Privacy Policy

Last updated: 12th August 2026

Your Privacy Matters

At Atomixair Technologies Ltd, we are committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, and protect your information in compliance with the UK GDPR, the Data Protection Act 2018 and the Data (Use and Access) Act 2025.

1. Introduction

Atomixair Technologies Ltd ("we", "us", or "our") is the data controller responsible for your personal data. This Privacy Policy applies to Intelli-BuildAI — our deterministic building performance, decarbonisation and project delivery platform — together with all of its modules, portals and related services (the "Service").

This policy should be read alongside our Terms of Service, which govern your use of the Service and our intellectual property.

We respect your privacy and are committed to protecting your personal data. This policy will inform you about how we look after your personal data and tell you about your privacy rights and how the law protects you.

2. Data Controller Information

Data Controller: Atomixair Technologies Ltd

Contact Email: info@muna-group.com

DPO Contact: info@muna-group.com

Supervisory Authority: Information Commissioner's Office (ICO), United Kingdom

3. Information We Collect

3.1 Personal Information

We collect the following personal information when you register for and use our Service:

  • Account Information: Full name, email address, password (encrypted)
  • Contact Details: Phone number, company name, job title, address
  • Profile Information: Company name, team/department name, professional details
  • Authentication Data: Login credentials, session tokens
  • Consent Records: Your separate choices for contact, marketing email and marketing telephone, each with the date and time recorded

No special category data. We do not collect or process special category personal data as defined by Article 9 of the UK GDPR — no health, biometric, genetic, racial or ethnic origin, political opinion, religious belief, trade union membership, sex life or sexual orientation data. Occupant feedback and indoor air quality monitoring are handled at building and zone level and are not used to draw conclusions about the health of identifiable individuals.

3.1a Business Contact and Enquiry Data

Where you contact us, request a demonstration, download a document or complete a building scan, we additionally hold a business enquiry record containing your professional contact details, the enquiry itself, your area of interest, the pages and campaigns that brought you to us, and a commercial qualification score and tier generated as described in section 5a.

3.2 Building and Project Data

When you use the Service, we collect and process:

  • Building characteristics (size, type, location)
  • Energy consumption data (electricity, gas, oil usage)
  • Energy Performance Certificate (EPC) information
  • Retrofit measure specifications and financial data
  • Project documents, drawings, schedules, tender packs and reports you create or upload
  • Commercial and financial project data, including cost plans, fee models and funding cases
  • Provenance and audit records — the standard, formula, input value, assumption, author and timestamp behind each calculated figure

How your data is processed: deterministic engines, not generative guesswork

Your building inputs are processed through our proprietary deterministic calculation engines — published CIBSE, ASHRAE and local-code methodologies executed as code. The same inputs produce the same outputs every time, and each figure is logged with the standard, formula and assumption that produced it. Your data is not fed to a language model to have an engineering number predicted.

AI is used only where it does not touch a calculated figure: reading and extracting from documents you upload, researching published standards, and drafting narrative text for your review.

We do not train generative models on your data

Anonymised and aggregated derivatives of your project data may be used to refine our deterministic engines and sector benchmarks. They are never used to train generative or large language models, and never in a form that could identify you, your client or your building.

3.3 Technical Information

We automatically collect certain technical information:

  • IP address and approximate geographic location
  • Browser type and version
  • Device information and operating system
  • Usage data (pages visited, features used, time spent)
  • Error logs and diagnostic information

3.4 Cookies and Tracking Technologies

We use cookies and similar technologies in three distinct categories. You control the analytics and marketing categories through the cookie banner shown on your first visit, and you can change your choice at any time. You can also instruct your browser to refuse all cookies.

Strictly necessary

No consent required

Sign-in sessions, security tokens and your cookie preference itself. The platform cannot function without these.

Analytics

Simplified consent

Low-risk statistical measurement of which pages and modules are used, so we can improve them. Handled under the relaxed consent rules introduced by the Data (Use and Access) Act 2025.

Marketing

Opt-in consent required

Advertising and campaign measurement. These are only set if you actively accept them, and you can withdraw at any time.

Refusing analytics or marketing cookies does not restrict your access to any part of the Service.

4. Legal Basis for Processing

We process your personal data under the following legal bases:

Contract Performance

Processing necessary to provide the Service you have registered for and to fulfill our contractual obligations.

