auth

Privacy Policy

Service: MIE Auth (https://auth.mhglobalgroup.com)

Last updated: 1 August 2026

This notice explains what personal data MIE Auth collects, why we collect it, how long we keep it, who else sees it, and the rights you have over it. It is written to be read: each dense section opens with a short plain-English summary, and every operational statement in it describes what the service actually does today.

Contents

1. Who we are and how to contact us

MIE Auth is an authentication service operated by MH Global Group Limited, a company registered in England and Wales under company number 16317481, whose registered office is at 16 St. Clare Street, London, England, EC3N 1LQ. MIE Auth is the name of the service; MH Global Group Limited is the legal person behind it and the data controller for the purposes of this notice. In this notice, 'we', 'us' and 'our' mean MH Global Group Limited; 'you' means the individual whose personal data we process. MIE, including MIE Pathways and MIE English Academy, is a brand of MH Global Group Limited; where the service or its home page refers to 'MIE Group', that means MH Global Group Limited.

Please put 'Privacy request' in the subject line so that your message reaches the right people quickly. We will acknowledge a rights request and respond within one month; if a request is complex or you have made several, we may extend that by up to two further months and will tell you why within the first month.

We have not appointed a data protection officer, and are not required to appoint one under Article 37. We have not appointed a representative in the European Union under Article 27 EU GDPR. If we become required to appoint one, that representative's name and contact details will be published in the table above.

This notice forms part of our Terms of Service, which govern your use of MIE Auth. This notice deliberately uses plain lower-case words (organisation, member, account) for the things clause 2 of those Terms defines as 'Organisation', 'Member' and 'Account'; they mean the same thing.

2. Who this notice is for, and our role

In short: if you signed up for MIE Auth yourself, we are the controller and this notice governs. If your employer or another organisation gave you the account, that organisation is the controller of your account data and we act as its processor, but we remain the controller of the security records we keep to protect the service.

MIE Auth is a multi-tenant sign-in service. It holds accounts, verifies who you are, and issues sessions and access tokens to the applications that rely on it. Two relationships are possible, and which one applies to you decides who is answerable for your data. A third role applies to you whichever of them you are in.

  1. We are the controller where you created your own account directly with MIE Auth. We decide what data the service needs to sign you in and keep the account secure, and this notice is our Article 13 notice to you.
  2. We are a processor where an organisation account manages your access: for example where your employer created the organisation, invited you into it, and administers your membership, role and access policies. That organisation is the controller of your account and access data. It decides who is invited, what role you hold, whether two-factor authentication is mandatory and which networks may sign in; we process that data on its documented instructions. Your rights in that relationship are exercised against the organisation, and we will assist it in answering you. One exception, and you should know it: the export and erasure controls described in section 11 are available to every account holder, including members of an organisation. If you use them, we act on your instruction rather than the organisation's, the erasure is written to the organisation's audit trail where its administrators can see it, and where you were its only member the organisation is deleted with you (section 11.2). Otherwise the organisation's own privacy notice governs, not this one; this notice still tells you accurately what the service does.
  3. We remain a controller, in both cases, for service integrity. The security audit trail, the sign-in throttling and lockout state, bot mitigation, and the list of email addresses we must stop mailing are things we do for our own purposes, to keep an identity service safe. No customer instructs us to do it and no customer can switch it off, so we are the controller of it. It is described in sections 4, 10 and 12.

Where we act as a processor, we do not use the personal data for our own purposes, do not sell it, and do not disclose it except to the sub-processors named in section 8 or where the law requires.

3. Where your personal data comes from

4. What we hold, why, on what lawful basis, and for how long

In short: we hold what an identity service needs and no more: who you are, proof that it is you, which organisations you belong to, and a security record of what happened to your account. We never store your password, and the secrets behind two-factor authentication are encrypted before they are written down.

The table below is derived from the actual database schema. 'Until erasure' means the data is deleted when your account is erased, by you or by an operator acting on your request (section 11). Article references are to the UK GDPR; the EU GDPR has the same numbering where it applies to you.

Where we rely on legitimate interests, we have balanced those interests against your rights. The interest is the security and availability of an identity service: without an audit trail, rate limiting, lockout and bot mitigation, a single stolen password becomes an undetected, persistent compromise of an account and of every application that trusts it. The data used is limited to what that requires, is not used for marketing or profiling, and is subject to the retention limits set out above. You may object at any time (section 11).

Do you have to give us this data? Your email address and at least one credential are a contractual requirement: they are what an account is, and we cannot create one or sign you in without them. Your name is not required. No statute obliges you to give us any of it. The only consequence of not providing it is that we cannot give you an account. Your IP address and user-agent string are collected automatically by the request itself and cannot be withheld while still using the service. Where an organisation invited you, it decided what to give us; ask that organisation.

We do not hold payment card details in this service, do not knowingly collect special category data (Article 9), and send no marketing email: every message MIE Auth sends is transactional or a security warning (section 7).

