1. Introduction and Scope
This Privacy Policy explains how MUZ SECURE LTD ("MUZ SECURE LTD", "we", "us" or "our") collects, uses, stores, shares and otherwise processes personal data when you visit or use the website located at muzsecure.cloud (the "Website"), when you contact us, or when you engage with our professional services. We are committed to protecting your privacy and handling your personal data in accordance with the United Kingdom General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR) as amended, and other applicable United Kingdom data protection and privacy laws.
MUZ SECURE LTD provides IT consulting, management advisory, digital transformation, computer systems design and related services, management consulting, enterprise architecture, cloud migration strategy, project management and agile consulting, and data analytics and business intelligence consulting. This Privacy Policy applies to personal data processed in connection with those activities and our Website, whether you are a prospective client, existing client, supplier, business partner, job applicant, website visitor, or other individual whose personal data we process.
By using the Website or providing personal data to us, you acknowledge that you have read this Privacy Policy. Where we rely on consent as a lawful basis, we will seek that consent separately and clearly. Where you do not agree with any part of this Privacy Policy, you should discontinue use of the Website and refrain from providing personal data to us except where required by law or contract.
This Privacy Policy does not apply to third-party websites, applications or services that may be linked from our Website. We encourage you to review the privacy notices of any third parties before providing them with personal data.
2. Data Controller and Contact Details
For the purposes of the UK GDPR and the Data Protection Act 2018, the data controller responsible for your personal data is:
MUZ SECURE LTD 51 Knowsley Street Manchester M8 8JF United Kingdom
Email: info@muzsecure.cloud Telephone: +44 7700 900246 Website: muzsecure.cloud
If you have questions about this Privacy Policy, wish to exercise your data protection rights, or wish to raise a concern about our processing of personal data, please contact us using the details above. We will respond in accordance with applicable law and within the statutory timeframes where required.
Where we act as a data processor on behalf of a client under a written agreement, the relevant client remains the data controller for that processing, and this Privacy Policy should be read alongside the contractual terms governing that engagement. In such cases, please direct primary enquiries about that processing to the client, although you may also contact us and we will assist as appropriate under our contractual obligations.
3. Categories of Personal Data We Collect
Depending on how you interact with us, we may collect and process the following categories of personal data:
3.1 Identity and Contact Data
This may include your full name, job title, employer or organisation name, business address, postal address, email address, telephone number, and other identifiers you provide when corresponding with us or completing forms on the Website.
3.2 Professional and Business Relationship Data
This may include information about your organisation, your role in procurement or decision-making, project requirements, meeting notes, correspondence history, contractual details, billing and account administration information, and records of services discussed or delivered.
3.3 Technical and Usage Data
When you visit the Website, we may automatically collect technical data such as Internet Protocol (IP) address, browser type and version, device type, operating system, referring uniform resource locator (URL), pages viewed, date and time of access, time spent on pages, clickstream data, and similar diagnostic or analytics information. Some of this information may be collected through cookies and similar technologies, as further described in our Cookie Policy and in Section 10 of this Privacy Policy.
3.4 Communication and Enquiry Data
If you contact us by email, telephone, post or via Website forms, we will process the content of your communications, any attachments you send, and metadata associated with those communications (such as timestamps and delivery status where available).
3.5 Marketing and Preference Data
Where permitted by law, this may include your preferences regarding marketing communications, newsletter subscriptions, event invitations, and records of consents or opt-outs.
3.6 Recruitment Data
If you apply for a role with us or submit a curriculum vitae or similar materials, we may process employment history, education, professional qualifications, references (where provided), and other information you voluntarily submit as part of a recruitment process.
3.7 Special Category and Sensitive Data
We do not generally seek to collect special category personal data (as defined under the UK GDPR) through the Website. Please do not send us information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for the purpose of uniquely identifying an individual, health data, or data concerning a person's sex life or sexual orientation, unless we expressly request it for a lawful purpose and provide a separate notice explaining the lawful basis and any additional conditions relied upon. If such data is incidentally provided, we will handle it in accordance with applicable law and delete or restrict it where appropriate.
