# Miggins Privacy Policy

**Version 1.3** | Last updated: August 2026

## 1. Introduction

Miggins Ltd ("Miggins", "we", "us", "our") operates the platform at migginsfinancial.com (the "Platform"). We are committed to protecting your privacy and handling your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

This policy explains what data we collect, how we use it, and your rights.

## 2. Data Controller

Miggins Ltd is the data controller for the personal data it holds about you directly — your account, your contact enquiry, and the technical records generated when you use the Platform. This notice describes that processing.

Where your organisation uploads documents that contain personal data about other people, **your organisation is the controller for that data and Miggins Ltd is its processor**, acting only on its instructions under a written agreement meeting UK GDPR Article 28. If you are one of those individuals, the organisation that uploaded the document is responsible for telling you how your data is used, and your rights are exercised against them. See Section 5.2.

**Registered office:** 5 South Charlotte Street, Edinburgh, EH2 4AN, United Kingdom
**Company number:** SC887230 (registered in Scotland)
**Contact:** hello@migginsfinancial.com

## 3. Data We Collect

### 3.1 Account Data

When you register or are provisioned an account, we collect:

- Email address
- Name (first and last)
- Organisation/tenant association
- Role and permissions within the Platform

### 3.2 Contact Enquiries

When you submit an enquiry through our contact form (on our website or CCI Lab), we collect:

- Name
- Email address
- Company name (optional)
- Your message
- The page you submitted from (e.g., landing page, CCI Lab)

We use this information to respond to your enquiry and may follow up with you about our services. We will not add you to any marketing mailing list without your explicit consent.

### 3.3 Authentication Data

We use Auth0 as our authentication provider. When you log in, your email address is used to authenticate your identity and associate you with your organisation's account. Authentication data (such as login timestamps and session tokens) is processed by Auth0 under their privacy policy. We store a reference to your Auth0 identity, your email address, and your last login timestamp.

### 3.4 Uploaded Documents

You may upload PDF and DOCX documents for compliance analysis, persona testing, style review, and enhancement. These documents are stored securely in cloud object storage (Cloudflare R2, EU jurisdiction) and are associated with your account and tenant.

### 3.5 Analysis Data

When you use the Platform's analysis features, we store:

- Compliance analysis results and scores
- Persona interview transcripts and scores
- Accessibility analysis results (WCAG structural, visual, and vulnerable-customer barrier assessments)
- Enhancement recommendations
- Style review results
- Document classification metadata

### 3.6 Usage Data

We collect limited technical data to operate the Platform, including:

- Request logs (IP address, user agent, timestamps)
- Error logs for debugging purposes

We use privacy-preserving, cookieless analytics (Cloudflare Web Analytics) and error monitoring (Sentry) as described in Sections 6 and 11. We do not use marketing or cross-site tracking cookies.

## 4. How We Use Your Data

We process your data for the following purposes:

| Purpose | Legal Basis |
|---------|-------------|
| Providing the Platform and its features | Performance of contract |
| Account authentication and security | Legitimate interest |
| Responding to contact enquiries | Legitimate interest |
| Following up on enquiries about our services | Legitimate interest |
| Storing and analysing your uploaded documents | Performance of contract |
| Generating AI-powered compliance reports | Performance of contract |
| Technical support and debugging | Legitimate interest |
| Platform performance monitoring (Cloudflare Web Analytics) | Legitimate interest |
| Platform improvements and service quality | Legitimate interest |
| Compiling anonymised, aggregated analytical data (industry benchmarks, compliance trends, scoring distributions) | Legitimate interest |

The legal bases above cover the personal data we hold about **you** — your account, your enquiry, your use of the Platform. Where your organisation uploads documents that contain personal data about other people, your organisation is the data controller for that data and determines the legal basis for it; we act as its processor and process that data only on its instructions. See Section 5.2.

## 5. AI and Document Processing

### 5.1 How Documents Are Processed

Uploaded documents are processed using AI language models to provide compliance analysis, persona simulations, document improvement recommendations, and accessibility analysis. Document text is extracted using Google Gemini or Adobe PDF Services, then analysed using OpenAI language models. For visual accessibility analysis, rendered images of document pages are sent to Google Gemini's multimodal models to assess visual presentation (such as colour use and image parity) against accessibility standards.

