This Privacy Policy explains how JURIMARU LTD ("the Company", "we", "us", "our") collects, uses, stores, processes and protects personal data relating to individuals who interact with our website at jurimaru.ink, who contact us in connection with our services, and who engage with us in the course of our professional advisory, corporate holding and engineering and marketing consultancy activities.
JURIMARU LTD is a company registered in England and Wales, with its registered office at 182-184 High Street North, London, E6 2JA, United Kingdom. We are the data controller for the purposes of the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018 ("DPA 2018").
This Privacy Policy applies to all personal data collected or processed by JURIMARU LTD in connection with our website, our services, and our business relationships. It should be read in conjunction with our Cookie Policy, our Terms of Service, and our Terms and Conditions, each of which is available on our website at jurimaru.ink.
If you have any questions about this Privacy Policy or about how we handle your personal data, please contact us at: info@jurimaru.ink, or by post at the registered office address above.
We collect personal data in several ways, depending on how you interact with our website and our business. The categories of personal data we collect include the following:
When you submit an enquiry through our website contact form, we collect the information you provide, which may include your full name, email address, telephone number, the name of your organisation, and the content of your message or deployment readiness request. You are not obligated to provide all of the fields requested; however, failure to provide certain information (such as your name and email address) may prevent us from responding to your enquiry.
When you correspond with us by email or other means, we collect and retain the correspondence, including your email address, any personal data contained in the body of the correspondence, and metadata associated with the communication where this is technically accessible to us.
When you enter into a contractual engagement with us, we collect the personal data necessary to establish and administer the contract, including the names of individuals authorised to act on behalf of your organisation, billing and payment information (which may include bank account details where relevant), and contact information for key personnel involved in the engagement.
When you visit our website, we or our service providers may automatically collect certain technical data about your device and your use of the website. This data may include your IP address or a hashed or anonymised derivative of it, the type and version of browser you are using, the operating system of your device, the pages of our website you visit and the time and duration of those visits, the URL of the website or other resource that referred you to our website, and data about the actions you take on our website including links you click and forms you interact with.
Please refer to our Cookie Policy for detailed information about the cookies and similar tracking technologies we use on our website and how you can control them.
We may receive personal data about you from third parties in limited circumstances. For example, if you are introduced to us by a third party such as an existing client, an intermediary or a professional adviser, we may receive your name and contact details from that party. We may also receive publicly available information about you from sources such as Companies House, the Financial Conduct Authority register, or other publicly accessible professional databases, where this is relevant to our business relationship with you or your organisation.
We process personal data for specific, explicit and legitimate purposes. We do not process personal data in a manner that is incompatible with those purposes. For each purpose, we rely on one or more of the lawful bases for processing established under the UK GDPR.
We process personal data provided through our website contact form, by email or by telephone for the purpose of responding to your enquiry and conducting pre-contractual communications with you. The legal basis for this processing is Article 6(1)(b) UK GDPR — processing necessary for the performance of a contract to which you are party, or for steps taken at your request prior to entering into a contract — and, where the enquiry does not lead to a contractual engagement, our legitimate interests in responding to and maintaining records of business enquiries (Article 6(1)(f) UK GDPR).
Where we enter into a contractual engagement with you or your organisation, we process personal data for the purposes of administering and performing that contract, including communicating with you about the engagement, delivering our services, managing billing and payment, and maintaining records of the engagement. The legal basis for this processing is Article 6(1)(b) UK GDPR — processing necessary for the performance of the contract.
We process personal data where this is necessary for compliance with a legal obligation to which we are subject. This includes obligations under the Companies Act 2006, anti-money laundering legislation, tax legislation, and other applicable laws and regulations. The legal basis for this processing is Article 6(1)(c) UK GDPR — processing necessary for compliance with a legal obligation.
We process personal data where this is necessary for the purposes of our legitimate interests, provided that those interests are not overridden by your interests or your fundamental rights and freedoms. Our legitimate interests include maintaining the security and integrity of our website and systems, preventing fraud and other unlawful conduct, maintaining records for the purposes of establishing, exercising or defending legal claims, and developing and improving our services and our understanding of our client base.
We do not send unsolicited marketing communications by email or other means. Where we send any communications about our services to existing clients or contacts, we do so on the basis of our legitimate interests in maintaining professional relationships, and we provide an opportunity to opt out of such communications in each communication. We will always respect any opt-out request promptly.
