Privacy notice

What we hold, why, and for how long.

Muster holds the names of your staff and volunteers and what they were briefed on. That is personal data and it deserves a plain account of how it is handled. This is that account.

Last updated 3 September 2026

01Who we are

Muster is run by BlocksUI Ltd, trading as Muster, based in Glasgow, Scotland. Company number SC649153. Questions about this notice go to [email protected].

02Controller or processor

For your account, your use of the website and the free scope checker, we are the controller: we decide what is collected and why.

For the records you put into Muster about your premises — the names, roles and optional email addresses of staff, volunteers and contractors, who was briefed on what, drills, reviews — you are the controller and we are the processor. We handle that data only on your instructions, under the data processing agreement, and we never use it for our own purposes.

03What we collect

When you create an account

Your name, email address and a password (stored only as a salted hash). Which organisations you belong to and your role in each.

When you use the product

Everything you enter: your premises, their capacity figures, the four procedures and every version of them, the register of people, briefing records, exercises, reviews and the SIA notification tracker. An audit trail of who changed what and when. Any logo or branding you upload.

When you use the free scope checker

Your answers and the outcome. No account is needed and no email is required. If you ask for a copy of your result by email, we keep the address you give us so we can send it.

Automatically

Server logs: IP address, browser type, the pages requested and the time, kept for security and to diagnose faults. We do not run analytics or advertising trackers, and we do not build profiles.

When you pay

Payments are taken by Stripe. We never see or store your card number. We hold your billing address, the invoices and a Stripe customer reference.

04Why, and on what basis

Under UK GDPR we need a lawful basis for each use. Ours are:

  • Performing our contract with you — running your account, storing your records, sending emails the product needs to send (verification, password resets, invitations, reminders you have set up, briefing requests you send to your volunteers).
  • Legitimate interests — keeping the service secure, keeping logs to diagnose faults, preventing abuse of the free checker, and telling you about material changes to the service or to the legislation it relates to. You can object to any of this.
  • Consent — sending you a copy of your scope checker result, which you ask for explicitly and can withdraw by asking us to delete the address.
  • Legal obligation — keeping invoices and tax records for the period the law requires.

We do not sell personal data, and we do not send marketing email to people who have not asked for it.

05How long we keep it

  • Account and organisation records: for as long as the organisation has an account, then deleted within 30 days of the end of the final billing period. You can export everything first, at any time, in open formats.
  • Scope checker submissions: 24 months, so we can see how the checker is used and improve its wording. Email addresses attached to a result are deleted on request at any time.
  • Server logs: 90 days.
  • Invoices and payment records: six years after the tax year they relate to, as HMRC requires.
  • Backups: encrypted, and rotated so that deleted data leaves them within 35 days.

06Who we share it with

Only the companies that help us run the service, listed with what they do and where they are on the sub-processor page. Each is bound by a contract that limits them to acting on our instructions. We will also disclose data where the law requires it, and we will tell you if we are allowed to.

Within your organisation, the people you invite see what their role allows. A volunteer you send a briefing request to sees the procedure, their own name and your organisation’s name — nothing about anyone else.

07Where it goes

The application and its database run on servers in the United Kingdom. Transactional email is sent through Microsoft 365, in UK and EU data centres. Card payments are handled by Stripe, some of whose processing takes place in the United States under the UK International Data Transfer Addendum to the EU Standard Contractual Clauses. We do not otherwise transfer personal data outside the UK.

08How we protect it

Encryption in transit (TLS) and at rest. Access to production limited to the people who run the service, with individual credentials and audit logging. Passwords stored as salted hashes. Role-based access within the product so a read-only auditor cannot change a record and a venue manager cannot see another venue. Daily encrypted backups. If we ever have a breach that puts you at risk, we will tell you without undue delay and report it to the ICO within 72 hours where the law requires.

09Your rights

You can ask us for a copy of the personal data we hold about you, ask us to correct or delete it, restrict or object to how we use it, and take it elsewhere. Where we act as your processor, the request should go to your organisation, which controls that data; we will help them answer it. Email [email protected] and we will respond within one month.

If you are unhappy with how we have handled something you can complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113. We would rather you told us first, and we will try to put it right.

10Cookies

We use only strictly necessary cookies: one to keep you signed in and one to protect forms against cross-site requests. Your choice of light or dark theme is stored in your browser and never sent to us. There are no analytics, advertising or tracking cookies, which is why there is no cookie banner.

11Changes and contact

If we change this notice in a way that matters we will email account holders before it takes effect. The date at the top is the date of the current version. Anything unclear: [email protected].