Privacy Policy

We are Murphy Ventures, S.L. (known as Murphy). This Policy explains how we (including our subsidiaries) protect your personal data and respect your privacy.

Last updated 31 July 2026

It applies when you visit our website, ask for a demo, deal with us in a business capacity or use a Murphy account. If Murphy’s technology was used to contact you about an account or payment, see “What if Murphy contacted me for a customer?” below.

Your privacy at a glance

What we collect. Business contact details, enquiries and communications, account information, and website or device data.

Why we use it. To respond to you, run and secure our services, manage business relationships, improve Murphy and send relevant B2B marketing where lawful.

Who receives it. Murphy personnel and carefully selected providers, advisers, business counterparties or authorities where needed.

How long we keep it. Only for as long as it is needed. Our usual periods are explained below.

Your choices. You can object to marketing, manage cookies and exercise your data protection rights.

Questions or privacy requests? Email legal@getmurphy.ai

1Our role in your privacy

Murphy Ventures, S.L. is a Spanish company that provides AI-enabled software for collections operations.

Murphy Ventures, S.L., business address at Pamplona 98, 08018 Barcelona, Spain, is the controller for the personal data covered by this Policy. Our Data Protection Officer can be contacted at legal@getmurphy.ai.

When are we the controller?

We decide why and how personal data is used when you browse our website, request a demo, communicate or do business with us, attend our events, or use a Murphy account. We are also the controller for our own legal, security and business administration.

What if Murphy contacted me for a customer?

Our customers - sometimes working through a debt collection agency or another service provider - normally decide why and how personal data is used in a collections workflow. For that data, the customer or other organisation named in the communication is the controller. Murphy acts as its processor or sub-processor and follows its documented instructions.

Please read the privacy information provided by the organisation identified in the call, message or other communication. It is normally the best first contact for a privacy request. If you contact us, we will direct your request to, or assist, the relevant controller as required. We do not use that service data for unrelated purposes.

What about recruitment?

If you are applying to work at Murphy, please read our careers privacy policy instead.

2When and how we collect data

We collect data when you interact with Murphy. Sometimes you give it to us, sometimes your organisation or another business contact gives it to us, and sometimes we collect it automatically or from lawful public and business sources.

You browse our website or manage cookie choices.

You request a demo, contact us, meet us or attend an event.

We identify you as a relevant business contact using professional or corporate sources.

Your organisation creates or administers your Murphy account.

You use an account, request support or receive service communications.

You receive or respond to our business marketing.

Sources may include you, your employer or colleagues, account administrators, referrers, event organisers, company websites, professional networking sites, public registers, business data providers, and your browser or device. If we obtain your business contact data indirectly, we will provide or point you to this Policy at our first communication or within the period required by law, unless an exception applies.

3The types of data we collect

Contact and work details. Your name, work email, telephone number, job title, organisation, location and professional profile.

Enquiries and relationships. Demo requests, interests, correspondence, meetings, events, feedback, preferences and our relationship history.

Account information. User identifiers, roles and permissions, authentication events, account activity, support requests and service messages.

Website and device data. IP address, browser and device type, operating system, approximate location, referral source, pages viewed, timestamps and similar identifiers.

Marketing data. Preferences, consent and objection records, campaign engagement and event or content interests.

Business and compliance data. Contracts, billing and payment administration, due diligence, security indicators and legally required records.

Communications. Emails, calls and meeting content and, where notified and lawful, recordings or transcripts.

What about sensitive data?

Please do not send health, biometric, political, religious, trade union or other special category data through our general website or demo forms unless we specifically request it and explain why it is needed.

What about children?

Our website and business services are not directed to children, and we do not knowingly collect children’s data through general website or demo forms. A customer’s processing of information about a minor is governed by that customer’s instructions, applicable law and its own privacy information.

4How and why we use your data

Data protection law allows us to use personal data only for specified purposes and where we have a legal basis. Here is what that means in practice.

What do these legal bases mean?

Consent. You have made a clear choice. You can withdraw it at any time.

Contract. The processing is needed for a contract with you or steps you ask us to take before one.

Legal obligation. The law requires us to use or retain the information.

Legitimate interests. The processing supports a genuine business need and your rights and interests do not override it. We assess that balance.

Privacy by design

We consider data protection throughout the design and development of our services and, where appropriate, configure them to limit personal data to what is necessary for the relevant purpose.

Do we make automated decisions about you?

We do not use data covered by this Policy to make decisions based solely on automated processing that produce legal or similarly significant effects. We may use lower-risk automation to route enquiries, manage communication preferences, flag security events or assist with meeting notes where notified. Customer collections workflows are covered by the relevant controller’s privacy information.