We do not knowingly collect personal data relating to children under the age of sixteen through the Website. If you believe we have inadvertently collected such data, please contact us so that we may delete it promptly.
4. How We Collect Personal Data
We collect personal data from the following sources:
Directly from you when you complete forms on the Website, send emails, speak with us by telephone, attend meetings, enter into contracts, or otherwise communicate with us.
Automatically through the Website using cookies, server logs, analytics tools and similar technologies, subject to your cookie preferences where consent is required under PECR.
From your organisation or colleagues, for example where a business contact shares your details in connection with a project or enquiry.
From publicly available professional sources, such as corporate websites, Companies House filings, and professional networking platforms, where it is lawful and proportionate to do so for business development or due diligence purposes.
From service providers who support our operations, such as hosting providers, email service providers, analytics providers, and customer relationship management systems, in accordance with our contracts with those providers.
5. Purposes of Processing and Lawful Bases
We process personal data only where we have a lawful basis under Article 6 of the UK GDPR. The principal purposes and corresponding lawful bases are set out below.
5.1 Providing and Improving the Website
We process technical and usage data to operate, secure, maintain and improve the Website, diagnose faults, and understand how the Website is used. Lawful bases may include legitimate interests (Article 6(1)(f)) in running a secure and effective online presence, and consent (Article 6(1)(a)) where required for non-essential cookies under PECR.
5.2 Responding to Enquiries and Pre-Contractual Steps
When you contact us about our services, we process your data to respond, assess suitability, prepare proposals, and take steps at your request prior to entering a contract. Lawful bases include taking steps at the request of the data subject prior to entering a contract (Article 6(1)(b)) and legitimate interests in developing business relationships (Article 6(1)(f)).
5.3 Performing Contracts and Delivering Services
Where you or your organisation engage MUZ SECURE LTD, we process personal data as necessary to perform the contract, deliver IT consulting, management advisory, digital transformation, computer systems design and related services, management consulting, enterprise architecture, cloud migration strategy, project management and agile consulting, and data analytics and business intelligence consulting, manage projects, communicate with stakeholders, and administer billing. The primary lawful basis is Article 6(1)(b) (contract) and, where processing relates to individuals who are not parties to the contract, Article 6(1)(f) (legitimate interests in performing our client engagements).
5.4 Legal and Regulatory Compliance
We may process personal data to comply with legal obligations, including tax, accounting, corporate, employment, and regulatory requirements applicable in the United Kingdom. The lawful basis is Article 6(1)(c) (legal obligation).
5.5 Security, Fraud Prevention and Dispute Management
We process data as necessary to protect our systems, prevent misuse, investigate incidents, enforce our terms, and establish, exercise or defend legal claims. The lawful basis is typically legitimate interests (Article 6(1)(f)) and, where applicable, legal obligation (Article 6(1)(c)).
5.6 Marketing and Business Development
Subject to PECR and the UK GDPR, we may send electronic marketing to existing clients about similar services where soft opt-in conditions are met, or where we have obtained consent. We may also conduct limited business-to-business outreach that is proportionate and respects opt-out rights. Lawful bases include consent (Article 6(1)(a)) and legitimate interests (Article 6(1)(f)), assessed through a balancing test considering your reasonable expectations and rights.
5.7 Recruitment
We process applicant data to assess candidacy, communicate about roles, and maintain records as required. Lawful bases include taking steps prior to a potential employment contract (Article 6(1)(b)), legitimate interests (Article 6(1)(f)), and legal obligation where employment law requires retention of certain records.
5.8 Legitimate Interests Assessment
Where we rely on legitimate interests, we consider the purpose of the processing, whether the processing is necessary for that purpose, and whether your interests, rights or freedoms override our interests. You may object to processing based on legitimate interests as described in Section 12.
