Privacy Policy
Last updated: 12th August 2026
Your Privacy Matters
At Atomixair Technologies Ltd, we are committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, and protect your information in compliance with the UK GDPR, the Data Protection Act 2018 and the Data (Use and Access) Act 2025.
1. Introduction
Atomixair Technologies Ltd ("we", "us", or "our") is the data controller responsible for your personal data. This Privacy Policy applies to Intelli-BuildAI — our deterministic building performance, decarbonisation and project delivery platform — together with all of its modules, portals and related services (the "Service").
This policy should be read alongside our Terms of Service, which govern your use of the Service and our intellectual property.
We respect your privacy and are committed to protecting your personal data. This policy will inform you about how we look after your personal data and tell you about your privacy rights and how the law protects you.
2. Data Controller Information
Data Controller: Atomixair Technologies Ltd
Contact Email: info@muna-group.com
DPO Contact: info@muna-group.com
Supervisory Authority: Information Commissioner's Office (ICO), United Kingdom
3. Information We Collect
3.1 Personal Information
We collect the following personal information when you register for and use our Service:
- Account Information: Full name, email address, password (encrypted)
- Contact Details: Phone number, company name, job title, address
- Profile Information: Company name, team/department name, professional details
- Authentication Data: Login credentials, session tokens
- Consent Records: Your separate choices for contact, marketing email and marketing telephone, each with the date and time recorded
No special category data. We do not collect or process special category personal data as defined by Article 9 of the UK GDPR — no health, biometric, genetic, racial or ethnic origin, political opinion, religious belief, trade union membership, sex life or sexual orientation data. Occupant feedback and indoor air quality monitoring are handled at building and zone level and are not used to draw conclusions about the health of identifiable individuals.
3.1a Business Contact and Enquiry Data
Where you contact us, request a demonstration, download a document or complete a building scan, we additionally hold a business enquiry record containing your professional contact details, the enquiry itself, your area of interest, the pages and campaigns that brought you to us, and a commercial qualification score and tier generated as described in section 5a.
3.2 Building and Project Data
When you use the Service, we collect and process:
- Building characteristics (size, type, location)
- Energy consumption data (electricity, gas, oil usage)
- Energy Performance Certificate (EPC) information
- Retrofit measure specifications and financial data
- Project documents, drawings, schedules, tender packs and reports you create or upload
- Commercial and financial project data, including cost plans, fee models and funding cases
- Provenance and audit records — the standard, formula, input value, assumption, author and timestamp behind each calculated figure
How your data is processed: deterministic engines, not generative guesswork
Your building inputs are processed through our proprietary deterministic calculation engines — published CIBSE, ASHRAE and local-code methodologies executed as code. The same inputs produce the same outputs every time, and each figure is logged with the standard, formula and assumption that produced it. Your data is not fed to a language model to have an engineering number predicted.
AI is used only where it does not touch a calculated figure: reading and extracting from documents you upload, researching published standards, and drafting narrative text for your review.
We do not train generative models on your data
Anonymised and aggregated derivatives of your project data may be used to refine our deterministic engines and sector benchmarks. They are never used to train generative or large language models, and never in a form that could identify you, your client or your building.
3.3 Technical Information
We automatically collect certain technical information:
- IP address and approximate geographic location
- Browser type and version
- Device information and operating system
- Usage data (pages visited, features used, time spent)
- Error logs and diagnostic information
3.4 Cookies and Tracking Technologies
We use cookies and similar technologies in three distinct categories. You control the analytics and marketing categories through the cookie banner shown on your first visit, and you can change your choice at any time. You can also instruct your browser to refuse all cookies.
Strictly necessary
No consent required
Sign-in sessions, security tokens and your cookie preference itself. The platform cannot function without these.
Analytics
Simplified consent
Low-risk statistical measurement of which pages and modules are used, so we can improve them. Handled under the relaxed consent rules introduced by the Data (Use and Access) Act 2025.
Marketing
Opt-in consent required
Advertising and campaign measurement. These are only set if you actively accept them, and you can withdraw at any time.
Refusing analytics or marketing cookies does not restrict your access to any part of the Service.
4. Legal Basis for Processing
We process your personal data under the following legal bases:
Contract Performance
Processing necessary to provide the Service you have registered for and to fulfill our contractual obligations.
