Skip to main content
BuruOps Data Governance and Privacy Framework
UK GDPR • DATA PROTECTION ACT 2018 • PRIVACY NOTICE

Privacy Policy & Data Protection

This statutory privacy notice sets out how BuruOps Intelligence Lab ("BuruOps", "we", "us", or "our"), operating as the specialized technical engineering arm of Mtengwa Strategic Advisory, collects, processes, stores, and safeguards personal data in strict compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Your Statutory Rights (DSAR) Cookie Policy Compliance Portal
DATA CONTROLLER
BuruOps Intelligence Lab
Mtengwa Strategic Advisory Lineage
SUPERVISORY AUTHORITY
Information Commissioner's Office (ICO)
United Kingdom Authority
DATA PROTECTION LEAD
principal@buruops.com
Response SLA: 1 Calendar Month

1. Data Controller Identification

For the purposes of the UK GDPR and the Data Protection Act 2018, the Data Controller responsible for your personal data is:

BuruOps Intelligence Lab
A technical engineering capability of Mtengwa Strategic Advisory
Postal Address: Burhani Mtengwa • 61 Bridge Street, Kington, HR5 3DJ, UK
Contact Email: principal@buruops.com
Telephone: +44 1483 928037

2. The Data We Collect & Process

We operate on a strict data minimization framework. We only collect personal information that is necessary to evaluate technical engineering scopes, execute commercial contracts, or safeguard the security of our infrastructure:

  • Contact & Identification Data: Full name, professional email address, organisation name, telephone number, and job title when you submit technical intake or advisory briefing requests.
  • Technical Scope Data: System architectural notes, cloud deployment specifications, code repository links, and compliance objectives voluntarily provided during assessment scoping.
  • Technical Access Telemetry: Anonymized client IP addresses, browser user-agent strings, HTTP request headers, and request timestamps captured in server-level access logs exclusively for security monitoring, DDoS mitigation, and anti-abuse controls.
  • Commercial & Billing Data: Company registration number, VAT ID, accounts payable contacts, and transaction verification records necessary to satisfy UK statutory accounting requirements.

3. Lawful Bases for Processing (UK GDPR Article 6)

Under UK data protection laws, we rely on the following lawful bases to process your personal data:

A. Contractual & Pre-Contractual Measures (Article 6(1)(b))

Processing your technical inquiry, assessing organizational requirements, drafting Statements of Work (SOW), and delivering fixed-price technical audit deliverables.

B. Legitimate Interests (Article 6(1)(f))

Protecting BuruOps infrastructure against malicious brute-force attempts, unauthorized vulnerability scanning, and cross-site scripting attacks; ensuring the resilience of our systems; and maintaining institutional correspondence.

C. Legal Obligation (Article 6(1)(c))

Satisfying statutory corporate accounting, tax filings with HM Revenue & Customs (HMRC), corporate records under the Companies Act 2006, and cooperating with statutory UK law enforcement when legally mandated.

D. Consent (Article 6(1)(a))

Where you choose to activate non-essential diagnostic telemetry cookies via our PECR Cookie Preference Center. Consent can be revoked at any time without detriment.

4. Technical & Organisational Security Measures (TOMs)

In accordance with UK GDPR Article 32, BuruOps implements state-of-the-art security safeguards designed for high-assurance environments:

  • Transport Layer Security: All data transmitted to and from our platforms is encrypted using TLS 1.3 with modern cipher suites and Strict-Transport-Security (HSTS) preloaded.
  • Encryption at Rest: All stored client documentation and database tables are encrypted with AES-256 using envelope key management with automated rotation.
  • Zero Trust Network Architecture: Internal administrative tools and research staging nodes require hardware multi-factor authentication (FIDO2 WebAuthn keys) and encrypted WireGuard/Tailscale mesh routing.
  • Ephemeral Staging of Audit Artifacts: Customer vulnerability reports and code snapshots are isolated in encrypted, zero-knowledge storage containers and systematically purged following project sign-off.

5. Data Retention Periods

We retain personal data only for as long as strictly necessary to fulfill the purposes for which it was gathered:

DATA CATEGORY RETENTION PERIOD DISPOSAL METHOD
Technical Inquiries & Contact Forms 12 months from last contact Permanent cryptographic deletion
Commercial Contracts & Invoices 6 years (UK Limitation Act 1980 / HMRC) Archived in cold encrypted vault
Client Architecture Snapshots & Audits 30 days post-remediation sign-off DoD 5220.22-M zero-overwrite purge
Web Server Access Logs 90 days rolling rotation Automated log rotation purge

6. International Data Transfers

BuruOps prioritizes United Kingdom sovereign infrastructure. Where data must be processed in secondary jurisdictions (such as cloud hosting nodes operated by AWS, Google Cloud, or Cloudflare), we ensure valid transfer mechanisms under UK GDPR Chapter V:

  • Transfers to countries recognized as providing adequate data protection by the UK Secretary of State under UK Adequacy Regulations.
  • Execution of the UK International Data Transfer Addendum (IDTA) to the European Commission's standard contractual clauses (SCCs) alongside supplementary technical encryption controls.

7. Your Statutory Rights Under UK GDPR (Articles 15–22)

As an individual residing in the United Kingdom or EU, you hold substantive statutory rights regarding your personal data:

Right of Access (DSAR)

Request a complete copy of all personal records we hold about you without fee.

Right to Rectification

Demand the immediate correction of inaccurate or incomplete information.

Right to Erasure

Request the permanent deletion ("right to be forgotten") of your data where no overriding legal basis applies.

Right to Restrict Processing

Request that we suspend processing while data accuracy or legal legitimacy is evaluated.

Right to Data Portability

Receive your personal records in a structured, commonly used, machine-readable format (JSON/CSV).

Right to Object

Object to processing based on legitimate interests or any direct marketing communication.

How to Exercise Your Rights (DSAR Process)

To submit a Data Subject Access Request (DSAR) or exercise any of the rights above, email our Data Protection Lead directly at principal@buruops.com with the subject line "UK GDPR Data Subject Request".

We will acknowledge your request within 48 hours and provide a full statutory response within one calendar month as mandated by UK GDPR Article 12(3). We may request proof of identity to protect against unauthorized disclosure.

8. Right to Complain to the Supervisory Authority (ICO)

You have the statutory right to lodge a complaint with the UK data protection supervisory authority if you believe your personal data has been handled unlawfully:

Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom
Helpline: +44 (0)303 123 1113