Privacy Policy

Privacy Policy

Last updated: 12 May 2026

This Privacy Policy explains how Muxelio ("Muxelio", "we", "us", or "our") collects, uses, discloses, and protects personal data when you visit our websites, create an account, or use our privacy-focused analytics software-as-a-service platform (the "Service"). We are based in the United Kingdom.

This Privacy Policy covers:

  • Visitors to our websites and marketing pages
  • Customers and authorised users of the Service
  • Billing contacts, prospects, and people who communicate with us

If you are an end user of a website or app that uses Muxelio analytics, please see Section 9 (End Users of Customer Sites/Apps).

1. Who We Are (Controller Information)

Muxelio is the controller for personal data we process for our own business purposes (e.g., account management, billing, website operations, and marketing).

Contact: [Insert privacy email]
Address: [Insert registered office address, UK]

2. Personal Data We Collect

2.1 Data you provide to us

  • Account data: name, email address, password (stored hashed), organisation name, role.
  • Billing data: billing contact details, billing address, VAT number (if applicable), payment status and invoices.
  • Communications: content of messages you send to us (support requests, emails, feedback).
  • Configuration data: settings you choose in the Service (e.g., properties, dashboards, alerts).

2.2 Data we collect automatically (website and Service)

  • Device and usage data: approximate device information, browser type, operating system, pages/screens viewed within our website or Service, and timestamps.
  • Log and security data: server logs, audit logs (e.g., sign-in events), and information used for fraud prevention and security monitoring.
  • Cookies and similar technologies: see Section 8.

2.3 Data from third parties

  • Payment processors: we receive limited payment-related information (e.g., last four digits, payment method type, transaction identifiers). We do not store full card details.
  • Service providers: we may receive delivery and engagement data for emails (e.g., bounce events) where enabled.

3. How We Use Personal Data

We use personal data to:

  • Provide, maintain, and secure the Service (including authentication and access control).
  • Create and manage accounts, subscriptions, and billing.
  • Provide support, respond to inquiries, and send service-related messages.
  • Monitor for security, abuse, and fraud, and to enforce our terms.
  • Improve our website, Service performance, and user experience.
  • Comply with legal obligations and protect our rights.
  • Send marketing communications where permitted (you can opt out at any time; see Section 7).

4. Legal Bases for Processing (UK GDPR)

If UK GDPR applies, our legal bases include:

  • Contract: to provide the Service and support, and to manage subscriptions and billing.
  • Legitimate interests: to secure, improve, and market our Service, and to prevent fraud (balanced against your rights).
  • Consent: where required (e.g., certain cookies or marketing in some contexts).
  • Legal obligation: to meet regulatory, tax, and other legal requirements.

5. How We Share Personal Data

We may share personal data with:

  • Service providers (processors): hosting/infrastructure, email delivery, customer support tools, payment processing, security and monitoring tools, and analytics for our own site (where used).
  • Professional advisers: lawyers, accountants, auditors, and insurers where necessary.
  • Authorities: where required by law or to respond to lawful requests.
  • Corporate transactions: in connection with a merger, acquisition, financing, or sale of assets (with appropriate protections).

We do not sell personal data. We do not share personal data for cross-context behavioural advertising.

6. International Transfers

We may process personal data in the United Kingdom and other countries where we or our service providers operate. Where personal data is transferred internationally, we use appropriate safeguards as required by law (for example, UK International Data Transfer Agreement (IDTA), EU Standard Contractual Clauses (SCCs), or other lawful mechanisms).

7. Marketing

We may send marketing communications about Muxelio where permitted by law. You can opt out at any time by using the unsubscribe link in the email, changing your preferences in the Service (if available), or contacting us.

Even if you opt out of marketing, we may still send non-marketing messages such as invoices, security notices, and service updates.

8. Cookies and Similar Technologies

We use cookies and similar technologies to operate and secure our website and Service, and to remember preferences. Depending on your configuration and jurisdiction, we may present a cookie banner and allow you to manage preferences.

Types of cookies we may use:

  • Strictly necessary: required for core site functionality, security, and login sessions.
  • Preferences: to remember settings (e.g., language).
  • Performance/measurement: to understand how our site is used and improve it (where enabled).

You can control cookies through your browser settings. Disabling certain cookies may affect functionality.

9. End Users of Customer Sites/Apps (Muxelio as Processor)

Our Customers may use the Service to collect privacy-focused analytics about their own websites or apps. In those cases, the Customer is typically the controller and Muxelio acts as a processor on the Customer’s behalf.

The categories of data processed depend on the Customer’s implementation and configuration. The Service is designed to support privacy-focused measurement, and Customers are prohibited under our Terms from attempting to identify individuals using the Service.

If you are an end user and want to exercise privacy rights regarding a Customer’s site/app, you should contact that site/app owner directly. If you contact us, we may redirect your request to the relevant Customer where appropriate.

10. Data Retention

We keep personal data only as long as necessary for the purposes described in this Privacy Policy, including to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements.

  • Account data: retained while the account is active and for a reasonable period after closure.
  • Billing records: retained as required by tax and accounting laws.
  • Support communications: retained for support, quality assurance, and record-keeping.
  • Security logs: retained for a limited period appropriate to security needs.

Retention of Customer Data (including analytics) is governed by Customer configuration and any applicable Data Processing Addendum (DPA).

11. Security

We use reasonable technical and organisational measures designed to protect personal data. This includes access controls, encryption in transit, and practices intended to reduce the risk of unauthorised access or disclosure. No system is completely secure, and we cannot guarantee absolute security.

12. Your Rights

Depending on your location, you may have rights such as access, rectification, deletion, restriction, objection, and data portability. You may also have the right to withdraw consent where processing is based on consent.

To exercise rights, contact us at [Insert privacy email]. We may need to verify your identity.

If UK GDPR applies, you also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO): https://ico.org.uk/.

13. Children

The Service is not directed to children, and we do not knowingly collect personal data from children under 13 (or other age as required by local law). If you believe a child has provided personal data to us, contact us and we will take appropriate steps to delete it.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If changes are material, we will take reasonable steps to notify you (for example, by posting an in-product notice or emailing the account owner). The "Last updated" date above shows when this Privacy Policy was last revised.