Skip to content
Machine Outcome
Proof How it works Integrate Work with us Trust boundary
Run locally
Explore MOVNavigation
  • Overview
  • Why MOV
  • Decisions
  • How it works
  • Proof
  • Integrate
  • Trust
  • FAQ
  • Work with us
← Back to MOV

Commercial trust

Privacy

This notice explains the limited personal data MOV may process when you visit the site, contact us, report a security issue, or enter a paid engagement.

Effective: 17 August 2026Controller contact: Sarmad Tawfeek · Sweden

Who controls the data?

Machine Outcome Verification (MOV) is operated by Sarmad Tawfeek in Sweden. For privacy questions or requests, email sarmad@machineoutcome.com.

What we process

  • Website request data: hosting infrastructure may process technical request information such as IP address, browser/device information, timestamps and requested URLs to deliver and protect the site.
  • Contact data: if you email us, we process the name, email address, organization and message content you provide.
  • Paid engagement data: if you become a customer, we may process business contact, scope, invoice, payment-status and transaction-reference information needed to contract, bill, reconcile and deliver the work.
  • Security reports: if you report a vulnerability, we process the report and contact details needed to investigate and respond.

Why we process it

  • to operate, secure and troubleshoot the public site;
  • to respond to inquiries and take steps requested before a contract;
  • to perform agreed paid work and reconcile billing/payment state;
  • to comply with accounting, tax and other legal obligations where they apply;
  • to protect MOV, customers and users from security abuse.

Depending on the activity, the legal basis is performance of a contract or pre-contract steps, compliance with legal obligations, or MOV's legitimate interests in operating and securing the service and communicating with prospective customers.

Who receives data

We use limited categories of service providers needed to operate the project, such as hosting infrastructure, email providers and—when a paid engagement occurs—payment/billing processors. We may also disclose information where required by law or to professional advisers when necessary.

Some providers may process data outside the EEA. Where applicable, transfers are handled using the safeguards required by data-protection law.

Retention

Website security/request records are retained according to the hosting provider's operational settings. Contact and security correspondence is kept only as long as reasonably needed for the conversation, follow-up, dispute/security history or legitimate business records. Billing and accounting records are retained for the period required by applicable law.

Cookies and tracking

The current MOV public site intentionally does not use advertising trackers or non-essential marketing cookies. If that changes, this notice and any consent mechanism will be updated before the new tracking is relied on.

Your rights

Depending on the circumstances, you may have rights to access, correct, erase or restrict personal data, object to certain processing, and receive portable data. You may also lodge a complaint with the Swedish Authority for Privacy Protection (IMY).

Start with sarmad@machineoutcome.com so we can identify and handle the request.

Scope: MOV is currently local-first software plus narrowly scoped paid implementation/verification work. This notice will be revisited before any broader hosted customer-data product is introduced.
Machine Outcome

The acceptance layer between machine payment and machine action.

sarmad@machineoutcome.com

Built and operated by Sarmad Tawfeek · Sweden.

Personal site LinkedIn GitHub

Product

Why MOV Failure proof How it works Try locally One real flow

Concepts & resources

x402 vs acceptance AI agent payments API contracts vs acceptance README llms.txt

Trust & legal

Security License Privacy Terms Contact
© 2026 Machine Outcome Verification Runtime Acceptance · x402-first · Local-first Back to MOV ↑