Mirabella Transatlantic (“Mirabella”, "we," "us," or "our") is committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, store, and share your personal information when you use our website (www.mirabellatransatlantic.com), purchase our products, or engage our services.
Mirabella is operated by Harlow & Co. AB, established in Sweden, and is therefore subject to Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR") and applicable Swedish data protection law.
Please read this policy carefully. If you do not agree with its terms, please discontinue use of our website and services. Questions or requests can be directed to contact@mirabellatransatlantic.com.
The data controller responsible for your personal data is:
Frances Harlow / Harlow & Co. AB, Bohusgatan 31, 116 67 Stockholm, Sweden
Email: contact@mirabellatransatlantic.com
For all data protection inquiries, please contact us at the email address above.
We may collect and process the following categories of personal data:
— Contact Details: full name, email address, phone number, postal address
— Identity and Nationality Information: data relevant to immigration and residency planning: passport details, date of birth, country of birth, and current visa or residency status
— Immigration and Travel History: prior visa applications, refusals, immigration status, time spent in Schengen, entry and exit records
— Ancestry and Ethnic Origin: where relevant to assessing citizenship by descent or other nationality-based residency pathways, and only with your explicit consent
— Financial Planning Information: household income, sources of income, assets, expenditures, pension and investment details, budget for relocation planning purposes
— Household and Family Information: marital status, dependants, family structure relevant to your move
— Employment Information: employer details, employment status, remote work arrangements
— Questionnaire Responses: answers submitted through our intake forms and personalized assessment tools
— Communications: emails, meeting notes (including AI-generated notes), follow-up correspondence
— Technical Data: IP address, browser type, device information
— Usage Data: pages visited, time on site, referral source; collected via cookies and analytics tools (see Section 9)
Below is a summary of each category of personal data we collect, why we collect it, the legal basis under which we process it, and how long we retain it.
Data Category: Identity and contact details
Purpose: Delivering services, invoicing, communication
GDPR Legal Basis: Contract performance (Art. 6(1)(b))
Retention Period: 3 years following conclusion of engagement, purchase, or last contact
Data Category: Immigration and travel history
Purpose: Residency pathway analysis and planning
GDPR Legal Basis: Contract performance (Art. 6(1)(b))
Retention Period: 3 years following conclusion of engagement, purchase, or last contact
Data Category: Ancestry and ethnic origin
Purpose: Citizenship by descent pathway assessment
GDPR Legal Basis: Explicit consent (Art. 9(2)(a))
Retention Period: 3 years following conclusion of engagement, purchase, or last contact
Data Category: Financial planning information
Purpose: Cross-border financial preparation
GDPR Legal Basis: Contract performance (Art. 6(1)(b))
Retention Period: 3 years following conclusion of engagement, purchase, or last contact
Data Category: Household and family information
Purpose: Pathway analysis, timeline planning
GDPR Legal Basis: Contract performance (Art. 6(1)(b))
Retention Period: 3 years following conclusion of engagement, purchase, or last contact
Data Category: Employment information
Purpose: Visa eligibility assessment, pathway planning
GDPR Legal Basis: Contract performance (Art. 6(1)(b))
Retention Period: 3 years following conclusion of engagement, purchase, or last contact
Data Category: Questionnaire responses
Purpose: Preparing personalized assessments and deliverables
GDPR Legal Basis: Contract performance (Art. 6(1)(b))
Retention Period: 3 years following conclusion of engagement, purchase, or last contact
Data Category: AI-generated meeting notes
Purpose: Internal recordkeeping, follow-up, service delivery
GDPR Legal Basis: Consent (Art. 6(1)(a))
Retention Period: 3 years following conclusion of engagement, purchase, or last contact
Data Category: Communications and correspondence
Purpose: Service delivery, follow-up, engagement management
GDPR Legal Basis: Legitimate interests (Art. 6(1)(f))
Retention Period: 3 years following conclusion of engagement, purchase, or last contact
Data Category: Financial and invoicing records
Purpose: Accounting and tax compliance
GDPR Legal Basis: Legal compliance (Art. 6(1)(c))
Retention Period: 7 years following conclusion of engagement (Swedish Accounting Act)
Data Category: Website analytics and technical data
Purpose: Website performance and improvement
GDPR Legal Basis: Consent (Art. 6(1)(a))
Retention Period: Per analytics provider's standard retention settings
Identity and contact details
Delivering services, invoicing, communication
Contract performance (Art. 6(1)(b))
3 years following conclusion of engagement, purchase, or last contact
Immigration and travel history
Residency pathway analysis and planning
Contract performance (Art. 6(1)(b))
3 years following conclusion of engagement, purchase, or last contact
Ancestry and ethnic origin
Citizenship by descent pathway assessment
Explicit consent (Art. 9(2)(a))
3 years following conclusion of engagement, purchase, or last contact
Financial planning information
Cross-border financial preparation
Contract performance (Art. 6(1)(b))
3 years following conclusion of engagement, purchase, or last contact
Household and family information
Pathway analysis, timeline planning
Contract performance (Art. 6(1)(b))
3 years following conclusion of engagement, purchase, or last contact
Employment information
Visa eligibility assessment, pathway planning
Contract performance (Art. 6(1)(b))
3 years following conclusion of engagement, purchase, or last contact
Questionnaire responses
Preparing personalized assessments and deliverables
Contract performance (Art. 6(1)(b))
3 years following conclusion of engagement, purchase, or last contact
AI-generated meeting notes
Internal recordkeeping, follow-up, service delivery
Consent (Art. 6(1)(a))
3 years following conclusion of engagement, purchase, or last contact
Communications and correspondence
Service delivery, follow-up, engagement management
Legitimate interests (Art. 6(1)(f))
3 years following conclusion of engagement, purchase, or last contact
Financial and invoicing records
Accounting and tax compliance
Legal compliance (Art. 6(1)(c))
7 years following conclusion of engagement (Swedish Accounting Act)
Website analytics and technical data
Website performance and improvement
Consent (Art. 6(1)(a))
Per analytics provider's standard retention settings
The three-year retention period reflects the standard limitation period for consumer claims under Swedish law (Preskriptionslagen), within which a client could reasonably bring a claim related to our services.
