This page is written to describe Millwonder’s current practices and legal position clearly. It should be read with any contract that applies to a specific service or project.
1. Privacy programme
Millwonder’s privacy programme is intended to connect governance, records of processing, risk assessment, contract controls, supplier review, security, retention and individual-rights handling across corporate and AI data activities.
2. Roles in AI projects
For client datasets, the contract identifies whether Millwonder is a controller or processor. Project documentation should define permitted data, purpose, instructions, access roles, approved locations, subprocessors, retention, deletion and incident responsibilities.
3. Data minimisation and de-identification
Projects should collect only attributes required for the documented objective. Where feasible, direct identifiers are removed, separated, tokenised or replaced before annotation and evaluation. De-identification lowers risk but is not described as anonymous unless re-identification is not reasonably possible under applicable law.
4. Human-in-the-loop access
Contributors and reviewers receive access according to task and need. Controls may include confidentiality obligations, restricted workspaces, segmented datasets, download limits, watermarking, activity logs, quality sampling and removal of access when work ends.
5. Rights request process
Email privacy@millwonder.com with your country, relationship with Millwonder and request. We acknowledge, verify, search relevant systems, assess exemptions, coordinate with a client controller when necessary, and respond within the applicable period. There is no charge unless a law permits a reasonable fee for manifestly unfounded or excessive requests.
6. Security and incidents
Security controls are selected according to data sensitivity and project risk. Suspected loss, unauthorised access or misuse is escalated for containment, evidence preservation, risk assessment, notification decision, remediation and lessons learned.
7. Retention and deletion
Retention schedules consider project instructions, contract, legal obligations, limitation periods and security needs. At the end of an approved period, data is securely deleted, anonymised or retained under a documented legal hold. Backup deletion follows the applicable backup lifecycle.
8. Supplier and transfer controls
Providers handling personal data are reviewed proportionately and bound by data-processing, confidentiality, security, breach and deletion obligations. International transfers use a recognised legal mechanism and supplementary measures where required.
9. Contact and escalation
Privacy enquiries and rights requests: privacy@millwonder.com. Security concerns: security@millwonder.com. Ethical or worker-welfare concerns: ethics@millwonder.com. You may also contact the competent data-protection authority.

Contact ↗