We do not sell, rent or otherwise make your personal data available to third parties for their own marketing purposes. We disclose personal data to third parties only in the following circumstances:
We engage third-party service providers to assist in the operation of our website, the delivery of our services and the management of our business. These providers may process personal data on our behalf as data processors. We ensure that all such processors are subject to contractual obligations that comply with the requirements of UK GDPR, including Article 28. Our service providers include hosting and web infrastructure providers, email delivery services, and professional advisers such as legal and accounting firms who act under obligations of professional confidentiality.
We may disclose personal data to law enforcement authorities, courts, regulators or other governmental bodies where we are required to do so by law, or where such disclosure is necessary for the establishment, exercise or defence of legal claims, or for the protection of the vital interests of any person.
In the event of a merger, acquisition, restructuring or sale of all or part of our business, personal data may be disclosed or transferred to the parties involved and their advisers as part of due diligence and transaction processes, subject to appropriate confidentiality obligations. We will notify you of any such transfer where required by applicable law.
We may share personal data with third parties in other circumstances where you have provided your explicit consent to such sharing.
We are based in the United Kingdom and our primary data processing activities take place within the United Kingdom. Where we use service providers or systems located outside the United Kingdom, we ensure that any transfer of personal data to countries that do not benefit from an adequacy decision by the UK Secretary of State is subject to appropriate safeguards in accordance with the UK International Data Transfer Agreement or other permitted mechanisms under the UK GDPR.
If you would like further information about the mechanisms we use for international transfers, please contact us at info@jurimaru.ink.
We retain personal data only for as long as is necessary for the purposes for which it was collected, unless a longer retention period is required or permitted by law. The specific retention periods we apply depend on the nature of the data and the purpose for which it was collected. In general, we apply the following retention periods:
At the end of the applicable retention period, personal data is securely deleted or anonymised in accordance with our data retention and destruction procedures.
Under UK GDPR, you have the following rights in relation to the personal data we hold about you:
You have the right to obtain confirmation of whether we process personal data about you and, if so, to receive a copy of that data and information about how it is processed. This is known as a subject access request. We will respond to such requests within one calendar month of receipt, and may extend this period by up to two further months in complex cases, in accordance with Article 12(3) UK GDPR.
You have the right to require us to correct inaccurate personal data about you, and to have incomplete personal data completed where this is relevant to the purposes for which it is processed.
You have the right to request the erasure of your personal data in certain circumstances, including where the data is no longer necessary for the purposes for which it was collected, where you withdraw consent and no other legal basis for processing applies, or where the data has been unlawfully processed. This right is not absolute and may be overridden by our legal obligations or our legitimate interests.
You have the right to request that we restrict the processing of your personal data in certain circumstances, for example while you challenge the accuracy of the data or pending the outcome of an objection to processing.
Where processing is carried out by automated means and based on your consent or on the performance of a contract, you have the right to receive your personal data in a structured, commonly used and machine-readable format, and to transmit that data to another controller.
You have the right to object to processing of your personal data where the legal basis for that processing is our legitimate interests. We will cease such processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or unless the processing is necessary for the establishment, exercise or defence of legal claims.
We do not make decisions about you that are based solely on automated processing, including profiling, and that produce legal effects or similarly significant effects on you. If we were to introduce any such automated decision-making, we would inform you and provide appropriate safeguards in accordance with Article 22 UK GDPR.
To exercise any of the above rights, please contact us at info@jurimaru.ink or at our registered office address. We will verify your identity before processing any request and will respond within the timeframes required by law. We do not charge a fee for exercising your rights in ordinary circumstances.
We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, accidental loss, alteration, unauthorised disclosure or access. These measures include the use of encrypted communications for our website, access controls and authentication requirements for our internal systems, and contractual requirements on our service providers to maintain equivalent security standards.
We review our security measures regularly and update them as appropriate in light of changes in technology and the threat environment. However, no system for the transmission of data over the internet or for the storage of data is completely secure, and we cannot guarantee absolute security. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours of becoming aware of the breach in accordance with our obligations under Article 33 UK GDPR, and will notify you without undue delay where the breach is likely to result in a high risk to your rights and freedoms.
Our website uses cookies and similar technologies. Detailed information about the cookies we use, the purposes for which we use them, and how you can control them is set out in our Cookie Policy, which is available at cookie-policy.html on our website. By using our website, you consent to our use of cookies as described in the Cookie Policy, subject to any choices you make through our cookie consent mechanism.