6. Cookies and Similar Technologies
The Website may use cookies, pixels, local storage and similar technologies. Non-essential cookies are used only with your consent in accordance with PECR, except where a relevant exemption applies (for example, cookies strictly necessary to provide a service expressly requested by you). For detailed information about the types of cookies we use, their purposes, retention periods, and how to manage your preferences, please refer to our Cookie Policy available on muzsecure.cloud.
Consent for non-essential cookies may be withdrawn at any time through our cookie preference controls or by adjusting your browser settings. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
7. Recipients and Categories of Recipients
We may share personal data with the following categories of recipients, only where necessary and subject to appropriate safeguards:
Service providers and processors who provide website hosting, cloud infrastructure, email delivery, analytics, IT support, professional advisers (including lawyers, accountants and auditors), and customer relationship or project management tools.
Clients and project stakeholders, where sharing is necessary to deliver contracted services or respond to joint enquiries, and where you would reasonably expect such sharing in a professional context.
Public authorities, regulators, courts or law enforcement agencies, where we are required to disclose information by law, court order, or regulatory request, or where disclosure is necessary to protect our legal rights.
Successors in connection with a merger, acquisition, restructuring, or sale of assets, in which case personal data may be transferred as part of the business assets, subject to continuity of appropriate protection and notice where required by law.
We do not sell personal data. We require processors to process personal data only on our documented instructions and to implement appropriate technical and organisational security measures, in accordance with Article 28 of the UK GDPR.
8. International Transfers
MUZ SECURE LTD is established in the United Kingdom. Personal data is primarily processed within the United Kingdom. If we transfer personal data to a country outside the United Kingdom, we will ensure that an appropriate transfer mechanism is in place as required by Chapter V of the UK GDPR. This may include:
Transfers to countries covered by UK adequacy regulations.
Transfers subject to the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or other approved contractual clauses.
Other derogations or safeguards permitted by the UK GDPR in specific circumstances, such as where the transfer is necessary for the performance of a contract with you or in your interest, or where you have provided explicit consent after being informed of the risks.
Details of specific transfer mechanisms for particular processors can be provided on request where it is reasonable and does not prejudice commercial confidentiality or security.
9. Retention of Personal Data
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, reporting and contractual requirements, and to resolve disputes. Retention periods vary depending on the nature of the data and the context of processing. Indicative retention practices include:
Website enquiry and correspondence data: typically retained for up to twenty-four months after the last meaningful contact, unless a longer period is required for an ongoing matter or legal claim.
Contractual and client engagement records: retained for the duration of the engagement and thereafter for a period generally of six to seven years to meet commercial, tax and limitation period considerations under English law, unless a longer period is required by the specific contract or law.
Marketing preference and consent records: retained for as long as we continue to market to you or need evidence of consent or opt-out, and for a reasonable period thereafter to demonstrate compliance.
Recruitment records relating to unsuccessful applicants: typically retained for up to twelve months unless you consent to a longer talent-pool retention or a longer period is required for equalities or defence of claims.
Server logs and security records: retained for periods proportionate to security monitoring needs, commonly between thirty and ninety days unless an investigation requires longer retention.
Technical cookie data: retained in accordance with the periods stated in our Cookie Policy.
When personal data is no longer required, we will securely delete or anonymise it. Anonymised data falls outside the scope of the UK GDPR and may be retained for statistical or service-improvement purposes.
10. Security Measures
We implement appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction or damage, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing as well as the risk to individuals. Measures may include access controls, encryption in transit where appropriate, secure configuration of systems, staff awareness, vendor due diligence, backup and recovery arrangements, and incident response procedures.
No method of transmission over the Internet or method of electronic storage is completely secure. While we strive to protect your personal data, we cannot guarantee absolute security. You are responsible for keeping confidential any credentials or access details issued to you in connection with our services.
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office (ICO) without undue delay and, where feasible, not later than seventy-two hours after becoming aware of it, unless the breach is unlikely to result in a risk. Where a breach is likely to result in a high risk to your rights and freedoms, we will also communicate the breach to you without undue delay as required by Articles 33 and 34 of the UK GDPR, unless an exemption applies.
