M
Muster

Data Processing Agreement (summary)

Version 1.0 · Effective 22 July 2026

Under UK/EU GDPR, your organisation is the data controller for the personal data of the volunteers and administrators you enrol on Muster, and we act as your data processor. This page summarises the processor obligations we commit to; it’s incorporated by reference into these terms for every organisation on the platform, and a signed, full-form copy is available on request — see Contact below.

What we process, and on whose instructions

We process personal data — account details, training progress, completion and attestation records — only to provide the platform to your organisation, and only on your documented instructions (as expressed through your use of the product: who you enrol, what retention period you set, what you export or erase). We don’t use your organisation’s data for our own purposes, and we don’t sell it.

Confidentiality

Anyone we authorise to process personal data (employees, contractors) is bound by confidentiality obligations, whether contractual or statutory.

Security measures

Sub-processing

We use a small number of specialist subprocessors (hosting, database, video, email, payments) to operate the platform. By using Muster, your organisation gives general authorisation for this sub-processing, on the condition that each subprocessor is bound by data protection terms at least as protective as this agreement. Our current subprocessor list, including purpose and data category, is published and versioned at /subprocessors. We’ll update that list if it changes materially.

Assisting with data subject requests

Because your organisation is the controller, most data subject requests (access, erasure, correction) should be handled directly by your organisation’s administrators using the self-serve tools in settings. Where a request needs our direct assistance — for example something outside those tools — we’ll help within a reasonable time.

Breach notification

If we become aware of a personal data breach affecting your organisation’s data, we will notify you without undue delay, and in any case within 72 hours of becoming aware, with what we know at the time and updates as our understanding develops.

International transfers

Personal data and video content are hosted in the EU. Where a subprocessor is headquartered outside the EU/UK (see subprocessors), we rely on that provider’s Standard Contractual Clauses or equivalent safeguard, and — for personal data specifically — an EU-region deployment where the provider offers one.

Deletion or return of data

On termination of your organisation’s account, you can export your data first via settings; deletion of the organisation is immediate and permanent once actioned (see the in-app warning on that action). Contact support within 30 days of an accidental deletion to ask about restoring from backups — this is a best-efforts option, not a guarantee.

Contact

To request a signed, full-form DPA, or to discuss any of the above: privacy@example.com.