Mulium · Privacy

Privacy Statement

Last updated 13 June 2026 · Version 2.0 · Mulium Holding LLC

Mulium treats discretion as a condition of the work, not a courtesy. This Privacy Statement explains in detail what information may be processed when you use this website, the purposes and legal bases for that processing, with whom it may be shared, how long it is kept, how it is protected, and the rights you can exercise over it. We keep our data practices deliberately minimal; this document is nonetheless set out in full for transparency.

01Introduction and scope

This Statement applies to personal data processed through this website and through the enquiry channel made available on it. It does not govern the separate, matter-specific processing carried out under a written engagement, which is addressed by the data-protection provisions of that engagement. By using this website, you acknowledge that you have read and understood this Statement.

We may provide additional or supplementary privacy notices for specific interactions where appropriate. In the event of any conflict between such a specific notice and this Statement, the specific notice prevails for that interaction.

02Definitions

In this Statement the following terms have the meanings given below:

03Who is responsible

The controller of personal data processed through this website is Mulium Holding LLC, a privately held advisory practice. You can reach the person responsible for data matters through the enquiry channel on this site; requests are routed internally to the appropriate handler.

04Information we collect

We collect only what is necessary. The categories of information that may be processed are:

Information you provide

When you open a channel, you choose to provide a name or identifier, an indication of where you are writing from, and a brief description of the matter. We receive only what you type; no field requests sensitive categories of data, and we ask that you not include them.

Information collected automatically

As with any website, the hosting and security layer records limited technical data necessary to deliver and protect the service, such as IP address, browser and device type, referring page, and the date and time of requests. This data is used for delivery, security, and abuse-prevention, and is not used to identify you personally.

Information we do not seek

We do not knowingly collect special categories of personal data through this website, and we do not purchase or enrich visitor data from third-party brokers.

05Cookies and similar technologies

This website uses only cookies or local storage that are strictly necessary for its operation, security, and performance. We do not operate advertising cookies, cross-site trackers, or social-media pixels, and we do not use analytics that build a profile of you across sites. Because only strictly necessary technologies are used, they operate without a consent banner; you may nonetheless block cookies in your browser, though parts of the site may then not function.

06How we use information

We process information for a limited set of purposes:

07Legal bases for processing

Where the GDPR applies, we rely on the following legal bases under Article 6(1):

Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms; you may object as described below.

08Disclosure of information

We do not sell, rent, or trade personal data. We may disclose information only:

09Service providers and infrastructure

We rely on a small number of infrastructure providers (principally web hosting located within the European Union and a content-delivery and security network) that process data only on our documented instructions and under appropriate confidentiality and data-protection terms. These providers are not permitted to use the data for their own purposes.

10International transfers

Because the controller is established in the United States while the website infrastructure is located in the European Union, personal data may be transferred across borders. Any transfer of personal data outside the European Economic Area is made under the safeguards required by the GDPR, such as adequacy decisions or standard contractual clauses, together with appropriate supplementary measures.

11Data retention

We keep personal data only for as long as necessary for the purpose for which it was collected, or as required by law, and then delete or anonymise it. Enquiry correspondence is retained only as long as needed to assess and respond to the matter; technical access logs are retained for a limited period for security purposes. Where an engagement proceeds, retention is governed by the terms of that engagement.

12Security

We apply technical and organisational measures appropriate to the risk, including transport encryption (HTTPS), access controls, network and platform security at the hosting and delivery layer, and the principle of data minimisation. No method of transmission or storage is completely secure; while we work to protect your information, we cannot guarantee absolute security.

13Your rights

Subject to the conditions and exemptions set out in applicable law, you have the right to:

To exercise any of these rights, write to us through the channel on this site. We will respond within the time limits set by applicable law and may ask you to verify your identity before acting.

14Complaints to a supervisory authority

If you believe our processing of your personal data infringes the law, you have the right to lodge a complaint with a data-protection supervisory authority, in particular the authority in your country of residence or place of work within the European Economic Area. We would, however, appreciate the opportunity to address your concern directly before you do so.

15Automated decision-making

We do not make decisions producing legal or similarly significant effects about you based solely on automated processing, and we do not carry out profiling of website visitors.

16Children

This website is intended for professional and institutional audiences and is not directed to children. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, please contact us and we will delete it.

17Third-party links

This website may contain links to third-party resources. We are not responsible for the privacy practices or content of those third parties, and this Statement does not apply to them. We encourage you to review the privacy notices of any site you visit.

18Changes and how to contact us

We may update this Statement from time to time to reflect changes in our practice or in the law. The date and version at the top indicate when it was last revised; material changes will be reflected there. For any question about this Statement or about how we handle your data, contact us through the channel on this site.

This Statement reflects our operating posture and is provided in good faith. It is not a substitute for the formal, matter-specific data-protection terms issued on engagement, which a qualified adviser settles for each matter.