Privacy Policy
Mutex Systems (Private) Limited ("Mutex Systems", "we", "us", "our") respects your privacy. This policy explains what personal data we collect through this website and our enquiry channels, how we use it, and the rights you have over it.
1. Who we are
Mutex Systems (Private) Limited is registered with a UK Headquarters at Ealing Cross, 85 Uxbridge Road, London, W5 5BW, United Kingdom, and a Pakistan Regional Office at Suite 716, 7th Floor, Park Avenue, PECHS Block 6, Sharah-e-Faisal, Karachi, Pakistan. We are the data controller for personal data collected through this website.
2. What data we collect
We collect personal data you provide directly, including:
- Full name, business email address, and phone/WhatsApp number, submitted via our enquiry form, the floating chat widget, or a booked meeting
- Company name and product of interest (grComply, TiLedger, or FlowChat)
- The content of any message you send us
- Newsletter subscription email addresses, where you opt in separately
We do not collect payment or financial information through this marketing website.
3. How we use your data
We use the personal data you submit through this website solely to respond to your enquiry and communicate with you about the product or service you asked about. We do not use your data for any other purpose — including unrelated marketing, profiling, or resale — and we do not sell, rent, or trade your personal data to third parties.
Specifically, we use your data to: respond to enquiries and route them to the right product team; schedule and confirm meetings you request; send you the newsletter, if and only if you've opted in, which you can unsubscribe from at any time; and maintain records required to meet our own legal and accounting obligations.
4. Legal basis for processing
Under the UK GDPR and the EU General Data Protection Regulation (GDPR), we process your data on the basis of: your consent, where you submit an enquiry or subscribe to the newsletter; and our legitimate interest in responding to business enquiries and operating this website, where that interest does not override your rights.
5. Data security
Personal data is encrypted both in transit and at rest, and access is restricted to authorised personnel who need it to do their job — enquiry routing, account management, or support. Our information security practices are designed in alignment with the ISO/IEC 27001 information security management framework and the NIST Cybersecurity Framework.
6. Compliance
We design our data handling to comply with the UK GDPR and Data Protection Act 2018, the EU General Data Protection Regulation (GDPR), and applicable data protection laws in the jurisdictions where we and our customers operate. Where our information security practices reference ISO 27001 or NIST, this means our practices are aligned with those frameworks — it is not, on its own, a claim of formal third-party certification unless stated separately in writing.
7. Data retention
We retain enquiry and contact data for as long as needed to respond to your enquiry and maintain a reasonable business record, and no longer than necessary for that purpose or as required by law. Newsletter subscriber data is retained until you unsubscribe.
8. Your rights
Under the UK GDPR and GDPR, you have the right to: access the personal data we hold about you; request correction of inaccurate data; request erasure of your data; restrict or object to our processing; request a portable copy of your data; and withdraw consent at any time where processing is based on consent. To exercise any of these rights, contact us using the details below. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) or your local supervisory authority.
9. Third-party processors
We may use third-party service providers to help operate this website and respond to enquiries — for example, hosting infrastructure, email delivery, and scheduling tools. These providers only process data on our instructions and under contractual confidentiality and security obligations.
10. International transfers
Given our UK headquarters and Pakistan engineering offices, personal data may be processed outside the country in which it was originally submitted. Where this happens, we take steps to ensure an equivalent level of protection, consistent with UK GDPR and GDPR requirements for international transfers.
11. Cookies
This website uses a limited set of cookies. See our Cookie Policy for details on what we use and how to manage your preferences.
12. Children's privacy
This website and our products are intended for business use and are not directed at children. We do not knowingly collect personal data from children.
13. Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top of this page reflects the most recent revision.
14. Contact us
For any question about this policy or to exercise your data rights, contact us via the Contact Us page, WhatsApp at +44 7493 282220, or in writing to Mutex Systems (Private) Limited, Ealing Cross, 85 Uxbridge Road, London, W5 5BW, United Kingdom.
Questions about your data?
We respond within one working day — or reach us instantly on WhatsApp.