5. Google user data

In short: if you sign in with Google, we ask Google for three basic scopes, use what they return only to create and identify your account, and touch nothing else in your Google account.

This section describes precisely what MIE Auth does with data obtained through Google Sign-In. It applies only if you choose to sign in with Google.

5.1 The scopes we request

When you press 'Continue with Google', we send you to https://accounts.google.com/o/oauth2/v2/auth with these OAuth scopes:

The request uses PKCE and returns to a fixed redirect URI on our own domain (https://auth.mhglobalgroup.com/api/auth/callback/google). We do not request sensitive or restricted scopes; if that ever changes we will update this notice before it takes effect. The request also sets include_granted_scopes, so Google may return scopes you have previously granted this application.

5.2 What we receive and store

We exchange the authorisation code at https://oauth2.googleapis.com/token and read the identity token Google returns. From it we take, and store:

We also store the tokens Google issued (the access token, the identity token, a refresh token where Google supplies one, their expiry times and the granted scope) against your account record, so that the link between the two accounts can be maintained.

5.3 What we do with it, and what we do not do

We use Google user data for one purpose: to create your MIE Auth account, to identify you when you return, and to sign you in. That is all.

MIE Auth's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

5.4 Withdrawing and deleting

You can disconnect MIE Auth from your Google account at any time at myaccount.google.com/connections. Doing so stops future sign-ins with Google; it does not by itself delete the data already stored here.

Erasing your MIE Auth account (section 11) deletes the account record holding your Google identifier and the stored Google tokens, along with the rest of your personal data, subject only to the audit-trail retention described in sections 4 and 13.

6. Other social sign-in providers

Which providers are available is a configuration choice. Google, GitHub, Microsoft Entra ID, Apple and other providers supported by the service can each be turned on or off by the operator; only providers with working credentials appear as buttons on the sign-in page, so what you can see is what is enabled.

For every provider, the pattern is the one described in section 5: we request basic identity scopes, receive an identifier, an email address, a display name and, where the provider supplies one, a picture URL, and we use them to create and identify your account. The provider's own privacy notice governs what it does at its end, including the fact that it learns you have signed in to MIE Auth. Signing in with a provider is entirely optional; an email address and password, a passkey or a magic link will do instead.

7. The emails we send you

In short: we send transactional and security email only. There is no marketing, so there is nothing to unsubscribe from. The security warnings cannot be switched off, because they are the only way we can reach you if someone else is in your account.

Security notifications carry no 'you can ignore this' footer and no one-click action link, deliberately: they exist for the case where someone else already controls your session, and they direct you to sign in rather than to click.

8. Third parties and sub-processors

In short: the service runs entirely on Cloudflare. Beyond that, a partial password hash goes to a breach-checking service, mail may go through a fallback transport where the operator has configured one, and social sign-in involves the provider you choose.

We do not use third-party analytics, advertising networks, tag managers, session recorders or social plug-ins. There is no advertising on this service.

We may also disclose personal data where we are legally obliged to (for example in response to a valid court order or a lawful request from a regulator or law enforcement body), and where necessary to establish, exercise or defend legal claims. If the business is reorganised, sold or merged, personal data may transfer as part of it; you would be told before it happened, and the protections in this notice would continue to apply. Google user data is excluded from this: where data obtained through Google Sign-In would transfer as part of such a transaction, we will obtain your explicit prior consent first, as the Google API Services User Data Policy requires.

9. Where your data is held, and international transfers

In short: the database, the audit archive and the database backups are pinned to the European Union (Western Europe). Cloudflare's network is global, so a request touches the edge location nearest you before it reaches us.

Where personal data is transferred outside the UK or the EEA, we rely on the safeguards in Article 46 of the UK and EU GDPR. Those are the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, both incorporated in our processors' data-processing terms, backed by a transfer risk assessment. We add technical measures that limit what a recipient outside the region could actually obtain: encryption in transit, encryption of secret material at rest, and regional pinning of the database. Where a processor is certified under the EU-US Data Privacy Framework and its UK Extension, we may additionally rely on the adequacy decisions covering it. You can ask us for details of the safeguards relied on for a particular transfer at info@mhglobalgroup.com.

10. Cookies, local storage and similar technologies

In short: one cookie keeps you signed in, a few short-lived ones carry a sign-in flow from one step to the next, and the bot check runs on Cloudflare's challenge platform. All of them are strictly necessary, so none of them needs your consent. We set no analytics or advertising cookies at all.

Under the Privacy and Electronic Communications Regulations (PECR), consent is not required for storage that is strictly necessary to provide a service you have expressly requested. Everything MIE Auth stores on your device falls within that exemption, because signing in and staying signed in is the service, and defending the sign-in against automated attack is inseparable from it.

We set no advertising, marketing, profiling or third-party analytics cookies, so there is no consent banner and nothing for you to opt out of. You can delete cookies and local storage in your browser at any time; deleting the session cookie signs you out.

