Privacy Policy

Last Updated: 19.08.2026

This Privacy Policy (the “Privacy Policy”) explains how MUFLON AGENCY LTD, a company incorporated in the Republic of Cyprus with registration number HE 465838 (“Muflon”, “Agency”, “Company”, “we”, “us”, or “our”), collects, uses, discloses, and otherwise processes personal data when you access or use our website https://www.muflon.com/ (the “Website”), when you make an enquiry or request a quotation, when you engage, receive, or interact with our design, development, marketing, and related services, and through the other channels, forms, and communications we may provide from time to time (collectively, the “Services”).

For the purposes of this Privacy Policy, the terms “you” or “your” refer to any individual who visits the Website, submits an enquiry, communicates with us, or acts on behalf of a client that engages our Services (each a “Client”). Where, in the course of providing the Services, we process personal data relating to a Client’s own customers, clients, end-users, employees, website visitors, or marketing audiences on the Client’s behalf — for example, when we design, develop, host, or maintain the Client’s website, online store, application, database, or systems, or when we manage the Client’s advertising or social media — such processing is carried out subject to this Privacy Policy and the applicable agreement, and we act as a data processor on the Client’s behalf. Individuals whose personal data is processed in that way should refer to the privacy notices of the relevant Client with whom they have a direct relationship.

For the purposes of this Privacy Policy, “personal data” shall mean any information relating to an identified or identifiable natural person (“data subject”). An identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, online identifier, location data, or account credentials, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that person. Personal data may include, without limitation, names, email addresses, phone numbers, company details, usernames and account identifiers, billing information, IP addresses, device and cookie identifiers, credentials and access details you provide, information contained in content, materials, records, or systems we build or manage on your behalf, communications submitted through our contact and support channels, and any other information that can reasonably be linked to an individual, alone or in combination with other data. Aggregated or de-identified information will not be considered personal data where it has been irreversibly anonymised such that individuals can no longer be identified.

If you do not agree with this Privacy Policy, you must not access or use the Website or the Services.

Disclaimer Clarification (Controller vs Processor)

This Privacy Policy primarily describes our privacy practices where the Company acts as a data controller of personal data — for example, in respect of visitors to our Website, individuals who make enquiries or request quotations, and the contacts of our Clients. It does not fully govern situations where the Company processes personal data solely on behalf of a Client in accordance with that Client’s instructions, in which case the Company acts as a data processor (for example, personal data held within a website, online store, database, marketing platform, or system that we build, host, maintain, or manage for a Client). Individuals whose personal data is processed through a Client’s use of such systems should refer to the privacy policies, notices, or terms of the relevant Client with whom they have a direct relationship. To the fullest extent permitted by applicable law, the Company may not be in a position to respond directly to requests relating to personal data processed solely on behalf of a Client, and such requests should be directed to the relevant Client (the data controller).

1. Roles of the Company Regarding Your Personal Data

When we design, develop, host, maintain, or otherwise work on a Client’s website, online store, application, database, or systems, or when we manage a Client’s marketing (such as advertising campaigns or social media accounts), the Client may input or make available information that relates to the Client’s own customers, clients, end-users, or other individuals (for example, information contained in a website, store, order records, contact forms, or a customer database). In those situations, the Client is the controller for such personal data and Muflon acts as a processor (or sub-processor), processing that data only on behalf of and under the instructions of the Client in order to provide the Services.

For the avoidance of doubt, the term “Client” does not include the Client’s own customers, clients, or end-users. Individuals whose personal data may be processed through a Client’s use of the Services should refer to the privacy notices, terms, or policies of the relevant Client with whom they have a direct relationship. To the fullest extent permitted by applicable law, this Privacy Policy does not create any direct rights or obligations between Muflon and a Client’s customers, clients, or end-users.

2. Personal Data We Collect

We may collect personal data from (a) you, (b) your device or browser, (c) platforms and integrations you ask us to connect or manage, and (d) third parties such as payment processors, analytics providers, and advertising platforms. The categories of personal data we may collect include:

2.1 Enquiry and contact data. Name, email address, telephone number, company or business name, website, and the details of your project or request that you submit through our contact and quotation forms or when you otherwise get in touch.

2.2 Client account and billing data. Contact and billing details, company and VAT information, purchase orders, invoices and receipts, payment status, and limited payment instrument information provided by our payment processors (for example, the last four digits and expiry date). We do not typically store full card numbers.