Legitimate Interests
Processing necessary for our legitimate interests in operating, improving, and securing the Service, provided your interests and fundamental rights do not override those interests. As clarified in the UK GDPR by the Data (Use and Access) Act 2025, this expressly includes information technology and network security, intra-group administrative transfers, and direct marketing to business contacts.
Recognised Legitimate Interests
The Data (Use and Access) Act 2025 introduced a lawful ground for a defined list of recognised legitimate interests, for which no balancing test is required. We rely on this ground only where it genuinely applies — for example preventing fraud or crime against the Service, safeguarding, and responding to an emergency.
Consent
Where you have given explicit consent for specific processing activities, such as marketing communications.
Legal Obligations
Processing necessary to comply with our legal obligations under UK law.
5. How We Use Your Information
We use the information we collect for the following purposes:
- Service Delivery: To provide, maintain, and improve the Service functionality
- Account Management: To create and manage your user account
- Calculations: To perform energy calculations, assessments, and generate reports
- Customer Support: To respond to your inquiries and provide technical support
- Service Improvement: To analyze usage patterns and improve Service features
- Security: To detect, prevent, and address technical issues and security vulnerabilities
- Communications: To send service-related notifications and updates
- Marketing: To send promotional communications (only with your consent)
- Research: To conduct research using anonymized and aggregated data, and to refine our deterministic calculation engines and sector benchmarks
- Legal Compliance: To comply with legal obligations and protect our rights
5a. Automated Decision-Making and Profiling
We want to be direct about the one place where we profile people. Where you make a commercial enquiry, we generate a qualification score and tier, together with suggested outreach and a suggested pitch, to help our team prioritise and personalise their response. This is profiling within the meaning of the UK GDPR, and it is carried out under our legitimate interest in operating a commercial business.
We do not use profiling to price the Service differently for different people, to refuse anyone access, or to make any decision about your legal rights or entitlements. Every enquiry is handled by a person, and no special category data is involved at any stage.
The engineering outputs of the platform are not automated decisions about you. They are deterministic calculations about a building, produced from the inputs you supply, and they are always subject to review and professional verification by you.
Your safeguards under the Data (Use and Access) Act 2025
Where we make a decision about you that is based solely on automated processing and has a legal or similarly significant effect, the following safeguards apply without exception:
- You will be informed. We tell you when a significant decision about you has been reached by automated means.
- You may make representations. You can put your own case to us before or after the decision is applied.
- You can obtain human intervention. A member of our team will review the decision meaningfully, not as a rubber stamp.
- You can contest the decision. You may challenge the outcome and ask for it to be reconsidered.
To exercise any of these safeguards, contact us at info@muna-group.com and we will route your request to a member of our team with authority to change the outcome.
6. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including:
- Account Data: Retained while your account is active, plus 12 months after account closure
- Project Data: Retained while your account is active, or as required by you
- Provenance, Audit and Evidence Records: Retained for 12 years from the date of the report they support. Because our outputs are relied upon for professional sign-off, the record of how each figure was derived must outlive the project itself so that any figure can be reconstructed and defended for the duration of professional liability
- Financial Records: Retained for 7 years in accordance with UK tax law
- Business Enquiry Records: Retained for 24 months from your last interaction with us, then deleted
- Support Communications: Retained for 3 years
- Analytics Data: Anonymized and retained for statistical purposes
You may request deletion of your data at any time by contacting us. We will comply with deletion requests except where we are required to retain data by law.
7. Data Sharing and Disclosure
7.1 We Do Not Sell Your Data
We do not sell, rent, or trade your personal data to third parties for their marketing purposes.
7.2 Service Providers
We share data with the following named sub-processors, each of which is bound by a written data processing agreement and may use your data only for the purpose we specify:
| Sub-processor | Purpose | Processing region |
|---|---|---|
| Base44 | Application hosting, database and authentication | EU / United States |
| Stripe | Payment processing and subscription billing | United States |
| Analytics, Maps, Drive integration and email delivery | United States | |
| Microsoft | OneDrive and SharePoint document integration | EU / United States |
| OpenAI | Document extraction and narrative drafting assistance | United States |
| Meta | Advertising measurement (only where you consent) | United States |
| Marketing publication and campaign measurement | United States | |
| Apify / Firecrawl | Public standards and product data collection | EU / United States |
Marketing and advertising sub-processors receive data only where you have consented to marketing cookies or communications. We will update this list before adding any new sub-processor that handles personal data.
