01Scope and roles
This agreement applies to personal data you enter into Muster about your premises and the people connected with them (“customer data”). For that data you are the controller and BlocksUI Ltd is the processor. It forms part of the terms of service. Terms such as controller, processor, personal data and processing have the meanings given in the UK GDPR and the Data Protection Act 2018.
It does not cover your own account details or the free scope checker, for which we are the controller under the privacy notice.
02Subject matter and duration
The subject matter is the hosting and processing of records of public protection readiness for your premises under the Terrorism (Protection of Premises) Act 2025. Processing lasts for as long as you hold an account, plus the retention period in clause 8.
03Data and data subjects
Data subjects: your staff, volunteers, contractors, trustees and committee members; the people you invite to use Muster; and anyone named in a procedure, exercise log or review note.
Categories of data: names, job or volunteer roles, email addresses where you choose to record them, which version of which procedure each person was briefed on and when, attendance at exercises, notes you write, and the audit trail of changes made by your users. We do not ask for, and you should not enter, special category data. A note such as “needs help on the stairs” is health data; the templates suggest describing the arrangement rather than the person.
04Our obligations as processor
We will:
- process customer data only on your documented instructions, which are: to provide the service as described in the terms and as you operate it through the product. We will tell you if we believe an instruction breaks data protection law;
- ensure the people who can access customer data are bound by confidentiality and have access only where their role needs it;
- implement the security measures in Annex A and keep them under review;
- engage sub-processors only as clause 5 allows;
- assist you as clause 6 describes;
- delete or return customer data as clause 8 describes;
- make available the information needed to demonstrate our obligations, and allow audits as clause 9 describes;
- notify you without undue delay, and in any event within 48 hours of becoming aware, of a personal data breach affecting customer data, with enough detail for you to meet your own reporting duties.
05Sub-processors
You give general written authorisation for the sub-processors listed on the sub-processor page, each engaged under a written contract imposing obligations equivalent to this agreement. We will give at least 30 days’ notice by email before adding or replacing one. If you object on reasonable data protection grounds and we cannot resolve it, you may terminate the affected service and we will refund any prepaid fees for the unused period. We remain fully responsible for our sub-processors’ performance.
06Assisting you
Taking into account the nature of the processing, we will help you respond to data subject requests — most simply through the product’s own export, which produces every record about a named person — and help you meet your obligations on security, breach notification, impact assessments and consultation with the ICO, so far as the information is available to us. If a data subject contacts us directly about customer data we will refer them to you and tell you.
07International transfers
Customer data is stored and processed in the United Kingdom. Transactional email passes through Microsoft 365 in UK and EU regions. We will not transfer customer data outside the UK except to a country with adequacy regulations or under appropriate safeguards such as the UK International Data Transfer Agreement or Addendum, and we will list any such transfer on the sub-processor page.
08Return and deletion
You can export all customer data at any time, in open formats (CSV, JSON and Markdown), from the organisation settings page, including after cancelling. Within 30 days of the end of your final billing period we delete customer data from live systems, and it leaves encrypted backups on their normal rotation within a further 35 days. We retain only what the law requires us to keep, such as invoices. On request we will confirm deletion in writing.
09Audit
We will answer reasonable written security and data-protection questionnaires once a year at no charge. Where that is not enough to satisfy a regulatory requirement you have, you or an independent auditor you appoint may audit our processing on 30 days’ notice, no more than once a year, during working hours, subject to confidentiality and without disrupting other customers. We will cooperate and provide the information the audit reasonably needs.
10Annex A — security measures
| Measure | What we do |
|---|---|
| Encryption | TLS for every connection. Database, backups and uploaded logos encrypted at rest. |
| Hosting | Servers in the United Kingdom, firewalled so only the application reaches the database. |
| Access control | Production access limited to named individuals with individual credentials and multi-factor authentication. No shared accounts. |
| Application roles | Owner, administrator, venue manager and read-only auditor, enforced on the server for every request. Per-site delegation so a venue manager sees one venue. |
| Passwords | Stored as salted hashes. Email verification on sign-up. Sessions expire and can be revoked from the profile page. |
| Audit trail | Every change to customer data is logged with who made it and when, visible to you in the product and included in your export. |
| Backups | Daily, encrypted, tested for restore, retained on a 35-day rotation. |
| Change control | All code changes reviewed and tested before deployment; dependencies monitored for known vulnerabilities. |
| Incident response | Breach notification to you within 48 hours of awareness; ICO notification within 72 hours where required. |
11Annex B — processing details
| Item | Detail |
|---|---|
| Controller | The organisation holding the Muster account. |
| Processor | BlocksUI Ltd, Glasgow, Scotland. |
| Nature of processing | Storage, retrieval, display, versioning, export and emailing of readiness records at the controller's direction. |
| Purpose | Enabling the controller to build, maintain and demonstrate public protection procedures for its premises. |
| Data subjects | Staff, volunteers, contractors, trustees, committee members and invited users of the controller. |
| Categories of data | Names, roles, optional email addresses, briefing and exercise records, notes, audit trail. No special category data intended. |
| Duration | The life of the account plus the 30-day retention period. |
| Contact | [email protected] |