Privacy Policy
What this policy covers
This policy applies to visitors to the Muurel website and to people who contact us through it. It does not describe processing inside the Muurel software platform. Where Muurel processes HR data on behalf of a customer, that customer is the controller, Muurel acts as processor, and the processing is governed by the customer agreement and its data processing agreement rather than by this policy.
The short version
This website uses no advertising, profiling, or cross-site tracking. Cloudflare provides server-side Traffic Analytics from requests handled through its network.
With your permission, we also use Cloudflare Web Analytics to measure page views and website performance. Web Analytics uses a JavaScript beacon and browser performance information. Cloudflare states that the service does not use cookies, local storage, session storage, or fingerprinting and does not track individual visitors across its customers' websites. The Web Analytics beacon is not loaded unless you select “Accept analytics.”
We store one first-party consent preference for up to six months so that the website can remember whether optional analytics was accepted or rejected, the time of the decision, and the applicable consent version.
Without analytics consent, a normal visit is limited to the technical connection and security information required to deliver and protect the website. Cloudflare may set strictly necessary security cookies where its security functions require them.
Without analytics consent, the personal data arising from an ordinary visit is limited to technical connection and security data. If you accept analytics, additional page-view and browser-performance information is processed as described below.
Controller
The controller responsible for data processing on this website is:
- Controller
- Muurel OÜ (registry code 17562771)
- Address
- Saare tee 6, Pringi küla, Viimsi vald, 74011 Harju maakond, Estonia
- [email protected]
- Data protection officer
- Muurel OÜ has not appointed a data protection officer. Data protection enquiries go to the address above. We keep this assessment under review as the business grows.
Server and connection data
When you open a page, your browser transmits data that is technically required to deliver it. Our website code does not write access logs or build request histories. Our hosting and delivery providers process connection data for delivery, security, and abuse prevention. This can include:
- your IP address
- the date and time of the request
- the page or file requested
- the amount of data transferred and the HTTP status returned
- your browser type and version, and your operating system
Purpose and legal basis
This processing serves the secure, stable, and correct delivery of the website. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is operating a functioning and reasonably protected website. We do not attempt to identify named visitors from this data or combine it with other data sources.
Retention
We do not operate our own logging and do not build request histories. Cloudflare determines retention of edge and security data under its published policy. Enquiries are covered under Contacting us below.
Traffic statistics
We use Cloudflare Traffic Analytics, which is produced from requests processed by Cloudflare's network. Its dashboard can show and filter request data by attributes such as IP address, country, device type, hostname, requested path, browser or operating system, and HTTP status. It also provides totals such as requests, data served, estimated unique visitors, and blocked requests. We use this information to understand whether the site is working, being read, or receiving abusive traffic. Cloudflare describes this service in its Traffic Analytics documentation.
Traffic Analytics is generated on the server side from the connection data described above. We review it mainly as totals and trends and do not use it to build visitor profiles, identify named individuals, combine it with other data, or advertise to anyone. Traffic Analytics does not require a browser script, and nothing is read from or stored on your device for this purpose, so we do not request device-storage consent for this processing. The legal basis is Art. 6 (1) (f) GDPR, our legitimate interest in understanding and protecting our own website.
Optional Cloudflare Web Analytics
If you consent, we use Cloudflare Web Analytics to understand how the
website is used and how it performs for visitors. The service loads
Cloudflare's beacon.min.js JavaScript file and uses browser
Performance APIs to collect page-view and performance measurements.
The resulting statistics can include the page path, referrer host, country, device category, browser, operating system, navigation type, page-load timing, Core Web Vitals, and technical information about elements or layout changes affecting website performance. Like any browser request, transmission of the beacon also exposes ordinary connection metadata, such as an IP address, to Cloudflare. Connection metadata is covered under “Server and connection data” above.
Cloudflare states that Web Analytics does not use cookies, local storage, session storage, or fingerprinting and does not track individual visitors across different Cloudflare customers' websites.
We use the resulting information only to understand visits, diagnose website-performance problems, and improve the website. We do not use it to identify named visitors, combine it with customer or employee information, build advertising profiles, or track visitors across websites.
The Web Analytics beacon is not loaded unless you select “Accept analytics.” The legal basis for the associated processing of personal data is your consent under Art. 6 (1) (a) GDPR. Browser-side collection is activated only after prior consent in accordance with Article 5 (3) of the ePrivacy Directive as applied in Estonia.
You may withdraw or change your consent at any time through “Privacy choices” in the website footer. Withdrawal prevents future analytics collection but does not affect processing that occurred before you withdrew consent.
Cloudflare states that it retains unsampled Web Analytics beacon data for seven days, after which it is aggregated down to around 10% of the original volume for longer-term storage. Muurel can access Web Analytics information for the previous six months. We do not export or maintain a separate copy of the underlying beacon data. Details are in Cloudflare's Web Analytics FAQ.
Cookies and browser storage
Muurel sets no analytics or advertising cookies.
We store one first-party item called
muurel_analytics_consent_v1 in browser local storage for up
to six months. It contains only whether analytics was accepted or
rejected, the time of the decision, and the applicable consent version.
