Muuh AS
Privacy notice
This notice explains how Muuh AS, as the controller for SiftBrief, handles personal data in this business-to-business service.
Effective 2026-08-02
Who is responsible
Muuh AS, organisation number 998153344, Sukkevannslia 4, 4638 Kristiansand, Norway, is responsible for the personal data described here. Øyvind Heggernes is the operational privacy contact.
SiftBrief is offered to businesses worldwide. Customer organisations remain responsible for ensuring that the instructions, sources, account users, and other personal data they submit to SiftBrief are lawful.
Data, purposes, and legal bases
We process business contact and account data, authentication and security data, workspace configuration, customer instructions, support correspondence, billing identifiers, service usage, consent choices, and public web content selected for Scan, Snapshot, or Monitor.
Data necessary to create accounts, deliver requested analysis, administer subscriptions, provide support, and fulfil customer requests is processed to perform the customer contract or requested pre-contract steps. Billing records and legally required documentation are processed to comply with legal obligations.
Security logging, abuse prevention, service reliability, product improvement using aggregated or minimised data, and limited business administration rely on our legitimate interests where those interests are not overridden by individual rights. Google Analytics runs only after consent and that consent can be withdrawn at any time.
Sources and recipients
Account data comes from users and customer administrators. Competitive evidence comes from public websites selected or approved through the service. Billing data comes from Stripe and Link, and technical data comes from use of the service.
We do not sell personal data. Data is disclosed only where needed to operate SiftBrief, comply with law, protect rights and security, or complete a corporate transaction subject to appropriate safeguards. Current service providers are listed on the Subprocessors page.
AI processing is limited to instructions and bounded evidence relevant to the requested analysis. SiftBrief does not intentionally collect sensitive personal data and customers must not submit it.
International transfers
Some providers may process data outside Norway or the EEA. Where required, Muuh AS will use an adequacy decision, approved standard contractual clauses, or another lawful transfer mechanism and assess supplementary safeguards.
Retention and deletion
When paid access ends, automated monitoring is paused and the workspace enters a 30-day recovery period. A new active subscription during that period cancels scheduled deletion. Otherwise, active customer service data is deleted or anonymised when the recovery period ends. A verified immediate deletion request bypasses the recovery period.
Protected backup copies expire no later than 90 days after the customer relationship ends or a valid immediate deletion request is accepted. Billing, accounting, security, fraud-prevention, contract-acceptance, dispute, and deletion-completion records may be retained longer when necessary to comply with law, establish or defend legal claims, or document deletion. Backups are not restored for ordinary product use after active data is deleted.
Workspace owners can request deletion in settings. Website operators can request exclusion from SiftBrief crawling on the crawler page.
Your rights
Subject to applicable law, individuals may request access, correction, deletion, restriction, portability, or objection, and may withdraw consent without affecting earlier lawful processing. We may need to verify identity before acting on a request.
Contact [email protected]. Individuals may also complain to the Norwegian Data Protection Authority or their competent local supervisory authority.
Automated analysis and security
SiftBrief uses AI to assist business analysis of public sources. It does not make decisions that produce legal or similarly significant effects about individuals. Output may be incomplete or incorrect and requires professional review.
We use access controls, encryption provided by managed infrastructure, bounded collection, private storage, redacted observability, and tested deletion workflows. No internet service can guarantee absolute security.
Operator and contact
Muuh AS, organisation number 998153344
Sukkevannslia 4, 4638 Kristiansand, Norway
Responsible contact: Øyvind Heggernes
General: [email protected]
Privacy: [email protected]