2.3 Project and materials data. Client Materials that you provide to us for a project — such as content, text, images, logos, brand assets, documents, credentials, and access details — which may contain personal data (for example, staff or customer details within content, testimonials, or images of identifiable individuals).

2.4 Data within systems we build or manage. Where we develop, host, maintain, or manage your website, online store, database, systems, or marketing, we may process personal data contained in or generated by those systems and platforms on your behalf, such as store and order data, form submissions, enquiries, CRM records, and advertising or audience data.

2.5 Usage and device data. IP address, device identifiers, browser type, operating system, referral URLs, pages viewed, time stamps, clickstream data, and logs relating to your use of the Website.

2.6 Support and communications. Information you provide when you contact us (for example, via email, telephone, chat, or a ticketing system), including message content and attachments.

2.7 Cookies and similar technologies. Cookie identifiers and related information, including data collected through tag management and analytics tools (such as Google Tag Manager and analytics services), as further described in Section 8 and in our Cookie Policy.

2.8 Security and fraud prevention data. Information used to secure accounts and prevent abuse, including logs, audit trails, and signals indicating suspicious activity.

3. How We Use Personal Data

We process personal data for the following purposes:

3.1 Respond to enquiries and provide quotations. Handling your enquiries, arranging scoping or kick-off discussions, preparing proposals and quotations, and taking steps at your request prior to entering into an agreement.

3.2 Provide, operate, and deliver the Services. Delivering projects and retainers, including design, development, hosting, maintenance, automation, marketing, and support, and setting up and operating integrations and third-party platforms on your behalf.

3.3 Improve and develop the Services. Troubleshooting, analytics, product and process improvement, and developing new offerings.

3.4 Personalise the experience. For example, remembering preferences and presenting relevant information.

3.5 Billing and payments. Processing transactions, managing engagements and subscriptions, accounting, tax compliance, and preventing payment fraud.

3.6 Security, safety, and abuse prevention. Protecting the Website, the Services, our Clients, and others from fraud, misuse, unauthorised access, and harmful activity.

3.7 Legal compliance and enforcement. Complying with legal obligations, responding to lawful requests, protecting our rights and property, and enforcing our Terms of Service and other agreements.

3.8 Communications and marketing. Sending service-related communications (for example, project updates, transactional emails, and notices) and, where permitted by law, marketing communications. You can opt out of marketing at any time.

4. Legal Bases for Processing (GDPR)

Where the GDPR applies and Muflon acts as controller, we rely on one or more of the following legal bases:

4.1 Performance of a contract. Processing necessary to provide the Services and perform our agreement with you, or to take steps at your request before entering into an agreement (for example, responding to enquiries, preparing quotations, project delivery, and billing).

4.2 Legitimate interests. Processing necessary for our legitimate interests, such as improving the Services, ensuring security, preventing fraud, promoting our business, and running our operations, provided those interests are not overridden by your rights.

4.3 Legal obligations. Processing necessary to comply with legal obligations (for example, tax and accounting, or responding to lawful requests).

4.4 Consent. Where required, we process certain data based on your consent (for example, some marketing communications or certain cookies). You can withdraw consent at any time, without affecting processing performed before withdrawal.

Where Muflon acts as processor for a Client, the Client is responsible for identifying the lawful basis for processing personal data relating to its own customers or end-users and for providing appropriate notices in accordance with all applicable data protection legislation.

5. Disclosure of Personal Data

We may disclose personal data to the following categories of recipients:

5.1 Service providers (processors/sub-processors). Cloud hosting and infrastructure providers, database providers, analytics providers, email and communication tools, payment processors, security providers, and trusted contractors or freelancers who assist us in delivering the Services.

5.2 Platforms and integrations used to deliver your Services. Where necessary to provide the Services, we may exchange data with third-party platforms that you ask us to use or manage, such as hosting providers, website and e-commerce platforms (for example, WordPress or Shopify), advertising platforms (for example, Google and Meta), analytics, and other tools.

5.3 Professional advisors. Lawyers, auditors, accountants, and insurers as necessary for professional services.

5.4 Corporate transactions. If we are involved in a merger, acquisition, financing, due diligence, reorganisation, or sale of assets, personal data may be disclosed as part of that process, subject to appropriate protections.

5.5 Legal and safety disclosures. We may disclose personal data if we believe in good faith that disclosure is necessary to comply with law, regulation, legal process, or a governmental request, to protect the rights, property, and safety of the Company, our Clients, or the public, or to prevent fraud or security issues.

