LEGAL · UK GDPR / GDPR

Privacy.

This notice explains how MUCRIV processes personal data when you use mucriv.com or contact us. Last updated: 17 July 2026.

1. Who we are (controller)

The data controller for this website and for enquiries sent to MUCRIV is Aiden Dunne, trading as MUCRIV (United Kingdom).

We do not currently appoint a separate Data Protection Officer. For any data protection request, use the email above and mark the subject Privacy / GDPR.

2. Scope

This notice covers:

It does not replace a client DPA for production systems, model traffic, or end-user data inside a Forge / Embed / Edge engagement.

3. What we collect

3.1 You give us

3.2 Collected automatically

3.3 We do not intentionally collect

4. Lawful bases (UK GDPR / GDPR)

We process personal data only where a lawful basis applies:

5. How we use personal data

We do not sell personal data. We do not use website enquiry data for automated decision-making that produces legal or similarly significant effects.

6. Cookies and similar technologies

This site is designed to work without non-essential cookies. CloudFront may set technically necessary cookies or use standard CDN mechanisms for delivery and security. We do not use advertising or cross-site tracking cookies. If we introduce analytics or other optional cookies, we will update this notice and, where required, seek consent.

7. Who we share data with (processors)

We use service providers under contract who process data on our instructions:

We may disclose data if required by law, or to establish, exercise, or defend legal claims. We do not share enquiry data with advertisers.

8. International transfers

We aim to keep website and mail processing in the UK / EEA (eu-west-2). Where a processor transfers personal data outside the UK / EEA, we rely on appropriate safeguards under UK GDPR / GDPR (for example the UK International Data Transfer Agreement / Addendum, EU Standard Contractual Clauses, or an adequacy regulation), as provided in that processor’s terms.

9. Retention

10. Security

We use private S3 origins, CloudFront with HTTPS, least-privilege AWS access for MUCRIV workloads, and honeypot fields on the contact form to reduce spam. No method of transmission or storage is perfectly secure; if you believe there has been a personal-data incident involving us, email hello@mucriv.com immediately.

11. Children

mucriv.com is directed at businesses and professionals. We do not knowingly collect personal data from children under 16. If you believe we have, contact us and we will delete it.

12. Your rights

Under UK GDPR (and GDPR where it applies), you may have the right to:

To exercise a right, email hello@mucriv.com with enough detail for us to verify and locate your data. We will respond within one month (or as extended under the law for complex requests).

You can complain to the UK Information Commissioner’s Office (ICO): ico.org.uk/make-a-complaint. We would rather fix the issue first — write to us and we will take it seriously.

If you are in the EEA, you may also complain to your local supervisory authority.

13. Client / product work (Forge · Embed · Edge)

When we build, embed, or secure systems for a client, personal data in your products, tenants, prompts, logs, and model traffic is handled under the statement of work / MSA and any DPA. Typical defaults we design for:

14. AI systems

For client AI systems, we apply permissions, logging, and human approvals as scoped in the engagement. Website enquiries are not fed into training sets for public models. If we use AI tools internally to draft replies, we avoid pasting secrets and treat enquiry content as confidential business correspondence.

15. Changes

We may update this notice. The “Last updated” date at the top is the source of truth. Material changes will be reflected on this page.

16. Contact

Privacy / GDPR: hello@mucriv.com
General: hello@mucriv.com

Terms of use →