Legitimate Interests

Processing necessary for our legitimate interests in operating, improving, and securing the Service, provided your interests and fundamental rights do not override those interests. As clarified in the UK GDPR by the Data (Use and Access) Act 2025, this expressly includes information technology and network security, intra-group administrative transfers, and direct marketing to business contacts.

Recognised Legitimate Interests

The Data (Use and Access) Act 2025 introduced a lawful ground for a defined list of recognised legitimate interests, for which no balancing test is required. We rely on this ground only where it genuinely applies — for example preventing fraud or crime against the Service, safeguarding, and responding to an emergency.

Consent

Where you have given explicit consent for specific processing activities, such as marketing communications.

Legal Obligations

Processing necessary to comply with our legal obligations under UK law.

5. How We Use Your Information

We use the information we collect for the following purposes:

  • Service Delivery: To provide, maintain, and improve the Service functionality
  • Account Management: To create and manage your user account
  • Calculations: To perform energy calculations, assessments, and generate reports
  • Customer Support: To respond to your inquiries and provide technical support
  • Service Improvement: To analyze usage patterns and improve Service features
  • Security: To detect, prevent, and address technical issues and security vulnerabilities
  • Communications: To send service-related notifications and updates
  • Marketing: To send promotional communications (only with your consent)
  • Research: To conduct research using anonymized and aggregated data, and to refine our deterministic calculation engines and sector benchmarks
  • Legal Compliance: To comply with legal obligations and protect our rights

5a. Automated Decision-Making and Profiling

We want to be direct about the one place where we profile people. Where you make a commercial enquiry, we generate a qualification score and tier, together with suggested outreach and a suggested pitch, to help our team prioritise and personalise their response. This is profiling within the meaning of the UK GDPR, and it is carried out under our legitimate interest in operating a commercial business.

We do not use profiling to price the Service differently for different people, to refuse anyone access, or to make any decision about your legal rights or entitlements. Every enquiry is handled by a person, and no special category data is involved at any stage.

The engineering outputs of the platform are not automated decisions about you. They are deterministic calculations about a building, produced from the inputs you supply, and they are always subject to review and professional verification by you.

Your safeguards under the Data (Use and Access) Act 2025

Where we make a decision about you that is based solely on automated processing and has a legal or similarly significant effect, the following safeguards apply without exception:

  • You will be informed. We tell you when a significant decision about you has been reached by automated means.
  • You may make representations. You can put your own case to us before or after the decision is applied.
  • You can obtain human intervention. A member of our team will review the decision meaningfully, not as a rubber stamp.
  • You can contest the decision. You may challenge the outcome and ask for it to be reconsidered.

To exercise any of these safeguards, contact us at info@muna-group.com and we will route your request to a member of our team with authority to change the outcome.

6. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including:

  • Account Data: Retained while your account is active, plus 12 months after account closure
  • Project Data: Retained while your account is active, or as required by you
  • Provenance, Audit and Evidence Records: Retained for 12 years from the date of the report they support. Because our outputs are relied upon for professional sign-off, the record of how each figure was derived must outlive the project itself so that any figure can be reconstructed and defended for the duration of professional liability
  • Financial Records: Retained for 7 years in accordance with UK tax law
  • Business Enquiry Records: Retained for 24 months from your last interaction with us, then deleted
  • Support Communications: Retained for 3 years
  • Analytics Data: Anonymized and retained for statistical purposes

You may request deletion of your data at any time by contacting us. We will comply with deletion requests except where we are required to retain data by law.

7. Data Sharing and Disclosure

7.1 We Do Not Sell Your Data

We do not sell, rent, or trade your personal data to third parties for their marketing purposes.

7.2 Service Providers

We share data with the following named sub-processors, each of which is bound by a written data processing agreement and may use your data only for the purpose we specify:

Sub-processorPurposeProcessing region
Base44Application hosting, database and authenticationEU / United States
StripePayment processing and subscription billingUnited States
GoogleAnalytics, Maps, Drive integration and email deliveryUnited States
MicrosoftOneDrive and SharePoint document integrationEU / United States
OpenAIDocument extraction and narrative drafting assistanceUnited States
MetaAdvertising measurement (only where you consent)United States
LinkedInMarketing publication and campaign measurementUnited States
Apify / FirecrawlPublic standards and product data collectionEU / United States

Marketing and advertising sub-processors receive data only where you have consented to marketing cookies or communications. We will update this list before adding any new sub-processor that handles personal data.