We do not sell personal data as that term is commonly understood.

6. International Transfers

Muflon is based in Cyprus, and we may process personal data within the European Economic Area (EEA) and in other jurisdictions where our service providers operate. Where personal data is transferred outside the EEA or the United Kingdom to a country not recognised as providing an adequate level of protection, we implement appropriate safeguards, such as the European Commission’s Standard Contractual Clauses (and the UK Addendum where applicable), together with other lawful transfer mechanisms.

7. Data Retention

We retain personal data for as long as necessary to fulfil the purposes described in this Privacy Policy, including to provide the Services, comply with legal obligations, resolve disputes, enforce agreements, and protect our legal rights. Retention periods vary depending on the type of data and the purpose of processing. For example:

7.1 Enquiry data is generally retained for a reasonable period sufficient to respond to and follow up on your enquiry, and thereafter deleted or anonymised where no engagement follows.

7.2 Client and project records are generally retained for the duration of the engagement and for a reasonable period thereafter.

7.3 Billing records may be retained for longer periods as required by tax, accounting, and legal obligations.

7.4 Logs and security records may be retained for shorter periods unless required for investigating incidents, security events, or compliance.

Where feasible, we may anonymise data so that it can no longer be linked to an identifiable person.

8. Cookies and Similar Technologies

We use cookies and similar technologies (such as pixels, tags, and local storage) to operate the Website, remember preferences, provide security, and analyse usage. The main categories are:

8.1 Essential cookies. Necessary for the Website to function and which cannot be switched off in our systems.

8.2 Functional cookies. Enable enhanced functionality and personalisation.

8.3 Analytics cookies. Help us understand usage and improve performance.

8.4 Marketing cookies. Used to deliver and measure advertising and marketing effectiveness, where permitted.

You can control cookies through your browser settings and, where applicable, through our cookie banner or management tools. Disabling certain cookies may affect functionality. Further detail is set out in our Cookie Policy.

9. Security

We implement appropriate technical and organisational measures designed to protect personal data against unauthorised access, disclosure, alteration, destruction, and loss. These measures include access controls, encryption where appropriate, logging and monitoring, and policies and procedures designed to safeguard data.

No method of transmission or storage is completely secure. You are responsible for maintaining the confidentiality of your login credentials and for securing your own systems, accounts, and integrations (including any hosting, website, e-commerce, advertising, or social media accounts under your control).

10. Your Rights

Where the GDPR applies and Muflon acts as controller, you may have the right to request: access to your personal data; rectification; erasure; restriction of processing; portability; objection to processing; and the right not to be subject to certain automated decision-making. You may also have the right to withdraw consent at any time where processing is based on consent.

If you wish to exercise your rights, contact us using the details in Section 14. We may need to verify your identity before responding. Where we process personal data on behalf of a Client (the controller), requests should usually be directed to that Client, and we may assist the Client as required by applicable law.

11. Communications

11.1 Service communications. We may send you administrative or service-related communications, such as enquiry responses, project updates, confirmations, invoices, and important notices. You cannot opt out of essential service communications while an engagement is active.

11.2 Marketing communications. Where permitted by law, or with your consent, we may send marketing communications. You may opt out at any time by using the unsubscribe link or by contacting us directly.

12. Children’s Privacy

The Website and Services are directed to businesses and are not intended for individuals under 18, and we do not knowingly collect personal data from children. Where we build or manage a website, store, or system for a Client that may collect personal data relating to minors, the Client (as controller) is solely responsible for ensuring an appropriate lawful basis, notices, and consents are in place in accordance with applicable law.

13. Third-Party Links and Services

The Website and Services may include links to, or integrations with, third-party websites or services. We are not responsible for the privacy practices of third parties. Please review their policies before providing personal data.

14. Contact Us

If you have questions about this Privacy Policy or our processing of personal data, or if you wish to exercise your rights, you may contact us as follows:

Company: Muflon Agency Ltd

Registration number: HE 465838 (Republic of Cyprus)

Registered office: Κώστα Καρυωτάκη, 23, Κάτω Πολεμίδια, 4170, Λεμεσός, Κύπρος (Kosta Karyotaki 23, Kato Polemidia, 4170, Limassol, Cyprus)

Email: hello@muflon.com

Website: https://www.muflon.com/

If required by law, we may provide additional contact information for a data protection representative or data protection officer.

15. Complaints

If you are located in the EEA or the United Kingdom, you have the right to lodge a complaint with your local supervisory authority. In Cyprus, this is the Office of the Commissioner for Personal Data Protection.

