MUUD
ColegiosEmpresas
🏫ColegioPlataforma para instituciones💼EmpresaBienestar para equipos
Agendar demo
Para colegiosPara empresas
Iniciar sesión🏫 Colegio💼 Empresa
Agendar demo

Política de Privacidad MUUD SpA

Última actualización: August 10, 2026 · Effective date: August 10, 2026

This Privacy Policy explains how MUUD SpA, RUT 77.634.166-5, Av. Presidente Kennedy 5600, Of. 507, Vitacura, Santiago, Chile ("MUUD", "we", "us"), processes personal data in connection with the MUUD websites, mobile and web applications and related services (the "Services"). The Services are a student wellbeing platform provided primarily to schools and other educational institutions, and a team wellbeing offering for organizations. This Policy should be read together with our Terms of Service and, for institutions, the Data Processing Addendum ("DPA").

This Policy is drafted to comply with the data protection laws of the jurisdictions where MUUD operates, including the GDPR and UK GDPR, Spain's LOPDGDD, Brazil's LGPD, Chile's Law No. 19.628 and Law No. 21.719 (in force December 1, 2026), Mexico's LFPDPPP, Colombia's Law 1581 of 2012, Peru's Law No. 29733, Argentina's Law No. 25.326, the U.S. FERPA, COPPA and applicable state privacy and student privacy laws, and India's Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025 (collectively, "Applicable Data Protection Laws").

Summary of Key Points

  • (a) When your school uses MUUD, your school controls your data. MUUD processes Student Data only as the school's processor, under its instructions, to provide the Services.
  • (b) We collect only what the Services need. We do not collect data revealing race or ethnicity, political opinions or religious beliefs, and we do not ask for precise geolocation.
  • (c) Wellbeing check-ins and journal entries are sensitive. They are protected with heightened confidentiality, are visible only as described in Section 5, and are never used for advertising.
  • (d) We do not sell personal data, we do not show third-party advertising in the Services, and we do not use personal data of students or of any user for targeted advertising, offer walls, contests or similar commercial schemes.
  • (e) Children use MUUD only through their school, with consent obtained as required in their country.
  • (f) You have rights over your data, described in Section 11, and students and parents can also exercise them through their school.

Contents

  1. Who Is Responsible for Your Data (Roles)
  2. Information We Collect
  3. Purposes and Legal Bases
  4. Automated Analysis and AI Features
  5. Wellbeing Data: Confidentiality and Visibility
  6. De-identified and Aggregated Data
  7. When and With Whom We Share Personal Data
  8. International Data Transfers
  9. Retention
  10. Security and Breach Notification
  11. Your Rights
  12. Cookies and Similar Technologies
  13. Children's Privacy
  14. Jurisdiction-Specific Disclosures
  15. Contact
  16. Changes to This Policy

1. Who Is Responsible for Your Data (Roles)

1.1 School deployments. When you use the Services through a school or other institution ("Institutional Customer"), the institution is the data controller (responsable del tratamiento, controlador, or Data Fiduciary under the India DPDP Act) of Student Data and of the personal data of its staff processed in the platform. MUUD acts as data processor (encargado, operador, Data Processor), processing that data only on the institution's documented instructions under the DPA. Questions and rights requests concerning Student Data can be addressed to the institution or to MUUD; where MUUD receives them, we will coordinate with the institution.

1.2 Individual adult users and business teams. Where MUUD offers accounts to individual adults, or wellbeing services to companies for their adult team members, MUUD is the controller of account data, and the specific controller/processor allocation for company deployments is set out in the applicable agreement.

1.3 Website visitors, prospects and event participants. MUUD is the controller of personal data collected through our websites, demos, sales and marketing activities.

2. Information We Collect

2.1 Account and profile data. Name, email address, username, password (stored hashed), role (student, teacher, counselor, administrator), school, grade or course, and language. For students, accounts are provisioned by or at the direction of the school; we ask schools to provide only the minimum fields necessary.

2.2 Wellbeing data (sensitive). Check-in responses (for example, mood selections and short answers), journal entries, and interactions with wellbeing content. This data may reveal information about emotional state and is treated as sensitive personal data under Applicable Data Protection Laws (including GDPR Art. 9, LGPD Arts. 5 and 11, and Chilean Law No. 21.719). Section 5 describes exactly how it is used and who can see it.

