Data Protection Policy

Version 1.0 · Last Updated:

1. Introduction

Murzo Group is committed to protecting personal data and respecting the privacy rights of individuals.

This Data Protection Statement explains how Murzo Group handles personal data in accordance with applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR), the EU GDPR, and the Data Protection Act 2018.

This statement applies across all Murzo Group operations, platforms, services, and divisions.

2. Data Controller

Murzo Group acts as the Data Controller for personal data processed in connection with its business activities.

Where Murzo Group engages third parties to process data on its behalf, such parties act as Data Processors under written agreements that impose confidentiality, security, and compliance obligations.

3. Principles of Data Protection

Murzo Group processes personal data in accordance with the following principles:

  • Lawfulness, fairness, and transparency
  • Purpose limitation
  • Data minimisation
  • Accuracy and currency
  • Storage limitation
  • Integrity and confidentiality
  • Accountability

These principles guide all data-handling activities.

4. Categories of Data Processed

Murzo Group may process the following categories of personal data:

4.1 Business & Contact Data

  • Names, job titles, organisations
  • Email addresses and telephone numbers
  • Business correspondence

4.2 Client & Project Data

  • Project communications and documentation
  • Notes, files, and deliverables
  • Platform access records

4.3 Technical & Usage Data

  • IP addresses
  • System logs and security records
  • Device and browser information

4.4 Recruitment & Professional Data

  • CVs and employment history
  • Qualifications and references

Murzo Group does not intentionally process special category data unless required by law and subject to enhanced safeguards.

5. Purposes of Processing

Personal data is processed for purposes including:

  • Delivering and managing services and projects
  • Operating secure digital platforms
  • Communicating with clients, suppliers, and partners
  • Legal, regulatory, and contractual compliance
  • Security monitoring, fraud prevention, and risk management
  • Business administration and improvement

Murzo Group does not engage in automated decision-making producing legal or similarly significant effects.

6. Client Platforms & Data Retention

Murzo Group may operate secure client platforms for project communication, documentation, and updates.

Client data stored on such platforms is retained for up to five (5) years following project completion.

Where appropriate, Murzo Group may request client confirmation for earlier deletion or data handover.

Upon expiry of the retention period, data is permanently deleted or securely destroyed.

Murzo Group advises clients not to upload sensitive or personal data that could cause harm if exposed.

7. Data Security

Murzo Group implements appropriate technical and organisational measures to protect personal data, including:

  • Encryption and access controls
  • Network security and monitoring
  • Segregation of systems and permissions
  • Physical security measures
  • Regular risk assessments

Despite robust safeguards, no system is immune to attack. Murzo Group cannot guarantee absolute security and limits liability to the extent permitted by law.

8. Data Breaches & Incidents

Murzo Group maintains procedures to detect, respond to, and manage personal data breaches.

  • Incidents are assessed promptly to determine risk
  • Where required by law, breaches are reported to regulators and affected individuals
  • Remedial actions are taken to prevent recurrence

Murzo Group shall not be liable for breaches caused by external attacks, force majeure, or factors beyond reasonable control.

9. Data Sharing

Murzo Group may share personal data only where necessary and lawful, including with:

  • Trusted service providers under contractual controls
  • Professional advisers
  • Regulators or law enforcement where legally required

Murzo Group does not sell personal data or share it for advertising purposes.

10. International Data Transfers

Where personal data is transferred outside the UK or EEA:

  • Appropriate safeguards are applied, including adequacy decisions or standard contractual clauses
  • Transfers are limited to what is necessary for business operations

Users accessing Murzo Group services from other jurisdictions are responsible for compliance with local laws.

11. Data Subject Rights

Individuals have rights under data protection law, including the right to:

  • Access personal data
  • Request correction or deletion
  • Restrict or object to processing
  • Data portability (where applicable)
  • Withdraw consent

Requests should be submitted to admin@murzo.co.uk.

Murzo Group may verify identity before responding.

12. Third-Party Responsibility

Murzo Group is not responsible for data breaches or misuse arising from:

  • Third-party platforms outside Murzo Group’s control
  • Client-side security failures
  • Unauthorised disclosures by users

Users are responsible for ensuring that data they share is appropriate and lawful.

13. Retention & Disposal

Murzo Group retains personal data only for as long as necessary for its intended purpose.

Data is securely deleted, anonymised, or archived in accordance with internal retention schedules and legal obligations.

14. Changes to This Statement

Murzo Group reserves the right to update this Data Protection Statement at any time to reflect:

  • Legal or regulatory changes
  • Operational or technical developments

Updated versions will be published on Murzo Group platforms.

Murzo Group signature