16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will post the updated version on the Website and update the “Last Updated” date above. Your continued use of the Website or the Services after the effective date of an updated Privacy Policy constitutes acceptance of the updated policy to the extent permitted by applicable law.

17. Allocation of Data Protection Responsibilities and Third-Party Rights

This Privacy Policy is intended solely to describe the Company’s data protection practices and does not create any contractual or other enforceable rights in favour of any third party, including the customers, clients, or end-users of Clients. To the fullest extent permitted by applicable law, individuals whose personal data is processed on behalf of a Client shall not rely on this Privacy Policy as creating any direct obligations between such individuals and the Company.

Where the Company processes personal data on behalf of a Client acting as data controller, the Client remains solely responsible for ensuring the lawful collection, use, and disclosure of personal data, including providing required privacy notices, obtaining necessary consents, responding to data subject requests, and complying with applicable data protection laws.

The Company is responsible for implementing appropriate technical and organisational measures to protect personal data within the Company’s own systems and infrastructure. Clients are responsible for securing their own systems, credentials, integrations, and environments (including hosting, website, e-commerce, advertising, and social media accounts) and for protecting the personal data they upload, manage, or control through the Services.

The Company shall not be responsible for breaches, incidents, or unauthorised disclosures arising from a Client’s own systems, integrations, personnel, instructions, or failure to implement appropriate security practices. Where required by applicable law, the Company will provide reasonable assistance to Clients to support their compliance obligations, including assistance relating to security incidents or data subject requests, subject to reasonable administrative, technical, and cost limitations.

Annex A: Processing Details (GDPR Information)

A.1 Subject matter and duration. Processing of personal data to provide the Services for the duration of the engagement and any additional retention period described in Section 7.

A.2 Nature and purpose. Designing, developing, hosting, maintaining, and managing websites, online stores, applications, databases, and systems; building automations and AI-assisted workflows; providing SEO, advertising, and social media services; providing support; and ensuring security and compliance.

A.3 Types of personal data. Depending on the engagement: contact and account identifiers, billing data, Client Materials, personal data contained within content, records, or systems we build or manage, marketing and audience data, and any personal data included in instructions provided to us.

A.4 Categories of data subjects. The Client’s personnel and authorised contacts, and (where relevant) the Client’s own customers, clients, end-users, website visitors, and marketing audiences.

A.5 Sub-processors. The Company may use sub-processors as described in Section 5.1.

A.6 Technical and organisational measures. The Company maintains the measures described in Section 9.

B. Where the Company processes personal data on behalf of Clients in connection with the Services, such processing is carried out strictly in accordance with the Client’s documented instructions and applicable data protection laws. In these circumstances, the Client acts as the data controller and is responsible for determining the purposes and legal bases of the processing, including providing any required notices to data subjects and obtaining all necessary consents.

C. The Company does not control the categories of personal data submitted by Clients through the Services and does not independently determine the purposes for which such data is processed. Accordingly, the Company generally does not have a direct relationship with the individuals whose personal data is processed on behalf of Clients and may not be in a position to respond directly to requests from such individuals. Where the Company receives such a request, it may direct the individual to the relevant Client or notify the Client so that the Client can respond in accordance with applicable law.

D. The Company may engage third-party service providers and sub-processors to support the delivery of the Services, including hosting providers, infrastructure providers, analytics providers, payment processors, and support platforms. Such sub-processors are authorised to process personal data only to the extent necessary to perform services on behalf of the Company and are subject to contractual obligations requiring them to implement appropriate security measures and maintain the confidentiality of personal data.

E. The Company may create, use, and disclose aggregated, statistical, or de-identified information derived from the use of the Services for purposes such as analytics, product improvement, research, benchmarking, and operational reporting, provided that such information does not reasonably identify any individual and cannot be re-identified.

F. The Company does not sell personal data provided through the Services and does not retain, use, or disclose personal data processed on behalf of Clients for any purpose other than providing, maintaining, improving, securing, and supporting the Services, or as otherwise permitted or required by applicable law.

G. To the extent required by applicable law, the Company may provide reasonable assistance to Clients to enable them to comply with their data protection obligations, including obligations relating to responding to data subject requests, security incident notifications, data protection impact assessments, and international transfer assessments, subject to reasonable administrative or technical limitations and, where applicable, reimbursement of reasonable costs.

— End of Privacy Policy —
© 2026 Muflon Agency Ltd. All rights reserved.