2.3 Usage and device data. IP address, device and browser type, operating system, app version, language settings, log data (timestamps, features used, error reports) and approximate country/region derived from IP. We collect this to operate, secure and improve the Services. We do not collect precise GPS geolocation and we do not access your camera, microphone, contacts or photos except where a specific feature you choose to use requires it, with the operating system permission prompt, and never in the student experience without the school's configuration.

2.4 Billing data. For paying customers, billing contact details, tax ID and invoicing information. Card payments for individual purchases are processed by the app stores or by our payment processors; MUUD does not store full card numbers.

2.5 Support and communications. The content of your messages when you contact support, respond to surveys we run for product feedback, or attend demos and events.

2.6 Data we do not collect. We do not collect or process data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, or data concerning sex life or sexual orientation. We do not request government identification numbers from students. We do not use social media login for the Services, and we do not receive advertising or data-broker data about users.

2.7 Sources. We collect data directly from you, from your institution when it provisions and manages accounts, and automatically from your device as described in 2.3. We do not purchase personal data from third parties.

3. Purposes and Legal Bases

We process personal data only for the purposes below and only with a valid legal basis. Where MUUD acts as processor for an institution, the institution establishes the legal basis; those most commonly relied on are indicated for transparency.

PurposeData usedLegal basis (GDPR / LGPD / Law 21.719 and equivalents)
Provide the Services: accounts, check-ins, journals, wellbeing content, staff dashboards and alertsAccount data; wellbeing data; usage dataPerformance of the contract with the institution or user; for wellbeing (sensitive) data, the basis established by the controller: explicit consent of the user or parent/guardian, or another basis permitted by law for the educational and wellbeing purpose, always in the best interest of the student
Safety escalation: enabling designated school staff to follow up on wellbeing alertsWellbeing data; account dataSubstantial public interest / protection of vital interests of the data subject where applicable; the institution's legal duties of care toward students; explicit consent where required
Security, fraud prevention, troubleshootingUsage and device data; logsLegitimate interest in securing the Services; legal obligation
Support and communications about the service (not marketing)Account data; support messagesPerformance of contract; legitimate interest
Billing and administration of institutional subscriptionsBilling dataPerformance of contract; legal obligations (tax, accounting)
Product improvement and research on student wellbeingDe-identified and aggregated data only (Section 6)Legitimate interest; not applicable to identified personal data
Marketing to prospective institutional customers (never to students)Business contact data of school representativesLegitimate interest or consent, with opt-out at any time
Legal complianceAs requiredLegal obligation; establishment, exercise or defense of legal claims

We do not process personal data for third-party advertising, targeted advertising, offer walls, sweepstakes or contests, or the publication of testimonials containing personal data without specific prior consent. We do not use Student Data for marketing of any kind.

4. Automated Analysis and AI Features

4.1 The Services use software, including AI-based analysis, to organize check-in responses and, where the institution enables it, to flag patterns that may warrant human attention (for example, a sustained negative trend). These features exist to prioritize human follow-up by trained school staff. They do not produce clinical assessments or diagnoses.

4.2 No decision producing legal effects or similarly significant effects on a user is taken solely by automated means. Alerts are informational and any follow-up decision is made by people at the institution. Users and institutions can request human review of, and information about, the logic of these features (GDPR Art. 22, LGPD Art. 20, Law No. 21.719 and equivalents).

4.3 We do not use personal data, including wellbeing data, to train models for third parties, and we do not use identifiable Student Data to train our own models without the documented instruction of the controller and a valid legal basis; where model improvement uses data, we use de-identified and aggregated data under Section 6.

5. Wellbeing Data: Confidentiality and Visibility

5.1 Private by default. Personal journal entries are private to the user. They are not visible to school staff, other students or MUUD personnel in the ordinary course, except as strictly necessary for technical operation and support under confidentiality obligations and access logging.

5.2 What the school sees. Depending on the configuration disclosed to the institution, designated school staff can see check-in results, wellbeing trends and alerts for the students under their care. The institution decides which roles have access. Visibility never extends beyond what is necessary for the wellbeing purposes of the Services, and the specific visibility rules for each feature are documented for the institution and available to users on request.

5.3 Safety disclosures. If information processed in the Services indicates a serious and imminent risk to the life, safety or wellbeing of a user or of another person, the platform is designed so that the institution's designated staff are alerted and can act under the institution's own protocols and legal duties. MUUD may disclose information to competent authorities only where legally required or where necessary to protect someone's life or safety, and will document any such disclosure. MUUD is not an emergency service and does not monitor content in real time.

