Trust
How we handle data, security and compliance.
Everything a procurement officer, programme funder or potential pilot partner would want to know on day one — in plain language, with honest status flags.
Data handling
What we collect, where it goes, who sees it.
-
What we collect from you
Field boundary data (GeoJSON / KML), soil chemistry results, crop and rotation history, target yields, weather observations, applied input records, and any photos / notes you choose to attach to records. We collect what you give us — no shadow telemetry.
-
Why we collect it
To produce field-level fertilisation plans, NDVI overlays, Farm Tasks and partner-ready evidence packs as described under your engagement agreement. Nothing else.
-
Where it's stored
Production data is held on infrastructure in the UK and EU (Cloudflare, AWS eu-west). Backups are encrypted at rest. Connection-level traffic is encrypted via TLS 1.3 in transit. We do not send your field data to third-party AI providers.
-
Who can see it
Your team and any advisers you invite. Mutus Tech staff with operational access (for support, debugging and platform improvement) — minimum necessary, audited. Never sold, never shared with advertisers or data brokers. Subprocessor list available on request under your engagement agreement.
-
Data you own
Your field data, soil test results, plan inputs and applied input records remain your data. You can export them at any time, and we will return or delete them on exit per the engagement terms.
-
Anonymised aggregates
We retain the right to use anonymised, aggregated learnings (e.g. average N rates by crop and region) to improve the platform and contribute to peer-reviewed research. Individual fields and farms are never identifiable in these aggregates.
Security posture
Where we stand, where we're heading.
We use honest status flags rather than "Certified ✓" badges. The roadmap below is what a procurement reviewer would actually want to evaluate.
| Control | Status | Note |
|---|---|---|
| Transport encryption | In place | TLS 1.3 enforced; HSTS preload candidate. |
| At-rest encryption | In place | Database and backup volumes encrypted using provider-managed keys. |
| Multi-factor auth (staff) | In place | Required for all production access; hardware-key preferred. |
| Cyber Essentials | Targeting 2026 | Standard UK government baseline — application in preparation. |
| Cyber Essentials Plus | Planned | Annual independent audit; targeted after stable production rollout. |
| ISO 27001 | Considering | Roadmap depends on enterprise / public-sector contract requirements. |
| Penetration testing | Annual | External pen-test on the platform; report available under NDA. |
| Vulnerability disclosure | Open | security@mutus.co.uk — responsible disclosure welcomed; we aim to acknowledge within 3 working days. |
Compliance & governance
The standards we operate under.
-
UK GDPR & Data Protection Act 2018
We process personal data as a controller in respect of our own users and as a processor where farm data is held on behalf of partners. Lawful basis: contract performance and legitimate interest. Subject rights honoured; requests via contact@mutus.co.uk.
-
PECR / cookies
This website does not set tracking cookies. No third-party analytics is loaded. The contact form uses Cloudflare Turnstile (no cookies). If we add analytics in future, we will declare it here and add a clear cookie banner first.
-
Companies House registration
Mutus Tech Ltd — company number 13274475 — UK private limited company since 2021. Registered office: 54 St James Street, Liverpool L1 0AB.
-
Accessibility
We aim to meet WCAG 2.1 AA across this website and the platform. See our accessibility statement for the current state, known issues and how to report problems.
Published policies
The policy documents behind that posture.
Mutus Tech maintains formal company policies covering data security, sharing and management. These are approved by the Managing Director, reviewed annually and published here so partners, funders and procurement reviewers can read them directly. A standard Data Use Agreement (DUA) template is also available on request under an active engagement or NDA.
-
Data Security Policy
Access control, classification, incident response and UK GDPR-aligned safeguards.
-
Data Sharing Policy
Controller / processor responsibilities, contracts and international transfers (UK GDPR Chapter V).
-
Data Management Policy
How data is collected, maintained, stored, shared and disposed of as a corporate asset.
-
Website Privacy Policy
How mutus.co.uk handles visitor data, server logs and contact form submissions.
-
Pezego App Privacy Policy
Privacy practices for the Pezego mobile application.
-
Accessibility Statement
WCAG 2.1 AA position, known issues and how to report accessibility problems.
Reporting issues
How to raise a concern.
Security disclosure
Found a vulnerability? Email contact@mutus.co.uk with subject "Security disclosure". We acknowledge within 3 working days.
Data request (GDPR)
Subject access, correction, deletion: contact@mutus.co.uk. We respond within one calendar month.
Accessibility issue
If something on this site is hard to use, email contact@mutus.co.uk. We aim to acknowledge within 5 working days.
This page is reviewed at least quarterly. Last reviewed: 23 May 2026.
Policies: Data Security · Data Sharing · Data Management · Website Privacy · Pezego App Privacy · Accessibility