LEGAL · UK GDPR / GDPR
Privacy.
This notice explains how MUCRIV processes personal data when you use mucriv.com or contact us. Last updated: 17 July 2026.
This is a privacy notice for the website and general enquiries. Paid client work is also covered by the engagement contract and, where required, a data processing agreement (DPA). If those conflict on client data, the contract / DPA wins for that engagement.
1. Who we are (controller)
The data controller for this website and for enquiries sent to MUCRIV is Aiden Dunne, trading as MUCRIV (United Kingdom).
- Email: hello@mucriv.com
- Site: https://mucriv.com
- Hosting / mail infrastructure: Amazon Web Services (AWS), region eu-west-2 (London)
We do not currently appoint a separate Data Protection Officer. For any data protection request, use the email above and mark the subject Privacy / GDPR.
2. Scope
This notice covers:
- Visitors to mucriv.com (including Field notes, Reels, and legal pages)
- People who email us or use the strike-call / contact form
- How we handle personal data in marketing and pre-contract conversations
It does not replace a client DPA for production systems, model traffic, or end-user data inside a Forge / Embed / Edge engagement.
3. What we collect
3.1 You give us
- Contact form / email: name, company, email address, how you found us, message content
- Any files or links you voluntarily send
3.2 Collected automatically
- Server / CDN logs (Amazon CloudFront → S3): IP address, date/time, URL, referrer, user agent, response status — for security, abuse prevention, and reliability
- We do not run third-party advertising cookies or pixels on this site
- Fonts are self-hosted; we do not load Google Fonts (or similar) at runtime
- We do not currently use analytics products (e.g. Plausible / GA). If that changes, this notice will be updated before they go live
3.3 We do not intentionally collect
- Special category data via the website form
- Children’s data — the site is aimed at business operators (see §11)
4. Lawful bases (UK GDPR / GDPR)
We process personal data only where a lawful basis applies:
- Legitimate interests (UK GDPR Art. 6(1)(f)) — operating a secure website; answering business enquiries; keeping records of correspondence; defending legal claims. We balance this against your rights and expect you to contact us about business services.
- Contract / pre-contract steps (Art. 6(1)(b)) — when you ask for a proposal, Strike call, or engage us, we process what is needed to take steps at your request or perform the contract.
- Legal obligation (Art. 6(1)(c)) — where we must keep records for tax, accounting, or regulatory reasons.
- Consent (Art. 6(1)(a)) — only if we ever ask for it expressly (e.g. optional marketing list). You can withdraw consent at any time without affecting prior lawful processing.
5. How we use personal data
- To respond to Strike calls and other enquiries
- To prepare proposals and run engagements you request
- To secure, debug, and operate mucriv.com
- To keep business records and comply with law
We do not sell personal data. We do not use website enquiry data for automated decision-making that produces legal or similarly significant effects.
6. Cookies and similar technologies
This site is designed to work without non-essential cookies. CloudFront may set technically necessary cookies or use standard CDN mechanisms for delivery and security. We do not use advertising or cross-site tracking cookies. If we introduce analytics or other optional cookies, we will update this notice and, where required, seek consent.
7. Who we share data with (processors)
We use service providers under contract who process data on our instructions:
- Amazon Web Services (AWS) — hosting (S3, CloudFront), contact form pipeline (API / Lambda), email (SES). Primary region: eu-west-2 (London). CloudFront distributes content globally as a CDN; edge logs may be processed in AWS’s infrastructure consistent with their DPA.
- Enquiry mail may be delivered to an inbox we control (including addresses used to operate MUCRIV day-to-day).
We may disclose data if required by law, or to establish, exercise, or defend legal claims. We do not share enquiry data with advertisers.
8. International transfers
We aim to keep website and mail processing in the UK / EEA (eu-west-2). Where a processor transfers personal data outside the UK / EEA, we rely on appropriate safeguards under UK GDPR / GDPR (for example the UK International Data Transfer Agreement / Addendum, EU Standard Contractual Clauses, or an adequacy regulation), as provided in that processor’s terms.
9. Retention
- Enquiries — kept as long as needed to respond, qualify, and (if you become a client) support the relationship; thereafter for legitimate business records, typically up to 7 years where accounting or legal reasons apply, then deleted or anonymised where practicable.
- CDN / access logs — retained according to AWS / CloudFront defaults and our operational needs for security (usually short-lived; not used as a marketing database).
- Client project data — as set out in the engagement / DPA (often returned or deleted at end of project unless law requires retention).
10. Security
We use private S3 origins, CloudFront with HTTPS, least-privilege AWS access for MUCRIV workloads, and honeypot fields on the contact form to reduce spam. No method of transmission or storage is perfectly secure; if you believe there has been a personal-data incident involving us, email hello@mucriv.com immediately.
11. Children
mucriv.com is directed at businesses and professionals. We do not knowingly collect personal data from children under 16. If you believe we have, contact us and we will delete it.
12. Your rights
Under UK GDPR (and GDPR where it applies), you may have the right to:
- Be informed about how we use your data (this notice)
- Access a copy of personal data we hold about you
- Rectify inaccurate or incomplete data
- Erase data in certain circumstances (“right to be forgotten”)
- Restrict processing in certain circumstances
- Data portability where processing is based on consent or contract and is automated
- Object to processing based on legitimate interests (including any future direct marketing)
- Withdraw consent where we rely on consent
- Not be subject to solely automated decisions with legal or similarly significant effects (we do not do this via the website)
To exercise a right, email hello@mucriv.com with enough detail for us to verify and locate your data. We will respond within one month (or as extended under the law for complex requests).
You can complain to the UK Information Commissioner’s Office (ICO): ico.org.uk/make-a-complaint. We would rather fix the issue first — write to us and we will take it seriously.
If you are in the EEA, you may also complain to your local supervisory authority.
13. Client / product work (Forge · Embed · Edge)
When we build, embed, or secure systems for a client, personal data in your products, tenants, prompts, logs, and model traffic is handled under the statement of work / MSA and any DPA. Typical defaults we design for:
- You remain controller for your end-users unless the contract says otherwise
- We act as processor (or sub-processor) only as documented
- Access control, audit logs, retention, and subprocessors are agreed in writing
- We do not use your confidential project data to train public foundation models unless you explicitly contract that
14. AI systems
For client AI systems, we apply permissions, logging, and human approvals as scoped in the engagement. Website enquiries are not fed into training sets for public models. If we use AI tools internally to draft replies, we avoid pasting secrets and treat enquiry content as confidential business correspondence.
15. Changes
We may update this notice. The “Last updated” date at the top is the source of truth. Material changes will be reflected on this page.
16. Contact
Privacy / GDPR: hello@mucriv.com
General: hello@mucriv.com