5.4 The Services are an educational wellbeing tool. They are not a medical, clinical, psychological or psychiatric service, and the data processed is not a medical record, without prejudice to its protection as sensitive data under Applicable Data Protection Laws.

6. De-identified and Aggregated Data

We may create de-identified, aggregated statistics (for example, overall wellbeing trends across a school, with no individual identifiable) to provide reporting to institutions, improve the Services and conduct research on student wellbeing. We apply the de-identification standards of Applicable Data Protection Laws, we contractually prohibit re-identification, and where a stricter student data standard applies (for example, certain U.S. state laws), we follow the stricter standard.

7. When and With Whom We Share Personal Data

7.1 With your institution. In school deployments, Student Data and staff data are available to the institution as controller, per the visibility rules in Section 5.

7.2 Subprocessors and service providers. We use vetted providers for hosting, infrastructure, communications and support (for example, cloud hosting providers). They process personal data only under contract, only on our instructions, with confidentiality and security obligations flowing down from the DPA. A current subprocessor list is available at [INSERT URL] or on request, and institutional customers receive advance notice of changes.

7.3 Legal and safety. We may disclose personal data where required by law, regulation or binding order of a competent authority, or where strictly necessary to protect the life or safety of a person (Section 5.3), or to establish, exercise or defend legal claims. Where legally permitted, we will notify the affected institution before disclosing Customer Data in response to a government request and will challenge overbroad requests.

7.4 Corporate transactions. If MUUD is involved in a merger, acquisition, financing or sale of assets, personal data may be transferred as part of that transaction, subject to this Policy and to Applicable Data Protection Laws. Institutional customers will be notified, protections applicable to Student Data will continue to apply, and if they do not, customers may terminate and require deletion of their data before the transfer takes effect.

7.5 What we never do. We do not sell or rent personal data. We do not share personal data with advertisers, ad networks or data brokers. We do not operate offer walls, third-party advertising or social plug-ins inside the Services, and no Student Data is ever disclosed for commercial purposes unrelated to the Services.

8. International Data Transfers

8.1 The Services are hosted in [INSERT HOSTING REGION(S)]. Where personal data is transferred to a country that does not provide an adequate level of protection, we implement the safeguards required by law: the European Commission's Standard Contractual Clauses (with the UK Addendum or IDTA, and Swiss adaptations, as applicable) together with transfer impact assessments; the mechanisms of LGPD Arts. 33 to 36 for Brazil, including the ANPD's standard contractual clauses; the international transfer conditions of Chilean Law No. 21.719; and equivalent mechanisms under the laws of Mexico, Colombia, Peru, Argentina and India, including any applicable government restrictions on transfers under the India DPDP framework.

8.2 We do not treat continued use of the Services as consent to international transfers. Copies of the relevant safeguards can be requested through the contacts in Section 15.

9. Retention

9.1 School deployments. We retain Customer Data, including Student Data, for the duration of the institution's subscription and as instructed by the institution, which can delete Student Data at any time using the administrative tools. Upon termination, data is available for export for at least 60 days and is then deleted from production systems within 90 days and from backups within the backup cycle, unless a longer retention is required by law. Deletion is certified on request.

9.2 Individual accounts. We retain personal data while the account is active. Upon deletion of the account, personal data is deleted or irreversibly anonymized within 90 days, except data we must retain to comply with legal obligations (for example, billing records for tax purposes), to resolve disputes or to enforce agreements, which is isolated and retained only as long as legally required. Free individual accounts inactive for 24 months may be deleted after at least 30 days' prior notice.

9.3 Website and marketing data. Business contact data of prospects is retained while relevant to the relationship and deleted upon opt-out or after a defined period of inactivity documented in our internal retention schedule.

10. Security and Breach Notification

10.1 We apply technical and organizational measures appropriate to the sensitivity of the data, including encryption in transit (TLS) and at rest, role-based access controls, least-privilege access for personnel, access logging and monitoring, environment segregation, secure development practices, regular backups and periodic security reviews. Personnel with access to personal data are bound by confidentiality obligations and receive privacy and security training.

