Privacy notice

Last updated: 2026-07-03 · Version: 1.0

This notice is tailored to the fields this site actually collects, and is written to be accurate rather than exhaustive. It is not legal advice; have it reviewed before you rely on its legal effect.

1. Who we are (Controller)

This registry is operated by MPAI Store Ltd, Whitehall House, 33 Yeaman Shore, Dundee, Scotland, DD1 4BJ. For any privacy question, or to exercise your rights, contact privacy@mpai.store.

2. What this notice covers

This notice explains the personal data we process when you register as an Implementer and submit MPAI standards metadata. The Store is a registry of standards metadata and cryptographic trust statements; it does not host the actual implementation code/artifacts — those live on third-party sites (e.g. GitHub, Hugging Face) governed by their own privacy policies.

3. What we collect, why, and our legal basis

DataWhyLegal basis (GDPR)
Organization name, contact name, contact email (required) Create your Implementer account, issue your Implementer ID, authenticate and contact you about submissions. Art. 6(1)(b) — contract / pre-contract steps
Website, country (optional) Describe registry entries. You may leave these blank. Art. 6(1)(f) — legitimate interests
Account password & 2FA secrets Secure your account. Stored hashed (password) / as needed for 2FA; never shown back. Art. 6(1)(b) & Art. 32 (security)
Submission token Authenticate submissions. We store only a hashed form and show the token once. Art. 6(1)(b) & Art. 32
Public registry listing Org name & website shown publicly so consumers know who stands behind an implementation. Your contact name is published only if you opt in. Art. 6(1)(f) for business identifiers; Art. 6(1)(a) consent for the contact name
Technical/security logs Timestamp, event type, your IDs, and a truncated/hashed form of your IP for security and abuse prevention. Art. 6(1)(f) — legitimate interests (security)

Please do not put personal data in metadata fields. Standards metadata you submit is published and cryptographically signed; we cannot guarantee removal of personal data from signed records.

4. Who can see your data

5. International transfers

This registry and its data are hosted in United Kingdom (OVHcloud, London). Where personal data is transferred outside the UK/EEA, we rely on an adequacy decision or on Standard Contractual Clauses with the receiving party.

6. How long we keep your data (retention)

7. Your rights

You have the right to access your data (Art. 15), correct it (Art. 16), have it erased (Art. 17), restrict or object to processing (Art. 18/21), and receive it in a portable machine-readable format (Art. 20). Where processing is based on consent, you may withdraw it at any time. Signed-in implementers can download a JSON copy of their data and request erasure from their account page, or contact privacy@mpai.store. Because the registry is an append-only trust record, we fulfil erasure by anonymising your personal identifiers while retaining the non-personal registry entries. You may also lodge a complaint with your supervisory authority (e.g. the ICO in the UK, or your national data protection authority in the EEA).

8. Cookies

We use one strictly necessary cookie to keep a signed-in user's session and carry one-time status messages. Under the ePrivacy rules (PECR) this cookie is exempt from consent because it is essential to a service you request, so we do not show a cookie banner. We do not use analytics, advertising, or tracking cookies.

9. Is providing your data mandatory?

Organization name, contact name, and contact email are required to create an account — without them we cannot register you. Website and country are optional.

10. Changes

We will post updates here and increment the version number above.

See also the Disclaimer.