11. Your rights, and how this service implements them

In short: you can download the account data we hold on you, and erase your account, from inside the product: no email, no waiting. The export deliberately leaves out secret material, and the security audit trail is kept after erasure; 11.1 and 11.2 explain both. The one refusal we build in is described at 11.3.

Under the UK GDPR and, where it applies to you, the EU GDPR, you have the rights to be informed, of access, to rectification, to erasure, to restrict processing, to data portability, to object, and not to be subject to solely automated decisions with legal or similarly significant effects. You also have the right to withdraw consent where we rely on it; we do not rely on consent for any of the processing in section 4.

Exercising these rights is free. We will not charge you or refuse a request unless it is manifestly unfounded or excessive, and we will explain ourselves if we do.

11.1 Self-service, inside the product

Organisation administrators holding the audit:read permission can additionally export their organisation's audit trail via GET /api/compliance/audit (JSON, or CSV with ?format=csv), which is how an organisation answers its own compliance obligations. Administrators see only their own organisation's records, and a manager scoped to part of an organisation sees only their own part of it.

11.2 What erasure actually deletes

Erasure runs as a single database transaction, so it either completes fully or changes nothing; there is no half-erased account. It deletes:

Two things deliberately survive, and you should know it:

An erased account can persist for a short period in an offline copy. Where a backup of the production database exists, erased data may persist in it until that backup expires, which is 35 days after the backup was taken (sections 12 and 13), so an erasure carried out today has worked through the backups within 35 days. We do not restore individual records from a backup, and we re-apply any outstanding erasure after a restore.

11.3 The one erasure we refuse, and why

If you are the sole owner of an organisation that still has other members, erasure is refused with a 409 response and the reason sole_owner_transfer_required. Nothing is deleted.

The reason is not administrative convenience. Erasing you would cascade away the last account able to manage that organisation, stranding every remaining member in an organisation that nobody can administer, invite to, or delete. That is a harm to other people that cannot be undone without direct intervention in the production database. Transfer ownership to another member, or remove the remaining members, and the erasure proceeds immediately. If you cannot resolve it yourself, contact info@mhglobalgroup.com and we will help.

11.4 Operator-assisted requests

If you cannot sign in, our support team can act for you once your identity is established:

These routes are restricted to authorised operators, require multi-factor authentication, and every use is written to the audit trail with the operator's identity. Write to info@mhglobalgroup.com to ask for any of them.

12. How we protect your data

In short: everything is encrypted in transit, passwords are hashed and checked against breach corpora, second factors and bot mitigation guard the sign-in, and every meaningful action leaves an audit record.

These are measures the service actually implements, not aspirations.

The audit trail is designed to support SOC 2-style evidence requirements. To be clear, that is a description of the capability: it is not a claim that we hold a SOC 2, ISO 27001 or any other certification, and nothing in this notice should be read as one.

No service can promise perfect security, and we do not.

13. Retention summary

14. Automated decision-making and profiling

We do not make decisions about you by solely automated means that produce legal effects or similarly significantly affect you, within the meaning of Article 22 UK GDPR and EU GDPR. We do not profile you, score you, or use your data to predict your behaviour, and we do not use your personal data to train any AI or machine-learning model.

The service does apply automated security controls: per-network rate limiting, sign-in lockout after five failed attempts, and the Turnstile bot check. These decide whether to allow a single request through; they are time-limited, self-clearing and reversible, and they do not have legal or similarly significant effects. If one of them blocks you unfairly, a human can review it and clear it immediately (section 11.4), and you can ask for that at info@mhglobalgroup.com.

15. Children

MIE Auth is a business authentication service. It is not designed for, directed at or marketed to children, and we do not knowingly create accounts for anyone under 16. If you believe a child has an account with us, write to info@mhglobalgroup.com and we will investigate and erase it.

16. Personal data breaches

We maintain procedures to detect, investigate and report personal data breaches. Where a breach is likely to result in a risk to your rights and freedoms, we will report it to the Information Commissioner's Office without undue delay and, where feasible, within 72 hours of becoming aware of it. Where it is likely to result in a high risk to you, we will tell you directly and without undue delay, and we will explain what happened, what data was involved and what you should do. Where we act as a processor for an organisation, we will notify that organisation without undue delay so that it can meet its own obligations.

17. Changes to this notice

We may update this notice as the service changes or the law does. The 'Last updated' date at the top always reflects the current version. If a change materially affects your rights or how we use your personal data, we will tell you before it takes effect: by email to the address on your account, or by a prominent notice when you next sign in. Continuing to use MIE Auth after a change takes effect means the updated notice applies to you.

18. Complaints

If you are unhappy with how we have handled your personal data, tell us first at info@mhglobalgroup.com. We would rather put it right than have you take it elsewhere, and we will respond within one month.

You also have the right to complain to a supervisory authority, without going to us first. In the United Kingdom that is the Information Commissioner's Office:

If you are in the European Economic Area, you may instead complain to the supervisory authority of the EU or EEA member state where you live, where you work, or where you believe the infringement took place.

Back to sign in