11. Automated Decision-Making and Profiling
We do not use personal data collected through the Website to make solely automated decisions that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 of the UK GDPR. If this changes, we will update this Privacy Policy and provide any required information about the logic involved, significance and envisaged consequences, and your related rights.
Limited profiling for analytics or business development (for example, understanding which pages are of interest to visitors as a group) may occur using aggregated or pseudonymised data where practicable. Where profiling is based on personal data and affects you individually in a meaningful way, we will ensure an appropriate lawful basis and respect your right to object.
12. Your Rights Under UK Data Protection Law
Subject to conditions and exemptions under the UK GDPR and the Data Protection Act 2018, you have the following rights:
Right of access: you may request confirmation as to whether we process your personal data and, if so, access to that data and certain related information.
Right to rectification: you may request correction of inaccurate personal data and completion of incomplete personal data.
Right to erasure: you may request deletion of personal data in certain circumstances, such as where it is no longer necessary for the purposes for which it was collected, or where you withdraw consent and there is no other lawful basis.
Right to restriction of processing: you may request that we restrict processing in specified circumstances, including while we verify accuracy or assess an objection.
Right to data portability: where processing is based on consent or contract and carried out by automated means, you may request to receive personal data you provided to us in a structured, commonly used and machine-readable format, and to transmit that data to another controller where technically feasible.
Right to object: you may object to processing based on legitimate interests, including profiling, on grounds relating to your particular situation. You also have an absolute right to object to processing for direct marketing purposes.
Rights related to automated decision-making: as described in Section 11.
Right to withdraw consent: where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
Right to complain: you may lodge a complaint with the Information Commissioner's Office. Contact details are set out in Section 14.
To exercise your rights, please contact us at info@muzsecure.cloud or write to us at the address in Section 2. We may need to verify your identity before fulfilling a request. We will respond without undue delay and in any event within one month of receipt of a valid request, subject to extensions permitted by law for complex or numerous requests. We will inform you of any extension and the reasons for it. In some cases we may charge a reasonable fee or refuse a request that is manifestly unfounded or excessive, in accordance with the UK GDPR.
13. Direct Marketing and Electronic Communications
We comply with PECR and the UK GDPR when sending electronic marketing communications. We will not send unsolicited marketing emails or SMS messages to individuals without consent or another PECR-compliant basis (such as the soft opt-in for existing customers in relation to similar products or services, where a clear opportunity to refuse was given at collection and is given in every subsequent communication).
You may opt out of marketing at any time by using the unsubscribe mechanism in our communications or by contacting info@muzsecure.cloud. Opting out of marketing does not affect communications that are necessary for the performance of a contract or for legitimate service administration.
Telephone marketing, if any, will comply with applicable Preference Service rules and PECR requirements. We honour registered preferences where legally required.
14. Complaints and Supervisory Authority
If you are dissatisfied with how we handle your personal data, please contact us first so that we may attempt to resolve your concern. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection.
Information Commissioner's Office Wycliffe House Water Lane Wilmslow Cheshire SK9 5AF United Kingdom
Website: https://ico.org.uk Helpline: 0303 123 1113
We would appreciate the opportunity to address your concerns before you approach the ICO, but this does not affect your right to complain at any time.
15. Third-Party Links and Social Features
The Website may contain links to third-party websites, plug-ins or applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements or practices. When you leave our Website, we encourage you to read the privacy policy of every website you visit.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements or business operations. The updated version will be posted on muzsecure.cloud with a revised effective date. Where changes are material, we may provide additional notice by email or a prominent notice on the Website where appropriate and practicable. We encourage you to review this Privacy Policy periodically.
Your continued use of the Website after an updated Privacy Policy has been posted constitutes acknowledgment of the updated terms, except where consent is required for a new processing purpose, in which case we will seek consent as required by law.
