Skip to content
Mutus Tech

Data Security Policy

First approved: 8 August 2023 · Review cycle: annual · Approved by Tim Li, Managing Director, Mutus Tech Ltd.

1. Introduction

This Data Security Policy sets out how Mutus Tech Ltd ("we", "us", or "our") safeguards sensitive personal information and confidential information as required by law, including the Data Protection Act 2018, UK GDPR, and the Common Law duty of confidentiality.

2. Purpose

We restrict access to confidential and sensitive data to protect it from being lost or compromised, in order to avoid adversely impacting our customers, incurring penalties for non-compliance and suffering damage to our reputation. At the same time, we ensure users can access data as required for them to work effectively.

This policy cannot eliminate all risks. Its primary objective is to increase user awareness, avoid accidental loss, and define requirements for breach prevention and incident response.

3. Scope

This policy applies to all customer data, personal data and other company data we classify as sensitive. It applies to every server, database and IT system handling such data, including any device regularly used for email, web access or work-related tasks.

Information classified as Public is not subject to this policy. Data may be excluded by management decision where protection is disproportionate to the risk.

The policy covers data in both hardcopy and digital form, including special category data under UK GDPR. It applies to all staff — permanent, temporary, contractors and project partners.

4. Data classification

Mutus Tech uses the following data classification levels:

  • Public — information intended for public use (e.g. marketing materials).
  • Internal — non-sensitive company information for internal use.
  • Confidential — sensitive business or client data, limited to authorised staff.
  • Restricted — highly sensitive data requiring additional security measures and limited access.

5. Policy

5.1 Principles

  • Staff and contractors have access only to the information necessary to perform their duties.
  • Access is reviewed regularly and revoked when no longer required.

5.2 General

  • Each user is identified by a unique user ID. Shared accounts are only permitted where appropriate (e.g. training accounts).
  • All users confirm in writing that they have read and understood this policy.
  • Access is granted on the principle of least privilege.
  • User access records may be used as evidence during investigations.

5.3 Access control

  • Account credentials follow a strong password policy aligned with current UK NCSC guidance.
  • Multi-factor authentication is required for all production and administrative access.
  • Accounts are issued by the IT administrator upon approval from management.
  • Role-based access control (RBAC) is applied where practical.

5.4 Network access

  • Staff and contractors are granted network access according to business need.
  • Remote access is restricted to authenticated, encrypted channels.
  • Networks are segregated where appropriate to reduce risk.

5.5 User responsibilities

  • Lock screens when leaving desks.
  • Keep work areas clear of sensitive documents.
  • Do not share passwords or use personal accounts for company work.
  • Do not use personal email, storage devices or unapproved cloud services for company data.

5.6 Application and information access

  • Access to applications and data is provided only where necessary for job roles.
  • Access to sensitive data requires management approval.
  • Sensitive systems are physically or logically restricted.

5.7 Access to confidential or restricted data

  • Limited to authorised staff with a clear business need.
  • Access restrictions are enforced by the IT administrator.

6. Responsibilities

  • Data Owners — executives, managers or team leaders responsible for the information they own.
  • Information Security Administrator — appointed IT staff responsible for implementing and overseeing security measures.
  • Users — all employees, contractors and partners with access to company data.
  • Incident Response — in the event of a data breach, the Managing Director and IT Administrator lead the response, escalating to external advisors (legal or compliance) if necessary.

7. Incident response

  • All suspected data breaches must be reported immediately to the IT Administrator or Managing Director.
  • We follow UK GDPR requirements, including reporting to the ICO within 72 hours where required.
  • Impacted customers and partners are notified in line with legal obligations.

8. Review

This policy is reviewed annually, or earlier if required by changes in law or business practice.


Related: Data Sharing Policy · Data Management Policy · Website Privacy Policy · Trust & compliance overview