This policy explains how Moheet Corpus — a research connector built on the Model Context Protocol (MCP) over a digital corpus of Ahlulbayt Library publications — collects, uses, and protects your data, in compliance with the General Data Protection Regulation (GDPR).
1. Data Controller
The data controller is SADIQOON TECHNOLOGIES LTD (registered in England & Wales, No. 17120720). For any privacy enquiry or to exercise your rights, write to info@sadiqoon.uk.
2. Data We Collect
- Your Google account email and display name — via OAuth 2.1 sign-in, solely to verify your identity and manage access authorisation.
- Access-request form data — name, email, academic institution, and stated research purpose.
- Your research query texts and tool-usage log (tool, timestamp, requester identity) — to operate the service, review its quality, and attribute usage.
We do not collect your location, your contacts, or your conversations with your AI assistant beyond the queries sent to the corpus. We show no advertising and never sell your data to anyone.
3. Purpose and Legal Basis
We process your data on the basis of your consent (GDPR Art. 6(1)(a)), given when you sign in with Google and connect the connector, and our legitimate interest (Art. 6(1)(f)) in securing the service and preventing abuse. The purpose is strictly: operating the service, controlling access, and improving retrieval quality. We make no automated decisions with legal effect on you.
4. Sharing with Third Parties (Technical Sub-processors)
- Google LLC — sign-in (OAuth), server hosting (Google Cloud), and language processing of some queries (Gemini).
- Cohere Inc. — processing of query text for semantic embedding and reranking.
- Groq Inc. — language processing for research-query formulation.
These providers receive only the query text needed for processing; your data is not used to train their models, under enterprise usage agreements. We share your data with no other party except under a binding legal obligation.
5. Retention
We retain access data and the usage log for as long as your account is active. Upon deletion of your data (see Data Deletion), it is erased within thirty days at most.
6. Your Rights
Under the GDPR you have the rights of access, rectification, erasure, restriction of processing, objection, and data portability. Write to info@sadiqoon.uk; you may also escalate to the supervisory authority in your country of residence.
7. Security
All connections are fully encrypted (TLS); access is via OAuth 2.1 with a controlled allow-list; the corpus tools are read-only and modify no content; and the infrastructure is isolated in independent containers.
8. Changes
We may update this policy; the date above reflects the latest revision. Continued use of the service after an update constitutes acceptance of it.