MBR Technology LLC Data Privacy Policy
Version 1.1 · Effective 3 July 2026 · Approved by Bernhard Ritz, CEO
MBR Technology LLC operates the Ainzel AI Capability Management Platform. This policy is the company privacy statement for MBR Technology LLC as a legal entity and supplier. How the Ainzel platform processes customer data is described in the Ainzel Data Privacy Policy.
1. Purpose
This policy describes how MBR Technology LLC collects, uses, shares, retains, and deletes personal data when it:
- Acts as a supplier or professional-services provider
- Names employees, contractors, or subcontractors to a customer for onboarding, security review, or third-party risk assessment
- Handles engagement communications and work product outside the Ainzel platform
It exists so that people whose data we handle, and customers who request that data, can see what we do with it.
2. Relationship to the Ainzel platform
MBR Technology LLC operates the Ainzel AI Capability Management Platform. When a customer uses the platform, the Ainzel Data Privacy Policy governs Customer Content, account data, and operational data processed by the platform. This MBR policy does not replace that document.
When both apply, the Ainzel Data Privacy Policy covers platform processing and this policy covers company and supplier processing. A signed customer agreement or Data Processing Agreement (DPA) governs if it conflicts with either policy.
3. Scope
This policy applies to:
- Personnel and due-diligence data — names, roles, contact details, and relationship disclosures of employees, contractors, and subcontractors that we provide to a customer for onboarding, security review, or third-party risk assessment
- Engagement data — communications and work product created while performing professional services for a customer, outside the platform
- Company contact data — business contact details used to contract, invoice, and support a customer relationship
It applies worldwide. It does not cover platform Customer Content. That is in the Ainzel Data Privacy Policy.
4. Roles
| Data | MBR role | Meaning |
|---|---|---|
| Personnel and due-diligence data about our people | Controller | We decide what to collect and what to share with a requesting customer |
| Engagement and company contact data we create or hold as the supplier | Controller | We determine the purpose and means of that processing |
| Customer Content on the Ainzel platform | Processor (via Ainzel) | Processed only on the customer's instructions, as described in the Ainzel Data Privacy Policy |
When a customer runs its own third-party risk or screening process on people we name, that customer is the controller of the screening it performs. We are the controller of the personnel data we choose to submit.
5. Data we process
| Category | Examples | Classification |
|---|---|---|
| Identity and role | Name, title, work email, work phone | Confidential |
| Engagement role | Employee, contractor, or subcontractor; assignment to a customer engagement | Confidential |
| Due-diligence disclosures | Employment or family relationship disclosures the person has already made, when a customer review asks for them | Confidential |
| Engagement records | Email, meeting notes, and work product created for a customer outside the platform | Confidential |
We collect and share only what the customer relationship or review requires. We do not sell personal data and do not use this data for advertising.
6. How we use data
MBR Technology LLC uses this data to:
- Identify the people who will work on a customer engagement
- Support a customer's onboarding, security, or third-party risk review
- Contract, invoice, and communicate with the customer
- Meet legal, contractual, and regulatory obligations
- Investigate and report security or compliance concerns
7. Legal bases (EU/EEA and UK)
Where the GDPR or UK GDPR applies:
| Activity | Legal basis |
|---|---|
| Performing a customer contract and naming the delivery team | Performance of a contract |
| Sharing named personnel with a customer for due diligence | Performance of a contract; legitimate interests |
| Security, compliance, and required records | Legitimate interests; legal obligation |
8. Personnel data shared with customers
MBR Technology LLC is a small company. The people who work on a customer engagement are named to that customer. That naming is intentional: there is no anonymous or unvetted staff assigned to customer work.
We may share with a customer:
- Identity and role (name, title, work email, work phone)
- Whether the person is an employee, contractor, or subcontractor
- Conflict or relationship disclosures the person has already made, when the customer's review asks for them
We share only what the review requires. The individuals concerned are told that their details are being submitted.
A customer may use the information we submit for its own due-diligence or screening process. That process is the customer's. This policy does not authorize improper use of our personnel data by a customer, and it does not replace any hold-harmless or consent language in that customer's own forms.
9. Security
Personnel and engagement data are treated as Confidential. They are shared only with the requesting customer and people at MBR Technology LLC who need them for the engagement. Platform security controls that also protect related systems are described in the Ainzel Data Privacy Policy and MBR's encryption, access-control, and data-loss-prevention standards.
10. Retention
| Data type | Retention |
|---|---|
| Personnel and due-diligence data submitted to a customer | Duration of that customer relationship, and longer if the customer or applicable law requires it for the review record |
| Engagement and company contact data | Duration of the customer relationship, plus the period needed for contract, tax, and dispute records |
11. Privacy rights
Subject to applicable law, individuals may request to access, correct, erase, or restrict personal data that MBR Technology LLC holds as a controller, and may object to certain processing. MBR Technology LLC does not sell personal information.
For data processed on the Ainzel platform as a processor, requests are handled under the Ainzel Data Privacy Policy and the customer's instructions.
Requests can be submitted to the contact below and are handled within the timeframes required by applicable law.
12. Breach notification
If a security incident affects personal data covered by this policy, MBR Technology LLC will notify affected customers without undue delay in accordance with contractual and legal obligations, including applicable US state breach laws and, where the GDPR applies, without undue delay and where feasible within 72 hours for controller-side duties. Incident handling follows MBR's incident-response policy.
13. Changes
This policy is reviewed at least quarterly. Material changes are communicated to customers when they affect data already shared with them.
14. Contact
MBR Technology LLC — Privacy Contact
Bernhard Ritz, CEO
167 Old State Road
Berwyn, PA 19312
United States
privacy@ainzel.com · bernhard.ritz@ainzel.com · +1 (484) 744-1324
For platform-specific privacy questions, also see the Ainzel Data Privacy Policy.