7.2a Collaborators, Clients and Lenders
The Service is built for collaboration, so project data you create may be shared with parties you or your team choose to involve:
- Team members and project collaborators you invite, at the access level you grant them
- Client portal guests — external parties given limited, capability-controlled access to milestones, documents, commercials or variations, as configured by the project team
- Lenders and funding parties — where your team issues a due-diligence access grant, an authorised lender may view the project's financial, programme and evidence records through a read-only portal
These parties are recipients of the data, not our sub-processors. Every grant is explicit, scoped, revocable and logged, and every action taken within a portal is recorded in the project audit trail. We never initiate such sharing ourselves.
7.3 Legal Requirements
We may disclose your personal data where required by law, court order, or governmental authority, or where necessary to:
- Comply with legal processes or regulatory requirements
- Protect our rights, property, or safety
- Prevent fraud or illegal activities
- Enforce our Terms of Service
8. International Data Transfers
Your personal data is stored and processed in the United Kingdom, the European Economic Area and the United States. Several of the sub-processors listed in section 7.2 — including our hosting, payment, analytics and document-extraction providers — operate infrastructure in the United States, so transfers outside the UK do occur as a routine part of delivering the Service.
For every such transfer we put appropriate safeguards in place:
- The UK International Data Transfer Agreement, or the EU Standard Contractual Clauses together with the UK Addendum
- Reliance on the UK Extension to the EU–US Data Privacy Framework where the receiving organisation is certified under it
- Transfer risk assessments, with supplementary technical measures such as encryption in transit and at rest
- Adequacy regulations where the destination country benefits from one
Following the Data (Use and Access) Act 2025, the European Commission began the process of adopting renewed adequacy decisions for the United Kingdom in July 2025, allowing personal data to continue flowing freely between the EEA and the UK. We monitor the status of those decisions and will update this section if the position changes.
9. Data Security
We implement appropriate technical and organizational measures to protect your personal data:
Technical Measures
- • Data encryption (in transit and at rest)
- • Secure authentication protocols
- • Regular security audits and testing
- • Automated backup systems
- • Intrusion detection systems
Organizational Measures
- • Staff training on data protection
- • Access controls and authorization
- • Confidentiality agreements
- • Incident response procedures
- • Regular policy reviews
While we strive to protect your personal data, no method of transmission or storage is 100% secure. You are responsible for maintaining the confidentiality of your account credentials.
10. Your Rights Under UK GDPR
Under UK data protection law, you have the following rights:
Right of Access
Request a copy of the personal data we hold about you.
Right to Rectification
Request correction of inaccurate or incomplete personal data.
Right to Erasure ("Right to be Forgotten")
Request deletion of your personal data in certain circumstances.
Right to Restrict Processing
Request limitation of how we process your personal data.
Right to Data Portability
Receive your personal data in a structured, commonly used format.
Right to Object
Object to processing based on legitimate interests or for marketing purposes.
Right to Withdraw Consent
Withdraw consent for processing activities that require your consent.
Rights in Relation to Automated Decisions
Under the Data (Use and Access) Act 2025, be informed about a significant automated decision, make representations about it, obtain meaningful human intervention, and contest the outcome. See section 5a.
To exercise any of these rights, please contact us at info@muna-group.com. We will respond to your request within one month.
11. Marketing Communications
We will only send you marketing communications if you have given us your explicit consent. You can opt out of marketing communications at any time by:
- Clicking the "unsubscribe" link in any marketing email
- Updating your preferences in your account settings
- Contacting us directly at info@muna-group.com
Note: You will continue to receive essential service-related communications regardless of your marketing preferences.
12. Children's Privacy
Our Service is not intended for individuals under 18 years of age. We do not knowingly collect personal data from children. If you become aware that a child has provided us with personal data, please contact us immediately.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. We will notify you of any material changes by:
- Posting the new Privacy Policy on this page with an updated "Last updated" date
- Sending an email notification to the address associated with your account
- Displaying a prominent notice within the Service
We encourage you to review this Privacy Policy periodically for any changes.
14. Contact Us and Complaints
If you have any questions about this Privacy Policy or our data practices, please contact us:
Privacy Team: info@muna-group.com
Data Protection Officer: info@muna-group.com
General Support: info@muna-group.com
Right to Lodge a Complaint
You have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues:
ICO Website: www.ico.org.uk
ICO Helpline: 0303 123 1113
© 2025 Atomixair Technologies Ltd. All rights reserved.
This Privacy Policy is compliant with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Data (Use and Access) Act 2025.
See also our Terms of Service.
