Privacy Notice — mAIb MVP Release Audit
> DRAFT — NOT LEGAL ADVICE. Requires review by a qualified solicitor before production use.
Version: 0.1 (draft) · Last updated: [DATE]
This notice explains how mAIb Tech LLC ("mAIb", "we", "us") handles personal data in connection with the mAIb MVP Release Audit service. mAIb Tech LLC is a Delaware (US) entity; the operator of the service is based in the United Kingdom.
[OWNER/SOLICITOR DECISION REQUIRED: UK GDPR / EU GDPR applicability, controller/processor allocation for each processing activity, legal bases, and any required international transfer mechanisms]
1. Who this notice covers
- Customers and prospective customers — founders, developers, and businesses who enquire about or purchase an audit.
- Individuals whose personal data appears in customer materials — repositories, databases, logs, and documentation supplied for an audit may incidentally contain personal data (for example names in commit history, email addresses in code, or test data). [OWNER/SOLICITOR DECISION REQUIRED: controller/processor roles for personal data contained in customer materials, and whether a data processing agreement is required]
2. What we collect
| Category | Examples | Source |
|---|---|---|
| Contact and account details | Name, email address, business name | You |
| Engagement details | Project description, scope, correspondence | You |
| Payment details | Handled by our payment provider (Stripe); we do not store full card details | You, via the payment provider |
| Customer materials | Code, repositories, configuration, logs, documentation supplied for the audit | You |
| Service records | Acceptance records, consent records, purge records, invoices | Generated by us |
We do not intentionally collect special category data. If it appears incidentally in customer materials, it is handled under the Code Handling and Confidentiality Policy and purged under the Data Retention Schedule.
3. Why we use it
- To assess, accept, or decline projects, and to deliver the engaged services.
- To communicate with you about your engagement.
- To take payment and keep required financial records.
- To keep evidence of consent, acceptance, and purges.
- To comply with legal obligations.
[OWNER/SOLICITOR DECISION REQUIRED: legal basis for each purpose]
4. AI processing modes
Each engagement uses exactly one of three AI-processing modes, selected and consented to before work begins. Full details are in the AI Processing Disclosure.
- Mode 1 — No external AI source processing. Your source materials are not sent to any external AI provider.
- Mode 2 — Redacted snippets only. Limited, redacted code snippets may be sent to a disclosed AI provider, only with your explicit consent.
- Mode 3 — Repository-level AI assistance. Repository content may be processed with a disclosed AI provider's tools, only with your explicit informed consent, under the provider's applicable data-processing terms.
Where Mode 2 or Mode 3 is selected, your code (or extracts of it) is transmitted to the disclosed external provider. We do not claim in those modes that your code never leaves our systems. We make no representations about a provider's own training or retention practices beyond what is described in the provider's applicable data-processing terms.
5. Who we share data with
- Stripe — payment processing.
- Object storage provider (TBD) — encrypted storage of engagement materials during the retention period.
- AI provider (TBD, per selected mode) — only under Mode 2 or Mode 3, only with your explicit consent, and only as disclosed for your engagement.
- Professional advisers and authorities — where required by law or for legal claims.
The current list is maintained in the Subprocessor Register. We do not sell personal data.
[OWNER/SOLICITOR DECISION REQUIRED: international transfer analysis (US entity, UK operator, provider locations) and applicable safeguards]
6. Retention
Engagement materials (repositories, archives, workspaces, and derived snippets beyond the evidence minimum) are purged by default 30 days after report delivery, configurable per engagement. You may request earlier deletion. A purge record is kept. Full details, including what is retained longer (for example invoices and consent records), are in the Data Retention Schedule.
7. Security
We apply the measures described in the Code Handling and Confidentiality Policy, including access limitation, encryption in transit and at rest, and scoped workspaces. No security measure removes all risk, and we do not represent otherwise.
8. Your rights
Depending on the law that applies to you, you may have rights to access, rectify, erase, restrict, object to, or port personal data, and to withdraw consent (including consent to Mode 2 or Mode 3 processing) without affecting processing already carried out. To exercise a right, contact us at [CONTACT EMAIL].
[OWNER/SOLICITOR DECISION REQUIRED: applicable rights regimes, response deadlines, and complaint routes (e.g. ICO or other supervisory authority)]
9. Cookies
The service website currently plans no non-essential cookies. See the Cookie Notice.
10. Contact
[CONTACT EMAIL] · mAIb Tech LLC, [REGISTERED ADDRESS]
[OWNER/SOLICITOR DECISION REQUIRED: whether a UK or EU representative, or a data protection officer, is required]