This page is written to describe Millwonder’s current practices and legal position clearly. It should be read with any contract that applies to a specific service or project.
1. Application
This statement describes Millwonder’s approach where Regulation (EU) 2016/679, the UK GDPR or related national data-protection law applies. The role of each Millwonder entity—controller, joint controller or processor—depends on the service and contract.
2. Data-protection principles
We seek to process personal data lawfully, fairly and transparently; collect it for specified purposes; limit it to what is necessary; keep it accurate; retain it no longer than required; protect it with appropriate security; and demonstrate accountability.
3. Controller and processor responsibilities
When acting as controller, Millwonder determines purposes and legal bases and provides required information. When acting as processor for a client, Millwonder processes data only on documented instructions, imposes confidentiality, applies security, controls subprocessors, assists with rights and incidents, and returns or deletes data as agreed.
4. Lawful bases
Depending on the processing, we rely on contract, pre-contract steps, legal obligation, legitimate interests, consent or another basis permitted by Article 6. Special-category data requires an additional Article 9 condition or equivalent UK condition. We document assessments where legitimate interests or high-risk processing is involved.
5. Privacy by design and DPIAs
New products, AI data programmes and material process changes are reviewed for privacy risks. We use data minimisation, access controls, retention rules and appropriate de-identification. A data protection impact assessment is completed where processing is likely to create a high risk to individuals.
6. International transfers
Transfers outside the EEA or UK use a lawful transfer mechanism and, where required, a transfer-risk assessment and supplementary measures. Mechanisms may include adequacy regulations, approved standard contractual clauses or the UK International Data Transfer Addendum.
7. Data-subject rights
Individuals may have rights of information, access, correction, erasure, restriction, portability, objection and withdrawal of consent, plus protections relating to solely automated decisions with legal or similarly significant effects. Rights are subject to statutory conditions and exemptions.
8. Security and breach response
Access is limited according to role and business need. We maintain incident assessment and escalation procedures. Where a personal-data breach creates the relevant legal threshold, the competent authority is notified within the legally required period and affected individuals are informed when required.
9. Requests and complaints
Send a rights request to privacy@millwonder.com. Include your country, relationship with Millwonder and the right you wish to exercise. We may request proportionate identity verification. You may also complain to the supervisory authority where you live, work or believe an infringement occurred.

Contact ↗