### 5.2 AI and Document Processing Providers

We use the following third-party providers to process document content:

| Provider | Purpose | Data Sent | Data Residency |
|----------|---------|-----------|----------------|
| OpenAI | Compliance analysis, persona interviews, enhancement, style review | Document text content, analysis prompts | United States |
| Google (Gemini API) | Document text extraction, structured data parsing, visual accessibility analysis | Document content, rendered page images | United States |
| Adobe PDF Services | PDF text and table extraction | PDF binary files | United States |

The Platform is designed for analysing published or draft financial communications (such as financial promotions, assessment of value reports, and general consumer communications). It is not designed for processing documents containing personal data of individuals. If uploaded documents incidentally contain personal data, such data is transmitted to the above providers on the terms described below. Clients are responsible for ensuring they have appropriate authority and legal basis before uploading documents containing personal data (see our Terms of Business, Section 7).

These providers act as data processors. Under the paid API terms on which we use them, they are bound to:

- Process data only for the purpose of providing our analysis
- Not use your data to train or improve their models

Retention by these providers varies by service. Where a provider offers a zero-retention configuration, we use it. Otherwise, providers may hold data for a limited period for abuse monitoring under their published API terms, after which it is deleted. We are formalising data processing agreements with our AI providers and will update this notice when that work is complete.

### 5.3 Aggregated Data

We may compile anonymised, de-identified statistical and analytical data from the processing of documents through the Platform ("Aggregated Data"). This includes industry-level compliance trends, common clarity patterns, scoring distributions, and document-type benchmarks. Aggregated Data does not contain document text, extracts, or any information from which you or your organisation could be identified.

We use Aggregated Data to improve the Platform's analysis capabilities, produce industry-level benchmarks, and provide comparative scoring features. We do not use your document content to train or fine-tune any machine learning model without your explicit consent.

Our legal basis for processing Aggregated Data is legitimate interest: improving our service quality benefits all users, and the data is fully anonymised so the impact on your privacy is minimal. You may object to this processing by contacting us (see Section 14), and we will consider your objection on its merits.

### 5.4 No Automated Decision-Making

The Platform provides advisory analysis only. No automated decisions with legal or similarly significant effects are made based on your data. All compliance assessments, scores, and recommendations are for informational purposes and should be reviewed by qualified professionals.

## 6. Data Sharing and Sub-Processors

We do not sell your personal data. We share data with the following sub-processors:

| Sub-Processor | Purpose | Data Shared | Data Residency |
|---------------|---------|-------------|----------------|
| **Cloudflare** (Workers, D1, R2) | Hosting, database, document storage | All platform data | EU (D1 and R2 configured with EU jurisdiction) |
| **Auth0** (Okta, Inc.) | Authentication and identity management | Email, name, login events | UK (eu-west-2, London) |
| **OpenAI** | AI document analysis | Document text content | United States |
| **Google** (Gemini API) | Document extraction and visual accessibility analysis | Document content, rendered page images | United States |
| **Adobe** | PDF text extraction | PDF files | United States |
| **Sentry** | Error monitoring and performance tracing | Error metadata, request paths, performance traces (no document content or user PII) | EU (Germany) |

Our hosting, authentication and monitoring sub-processors are bound by data processing agreements. Processing by our AI providers is currently governed by each provider's published API and data processing terms, and we are formalising separate data processing agreements with them. A current list of sub-processors is available on request.

## 7. Data Retention

| Data Type | Retention Period |
|-----------|-----------------|
| **Contact enquiries** | Up to 24 months from submission, or until you request deletion |
| **Account data** | While your account is active, and for up to 12 months after account closure |
| **Uploaded documents** | For the duration of your organisation's engagement. Deleted on request, or on termination within 90 days of the export window (see below). |
| **Analysis results** | Retained alongside the associated documents. On termination, deleted within 90 days of the export window. |
| **Audit logs** | Archived daily to immutable storage (EU); database records are deleted once archived, 365 days after creation. On termination, audit records are anonymised (user identifiers removed) but retained for compliance purposes. |
| **AI processing logs** | 90 days (automatically purged) |
| **Authentication rate limit records** | 2 hours (automatically purged) |

Automated retention enforcement runs daily for contact enquiries, AI processing logs and authentication rate limit records. Data beyond its retention period is permanently deleted in accordance with our Data Retention & Disposal Policy.

Deletion of uploaded documents and their extracted text is carried out by us on request rather than through a self-service control in the Platform. Ask your organisation's administrator to raise the request, or contact us directly (Section 14), and we will delete the documents and confirm in writing. We are building a self-service deletion control and will update this notice when it is available.