We process your personal data on the following legal bases under GDPR Article 6:
— Contract Performance (Art. 6(1)(b)): processing necessary to deliver the services or products you have purchased.
— Legitimate Interests (Art. 6(1)(f)): processing necessary for our legitimate business interests, including maintaining records, improving our services, evaluating potential professional referrals, and communicating with you about your engagement, where these interests are not overridden by your rights.
— Legal Compliance (Art. 6(1)(c)): processing required to comply with applicable law.
— Consent (Art. 6(1)(a)): where explicitly obtained, including for AI-assisted note-taking during meetings, processing of ancestry and ethnic origin data, marketing communications, and non-essential cookies.
We use your personal data to:
— Provide advisory services, including written deliverables such as the Residency Brief, Pre-Departure Guide, and Post-Arrival Guide, document coordination, and third-party liaising
— Generate personalized assessments by matching your inputs against our database of human-authored content
— Schedule and conduct meetings, including generating internal notes and summaries using AI-assisted tools
— Evaluate and make referrals to vetted third-party professionals where relevant to your engagement
— Issue invoices, process payments, and manage your account
— Respond to your inquiries and provide follow-up support
— Comply with our legal and regulatory obligations
— Improve our services and maintain internal business records
We may use AI note-taking software during meetings to generate internal notes, summaries, and action items. These are used for recordkeeping, follow-up, and service delivery only. By participating in a meeting, you consent to this use. You may opt out at any time by notifying us in writing before a meeting begins.
We use AI tools to support research, drafting, and analysis in preparing written deliverables. All AI-assisted work is reviewed and verified by a human advisor before delivery.
AI tools are operated by independent third-party providers. We take reasonable steps to ensure they meet appropriate standards for confidentiality and data protection, but we cannot fully control their internal data practices. Where these tools process personal data on our behalf, we ensure appropriate data processing agreements are in place.
We do not sell your personal data. We may share it in the following limited circumstances:
— Professional Referrals: Where you have engaged us to make referrals or where a referral is relevant to your situation, we may share relevant information with vetted legal, tax, financial, or relocation professionals. We share only what is reasonably necessary and do so in accordance with our confidentiality obligations.
— Sub-contractors: We may engage sub-contractors to support service delivery. Sub-contractors are bound by confidentiality obligations consistent with our own and are not permitted to use your data for any other purpose.
— Service Providers and Processors: We use trusted third-party tools for scheduling, payment processing, cloud storage, AI note-taking, and similar functions. Where these providers process personal data on our behalf, we ensure appropriate data processing agreements are in place.
— Legal Compliance: We may disclose data where required by law, court order, or regulatory authority. We will notify you before doing so where permitted by law.
We may receive referral fees or commissions from some third-party providers we recommend or introduce you to. This is disclosed transparently and does not affect our obligations to you under this policy.
As a Sweden-based company operating within the EEA, we process your personal data in Sweden. Some of the third-party tools we use to deliver our services transfer personal data outside the EEA.
Below is a summary of each tool that involves international transfers, the purpose of that tool, the countries to which data is transferred, and the safeguard in place for each transfer.