17. Governing Law and Jurisdiction
This Privacy Policy and any dispute or claim arising out of or in connection with it or its subject matter (including non-contractual disputes or claims) shall be governed by and construed in accordance with the laws of England and Wales. Subject to any mandatory rights you may have as a consumer under applicable law, the courts of England and Wales shall have exclusive jurisdiction to settle such disputes or claims.
Nothing in this Section limits your statutory rights, including rights under the Data Protection Act 2018 and the UK GDPR, or your right to bring a complaint before the ICO.
18. Professional Services and Client Data
When MUZ SECURE LTD provides professional consulting and advisory services, the treatment of personal data within client environments is typically governed by a separate statement of work, master services agreement, data processing agreement, or confidentiality agreement. In many engagements we act as an independent controller for our own business administration data and as a processor for personal data processed solely on the client's documented instructions within the client's systems or datasets.
Clients remain responsible for ensuring they have a lawful basis to share personal data with us and for providing appropriate privacy notices to data subjects. We will process such data only for the purposes agreed in writing, implement agreed security measures, assist with data subject requests as contractually required, and delete or return personal data at the end of the engagement in accordance with the contract, subject to retention required by law.
If you are an individual whose data is processed by a client of MUZ SECURE LTD and you wish to exercise rights in respect of that processing, please contact the relevant client as controller. We will support our clients in responding to such requests where our role as processor requires it.
19. Accuracy and Your Responsibilities
It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us. You are responsible for ensuring that any personal data you provide about other individuals (for example, colleagues named in a project team list) is provided lawfully and that those individuals are aware of this Privacy Policy where appropriate.
You must not provide false or misleading information. Misuse of the Website or attempts to circumvent security may result in restriction of access and, where appropriate, reporting to relevant authorities.
20. Contact for Privacy Matters
For all privacy-related enquiries, including requests to exercise rights under Sections 12 and 13, please contact:
MUZ SECURE LTD Data Protection Enquiries 51 Knowsley Street, Manchester, M8 8JF, United Kingdom Email: info@muzsecure.cloud Telephone: +44 7700 900246
Please include sufficient detail to allow us to identify you and understand your request. If you are making a request on behalf of another person, we may require evidence of your authority to act.
Effective date: 17 July 2026 Last updated: 17 July 2026
MUZ SECURE LTD — Privacy Policy for muzsecure.cloud
21. Detailed Description of Processing Activities
The following subsections provide additional transparency regarding how MUZ SECURE LTD processes personal data in the ordinary course of business. They are intended to help you understand the practical context of our processing and do not limit the rights described elsewhere in this Privacy Policy.
21.1 Website Administration and Security Monitoring
We process IP addresses, device identifiers, browser characteristics and access logs to detect malicious activity, deny abusive traffic, maintain availability of muzsecure.cloud, and investigate security incidents. This processing is necessary for our legitimate interests in protecting our systems, staff and clients, and may also be necessary to comply with legal obligations relating to cybersecurity and fraud prevention. Access to detailed logs is restricted to authorised personnel and retained only for the periods described in Section 9.
21.2 Client Onboarding and Know-Your-Client Checks
Before or during an engagement, we may collect identity and organisation details, authorised signatory information, billing contacts, and documentation reasonably required for anti-fraud, conflicts checking, and commercial due diligence. Where such checks are required by law or professional standards, we process the data under Article 6(1)(c). Otherwise, we rely on legitimate interests in managing commercial risk and entering contracts with appropriate counterparties, or on contractual necessity where the checks form part of pre-contractual steps you request.
21.3 Project Delivery and Stakeholder Communication
During consulting engagements involving IT consulting, management advisory, digital transformation, computer systems design, enterprise architecture, cloud migration strategy, project management, agile consulting, or data analytics and business intelligence consulting, we may process names, roles, contact details and opinions of client personnel and third-party stakeholders. Processing is limited to what is necessary to plan, deliver, document and review the services. We instruct our staff and subprocessors to use such data only for authorised project purposes and to apply confidentiality obligations consistent with our client contracts.
