Privacy & data processing
Muluno Limited Platform Privacy and Data Processing Terms
How Muluno Limited handles platform data, works with salon businesses and supports their responsibilities as data controllers.
This published document matches the current Muluno platform agreement. The Organisation's owner accepts the applicable version within Muluno.
1. Roles and scope
These terms form the data-processing agreement between the Organisation and Muluno Limited required where Muluno processes personal data for the Organisation. For customer, patient, client, staff and contact information placed in the platform, the Organisation normally determines the purposes and essential means and acts as controller; Muluno Limited normally acts as processor on its documented instructions. Muluno Limited acts as an independent controller only for processing where it determines the purposes, including limited account administration, billing, security, fraud prevention, legal compliance, service protection and business-contact activities. The factual processing determines each role; labels do not override applicable law.
2. Article 28 processing schedule
Subject matter: operating, hosting, supporting and securing the Muluno modules selected and configured by the Organisation. Duration: the authorised service term, any agreed transition period and the limited backup or legal-retention periods described below. Nature and purposes: collecting where configured, recording, organising, structuring, storing, adapting, retrieving, consulting, transmitting, making available to authorised recipients, restricting, supporting, securing, exporting and deleting data to provide websites, appointments, client records, questionnaires, consultation workflows, communications, subscriptions, SMS credit wallets, vouchers, staff administration, data-migration review, technical support, audit and payment integrations. Personal-data types may include names, contact and demographic details; account and authentication data; staff roles, work schedules and permissions; appointment and transaction details; questionnaire answers, consultation records, notes, signatures and health information; communication preferences, recipient details, message categories, encoded segment counts, provider delivery identifiers and delivery records; subscription entitlement, SMS credit balance, purchase, refund, deficit and usage-ledger information; migration source files, mapping instructions, support-ticket messages and attachments; device, network, diagnostic, security and audit information; vouchers and payment references, but not full card details handled by the payment provider. Data subjects may include customers, patients, clients, prospective customers, website visitors, staff, practitioners, contractors, owners, authorised users and business contacts. The Organisation retains the rights and obligations of controller.
3. Organisation obligations as controller
The Organisation warrants on an ongoing basis that its processing and instructions are lawful, fair, transparent, necessary and proportionate. It must identify and document an Article 6 lawful basis and, where applicable, an Article 9 condition and Data Protection Act 2018 Schedule 1 condition; provide complete privacy information; obtain valid consent where consent is relied on; comply with direct-marketing and electronic-communications rules; minimise and keep data accurate; define retention; verify identity when handling rights requests; protect confidentiality; manage staff access; assess risk; and make any required regulator or individual notifications. It must not instruct Muluno to collect or use data that the Organisation could not lawfully process itself.
4. Documented instructions and legal requirements
Muluno will process Organisation-controlled personal data only on documented instructions, including the Organisation's configuration and use of the platform, authorised user actions, support requests and this agreement, unless UK law requires otherwise. If legally permitted, Muluno will inform the Organisation before processing required by law. Muluno will notify the Organisation if, in its reasonable opinion, an instruction infringes applicable data-protection law and may pause the affected processing while the parties address it. Muluno does not determine the Organisation's clinical, professional, employment, marketing or customer-service purposes.
5. Personnel and confidentiality
Muluno will limit access to Organisation-controlled personal data to personnel and contractors who require it for authorised operation, security or support. People authorised to process such data will be bound by confidentiality obligations or an appropriate statutory duty and receive relevant security and privacy instruction. The Organisation is responsible for confidentiality obligations, training, supervision and access controls for its own users, staff, contractors and devices.
6. Technical and organisational measures
Taking account of the state of the art, implementation cost, processing scope and risks, Muluno will maintain measures designed to provide security appropriate to risk. These measures include, as appropriate to the service: identity, authentication and role-based access controls; least-privilege operational access; encryption in transit and provider-managed protection of stored data; tenant and environment controls; logging, monitoring and audit records; secure configuration, change and dependency management; availability, backup and recovery arrangements; incident response; personnel confidentiality; and proportionate supplier assessment. Measures may evolve and may be replaced by controls providing an equivalent or stronger level of protection. No system eliminates all risk, and the Organisation must secure its own endpoints, networks, credentials, exports and local copies.
