Easy Merlin International Website Privacy Policy

Last Updated: July 2026

Policy Version: 2.0

Introduction

Easy Merlin International respects your privacy and is committed to protecting your personal data. This Privacy Policy outlines how Easy Merlin International Limited collects, processes, stores, and transfers your personal information when you visit our website, request a demonstration, or interact with our services.

When we refer to “Easy Merlin International”, “Easy Merlin”, “Merlin”, “we”, “us”, or “our” in this policy, we refer to Easy Merlin International Limited (registered at 303 Aarti Chambers, Victoria, Mahé, Seychelles), the data controller responsible for this website and its associated services.

Data Protection Framework & Legislative Compliance

Although Easy Merlin International Limited is based in the Seychelles, our core server infrastructure is hosted within London, United Kingdom, and the European Union. Because we offer services to individuals located within the UK and the European Economic Area (EEA), we comply fully with applicable data protection legislation:

  • UK Data Protection Regime: The UK General Data Protection Regulation (UK GDPR) and the UK Data Protection Act 2018, regulated by the Information Commissioner’s Office (ICO).

  • EU Data Protection Regime: The EU General Data Protection Regulation (EU GDPR) (Regulation (EU) 2016/679).

Easy Merlin International completes Data Protection Impact Assessments (DPIAs) for high-risk processing activities related to our platform and services. Summaries of these assessments are available upon request from our Data Protection Officer (DPO).

Purpose of this Privacy Policy

This Privacy Policy informs you about how we collect and process your personal data through your use of this website, including data provided when you subscribe to a newsletter, request a product demonstration, or contact customer support.

This policy supplements other fair processing notices or specific privacy terms we may provide on specific occasions and is not intended to override them.

Legal Bases for Processing Personal Data

Under the UK and EU GDPR, we must have a valid lawful basis to process your personal data. Depending on the context, we rely on the following legal grounds:

  1. Consent (Art. 6(1)(a)): You have given clear consent for us to process your personal data for a specific purpose (e.g., subscribing to direct marketing or submitting an inquiry via our web forms).

  2. Performance of a Contract (Art. 6(1)(b)): Processing is necessary to fulfill a contract with you or to take pre-contractual steps at your request (e.g., arranging a platform demonstration).

  3. Legitimate Interests (Art. 6(1)(f)): Processing is necessary for our legitimate business interests, provided these are not overridden by your fundamental rights and interests (e.g., website security, system analytics, and service improvements).

  4. Legal Obligation (Art. 6(1)(c)): Processing is necessary to comply with legal or regulatory obligations.

The Data We Collect About You

Personal data (or personal information) means any information relating to an identified or identifiable living individual. It does not include anonymized data where the identity has been permanently removed.

We group the personal data we collect into the following categories:

Data Category Types of Data Included
Identity Data First name, last name, job title, company name.
Contact Data Business address, email address, telephone numbers.
Technical Data Internet Protocol (IP) address, login data, browser type and version, time zone setting, location data, browser plug-in types, operating system, and hardware platform.
Usage Data Information about how you interact with and navigate our website, products, and services.
Marketing Data Your preferences regarding receiving direct marketing communications from us and your communication choices.

How We Collect Your Personal Data

We use different methods to collect data from and about you:

1. Direct Interactions

You may give us your Identity and Contact Data by filling in web forms or by corresponding with us by phone, email, live web chat, or otherwise. This includes data provided when you:

  • Request a product demonstration or software pricing.

  • Subscribe to our newsletters or publications.

  • Chat directly with team members via our website or messaging tools.

  • Participate in surveys, promotional activities, or events.

  • Submit customer support inquiries or feedback.

2. Automated Technologies

When you interact with our website, we automatically collect Technical and Usage Data about your equipment, browsing actions, and usage patterns. We collect this data using cookies, server logs, and web beacons. Please review our Cookie Policy for complete details.

3. Third Parties and Publicly Available Sources

We may receive personal data about you from analytics providers (such as Google Analytics) and search information providers based both inside and outside the UK/EEA.

How We Use Your Personal Data

We only use your personal data when permitted by law. Most commonly, we process your personal data to:

  • Provide software information, sales demonstrations, and requested services.

  • Manage customer relationships and deliver ongoing contract support.

  • Maintain website stability, application security, and network performance.

  • Send relevant marketing communications where you have explicitly opted in or where permitted by soft opt-in rules.

Direct Marketing Notice: You have the right to withdraw your consent to direct marketing at any time by clicking the “Unsubscribe” link in any promotional email or by contacting our DPO.

Special Category (Sensitive) Data

The UK and EU GDPR define “Special Category Data” as personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic/biometric data, health data, or data concerning a person’s sex life or sexual orientation.

This website does not intentionally collect or process any Special Category Data, nor do we collect information regarding criminal convictions or offenses.

Children’s Data

Our website and services are targeted exclusively at commercial businesses and are not intended for children under 16 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data without parental consent, please contact our Data Protection Officer immediately for prompt removal.