This storage is necessary to remember and respect your privacy choice.
Cloudflare Web Analytics itself does not use cookies, local storage, session storage, or fingerprinting. Its JavaScript beacon is loaded only after you have accepted analytics.
Cloudflare may separately set strictly necessary security cookies where its bot management, challenge, rate-limiting, or related security functions require them. Depending on the enabled function and request, this may occur during an ordinary website request or following a security challenge. The cookie name and duration depend on the security function involved. Cloudflare publishes the current list in its Cloudflare cookie documentation.
Muurel does not use Cloudflare security cookies for analytics, advertising, audience measurement, or cross-site profiling.
Necessary website-security functions and the storage used to remember your privacy choice remain active without optional analytics consent. Cloudflare Web Analytics is optional and is activated only after you select “Accept analytics.”
Limited external resources
The website does not embed Google Fonts, video, maps, social-media widgets, advertising networks, chat tools, or third-party booking tools. Typefaces and ordinary website assets are self-hosted.
If you accept optional analytics, your browser loads Cloudflare's Web Analytics beacon and sends page-view and performance measurements to Cloudflare. If you reject analytics or have not made a choice, the analytics beacon is not loaded.
Contacting us
If you contact us by email or through the website enquiry form, we process the details you provide to handle your enquiry. The form asks for your name, email address, message, and optionally your company; its delivery metadata can also include the country associated with the request. The legal basis is Art. 6 (1) (b) GDPR where your message concerns a contract or pre-contractual steps, and otherwise Art. 6 (1) (f) GDPR based on our interest in responding to enquiries.
The website is hosted on Cloudflare Pages. Form submissions are
initially processed by Cloudflare and transmitted through Microsoft 365
for delivery to our [email protected] mailbox. Microsoft 365
processes the form content and related delivery metadata for email
transmission and mailbox hosting. The website application does not
maintain an additional database copy of the submission.
Enquiries that do not lead to a customer relationship are kept for up to 24 months after our last substantive contact, then deleted. Correspondence is kept longer only where it becomes part of a contract, a legal claim, or a record we are required to retain — for example an accounting source document, which §12 of the Estonian Accounting Act (raamatupidamise seadus) requires us to keep for seven years.
Please do not send sensitive HR information this way. Ordinary email is not end-to-end encrypted. Do not send employee records, payroll data, health information, or other special-category data to us by email or through this website — including when discussing a demo. If you need to share real data with us, ask and we will arrange an appropriate channel under a data processing agreement.
Processors and international transfers
We keep the list of providers deliberately short. The following process personal data on our behalf:
- Cloudflare, Inc.
- Domain management, website security, content delivery, website hosting, server-side traffic and security statistics, optional Web Analytics after visitor consent, and initial processing of website enquiry-form submissions before transmission to Microsoft 365. Cloudflare processes technical request information, consented analytics beacon information, and form submissions as needed to provide these services. Terms and safeguards are in the Cloudflare Data Processing Addendum.
- Microsoft Corporation
-
Email transmission and mailbox hosting through Microsoft 365 for
[email protected]. Processes the contents and related delivery metadata of direct emails and website enquiries.
We use no browser analytics provider other than Cloudflare, advertising network, customer-data platform, or third-party form or booking tool. We do not sell personal data, and we do not pass it to third parties for advertising.
Transfers outside the EEA
These providers are US-controlled and operate globally, so personal data may be processed outside the European Economic Area. Where that happens, the transfer is protected either by an applicable adequacy decision — including the EU–US Data Privacy Framework, where the recipient is certified under it — or by the European Commission's Standard Contractual Clauses together with any supplementary safeguards the transfer requires.
Product screenshots
The product screenshots on this site show a demonstration environment. The people, names, photographs, and records in them are fictional and generated; they are not real employees and contain no real personal data.
Your rights
Under the GDPR you have the right to:
- access your personal data (Art. 15)
- have inaccurate data corrected (Art. 16)
- have your data erased (Art. 17)
- have processing restricted (Art. 18)
- receive your data in a portable format, where the conditions in Art. 20 are met
- object to processing carried out on the basis of a legitimate interest, on grounds relating to your particular situation (Art. 21)
- withdraw consent at any time, where processing is based on consent (Art. 7 (3))
To exercise any of these, contact us at the address above. You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in the member state of your residence, place of work, or the place of the alleged infringement.
You can change or withdraw your Cloudflare Web Analytics consent at any time by selecting “Privacy choices” in the footer. Rejecting or withdrawing analytics consent does not restrict access to any part of the website. Withdrawal prevents future analytics collection but does not affect processing carried out before withdrawal.
For a company established in Estonia the competent authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), www.aki.ee. You may also complain to the authority in your own country of residence or workplace.
- Address
- Tatari 39, 10134 Tallinn, Estonia
- [email protected]
- Telephone
- +372 627 4135
Automated decision-making
This website carries out no automated decision-making or profiling within the meaning of Art. 22 GDPR.
Changes to this policy
We update this policy when the site changes or the legal position requires it. The date at the top reflects the current version.