Privacy Policy

What this policy covers

This policy applies to visitors to the Muurel website and to people who contact us through it. It does not describe processing inside the Muurel software platform. Where Muurel processes HR data on behalf of a customer, that customer is the controller, Muurel acts as processor, and the processing is governed by the customer agreement and its data processing agreement rather than by this policy.

The short version

This website runs no tracking, no profiling, and no advertising, loads no content from third-party servers, and contains no analytics or tracking scripts. Fonts, styles, and images are served from the same domain as the page, and we set no cookies of our own.

Our security and delivery network, Cloudflare, may set a small number of strictly necessary cookies to tell human visitors from automated traffic. These are described under Cookies. They carry no advertising or profiling function, which is why you are not asked for consent: Article 5 (3) of the ePrivacy Directive exempts storage that is strictly necessary to provide the service you requested.

The only personal data that arises from a normal visit is the connection data your browser necessarily sends in order to receive the page, and that is handled as described below.

Controller

The controller responsible for data processing on this website is:

Controller
Muurel OÜ (registry code 17562771)
Address
Saare tee 6, Pringi küla, Viimsi vald, 74011 Harju maakond, Estonia
Email
info@muurel.com
Data protection officer
Muurel OÜ has not appointed a data protection officer. Data protection enquiries go to the address above. We keep this assessment under review as the business grows.

Server and connection data

When you open a page, your browser transmits data that is technically required to deliver it. Our website code does not write access logs or build request histories. Our hosting and delivery providers process connection data for delivery, security, and abuse prevention. This can include:

Purpose and legal basis

This processing serves the secure, stable, and correct delivery of the website. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is operating a functioning and reasonably protected website. We do not attempt to identify named visitors from this data or combine it with other data sources.

Retention

We do not operate our own logging and do not build request histories. Cloudflare determines retention of edge and security data under its published policy. Enquiries are covered under Contacting us below.

Traffic statistics

We use Cloudflare Traffic Analytics, which is produced from requests processed by Cloudflare's network. Its dashboard can show and filter request data by attributes such as IP address, country, device type, hostname, requested path, browser or operating system, and HTTP status. It also provides totals such as requests, data served, estimated unique visitors, and blocked requests. We use this information to understand whether the site is working, being read, or receiving abusive traffic. Cloudflare describes this service in its Traffic Analytics documentation.

This analytics is generated on the server side from the connection data described above. We review it mainly as totals and trends and do not use it to build visitor profiles, identify named individuals, combine it with other data, or advertise to anyone. No analytics script runs in your browser and nothing is read from or stored on your device for this purpose, so we do not request device-storage consent for this processing. The legal basis is Art. 6 (1) (f) GDPR, our legitimate interest in understanding and protecting our own website.

Cloudflare Web Analytics, the optional browser-based analytics product, is not enabled. If we enable it later, we will update this notice before doing so.

Cookies

We set no cookies ourselves, and we use no local storage, session storage, pixels, fingerprinting, A/B testing, heatmaps, or advertising and conversion tracking.

Cloudflare may set a strictly necessary security cookie only when a security challenge or bot-protection feature is triggered. The name and duration depend on the protection active at that time, so no such cookie is present on every visit. Cloudflare publishes the current list in its Cloudflare cookie documentation. Muurel does not use any of them for advertising, audience measurement, or cross-site profiling. Identifiers of this kind can still constitute personal data, which is why they are described here and covered by the rights set out below.

The consent requirement in Article 5 (3) of the ePrivacy Directive — implemented in Estonia through the Electronic Communications Act (elektroonilise side seadus) — exempts storage that is strictly necessary to deliver the service requested. On that basis no consent banner is shown.

No third-party content

The site loads no external resources. In particular there is no Google Fonts, no CDN, no embedded video, no map, no social media widget, and no chat tool. Typefaces are self-hosted, which means your IP address is never disclosed to a font provider — the practice a German court held unlawful in LG München I, 20 January 2022, 3 O 17493/20. The pages we author contain no JavaScript at all; the interactive elements are implemented in CSS.

Contacting us

If you contact us by email or through the website enquiry form, we process the details you provide to handle your enquiry. The form asks for your name, email address, message, and optionally your company; its delivery metadata can also include the country associated with the request. The legal basis is Art. 6 (1) (b) GDPR where your message concerns a contract or pre-contractual steps, and otherwise Art. 6 (1) (f) GDPR based on our interest in responding to enquiries.

The website is hosted on Cloudflare Pages. Form submissions are processed by Cloudflare and delivered to our info@muurel.com mailbox, which is hosted in Microsoft 365. The website does not store a separate copy of the submission.

Enquiries that do not lead to a customer relationship are kept for up to 24 months after our last substantive contact, then deleted. Correspondence is kept longer only where it becomes part of a contract, a legal claim, or a record we are required to retain — for example an accounting source document, which §12 of the Estonian Accounting Act (raamatupidamise seadus) requires us to keep for seven years.

Please do not send sensitive HR information this way. Ordinary email is not end-to-end encrypted. Do not send employee records, payroll data, health information, or other special-category data to us by email or through this website — including when discussing a demo. If you need to share real data with us, ask and we will arrange an appropriate channel under a data processing agreement.

Processors and international transfers

We keep the list of providers deliberately short. The following process personal data on our behalf:

Cloudflare, Inc.
Domain, security, content delivery, website hosting, and delivery of website enquiry-form messages. Processes request metadata and form submissions as needed to provide those services. Terms and safeguards are in the Cloudflare Data Processing Addendum.
Microsoft Corporation
Mailbox provider for info@muurel.com (Microsoft 365). Processes the contents of email and website enquiries delivered to that mailbox.

We use no separate browser analytics provider, advertising network, customer-data platform, or third-party form or booking tool. We do not sell personal data, and we do not pass it to third parties for advertising.

Transfers outside the EEA

These providers are US-controlled and operate globally, so personal data may be processed outside the European Economic Area. Where that happens, the transfer is protected either by an applicable adequacy decision — including the EU–US Data Privacy Framework, where the recipient is certified under it — or by the European Commission's Standard Contractual Clauses together with any supplementary safeguards the transfer requires.

Product screenshots

The product screenshots on this site show a demonstration environment. The people, names, photographs, and records in them are fictional and generated; they are not real employees and contain no real personal data.

Your rights

Under the GDPR you have the right to:

To exercise any of these, contact us at the address above. You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in the member state of your residence, place of work, or the place of the alleged infringement.

For a company established in Estonia the competent authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), www.aki.ee. You may also complain to the authority in your own country of residence or workplace.

Address
Tatari 39, 10134 Tallinn, Estonia
Email
info@aki.ee
Telephone
+372 627 4135

Automated decision-making

This website carries out no automated decision-making or profiling within the meaning of Art. 22 GDPR.

Changes to this policy

We update this policy when the site changes or the legal position requires it. The date at the top reflects the current version.