M
Muster

Privacy notice

Version 1.0 · Effective 22 July 2026

This notice explains what personal data Muster processes, why, and what rights you have. It applies to anyone who signs in to Muster — whether you’re a volunteer completing training, or an administrator (“owner” or “manager”) running an organisation’s account.

Who we are, and who’s in charge of your data

Muster (“we”, “us”) provides the software. If you’re a volunteer, the organisation that invited you (your church, camp or charity) is the data controller — they decide what training you’re assigned, who can see your record, and how long it’s kept. We are the data processor: we host the platform and process data only on that organisation’s instructions. If you have a question about your personal data as a volunteer, your organisation’s administrator is the right first point of contact — we can’t act on your data without their instruction, except where the law requires otherwise.

If you’re an administrator, the same split applies to your own organisation’s account: your organisation is the controller for the data of everyone in your roster, and we process it on your behalf under our Data Processing Agreement.

What we store

We don’t run advertising trackers or sell data. Training content itself (videos, PDFs, policy text) is supplied by your organisation — we host and play it back but don’t examine or use it for anything else.

Identity assurance — please read this carefully

Muster confirms that someone typed their name and clicked through training under a given login. It does not verify government ID, and a login can in principle be shared. The IP address, browser string and timestamp we capture at attestation exist to make that limitation visible and auditable, not to eliminate it. Organisations relying on completion records for safeguarding or insurance purposes should factor this into their own risk assessment.

Retention, and what happens when a record is erased

Each organisation can set a retention period (or keep records indefinitely) for volunteers who go inactive. When that period elapses, or when an administrator erases an individual on request, we remove personal data associated with that person from the organisation — but we don’t delete the underlying record that training took place. Instead, the completion record is pseudonymised: the link to your account is removed and the name on the record is replaced with “Erased volunteer”, while the fact, date and course of completion are kept. This is a deliberate design choice, not an oversight — it resolves the tension between your right to erasure and your organisation’s legitimate need to retain evidence that safeguarding training occurred, without retaining data that identifies you. It’s documented in more detail under Your rights below.

Your account and any memberships in other organisations are unaffected by erasure from one organisation — a global account deletion is a separate, additional step (contact us directly).

Where your data is hosted

Personal data and video content are hosted in EU data centres. Our infrastructure providers (subprocessors) are listed, with their role and region, on our subprocessor page, which we keep up to date and versioned.

Your rights

Security

Data is encrypted in transit and at rest. Access to production data is limited to the people who need it to operate the service. See our DPA for the fuller list of security measures and our breach notification commitment.

Changes to this notice

We version this notice. If we make a material change, you’ll be asked to review and accept the new version the next time you sign in.

Contact

Questions about this notice, or about Muster acting as a processor: privacy@example.com.
Muster, [Company address].