Effective: August 5, 2026 Last updated: August 5, 2026
This policy is an operating rule of Muze ME at https://amuzeme.fun/. It governs the current Muze ME service and is effective now. It must be followed as written unless a later published revision applies. It is reviewed and updated when the service, law, card-network rules, or providers change, and qualified counsel may revise it for the operator’s verified jurisdiction.
When this notice applies
This notice supplements the Privacy Notice when EU GDPR, EEA national law, or UK GDPR applies, including when Muze intentionally offers services to people in those territories or monitors their behavior there. Mere worldwide accessibility does not by itself decide territorial scope. Muze must document the territorial analysis before marketing to, onboarding, or behaviorally profiling people in the EEA or UK.
Controller, representatives, and data-protection contact
The exact legal controller name, registered address, privacy contact, and any jointly controlling party must be published before EEA or UK processing begins. If Article 27 or the UK equivalent requires a representative, the representative’s name and address must also be published. The operator must document whether large-scale monitoring or large-scale special-category processing requires a data protection officer and publish that contact when required. Until those verified details exist, EEA/UK targeting and monitoring are launch-blocked rather than covered with invented placeholders.
Purposes, lawful bases, and legitimate interests
Muze processes account and transaction data to perform a contract; security, fraud, moderation, service measurement, and limited personalization for documented legitimate interests balanced against user rights; tax, 2257, court, safety-reporting, and other records for legal obligations; and optional marketing or non-essential tracking on consent when required. Vital-interests or legal-claims bases are used only in the narrow circumstances the law permits. A purpose is not silently changed to an incompatible one.
Special-category and creator-verification data
Adult creator participation, sexual-life or orientation information, biometric comparison, health-related safety reports, and identity records can require Article 9 or equivalent safeguards. Before accepting this data from an EEA or UK person, Muze must document the precise lawful condition, complete any required data-protection impact assessment, minimize raw media, segregate access, set deletion and legal-hold rules, and obtain explicit consent only where consent is genuinely freely given and can lawfully be the basis. Agreement to the Terms is not Article 9 consent.
Recipients and international transfers
Necessary recipients may include hosting and security providers, adult-approved payment and payout providers, email services, analytics or anti-fraud vendors selected under the Cookie Notice, carriers and approved fulfillment providers, professional advisers, and authorities acting lawfully. Before an EEA or UK transfer, Muze must document the destination, role, data-processing agreement, subprocessor chain, and valid transfer mechanism, such as an adequacy decision or approved contractual clauses plus any required transfer-risk assessment and supplementary measures.
Retention and individual rights
The Data Retention Policy supplies working periods by record type. A person may request access, rectification, erasure, restriction, portability, objection to legitimate-interest or direct-marketing processing, and withdrawal of consent. They may complain to the supervisory authority where they live, work, or believe an infringement occurred. Muze answers within the applicable GDPR period, records extensions and exceptions, and does not charge unless a request is manifestly unfounded or excessive as the law permits.
Automated decisions and recommender systems
Muze may use bounded signals to order eligible content, detect fraud, or prioritize safety review, but server-side privacy, block, paid-access, moderation, and age rules control eligibility. Muze does not make a solely automated decision with legal or similarly significant effects unless a lawful Article 22 exception and required safeguards, meaningful information, human review, and contest route are documented. Main ranking factors and user controls are described in the Platform Integrity notice.
Operational readiness gate
A public notice is not enough. Before EEA or UK service is enabled, the owner must complete the controller and representative details, records of processing, vendor agreements, transfer assessment, consent records, cookie blocking, rights-response workflow, breach workflow, security review, DPIA decisions, deletion testing, and staff training. Where those controls are not ready, Muze must restrict the affected processing or territory.
Contact and notices
Use the Site contact process or the Complaints & Content Removal page. Do not send identity documents, tax forms, card data, or passwords through ordinary email.