21.4 Invoicing, Credit Control and Accounting
We process billing names, addresses, purchase order numbers, bank transfer references and related financial administration data to issue invoices, collect payment, maintain accounting records and comply with tax law. Retention of such records is aligned with statutory requirements under United Kingdom tax and company law. Personal data within accounting records is accessed on a need-to-know basis.
21.5 Supplier and Partner Management
If you are a supplier or partner, we process contact and contract data to manage the commercial relationship, assess performance, and ensure compliance with confidentiality, data protection and security obligations in our supply chain. Processors acting for us are subject to written terms meeting Article 28 UK GDPR requirements.
22. Data Protection Impact Assessments and High-Risk Processing
Where a type of processing is likely to result in a high risk to the rights and freedoms of individuals, MUZ SECURE LTD will carry out a data protection impact assessment in accordance with Article 35 of the UK GDPR before commencing that processing. We will consult the Information Commissioner's Office where required by Article 36. Examples of processing that may trigger such assessment include large-scale systematic monitoring, extensive processing of special category data, or introduction of new technologies that significantly affect individuals. Routine Website analytics conducted with appropriate safeguards and consent where required will not ordinarily constitute high-risk processing, but we keep this assessment under review as our tools and practices evolve.
23. Record of Processing Activities
As a controller, we maintain records of processing activities where required by Article 30 of the UK GDPR, including the purposes of processing, categories of data subjects and personal data, categories of recipients, transfers to third countries, envisaged time limits for erasure where possible, and a general description of technical and organisational security measures. Relevant extracts may be made available to the ICO on request. We do not publish the full internal record because it may contain commercially sensitive and security-sensitive information.
24. Staff Training and Confidentiality
Personnel who process personal data on behalf of MUZ SECURE LTD are subject to confidentiality obligations and receive guidance appropriate to their roles on data protection, information security and acceptable use. Access to personal data is granted according to the principle of least privilege. Breaches of internal policies may result in disciplinary action and, where appropriate, notification to clients or regulators.
25. Subprocessors and Change Notification
We may appoint subprocessors to support hosting, communications, analytics and business systems. We remain responsible for their compliance with our instructions and applicable law under Article 28. Where we act as a processor for a client, we will not engage a subprocessor without prior general or specific written authorisation as set out in the relevant data processing agreement, and we will inform the client of intended changes so that the client may object where the contract so provides.
26. Interaction with Consumer Rights Act 2015
Where you deal with MUZ SECURE LTD as a consumer within the meaning of the Consumer Rights Act 2015, nothing in this Privacy Policy excludes or limits rights that cannot be excluded or limited by law, including rights relating to unfair terms and digital content where applicable. Our Website content is provided for general information about our business services and does not itself constitute a consumer digital content subscription unless expressly stated in a separate agreement. If a conflict arises between this Privacy Policy and mandatory consumer protections, the mandatory protections prevail.
27. Language, Interpretation and Entire Notice
This Privacy Policy is provided in the English language. Headings are for convenience only and do not affect interpretation. References to legislation include that legislation as amended, extended or re-enacted from time to time, and include any subordinate legislation. If any provision of this Privacy Policy is held to be invalid or unenforceable, the remaining provisions continue in full force and effect. This Privacy Policy should be read together with our Cookie Policy, Terms of Service and Terms and Conditions published on muzsecure.cloud. In the event of inconsistency regarding personal data processing, this Privacy Policy prevails for privacy-specific matters, except where a signed contract with you or your organisation expressly provides otherwise for a particular engagement.
For further information about how cookies are used on muzsecure.cloud, please see our Cookie Policy. For contractual terms governing use of the Website and engagement of our professional services, please see our Terms of Service and Terms and Conditions.
If you require this Privacy Policy in an alternative format due to a disability, please contact info@muzsecure.cloud and we will take reasonable steps to assist you.
MUZ SECURE LTD processes personal data fairly, lawfully and transparently, for specified purposes, and with integrity and confidentiality as core principles under Article 5 of the UK GDPR. We welcome constructive dialogue with individuals, clients and the ICO regarding continuous improvement of our privacy practices.