Our website and services are directed at business professionals and organisations and are not directed at individuals under the age of 18. We do not knowingly collect or process personal data of individuals under 18. If we become aware that we have collected personal data of an individual under 18 without appropriate verification of parental consent where required, we will take steps to delete that data as soon as practicable.
Our website may contain links to third-party websites or services. This Privacy Policy applies only to our website and our processing of personal data. We are not responsible for the privacy practices of third-party websites or services, and we encourage you to review the privacy policies of any third-party websites you visit. The inclusion of a link on our website does not constitute an endorsement or recommendation of the linked website or service.
If you have concerns about how we handle your personal data, we ask that you contact us in the first instance at info@jurimaru.ink so that we have the opportunity to address your concerns. However, you also have the right to lodge a complaint with the Information Commissioner's Office (ICO), which is the supervisory authority for data protection in the United Kingdom. The ICO can be contacted at:
Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire, SK9 5AF
Tel: 0303 123 1113
Website: ico.org.uk
We review this Privacy Policy periodically and may update it from time to time to reflect changes in our processing activities, changes in applicable law, or changes in best practice. Where we make material changes to this Privacy Policy, we will notify you by posting a notice on our website or, where we have your contact details, by email, prior to the changes taking effect. The date of the most recent version of this Privacy Policy is shown at the top of the document. Your continued use of our website and services following any changes to this Privacy Policy constitutes your acceptance of those changes.
In addition to the processing activities described in clauses 3 through 9 of this Privacy Policy, we may process personal data in the following circumstances:
Where we enter into a paid engagement with a client, we process personal data that is necessary for invoicing, payment collection, and financial record-keeping. This includes the names of individuals authorised to receive invoices, payment authorisation details, and banking information required to process payments or to receive payment by bank transfer. This processing is carried out on the basis of the performance of a contract (Article 6(1)(b) UK GDPR) and, in relation to the retention of financial records beyond the life of the engagement, on the basis of our legal obligations under applicable accounting and tax legislation (Article 6(1)(c) UK GDPR).
We do not store payment card details in our own systems. Where payments are made by credit or debit card, these are processed through a third-party payment processor subject to that processor's own security and data protection measures. We retain only limited information about card payments — typically the last four digits of the card used and the date and amount of the transaction — for the purposes of our own financial records.
In the course of maintaining and improving our website and information systems, we may access technical logs and other system data that incidentally contains personal data, such as IP addresses in access logs. This processing is carried out on the basis of our legitimate interests in maintaining secure and functioning systems (Article 6(1)(f) UK GDPR). We take steps to minimise the extent to which such incidental processing involves identifiable personal data, for example by anonymising IP addresses where this is technically feasible and where it does not compromise our security monitoring capabilities.
We may use anonymised or pseudonymised case examples drawn from our experience of providing services to develop training materials, internal guidance, and professional development resources for our Personnel. Where any such materials are derived from our work on a specific client engagement, we take steps to ensure that the client and the specific circumstances of the engagement are not identifiable from the training materials. We do not use identifiable client personal data in training materials without the express prior consent of the relevant client.
As part of our client acceptance and due diligence procedures, and as required by our anti-money laundering obligations, we may carry out checks on the individuals and organisations who engage our services. This may involve processing personal data obtained from publicly available sources, such as Companies House, the Land Registry, the Financial Conduct Authority register, and other public databases. We process this data on the basis of our legitimate interests and our legal obligations in relation to anti-money laundering and know-your-client compliance.
We do not routinely collect or process special category personal data (as defined in Article 9 UK GDPR), which includes data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for identification purposes, data concerning health, data concerning a natural person's sex life or sexual orientation.
In some circumstances, special category data may be incidentally disclosed to us in correspondence or in the course of providing our services. For example, if you inform us of a health condition that is relevant to your availability for meetings or your ability to participate in the engagement, we may retain a record of this information in connection with the relevant engagement. Any such incidental processing of special category data is carried out on the basis of explicit consent (Article 9(2)(a) UK GDPR) or on the basis of our legal obligations (Article 9(2)(b) UK GDPR), and is retained only for the minimum period necessary for the relevant purpose.
If you are concerned about the processing of special category personal data in connection with your engagement with us, please contact us at info@jurimaru.ink and we will discuss the specific circumstances and take appropriate steps to address your concerns.