### 7.1 Post-Termination Deletion

When a Client's engagement ends, the following process applies:

1. **Export window (30 days):** The Client may request an export of all their data within 30 days of termination.
2. **Deletion (90 days):** After the export window, or upon the Client's written instruction, we delete Client data within 90 days. This includes: uploaded documents and extracted text, analysis results and scores, user account records, and team/permission structures.
3. **What we retain:** Anonymised audit log records (user identifiers removed) for our own compliance purposes; any anonymised, aggregated statistical data as described in our Terms of Business (Section 6.3); and any data we are required to retain by law.
4. **Confirmation:** We will confirm deletion in writing to the Client upon completion.

## 8. Data Security

We implement appropriate technical and organisational measures to protect your data, including:

- Encryption in transit (TLS 1.2+ / HTTPS on all connections)
- Encryption at rest for stored documents and database via Cloudflare-managed infrastructure encryption
- Tenant-level data isolation (multi-tenant architecture with strict query-level separation)
- Role-based access controls with module-level permissions and data scope controls
- Application-level encrypted session cookies (AES-256-GCM) with CSRF protection
- Rate limiting on authentication endpoints
- SHA-256 integrity hashing on all audit log records for tamper detection
- Daily immutable archival of audit logs to EU-jurisdiction storage
- Automatic PII redaction in application logs
- Security headers (CSP, HSTS, X-Frame-Options, Permissions-Policy)
- Input validation on all API endpoints

## 9. International Transfers

Your account data and uploaded documents are stored in the European Union (Cloudflare D1 and R2 with EU jurisdiction). Authentication data is processed in the UK (Auth0 eu-west-2, London).

Document content is transmitted to AI providers in the United States for analysis (see Section 5.2). These transfers are made under each provider's paid API terms, which prohibit use of the content for model training. Document content is encrypted in transit (TLS). Provider-side retention is described in Section 5.2.

Where data is transferred outside the UK, appropriate safeguards are in place, including Standard Contractual Clauses, the UK-US Data Bridge, and adequacy decisions where applicable.

## 10. Your Rights

Under UK GDPR, you have the right to:

- **Access** your personal data
- **Rectify** inaccurate data
- **Erase** your data ("right to be forgotten")
- **Restrict** processing of your data
- **Port** your data to another service
- **Object** to processing based on legitimate interest
- **Withdraw consent** where processing is based on consent

To exercise any of these rights, contact us at hello@migginsfinancial.com. Organisation administrators can also initiate data exports and erasure requests directly through the Platform's admin interface. Erasure removes your permissions, team memberships and analysis records, and anonymises your account record and audit history; uploaded documents are deleted by us alongside it on request (see Section 7).

We will respond to data subject requests within 30 days, in accordance with UK GDPR Article 12.

## 11. Cookies and Analytics

The Platform uses only essential cookies required for authentication and session management. We do not use marketing or tracking cookies.

We use Cloudflare Web Analytics to monitor page performance and usage patterns. This service is cookieless, does not collect personally identifiable information, and does not track individual users across sessions. Data collected is limited to page load times, pageviews, referrers, and general browser/device information. This processing is carried out under our legitimate interest in maintaining and improving the Platform.

We also use Sentry for error monitoring and performance tracing (see Section 6). Sentry processes technical error and performance data (such as stack traces, request paths, and timing) in the EU and does not capture document content or record user sessions.

## 12. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via the Platform or by email. The "Last updated" date at the top of this page will reflect the most recent revision.

## 13. Complaints

If you are not satisfied with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

- Website: https://ico.org.uk
- Helpline: 0303 123 1113

## 14. Contact Us

For any questions about this privacy policy or our data practices:

**Email:** hello@migginsfinancial.com

## 15. Revision History

| Version | Date | Summary of changes |
|---------|------|--------------------|
| **1.3** | August 2026 | Clarified that the legal bases in Section 4 cover the data we hold about you, and that your organisation determines the legal basis for personal data inside documents it uploads. Corrected the description of how uploaded documents are deleted: deletion is carried out by us on request, not through a self-service control. |
| **1.2** | August 2026 | Removed Google Cloud Vision, which is no longer used for document extraction. Clarified what our AI providers are contractually bound to, and how long they may retain data, replacing an unqualified zero-retention statement. Stated that data processing agreements with AI providers are being formalised. Confirmed contact enquiries are covered by automated deletion. |
| **1.1** | June 2026 | Added accessibility analysis and vulnerable-customer barrier assessment. Added visual accessibility processing by Google Gemini. Added Sentry as a sub-processor. |
| **1.0** | March 2026 | First published. |

Earlier versions of this notice are available on request.