7.2a Collaborators, Clients and Lenders

The Service is built for collaboration, so project data you create may be shared with parties you or your team choose to involve:

  • Team members and project collaborators you invite, at the access level you grant them
  • Client portal guests — external parties given limited, capability-controlled access to milestones, documents, commercials or variations, as configured by the project team
  • Lenders and funding parties — where your team issues a due-diligence access grant, an authorised lender may view the project's financial, programme and evidence records through a read-only portal

These parties are recipients of the data, not our sub-processors. Every grant is explicit, scoped, revocable and logged, and every action taken within a portal is recorded in the project audit trail. We never initiate such sharing ourselves.

7.3 Legal Requirements

We may disclose your personal data where required by law, court order, or governmental authority, or where necessary to:

  • Comply with legal processes or regulatory requirements
  • Protect our rights, property, or safety
  • Prevent fraud or illegal activities
  • Enforce our Terms of Service

8. International Data Transfers

Your personal data is stored and processed in the United Kingdom, the European Economic Area and the United States. Several of the sub-processors listed in section 7.2 — including our hosting, payment, analytics and document-extraction providers — operate infrastructure in the United States, so transfers outside the UK do occur as a routine part of delivering the Service.

For every such transfer we put appropriate safeguards in place:

  • The UK International Data Transfer Agreement, or the EU Standard Contractual Clauses together with the UK Addendum
  • Reliance on the UK Extension to the EU–US Data Privacy Framework where the receiving organisation is certified under it
  • Transfer risk assessments, with supplementary technical measures such as encryption in transit and at rest
  • Adequacy regulations where the destination country benefits from one

Following the Data (Use and Access) Act 2025, the European Commission began the process of adopting renewed adequacy decisions for the United Kingdom in July 2025, allowing personal data to continue flowing freely between the EEA and the UK. We monitor the status of those decisions and will update this section if the position changes.

9. Data Security

We implement appropriate technical and organizational measures to protect your personal data:

Technical Measures

  • • Data encryption (in transit and at rest)
  • • Secure authentication protocols
  • • Regular security audits and testing
  • • Automated backup systems
  • • Intrusion detection systems

Organizational Measures

  • • Staff training on data protection
  • • Access controls and authorization
  • • Confidentiality agreements
  • • Incident response procedures
  • • Regular policy reviews

While we strive to protect your personal data, no method of transmission or storage is 100% secure. You are responsible for maintaining the confidentiality of your account credentials.

10. Your Rights Under UK GDPR

Under UK data protection law, you have the following rights:

Right of Access

Request a copy of the personal data we hold about you.

Right to Rectification

Request correction of inaccurate or incomplete personal data.

Right to Erasure ("Right to be Forgotten")

Request deletion of your personal data in certain circumstances.

Right to Restrict Processing

Request limitation of how we process your personal data.

Right to Data Portability

Receive your personal data in a structured, commonly used format.

Right to Object

Object to processing based on legitimate interests or for marketing purposes.

Right to Withdraw Consent

Withdraw consent for processing activities that require your consent.

Rights in Relation to Automated Decisions

Under the Data (Use and Access) Act 2025, be informed about a significant automated decision, make representations about it, obtain meaningful human intervention, and contest the outcome. See section 5a.

To exercise any of these rights, please contact us at info@muna-group.com. We will respond to your request within one month.

11. Marketing Communications

We will only send you marketing communications if you have given us your explicit consent. You can opt out of marketing communications at any time by:

  • Clicking the "unsubscribe" link in any marketing email
  • Updating your preferences in your account settings
  • Contacting us directly at info@muna-group.com

Note: You will continue to receive essential service-related communications regardless of your marketing preferences.

12. Children's Privacy

Our Service is not intended for individuals under 18 years of age. We do not knowingly collect personal data from children. If you become aware that a child has provided us with personal data, please contact us immediately.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. We will notify you of any material changes by:

  • Posting the new Privacy Policy on this page with an updated "Last updated" date
  • Sending an email notification to the address associated with your account
  • Displaying a prominent notice within the Service

We encourage you to review this Privacy Policy periodically for any changes.

14. Contact Us and Complaints

If you have any questions about this Privacy Policy or our data practices, please contact us:

Privacy Team: info@muna-group.com

Data Protection Officer: info@muna-group.com

General Support: info@muna-group.com

Right to Lodge a Complaint

You have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues:

ICO Website: www.ico.org.uk
ICO Helpline: 0303 123 1113

© 2025 Atomixair Technologies Ltd. All rights reserved.

This Privacy Policy is compliant with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Data (Use and Access) Act 2025.

See also our Terms of Service.