at privacy.openai.com or dsar@openai.com, as described in their privacy policy at https://openai.com/privacy. We will review your request in accordance with GDPR and our technical capabilities.
9. Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, as outlined in this Privacy Policy, or to comply with our legal obligations under the General Data Protection Regulation (GDPR). The retention period depends on several factors, including:
- The purpose of processing, such as providing our Services or ensuring their security;
- The nature, amount, and sensitivity of the personal data;
- The potential risk of harm from unauthorized use or disclosure;
- Applicable legal requirements, such as tax or corporate record-keeping obligations.
Specific retention periods include:
- Account Information: We retain data associated with your account, such as your name, email, and password, for as long as your account remains active and up to 6 months after account deletion, unless longer retention is required to comply with European Union legal obligations, such as tax, accounting, or dispute resolution requirements.
- Marketing Data: Data used for marketing purposes, such as email preferences, is retained until you withdraw your consent.
- Analytics Data: Aggregated or anonymized data used for improving our Services may be retained for up to 3 years.
When personal data is no longer needed, we will securely delete it or anonymize it so that it can no longer be associated with you. For inquiries about your data or to exercise your rights, please refer to Section 13 (How to Contact Us).
10. Security
We implement appropriate technical, organizational, and administrative measures to protect your personal data against unauthorized access, loss, misuse, disclosure, alteration, or destruction, in compliance with the General Data Protection Regulation (GDPR). These measures include:
- Using TLS (Transport Layer Security) encryption to secure data transmission between your device and our website and API;
- Restricting access to personal data to authorized personnel only, with strict access controls;
- Regularly monitoring and updating our systems to address potential security vulnerabilities;
- Partnering with trusted third-party providers, such as Stripe, which employ industry-standard security measures for payment processing, as described in Section 5 (Payment Service).
Despite these measures, no internet or electronic transmission is entirely secure. We cannot guarantee absolute security of data transmitted over the internet or stored in our systems. You are responsible for taking appropriate precautions when sharing personal data through our Services. We are not liable for any circumvention of privacy settings or security measures on our Services or third-party platforms, such as those used for Google or Facebook authentication.
For questions about our security practices or to report a concern, please refer to Section 13 (How to Contact Us).
11. Children
Our Services are not directed to or intended for children under 13 years of age. We do not knowingly collect personal data from children under 13. If you have reason to believe that a child under 13 has provided personal data to Mingleego through our Services, please contact us at Info@cognera.cloud, and we will promptly investigate and, if appropriate, delete such data from our systems.
Users aged 13 to 15 must have permission from a parent or legal guardian to use our Services. We comply with the General Data Protection Regulation (GDPR) and other applicable data protection laws in the EU to ensure the protection of children’s personal data.
12. Changes to the Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our Services, legal requirements, or other operational needs, in compliance with the General Data Protection Regulation (GDPR). When we make material changes, we will notify you at least 30 days in advance by posting an updated version of this Policy with a new effective date on our website (https://mingleego.com) or by sending you an email, unless another type of notice is required by applicable law.
Your continued use of our Services after the updated Policy takes effect constitutes your acceptance of the changes. If you have opted out of receiving legal notice emails, you are still responsible for reviewing the updated Policy on our website. We maintain electronically stored copies of this Privacy Policy, which serve as the true, complete, and enforceable version in effect on the date you visit our website.
13. How to Contact Us
If you have any questions, concerns, or complaints about this Privacy Policy, our data practices, or wish to exercise your rights under GDPR (such as access, rectification, erasure, or data portability), please reach out to us using the contact details provided in Section 1 (Data Controller).
You may contact us by email at:
Email: Info@cognera.cloud
Alternatively, you can write to us at:
Cognera OÜ
Harju maakond, Kesklinna linnaosa, Vesivärava tn 50-201, 10152, Tallinn, Estonia
We aim to respond to all inquiries within 30 days, as required by GDPR. If you are not satisfied with our response, you have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or another competent supervisory authority in the European Union.