Privacy & data protection
Last updated: 10 September 2026
GMuller AI, Helsinki, Finland, is the controller for personal data submitted through this website and its B2B portals. Contact: goncalomuller@hotmail.com.
Data we process
We process name, email, optional contact details, Digital Product acquisition and entitlement records, enquiry and application content, authenticated account details, project and support records, approvals, audit and security events, files you choose to provide, and manually initiated contract or payment records.
Purposes and legal bases
Data is used to fulfil requested Digital Product acquisitions, create and maintain a CRM contact record, manage product entitlement and controlled fulfilment, answer B2B enquiries, prepare or perform agreements, deliver services, secure systems, meet legal obligations, and pursue legitimate interests in operating and improving GMuller AI.
Marketing choices
Acquiring a product does not automatically provide marketing consent. Marketing consent is a separate choice and is recorded with its status and provenance. You may withdraw consent at any time without affecting an acquisition already requested.
The optional weekly Digital Products email is unchecked by default and requires confirmation by email. Pending requests receive at most one reminder after approximately three days and expire after seven days. Transactional product-access messages are independent from marketing consent. Withdrawal immediately suppresses further marketing messages.
Processors and transfers
Approved infrastructure and service providers may process data for hosting, authentication, database, communications, AI inference or governed voice synthesis. Access is scoped server-side. International transfers require an applicable lawful safeguard.
Retention and rights
Data is retained only while needed for the stated purpose, security, contractual or legal requirements. Subject to applicable law, you may request access, correction, deletion, restriction, portability or object to processing. You may complain to Finland’s Data Protection Ombudsman.
Raw anonymous Digital Product interaction events are retained for no more than 90 days; longer-lived reporting uses aggregated metrics. Anonymous measurement does not use fingerprinting, and conversions that cannot be reliably attributed remain unattributed.
Security
We use authentication, role-based access, row-level isolation, approval gates, audit records and server-side secret handling. No internet system is risk-free; suspected incidents should be reported promptly to the contact above.
Paid digital-product privacy supplement
Working consumer wording. Independent legal review remains pending. Checkout is closed. consumer-commerce-privacy-2026-09-25-v3
Order and contact data
For consumer purchases we process purchaser email and contact details, Stripe/Sold through Link order and transaction identifiers, amount, currency, payment state, product and edition, consent evidence and legal-copy versions. Stripe and Sold through Link handle payment information in their roles; GMuller AI does not store card credentials.
Fulfilment and support
We connect the purchase to our person-first CRM, entitlement, secure delivery and recovery records, transactional confirmation and access emails, and support, withdrawal, defect, refund and security records. Transactional messages do not depend on marketing consent; optional marketing is a separate choice.
Purpose, retention and rights
We keep the minimum purchaser, order and edition-entitlement link while permanent access is owed. Transaction and accounting evidence is retained for the applicable legal period according to its record type and the seller's obligations. Consent, contract confirmation and withdrawal, refund or defect evidence remains while needed for consumer rights, unresolved claims or legal holds, then is reviewed for minimisation. Temporary access links expire independently of entitlement; a successfully sent access link is removed from our email outbox. Operational and security records are reviewed separately for their purpose. Optional marketing consent and its suppression evidence are separate from the purchase. We use controlled server access and applicable safeguards for international transfers. Privacy requests: gmullerai@gmail.com.
This notice requires final legal review before public production launch.