Acceptable Use, BYOD & Remote Working Policy

Version 1.0 · Last Updated:

1. Purpose

This policy sets out Murzo Group's rules for acceptable use of technology, bring your own device arrangements, remote working, email, cloud services, internet access, collaboration tools, and digital information.

The purpose is to protect Murzo Group systems, confidential information, personal data, intellectual property, customers, workers, partners, and operational continuity.

2. Scope

This policy applies to directors, workers, contractors, consultants, suppliers, temporary workers, agency workers, and authorised third parties using Murzo Group systems, accounts, information, networks, files, devices, or communication channels.

It applies whether access takes place from company devices, personal devices, client devices, home networks, public networks, overseas locations, or third-party platforms.

3. Acceptable Use

Murzo Group technology must be used lawfully, responsibly, securely, and primarily for authorised business purposes.

  • Use approved accounts, devices, and services for Murzo Group work wherever practicable
  • Keep business information in approved storage locations rather than unmanaged personal accounts
  • Protect confidential information, personal data, credentials, source material, product data, and intellectual property
  • Follow information classification, data protection, cybersecurity, and records-retention requirements
  • Report suspicious messages, lost devices, accidental disclosure, malware, unusual account activity, or unauthorised access promptly

4. Prohibited Use

Users must not use Murzo Group systems, accounts, devices, or information for unlawful, unsafe, abusive, misleading, discriminatory, harassing, fraudulent, malicious, or unauthorised activity.

  • Bypassing security controls, sharing passwords, disabling protection tools, or using unapproved administrator access
  • Uploading confidential information to unapproved AI, file-sharing, translation, design, or messaging tools
  • Accessing, storing, or transmitting illegal, hateful, abusive, discriminatory, extremist, sexually explicit, or otherwise inappropriate material
  • Running unauthorised scanning, scraping, mining, hosting, automation, surveillance, or testing tools
  • Misrepresenting Murzo Group, making unauthorised public statements, or using company accounts for personal commercial activity

5. Personal Devices & BYOD

Use of personal devices for Murzo Group work may be permitted only where it is appropriate, secure, and authorised.

Murzo Group may require personal devices used for work to have screen locks, supported operating systems, security updates, encryption, anti-malware protection, device tracking, separate work profiles, remote wipe capability, or restricted access to sensitive information.

6. Remote Working

Remote working must be carried out in a way that protects confidentiality, availability, and professionalism.

  • Avoid discussing sensitive matters where conversations can be overheard
  • Position screens to reduce shoulder-surfing and lock devices when unattended
  • Use trusted networks and avoid public Wi-Fi for sensitive work unless suitable protection is in place
  • Store paper notes, samples, prototypes, labels, records, and devices securely
  • Comply with health, safety, working time, confidentiality, data protection, and local legal requirements

7. Email, Messaging & Cloud Tools

Business communications should use approved Murzo Group channels where practicable. Users must take care with attachments, links, recipient lists, forwarding rules, shared folders, and permissions.

Sensitive information should not be sent externally unless authorised, necessary, and protected appropriately.

8. Monitoring, Access & Privacy

Murzo Group may monitor use of its systems, accounts, devices, networks, and data where lawful and proportionate for security, compliance, business continuity, audit, investigation, and legal purposes.

Users should not expect personal privacy when using Murzo Group business systems, while Murzo Group will handle monitoring data in line with data protection requirements.

9. Loss, Theft, Incident & Offboarding

Lost or stolen devices, suspected compromise, accidental disclosure, unusual account activity, or unauthorised access must be reported promptly.

On role change, contract end, or termination, users must return Murzo Group devices, records, access tokens, files, documents, samples, and confidential information, and must not retain unauthorised copies.

10. Review & Responsibilities

All users are responsible for following this policy. Managers, system owners, and authorised representatives are responsible for access decisions, incident escalation, and proportionate enforcement.

This policy will be reviewed periodically and after material changes to technology, working arrangements, legal requirements, or threat conditions.

Murzo Group signature