7. Personal-data breaches and incidents
Muluno will notify the Organisation without undue delay after becoming aware of a personal-data breach affecting Organisation-controlled data and will provide available information reasonably required for the Organisation to assess risk and meet its notification duties, including the nature of the incident, affected categories, likely consequences and mitigation where known. Information may be supplied in phases as investigation continues. The Organisation remains responsible for deciding whether and when to notify the UK data-protection regulator, affected individuals or another authority. The Organisation must notify Muluno without undue delay of compromised accounts, devices, exports, credentials or other incidents that may affect the platform. Notification is not an admission of fault.
8. Sub-processors
The Organisation gives general written authorisation for Muluno to appoint sub-processors reasonably required for cloud hosting, storage, authentication, communications, payments, mapping, support, monitoring, security and related platform operation. Muluno will conduct proportionate diligence, impose written data-protection obligations offering materially equivalent protection and remain responsible to the Organisation for sub-processor performance to the extent required by law. Muluno will give reasonable notice of a material new sub-processor through the platform, account contact or another durable service channel. The Organisation may object on documented, legitimate data-protection grounds; if the parties cannot reasonably resolve the objection, Muluno may offer an alternative where practical or either party may end the affected service in accordance with the agreement.
9. International transfers
Where processing involves a restricted transfer of personal data outside the United Kingdom, Muluno will ensure that an applicable adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses or another lawful safeguard or exception is used as required. Muluno will carry out or support any required data-protection test or transfer assessment and apply supplementary measures where reasonably necessary. The Organisation authorises transfers inherent in the approved sub-processors and configured services, subject to these safeguards.
10. Individual rights requests
Taking account of the nature of processing, Muluno will provide appropriate technical and organisational assistance reasonably available through the platform to help the Organisation respond to access, correction, erasure, restriction, objection, portability and related requests. If Muluno receives a request concerning Organisation-controlled data, it will normally direct or transmit the request to the Organisation and will not determine the substantive response unless legally required. The Organisation is responsible for verifying identity, locating all relevant records, applying exemptions, communicating with the individual and meeting statutory deadlines.
11. Compliance assistance
Taking account of the nature of processing and information available, Muluno will provide reasonable assistance required by law with security assessments, breach obligations, data protection impact assessments and prior consultation with regulators. The Organisation remains responsible for deciding whether a DPIA or consultation is required, documenting its assessment and implementing measures relating to its purposes and professional activities. Assistance outside ordinary platform functionality may be subject to reasonable agreed charges unless required because of Muluno's breach.
12. Return, deletion and backups
At the end of processor services, and at the Organisation's choice where technically and legally applicable, Muluno will delete or return Organisation-controlled personal data and delete remaining active copies unless law requires retention. The Organisation must request and securely retain any permitted export during the available transition period. Data may remain in protected backups until overwritten through the applicable backup cycle; during that period it will remain protected, be put beyond ordinary operational use and not be restored except for disaster recovery or legal necessity. Muluno may retain limited records required for security, billing, dispute resolution, legal claims or compliance in its independent-controller capacity.
13. Information, audits and regulator access
Muluno will make information reasonably necessary to demonstrate compliance with applicable processor obligations available to the Organisation and permit proportionate audits or inspections required by Article 28. Audits must normally use available reports and documentation first, be requested on reasonable written notice, occur during business hours, protect other customers and security, be conducted by a suitably qualified independent person bound by confidentiality, and avoid unnecessary disruption. The Organisation bears reasonable audit costs unless the audit identifies a material breach by Muluno. Nothing prevents lawful access by the UK data-protection regulator or another competent authority.
14. Health and other special-category data
Health information, including appointment details that reveal health status, questionnaire answers, consultation records and clinical notes, may be special-category data. Before directing its processing, the Organisation must identify and document both an Article 6 lawful basis and an Article 9 condition and, where relevant, a Data Protection Act 2018 Schedule 1 condition. It must maintain any required appropriate policy document, professional secrecy, record of processing and DPIA, and must ensure that collection is necessary and proportionate. Muluno does not select the Organisation's clinical purpose, lawful basis, diagnosis, treatment, consent standard or retention period.