What we doWhy we do itLegal basis
Keep Murphy running and secureOperate the website and accounts, authenticate users, prevent misuse, troubleshoot and protect our customers, users and systems.Legitimate interests; legal obligations where applicable
Respond and do business with youAnswer enquiries, arrange demos, manage customer, supplier and partner relationships, and provide support.Legitimate interests; contract or pre-contract steps where applicable
Improve MurphyUnderstand website and service use, obtain feedback, test and improve our communications and services.Consent for non-essential technologies; legitimate interests for permitted service analytics
Market MurphyIdentify and contact relevant business prospects and send product, event or content communications.Consent where required; otherwise legitimate interests in relevant B2B marketing
Meet legal and business obligationsCompliance, audits, security, claims, disputes, financing, reorganisation or a corporate transaction.Legal obligations; legitimate interests in governance and protecting legal rights

5Your choices and rights

You can choose not to provide data

You can browse much of our website without giving us information directly. If you do not complete a required field, however, we may not be able to respond, arrange a demo, create or secure an account, or provide support. Some identity and security information is necessary to give authorised users platform access.

You can stop direct marketing

Use the unsubscribe option in a message or email legal@getmurphy.ai. We may keep a minimal suppression record so that we remember your choice.

You can manage cookies

You can accept, reject or change non-essential cookie choices through Cookie Settings. Our Cookie Policy explains the technologies, providers, purposes and lifetimes. Strictly necessary technologies may be used without consent where the law permits.

You have data protection rights

Depending on the circumstances and applicable law, you may ask us to:

explain how we use your data and give you a copy;

correct inaccurate or incomplete data;

erase or restrict our use of data;

provide certain data in a portable format or transfer it to another controller;

stop processing based on legitimate interests, including profiling; or

withdraw consent and object to direct marketing at any time.

These rights are not absolute. Email legal@getmurphy.ai to exercise one. We may ask for information needed to verify your identity and locate the records, and normally respond within one month, subject to any lawful extension.

6Who receives your data?

Like most technology companies, we use specialist providers to host services, run forms, communicate, schedule meetings, provide support, analyse permitted usage and protect our systems. We share only what is reasonably necessary and require appropriate protection.

Our supplier programme includes proportionate due diligence, contractual data protection and security requirements, and ongoing review based on risk.

Technology providers. Hosting, cloud infrastructure, website and forms (including Typeform for demo requests), CRM, communications, scheduling, analytics, support, security and document systems.

Murphy personnel and group companies. Authorised people who need the information for the relevant purpose.

Your organisation and business parties. Account administrators, customers, partners or introducers where needed for the relationship or request.

Advisers and assurance providers. Lawyers, accountants, auditors, certification bodies, insurers and similar advisers.

Authorities and transaction parties. Courts, regulators, law enforcement, or parties involved in a financing, reorganisation, acquisition or sale, subject to appropriate safeguards.

7Where is your data processed?

Murphy is established in Spain. Some recipients or support teams may be outside the European Economic Area or access data from another country. Where the law restricts a transfer, we use an approved mechanism such as an adequacy decision, the European Commission’s Standard Contractual Clauses, or the UK International Data Transfer Agreement or Addendum, with supplementary safeguards where appropriate.

Email legal@getmurphy.ai for more information about relevant safeguards. We may redact confidential or security-sensitive details.

8How long do we keep your data?

We keep data only for as long as it is needed for the relevant purpose. A legal hold, investigation, dispute, contract or law may require a longer period.

Type of recordUsual period
Website technical and security logsUsually up to 12 months
Cookies and similar technologiesFor the lifetime shown in the Cookie Policy or consent tool
Enquiries, prospects and marketing contactsUsually 24 months after the last meaningful interaction; suppression records may be kept longer
Customer, supplier, partner and account recordsFor the relationship and then applicable legal periods, usually up to six years
Support and service-administration recordsFor the relationship and then usually up to 12 months
Rights requests, complaints and compliance recordsUsually three years after closure
Call or meeting recordingsFor the period notified and no longer than needed for that purpose

9How do we protect your data?

We use appropriate technical and organisational safeguards designed to prevent accidental or unlawful loss, alteration, disclosure or access. Depending on the risk, these include access controls, encryption, logging and monitoring, secure development, incident response, resilience and recovery, staff training and supplier checks.

We maintain procedures to identify, investigate, contain and respond to security incidents and make notifications required by applicable law and our customer contracts.

No system is completely secure. We review safeguards in light of the data, risks and available technology. If you believe your privacy has been affected, contact legal@getmurphy.ai.

10Complaints

Please contact our Data Protection Officer first so that we can try to resolve your concern. You may also complain to the Spanish Data Protection Agency (AEPD), the UK Information Commissioner’s Office, or another competent supervisory authority.

11Other websites and services

Our website may link to third-party websites, forms or services. Those operators are responsible for their own privacy practices when they act as controllers. Please read the privacy information they provide.

Keeping this Policy useful

We review this Policy at least once a year and when our processing, services or legal obligations change significantly. We will update the date on this page and take additional steps to tell affected people where a change is material. This Policy was last updated on 31 July 2026. Questions, complaints or rights requests: legal@getmurphy.ai