10.2 If a personal data breach occurs, we will notify the affected institution without undue delay and in any event within 72 hours of becoming aware of it, with the information needed for the institution to meet its own obligations. Where MUUD is the controller, we will notify the competent supervisory authority (including, as applicable, the relevant EU/EEA authority, the AEPD, the ANPD, Chile's Agencia de Proteccion de Datos Personales, or India's Data Protection Board) and affected individuals, within the deadlines and with the content required by Applicable Data Protection Laws.

10.3 No system is completely secure, but MUUD does not disclaim its legal responsibility for implementing and maintaining the security measures required by Applicable Data Protection Laws.

11. Your Rights

11.1 Depending on your jurisdiction, you have the rights of access, rectification, erasure (deletion), restriction of processing, objection, data portability, withdrawal of consent (without affecting prior processing), and the right not to be subject to solely automated decisions with legal or similarly significant effects. These include the ARCO rights recognized across Latin America, the rights in GDPR Arts. 15 to 22, LGPD Art. 18, Chilean Law No. 21.719 (ARCO plus portability), the rights of Data Principals under the India DPDP Act (access, correction and erasure, grievance redressal, nomination), and the rights of U.S. state privacy laws where applicable (access, correction, deletion, portability, opt-out of targeted advertising, sale and profiling; note that MUUD does not sell or share personal data or engage in targeted advertising).

11.2 How to exercise your rights. Contact us at privacy@muud.app [OR INSERT ADDRESS], through in-product settings where available, or through the data request form linked in the Site footer. We will verify your identity using only the information necessary for verification, respond within the deadline set by your law (for example, one month under the GDPR, extendable as permitted; 15 days for confirmation and simplified access under the LGPD; the deadlines of Law No. 21.719 in Chile; 45 days under most U.S. state laws), and will not discriminate against you for exercising your rights. You may use an authorized agent where your law allows it, subject to proof of authorization.

11.3 Students and parents. In school deployments, students, parents and guardians can exercise rights directly with the institution, which remains the point of contact under FERPA and equivalent frameworks; MUUD provides the institution with the tools to review, correct, export and delete Student Data. Parents and guardians may review and request deletion of their child's data, and may refuse to permit further collection, through the institution or through MUUD, which will coordinate with the institution.

11.4 Complaints. You may lodge a complaint with your supervisory authority, including any EU/EEA data protection authority or the UK ICO, the Spanish AEPD, Brazil's ANPD, Chile's Agencia de Proteccion de Datos Personales (and consumer complaints before SERNAC), Mexico's data protection authority, Colombia's SIC, Peru's ANPD, Argentina's AAIP, the U.S. FTC or your state Attorney General, or India's Data Protection Board. We would appreciate the chance to address your concern first through the contacts in Section 15.

12. Cookies and Similar Technologies

12.1 The Site uses strictly necessary cookies (session, security, load balancing) and, with your consent where required, analytics cookies to understand aggregate usage. We do not use advertising or cross-site tracking cookies, and no advertising cookies are used in the student experience. A cookie banner and settings page allow you to accept, refuse and change your choices for non-essential cookies at any time; refusing them does not degrade core functionality.

12.2 We honor opt-out preference signals such as Global Privacy Control where required by applicable law. Because we do not track users across third-party sites, browser Do-Not-Track signals do not change our practices, which already do not include such tracking.

13. Children's Privacy

13.1 Children do not create MUUD accounts on their own. Student accounts exist only under an institutional subscription, provisioned by or at the direction of the school, with the notices and consents required by the law of the student's country obtained as described in the Terms of Service: parental notice and school authorization or verifiable parental consent under COPPA in the United States; consent of holders of parental authority for children under the applicable digital consent age in the EU (Art. 8 GDPR; 14 in Spain under the LOPDGDD); processing in the best interest of children and adolescents with specific and highlighted parental consent where required in Brazil (LGPD Art. 14); the requirements of Chilean law, including Law No. 21.719 as of its entry into force; equivalent requirements in other Latin American jurisdictions; and verifiable parental or guardian consent for all users under 18 in India (DPDP Act Section 9 and Rule 10 of the DPDP Rules, 2025), except to the extent a statutory exemption applies to educational contexts.

13.2 We do not track or behaviourally monitor children, do not profile children except as necessary to provide the contracted wellbeing features, and do not direct any advertising at children. If we learn that a child's personal data was collected without the required consent or authorization, we will delete it without undue delay and notify the institution.