15. Organisation websites, communications and marketing
The Organisation is responsible for the privacy notice, cookie information, customer terms and consent wording presented for its own services, and for ensuring they accurately describe its purposes, recipients, retention and use of Muluno. It is responsible for lawful contact lists, accurate telephone numbers, marketing consent or another valid permission, suppression and objection lists, sender identification, required opt-outs, message content and compliance with the Privacy and Electronic Communications Regulations, UK data-protection law and consumer law. Platform delivery settings, a stored telephone number, an SMS credit balance or a previous appointment do not by themselves establish consent or make a communication lawful. Neutral transactional service messages must not be used to disguise advertising, promotion or marketing.
16. Muluno Limited as independent controller
Where Muluno Limited acts as controller, it may receive account-owner and user identity and contact details from the individual or Organisation; authentication, device, network, diagnostic, security and usage events from use of the service; billing, subscription, complimentary-entitlement, SMS credit purchase, balance, refund, reversal, deficit and payment-status information from the Organisation or payment provider; and support communications from correspondents. It uses this information to create and administer accounts and perform contracts, verify entitlements and credit purchases, maintain auditable balances, secure and operate the platform, prevent fraud and misuse, provide support, manage billing, comply with legal obligations and establish or defend legal claims. Applicable bases may include contract, legal obligation and legitimate interests in operating, improving and protecting the service. Muluno does not use Organisation-controlled health records for advertising or its own unrelated marketing.
17. Recipients, sources, cookies and automated decisions
Muluno Limited may disclose controller data to personnel who need it, professional advisers, payment and communications providers, cloud and security suppliers, regulators, courts, law enforcement where lawfully required, and a buyer or reorganised business subject to appropriate safeguards. Sources are described above and may include the individual, the Organisation, authorised users, devices and service providers. Essential session, authentication and security technologies may be used to operate the platform. Non-essential analytics or marketing technologies will be used only where separately disclosed and any required consent has been obtained. Muluno does not make solely automated decisions using Organisation-controlled health data that produce legal or similarly significant effects for individuals.
18. Retention and minimisation
Muluno retains controller information only for periods reasonably necessary for the account, service, security, billing, dispute, backup and legal purpose concerned, using the nature, sensitivity, risk and applicable limitation or statutory periods as criteria. Subscription and SMS credit transaction ledgers, purchase and refund evidence, provider references and associated audit records may be retained for the account term and an appropriate accounting, fraud, dispute or legal limitation period even after a balance becomes unusable or the account closes. Organisation-controlled data remains subject to the Organisation's configured service use, instructions, professional retention rules and the deletion terms above. The Organisation must not retain excessive information merely because the platform permits it. Acceptance records, including signatory and signature evidence, may be retained for the agreement term and an appropriate limitation period to evidence the contract and protect legal rights.
19. Privacy rights, contact and complaints
Individuals retain applicable rights of access, correction, erasure, restriction, objection and portability, the right to withdraw consent where processing relies on consent, and the right to complain. Requests about an Organisation's services or records should normally be sent to that Organisation as controller. Questions about Muluno Limited's independent-controller processing may be submitted through the privacy or support contact published on Muluno's official website or supplied in the relevant account, order or service communication. Individuals may complain to the UK data-protection regulator using the contact route at ico.org.uk. Nothing in these terms limits a right or regulatory power that cannot lawfully be restricted.
20. Responsibility and data-protection liability
The Organisation is responsible for damage, claims and regulatory consequences caused by its unlawful purposes, collection, disclosures, retention, marketing, access decisions, content or instructions. Muluno Limited remains responsible for obligations imposed directly on it as processor or controller, including acting within lawful instructions, appropriate security, sub-processor obligations and its own controller processing. Muluno is not responsible for an event to the extent it proves that it was not responsible for that event. Nothing in this agreement excludes compensation rights, regulatory powers or liability that cannot lawfully be limited, and the contractual liability and indemnity provisions apply only to the lawful extent.
21. Signature privacy and public status
The owner acceptance record includes the signatory's entered name, authenticated account details, timestamp, document versions, document digest and electronic signature evidence. It is restricted contractual evidence and is not published on the Organisation's website. The public website may show only that the Organisation has accepted the current Muluno Limited legal documents, the current version and acceptance date; it must not reveal the signatory's name, email address, account identifier or signature.
