1. Introduction
Murzo Group is committed to protecting personal data and respecting the privacy rights of individuals.
This Data Protection Statement explains how Murzo Group handles personal data in accordance with applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR), the EU GDPR, and the Data Protection Act 2018.
This statement applies across all Murzo Group operations, platforms, services, and divisions.
2. Data Controller
Murzo Group acts as the Data Controller for personal data processed in connection with its business activities.
Where Murzo Group engages third parties to process data on its behalf, such parties act as Data Processors under written agreements that impose confidentiality, security, and compliance obligations.
3. Principles of Data Protection
Murzo Group processes personal data in accordance with the following principles:
- Lawfulness, fairness, and transparency
- Purpose limitation
- Data minimisation
- Accuracy and currency
- Storage limitation
- Integrity and confidentiality
- Accountability
These principles guide all data-handling activities.
4. Categories of Data Processed
Murzo Group may process the following categories of personal data:
4.1 Business & Contact Data
- Names, job titles, organisations
- Email addresses and telephone numbers
- Business correspondence
4.2 Client & Project Data
- Project communications and documentation
- Notes, files, and deliverables
- Platform access records
4.3 Technical & Usage Data
- IP addresses
- System logs and security records
- Device and browser information
4.4 Recruitment & Professional Data
- CVs and employment history
- Qualifications and references
Murzo Group does not intentionally process special category data unless required by law and subject to enhanced safeguards.
5. Purposes of Processing
Personal data is processed for purposes including:
- Delivering and managing services and projects
- Operating secure digital platforms
- Communicating with clients, suppliers, and partners
- Legal, regulatory, and contractual compliance
- Security monitoring, fraud prevention, and risk management
- Business administration and improvement
Murzo Group does not engage in automated decision-making producing legal or similarly significant effects.
6. Client Platforms & Data Retention
Murzo Group may operate secure client platforms for project communication, documentation, and updates.
Client data stored on such platforms is retained for up to five (5) years following project completion.
Where appropriate, Murzo Group may request client confirmation for earlier deletion or data handover.
Upon expiry of the retention period, data is permanently deleted or securely destroyed.
Murzo Group advises clients not to upload sensitive or personal data that could cause harm if exposed.
7. Data Security
Murzo Group implements appropriate technical and organisational measures to protect personal data, including:
- Encryption and access controls
- Network security and monitoring
- Segregation of systems and permissions
- Physical security measures
- Regular risk assessments
Despite robust safeguards, no system is immune to attack. Murzo Group cannot guarantee absolute security and limits liability to the extent permitted by law.
8. Data Breaches & Incidents
Murzo Group maintains procedures to detect, respond to, and manage personal data breaches.
- Incidents are assessed promptly to determine risk
- Where required by law, breaches are reported to regulators and affected individuals
- Remedial actions are taken to prevent recurrence
Murzo Group shall not be liable for breaches caused by external attacks, force majeure, or factors beyond reasonable control.
9. Data Sharing
Murzo Group may share personal data only where necessary and lawful, including with:
- Trusted service providers under contractual controls
- Professional advisers
- Regulators or law enforcement where legally required
Murzo Group does not sell personal data or share it for advertising purposes.
10. International Data Transfers
Where personal data is transferred outside the UK or EEA:
- Appropriate safeguards are applied, including adequacy decisions or standard contractual clauses
- Transfers are limited to what is necessary for business operations
Users accessing Murzo Group services from other jurisdictions are responsible for compliance with local laws.
11. Data Subject Rights
Individuals have rights under data protection law, including the right to:
- Access personal data
- Request correction or deletion
- Restrict or object to processing
- Data portability (where applicable)
- Withdraw consent
Requests should be submitted to admin@murzo.co.uk.
Murzo Group may verify identity before responding.
12. Third-Party Responsibility
Murzo Group is not responsible for data breaches or misuse arising from:
- Third-party platforms outside Murzo Group’s control
- Client-side security failures
- Unauthorised disclosures by users
Users are responsible for ensuring that data they share is appropriate and lawful.
13. Retention & Disposal
Murzo Group retains personal data only for as long as necessary for its intended purpose.
Data is securely deleted, anonymised, or archived in accordance with internal retention schedules and legal obligations.
14. Changes to This Statement
Murzo Group reserves the right to update this Data Protection Statement at any time to reflect:
- Legal or regulatory changes
- Operational or technical developments
Updated versions will be published on Murzo Group platforms.