14. Jurisdiction-Specific Disclosures

14.1 EEA, UK and Switzerland. Our legal bases are described in Section 3. Where required by Art. 27 GDPR / UK GDPR, our EU representative is [INSERT] and our UK representative is [INSERT]. Transfers are protected as per Section 8.

14.2 Spain. The digital consent age is 14 (LOPDGDD Art. 7). The AEPD is the supervisory authority. Where a Spanish school is the controller, the school determines the legal basis in accordance with Spanish education regulations and AEPD guidance for educational centers.

14.3 Brazil. Our encarregado (DPO) for LGPD purposes is [INSERT NAME AND CONTACT]. Data subjects may exercise LGPD Art. 18 rights through Section 11 and may petition the ANPD. Processing of children's and adolescents' data follows LGPD Art. 14 and ANPD guidance.

14.4 Chile. Processing is subject to Law No. 19.628 and, from December 1, 2026, Law No. 21.719, including its principles, sensitive data rules, ARCO and portability rights, breach notification and the authority of the Agencia de Proteccion de Datos Personales. This Policy is intended to operate in conformity with Law No. 21.719 as of its entry into force.

14.5 Other Latin American jurisdictions. In Mexico this document serves as the aviso de privacidad integral required by the LFPDPPP; ARCO requests follow Section 11. In Colombia, processing follows Law 1581 of 2012 and Decree 1377 of 2013, and this Policy, together with the institution's authorization records, implements the required data processing policy. In Peru (Law No. 29733) and Argentina (Law No. 25.326), registered databases and local requirements are maintained as applicable, and mandatory local rules prevail over any conflicting statement in this Policy.

14.6 United States. For school deployments, MUUD operates as a school official under FERPA and relies on school consent under COPPA as described in the Terms of Service; parents can review and request deletion of their child's information through the school. MUUD complies with state student privacy laws (including SOPIPA) and, where state consumer privacy laws such as the CCPA/CPRA, Virginia CDPA and similar laws apply, users have the rights listed in Section 11. MUUD does not sell or share personal information as defined by the CCPA, has not done so in the preceding 12 months, does not use or disclose sensitive personal information for purposes other than providing the Services, and does not knowingly process personal data for targeted advertising or profiling in furtherance of decisions with legal or similarly significant effects. California minors may request removal of content they posted (Cal. Bus. & Prof. Code 22581) through the contacts in Section 15. Categories of personal information collected are those described in Section 2; categories of recipients are those described in Section 7. Appeals of rights decisions, where state law grants them, may be sent to privacy@muud.app and will be answered with reasons within the statutory deadline, with information on contacting your Attorney General.

14.7 India. For users in India, MUUD and, where applicable, the institution as Data Fiduciary comply with the DPDP Act, 2023 and DPDP Rules, 2025: itemized notices in English or an Eighth Schedule language on request, consent as easy to withdraw as to give, verifiable parental consent for users under 18 (Section 13), no tracking, behavioural monitoring or targeted advertising directed at children, breach notification to affected Data Principals and the Data Protection Board, defined erasure timelines, and grievance redressal. Our Grievance Officer is [INSERT NAME], reachable at [INSERT EMAIL]; unresolved grievances may be escalated to the Data Protection Board of India.

15. Contact

Privacy contact / Data Protection Officer: privacy@muud.app

General support: soporte@muud.app | Tel: +56 9 2691 3974

Postal: MUUD SpA, Av. Presidente Kennedy 5600, Of. 507, Vitacura, Santiago, Chile

16. Changes to This Policy

We may update this Policy. Material changes will be notified at least 30 days in advance by email and/or in-product notice, identifying what changed; where a change requires renewed consent under Applicable Data Protection Laws (for example, a new purpose for sensitive data), we will obtain it before applying the change. The current version and its date are always published on the Site, and previous versions are available on request. In school deployments, changes affecting the processing of Student Data are also governed by the DPA and require the process set out there.

© 2026 MUUD SpA. All rights reserved.

MUUD

Impulsamos el desarrollo socioemocional de estudiantes y docentes con inteligencia artificial, para promover una sana convivencia escolar.

InstagramLinkedInFacebook

Soluciones

Para colegiosPara empresasInicioAcceso colegios

Legal

Términos y condicionesPolítica de privacidadEULAEliminar cuenta

Contacto

Av. Presidente Kennedy 5600, Of. 507, Vitacura, Chile
hola@muud.app

© 2026 MUUD SpA · Todos los derechos reservados

||
Hecho con cariño en Chile 🇨🇱