We do not currently use automated processing tools or profiling systems to make decisions about individuals that produce legal or similarly significant effects on them. We do not segment, score, or build profiles of individual website users for the purposes of personalised advertising. If we were to introduce any such processing in the future, we would update this Privacy Policy to reflect the relevant processing activities and would ensure that appropriate safeguards are in place as required by the UK GDPR.
We may use analytics tools to understand aggregate patterns of website usage and to improve our website and services. Such analytics are conducted at an aggregate level and are not used to make decisions about individual users or to build individual user profiles. Where such analytics tools involve the use of cookies or similar technologies, these are described in our Cookie Policy.
Our email communications systems may record whether a recipient has opened a communication or clicked on a link within it. This information is used only for the purposes of evaluating the effectiveness of our communications and is not used to make decisions that produce legal or similarly significant effects on any individual.
We do not purchase mailing lists or engage in unsolicited mass marketing communications. Where we send any informational or promotional communications about our services, this is done on the basis of our legitimate interests in maintaining professional relationships with individuals and organisations that have previously engaged with us or expressed an interest in our services, or on the basis of consent where this has been given.
Each such communication will include a clear and conspicuous opportunity to opt out of receiving future communications of that type. We will honour all opt-out requests promptly and will not send further marketing communications to individuals who have opted out. However, we may continue to send communications that are necessary for the performance of a contract or for the fulfilment of a legal obligation, as these do not constitute direct marketing communications for the purposes of the UK GDPR or the PECR.
If you have previously consented to receive marketing communications from us and wish to withdraw that consent, or if you wish to opt out of marketing communications received on the basis of our legitimate interests, please contact us at info@jurimaru.ink. We will process your request without undue delay and at no charge to you.
We take reasonable steps to ensure that personal data we hold is accurate, complete, and kept up to date, having regard to the purposes for which it is processed. We encourage individuals to notify us of any changes to their personal data by contacting us at info@jurimaru.ink, and we will update our records promptly upon receiving notification of any inaccuracy or change.
Personal data provided to us in connection with a specific engagement is generally not updated on an ongoing basis following the conclusion of that engagement. If you believe that we hold inaccurate personal data about you in connection with a past engagement, please contact us to request rectification in accordance with your rights under clause 7 of this Privacy Policy.
For any questions, concerns or requests in relation to this Privacy Policy or to the personal data we hold about you, please contact us using the following details:
JURIMARU LTD
182-184 High Street North
London, E6 2JA
United Kingdom
Email: info@jurimaru.ink
Telephone: +44 7392 876543
We will respond to all privacy-related enquiries within the timeframes required by applicable law and, where practicable, within 5 working days of receipt of your enquiry. We aim to resolve all data protection concerns promptly and fairly, and we take all privacy-related complaints and enquiries seriously. Where we are unable to resolve a concern to your satisfaction, you have the right to complain to the Information Commissioner's Office as set out in clause 12 of this Privacy Policy.
For subject access requests and other formal exercises of your rights under UK GDPR, we may ask you to provide proof of identity before processing your request. This is to protect the security of personal data held about you and to ensure that we only disclose information to the person who is entitled to it. Where we ask for proof of identity, we will specify the types of identification we require and will process your request promptly once satisfactory identification has been provided. We will not use the identity verification process to delay or discourage the exercise of your rights.
We recognise that the right to privacy is a fundamental right, and we are committed to handling personal data about our website visitors and clients with the care and respect that this right demands. Our approach to data protection is not merely about legal compliance — it reflects our professional commitment to treating all individuals with respect and to maintaining the trust that is essential to our business relationships. We invest in appropriate technical and organisational measures to protect personal data, we train our Personnel in data protection responsibilities, and we take all privacy-related concerns seriously. If you feel that we have fallen short of these commitments in any respect, we want to hear from you so that we can address the issue and improve our practices.
This Privacy Policy is reviewed at least annually and updated whenever there is a material change in our processing activities or in the applicable legal framework. Minor updates — such as corrections to contact details or formatting changes — may be made without a formal review cycle. The date shown at the top of this Privacy Policy reflects the date of the most recent substantive update. If you have any questions about how this Privacy Policy applies to your specific circumstances, or if you would like to understand more about the personal data we hold about you, please contact us using the contact details provided in this clause.