Privacy notice
Last updated: 2026-07-03 · Version: 1.0
1. Who we are (Controller)
This registry is operated by MPAI Store Ltd, Whitehall House, 33 Yeaman Shore, Dundee, Scotland, DD1 4BJ. For any privacy question, or to exercise your rights, contact privacy@mpai.store.
2. What this notice covers
This notice explains the personal data we process when you register as an Implementer and submit MPAI standards metadata. The Store is a registry of standards metadata and cryptographic trust statements; it does not host the actual implementation code/artifacts — those live on third-party sites (e.g. GitHub, Hugging Face) governed by their own privacy policies.
3. What we collect, why, and our legal basis
| Data | Why | Legal basis (GDPR) |
|---|---|---|
| Organization name, contact name, contact email (required) | Create your Implementer account, issue your Implementer ID, authenticate and contact you about submissions. | Art. 6(1)(b) — contract / pre-contract steps |
| Website, country (optional) | Describe registry entries. You may leave these blank. | Art. 6(1)(f) — legitimate interests |
| Account password & 2FA secrets | Secure your account. Stored hashed (password) / as needed for 2FA; never shown back. | Art. 6(1)(b) & Art. 32 (security) |
| Submission token | Authenticate submissions. We store only a hashed form and show the token once. | Art. 6(1)(b) & Art. 32 |
| Public registry listing | Org name & website shown publicly so consumers know who stands behind an implementation. Your contact name is published only if you opt in. | Art. 6(1)(f) for business identifiers; Art. 6(1)(a) consent for the contact name |
| Technical/security logs | Timestamp, event type, your IDs, and a truncated/hashed form of your IP for security and abuse prevention. | Art. 6(1)(f) — legitimate interests (security) |
Please do not put personal data in metadata fields. Standards metadata you submit is published and cryptographically signed; we cannot guarantee removal of personal data from signed records.
4. Who can see your data
- The public: your organization name, website, opted-in contact name, your Implementer/Implementation IDs, and the standards metadata you publish.
- The Store administrator: the above plus your contact email and logs.
- We do not sell your data, and we do not use it for advertising or profiling.
5. International transfers
This registry and its data are hosted in United Kingdom (OVHcloud, London). Where personal data is transferred outside the UK/EEA, we rely on an adequacy decision or on Standard Contractual Clauses with the receiving party.
6. How long we keep your data (retention)
- Account data: kept while your account is in use. If you ask us to erase it, we act on that request straight away — see Your rights below. Otherwise an account with no sign-in for 24 months is treated as abandoned and its personal identifiers are anonymised automatically, unless we still need them to defend a legal claim. If you have published implementations, your account is referred to an operator for review instead of being anonymised automatically, because those entries remain part of the public registry.
- Public registry entries and signed trust statements: retained as a permanent registry record. If you ask us to erase your data, we anonymise your personal identifiers (name, email, IP) while keeping the pseudonymous Implementer/Implementation IDs and the technical standards metadata, which no longer identify you.
- Security/IP logs: we never store your raw IP address — it is replaced by a one-way pseudonym at the moment it is written. That pseudonym is removed after 90 days. The audit record of the action itself is kept without it, so the event history remains but stops being linkable to you.
7. Your rights
You have the right to access your data (Art. 15), correct it (Art. 16), have it erased (Art. 17), restrict or object to processing (Art. 18/21), and receive it in a portable machine-readable format (Art. 20). Where processing is based on consent, you may withdraw it at any time. Signed-in implementers can download a JSON copy of their data and request erasure from their account page, or contact privacy@mpai.store. Because the registry is an append-only trust record, we fulfil erasure by anonymising your personal identifiers while retaining the non-personal registry entries. You may also lodge a complaint with your supervisory authority (e.g. the ICO in the UK, or your national data protection authority in the EEA).
8. Cookies
We use one strictly necessary cookie to keep a signed-in user's session and carry one-time status messages. Under the ePrivacy rules (PECR) this cookie is exempt from consent because it is essential to a service you request, so we do not show a cookie banner. We do not use analytics, advertising, or tracking cookies.
9. Is providing your data mandatory?
Organization name, contact name, and contact email are required to create an account — without them we cannot register you. Website and country are optional.
10. Changes
We will post updates here and increment the version number above.
See also the Disclaimer.