Tool: Google Workspace
Purpose: Email, document storage, calendar
Data Transfer Destination: United States
Transfer Safeguard: EU–US Data Privacy Framework and Standard Contractual Clauses (SCCs)
Tool: Airtable
Purpose: Client records, project management
Data Transfer Destination: United States
Transfer Safeguard: Standard Contractual Clauses (SCCs)
Tool: Granola
Purpose: AI-assisted meeting note-taking
Data Transfer Destination: United States
Transfer Safeguard: EU–US Data Privacy Framework and Standard Contractual Clauses (SCCs)
Tool: Systeme.io
Purpose: Website, booking, email marketing
Data Transfer Destination: Ireland (EEA)
Transfer Safeguard: No transfer outside EEA
Tool: Tally
Purpose: Intake forms and questionnaires
Data Transfer Destination: Belgium (EEA)
Transfer Safeguard: No transfer outside EEA
Tool: DocuSeal
Purpose: Client e-signatures
Data Transfer Destination: Ireland (EEA)
Transfer Safeguard: No transfer outside the EEA
Tool: Make
Purpose: Data integration and automations
Data Transfer Destination: United States
Transfer Safeguard: EU–US Data Privacy Framework and Standard Contractual Clauses (SCCs)
Tool: Stripe
Purpose: Payment processing
Data Transfer Destination: United States
Transfer Safeguard: Standard Contractual Clauses (SCCs)
Google Workspace
Email, document storage, calendar
United States
EU–US Data Privacy Framework and Standard Contractual Clauses (SCCs)
Airtable
Client records, project management
United States
Standard Contractual Clauses (SCCs)
Granola
AI-assisted meeting note-taking
United States
EU–US Data Privacy Framework and Standard Contractual Clauses (SCCs)
Systeme.io
Website, booking, email marketing
Ireland (EEA)
No transfer outside EEA
Tally
Intake forms and questionnaires
Belgium (EEA)
No transfer outside EEA
DocuSeal
Client e-signatures
Ireland (EEA)
No transfer outside EEA
Make
Data integration and automations
United States
EU–US Data Privacy Framework and Standard Contractual Clauses (SCCs)
Stripe
Payment processing
United States
Standard Contractual Clauses (SCCs)
Where Standard Contractual Clauses are listed as the transfer safeguard, these are the EU Commission-approved contractual terms that require the data importer to provide an equivalent level of protection to that guaranteed within the EEA. Where an adequacy decision exists — such as for transfers covered by the EU-US Data Privacy Framework — the European Commission has determined that the destination country provides an equivalent level of protection.
We periodically review and update this table to reflect our current tools and practices. If you have questions about a specific transfer, please contact us at contact@mirabellatransatlantic.com.
Our website (www.mirabellatransatlantic.com) uses cookies and similar tracking technologies. We use the following categories:
— Strictly Necessary Cookies: required for the website to function and cannot be disabled.
— Analytics Cookies: help us understand how visitors use our site (e.g. Google Analytics) and are set only with your consent.
— Functional Cookies: remember your preferences and settings.
You can manage your cookie preferences through our cookie consent tool or your browser settings. Withdrawing consent for non-essential cookies does not affect the lawfulness of prior processing. A full Cookie Policy is available at www.mirabellatransatlantic.com/cookie.
We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by law:
— Client Engagement Records and Correspondence and AI-generated Meeting Notes: retained for three years following the conclusion of the engagement, the date of a one-off purchase, or the date of last contact, whichever applies, aligned with the standard limitation period for consumer claims under Swedish law.
— Financial and Invoicing Records: retained in accordance with applicable Swedish accounting law, currently a minimum of seven years.
— Website Analytics Data: retained in accordance with our analytics provider's standard retention settings.
When data is no longer required, it is securely deleted or anonymized.
Under the GDPR, you have the following rights:
— Right of Access: To request a copy of the personal data we hold about you.
— Right to Rectification: To request correction of inaccurate or incomplete data.
— Right to Erasure ('right to be forgotten'): To request deletion of your data, subject to legal retention obligations.
— Right to Restriction of Processing: To request that we limit how we use your data in certain circumstances.
— Right to Data Portability: To receive your data in a structured, machine-readable format.
— Right to Object: To object to processing based on legitimate interests.
— Right to Withdraw Consent: Where processing is based on consent, to withdraw it at any time without affecting prior lawful processing.
To exercise any of these rights, please contact us at contact@mirabellatransatlantic.com. We will respond within one calendar month. You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) at www.imy.se.
We implement commercially reasonable technical and organizational measures to protect your personal data against unauthorized access, loss, destruction, or alteration. No method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority as required by the GDPR.
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe we have inadvertently done so, please contact us and we will delete it promptly.
Where clients provide information about their children or other minors in their household in connection with relocation planning, we treat such data with additional care in accordance with GDPR.
Our website and other content may contain links to third-party websites. We are not responsible for the privacy practices of those sites and encourage you to review their privacy policies independently.
We may update this Privacy Policy from time to time. Material changes will be communicated via our website with an updated effective date. We encourage you to review this policy periodically.
For any questions, requests, or complaints relating to this Privacy Policy or your personal data, please contact:
Post: Frances Harlow / Harlow & Co. AB, Bohusgatan 31, 116 67 Stockholm, Sweden
Email: contact@mirabellatransatlantic.com
If you are not satisfied with our response, you have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY) at www.imy.se.
Mirabella Transatlantic provides informational and strategic guidance only and does not offer legal, immigration, tax, or financial advice or representation. Visa eligibility, residency rights, and immigration outcomes are determined solely by the relevant governmental authorities.
© 2026 Harlow & Co. AB, operating as Mirabella Transatlantic