International Data Transfers

Because Easy Merlin International operates globally with service entities and processors located outside the UK and EEA (including the USA, Mauritius, Seychelles, Barbados, and South Africa), your personal data may be transferred across international borders.

Whenever we transfer your personal data out of the UK or EEA, we ensure an equivalent degree of protection is afforded to it by enforcing at least one of the following recognized safeguards:

  • Adequacy Decisions: We transfer data to countries that have been formally recognized by the UK Government or European Commission as providing an adequate level of data protection.

  • EU-US Data Privacy Framework (DPF) & UK Extension: When transferring data to US-based service providers, we verify their active certification under the EU-US DPF and the UK Extension to the EU-US DPF.

  • Standard Contractual Clauses (SCCs) & UK IDTA: For transfers to countries without an adequacy decision, we execute approved European Commission Standard Contractual Clauses (SCCs) and the UK International Data Transfer Agreement (IDTA) / UK Addendum with our international entities and vendors.

Authorized Third-Party Processors

To deliver our services, we engage verified third-party organizations to process data on our behalf. These third parties act strictly under our instructions and are bound by data processing agreements requiring high security standards:

  • EVC Marketing (Processor): Located in the United Kingdom and Barbados; processes data for marketing, lead generation, and client liaison. (UK ICO Registration: A8253934).

  • QuickMerlin Pty. Ltd. (Processor): Located in South Africa; processes data for system training, implementation, software development, and technical support.

  • Ithaca Management Services Limited (Processor): Located in Mauritius; processes data for system training, client implementation, development, and support.

  • Merlin Software Services Limited (Processor): Located in the United Kingdom; processes data for operational implementation, software development, and tier-two client support.

  • Intuit / Mailchimp (Sub-processor): Located in the USA; processes contact details for automated email communication under the EU-US DPF / UK Extension safeguards.

Your Legal Rights Under GDPR

Under UK and EU data protection laws, you possess specific statutory rights regarding your personal data:

  • Right to be Informed: The right to receive clear, transparent information about how we use your data.

  • Right of Access (Subject Access Request): The right to request a copy of the personal data we hold about you.

  • Right to Rectification: The right to request correction of inaccurate or incomplete personal data.

  • Right to Erasure (‘Right to be Forgotten’): The right to request the permanent deletion of your personal data where there is no overriding legal reason to retain it.

  • Right to Restrict Processing: The right to suspend the processing of your personal data under specific conditions.

  • Right to Data Portability: The right to receive your personal data in a structured, commonly used, machine-readable format.

  • Right to Object: The right to object to processing based on legitimate interests or direct marketing.

  • Rights Related to Automated Decision-Making: The right not to be subject to decisions based solely on automated processing or profiling.

Exercising Your Rights

  • No Fee Required: You will not have to pay a fee to access your personal data or exercise any of these rights. However, we may charge a reasonable fee or refuse to comply if your request is clearly unfounded, repetitive, or excessive.

  • Verification: We may request specific information to verify your identity before fulfilling a request to protect against unauthorized data disclosure.

  • Response Time: We respond to all legitimate requests within one calendar month. If your request is particularly complex or you have submitted multiple requests, it may take longer, and we will keep you informed.

Data Security & Storage

We store and handle your personal data in alignment with ISO/IEC 27001 standards for information security management. We maintain appropriate physical, technical, and administrative security measures to prevent your personal data from accidental loss, unauthorized access, destruction, or disclosure.

Access to personal data is strictly limited to authorized employees, agents, contractors, and processors who have a business “need-to-know” and operate under strict confidentiality duties.

We maintain formal incident response procedures to investigate suspected personal data breaches and will notify affected individuals and regulatory authorities whenever legally required.

Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including satisfying any legal, accounting, tax, or regulatory reporting obligations.

To determine appropriate retention periods, we evaluate the volume, nature, sensitivity, and potential risk of harm from unauthorized disclosure of the personal data, alongside applicable statutory retention mandates.

External Website Links

Our website may include links to third-party websites, plug-ins, and applications. Clicking on those links may allow third parties to collect or share data about you. We do not control these external websites and are not responsible for their privacy policies. When leaving our website, we encourage you to read the privacy notice of every site you visit.

Policy Updates & Governance

We review this Privacy Policy periodically to reflect technological, operational, or legal updates. Any amendments will be posted directly to this page.

  • Current Version: 2.0

  • Effective Date: July 2026

Contact Us & Supervisory Authority Complaints

If you have questions about this Privacy Policy, wish to exercise any of your legal rights, or wish to make a inquiry, please contact our Data Protection Officer:

Data Protection Officer

Easy Merlin International Limited

C/O Acclime Limited

303 Aarti Chambers, Victoria, Mahé, Seychelles

Email: DPO@quickmerlin.com

Contacting Regulatory Authorities

If you are unsatisfied with our response or believe your data is being processed unlawfully, you have the right to lodge a complaint with a data protection supervisory authority:

  • United Kingdom (ICO): You can contact the Information Commissioner’s Office via their website at www.ico.org.uk or by calling +44 (0) 303 123 1113.

  • European Union: You may contact your local EU Member State Data Protection Authority (DPA).