Merus Privacy Policy
Effective date: 14th July 2026
The short version
Merus Ltd ("Merus", "we", "us" or "our") uses a small amount of personal data to:
- respond when you contact us;
- understand how our website is being used; and
- keep our website and services secure.
We do not sell personal data. The main Merus website does not use advertising cookies or third-party advertising trackers. We use a temporary session identifier for basic, first-party website analytics.
You may ask us to access, correct, restrict, erase or provide a copy of your personal data, or object to how we use it. Contact our privacy team at info@merushq.com
1. Who is responsible for your data?
The organisation responsible for the personal data described in this policy is:
Merus Ltd
Kigali, Rwanda
Company registration number: 156331853
General enquiries: info@merushq.com
Privacy email: privacy@merushq.com
Telephone: +250 783 041 610
This policy applies to the main website at merushq.com, including its contact form and first-party website analytics.
Some Merus products, surveys and client projects involve additional types of data or involve Merus processing data on a client's instructions. Those activities should have their own privacy notice, project agreement or data-processing agreement. If a project-specific notice conflicts with this website policy, the project-specific notice applies to that project.
2. What information do we collect?
When you contact us
We collect the information you submit, including:
- your name;
- email address;
- telephone number;
- subject; and
- the contents of your message.
The current contact form requires each of these fields before it can be submitted. You choose whether to send an enquiry at all. If you do not want to provide a telephone number through the form, you may contact us directly at info@merushq.com.
Please do not include sensitive personal information in a general website message unless it is necessary and we have asked you to provide it securely.
When you visit the website
When the production website loads, our first-party analytics automatically collects:
- a randomly generated session identifier stored in your browser's session storage;
- a protected hash of your IP address, but not the raw IP address in our analytics database;
- approximate country and city;
- the page path you visited, which may include query parameters;
- the referring page;
- browser and device information, including the user-agent string and device type;
- page-view and page-exit events;
- visit duration; and
- whether a short visit appears to be a bounce.
The session identifier is temporary and normally disappears when the browser session ends. It is not an advertising identifier and is not used to track you across unrelated websites. This information is only used to understand how our website is performing and to improve it, and it also helps us with abuse prevention.
Information from clients or partners
If you become a client, supplier or partner, we may also collect professional contact details, correspondence, contract information, billing information and records needed to deliver the agreed work. The signed service agreement and any project-specific privacy terms will provide more detail where needed.
3. Why do we use this information?
| Purpose | Information used | Our reason for using it |
|---|---|---|
| Respond to an enquiry and discuss a possible project | Contact details and message | To take steps you request before entering a contract and for our legitimate interest in answering genuine enquiries |
| Deliver an agreed service | Client and project information | To perform our contract and meet related legal obligations |
| Understand and improve the website | First-party visit analytics | Our legitimate interest in knowing whether the website works well and which content is useful |
| Protect the website and prevent abuse | Hashed IP address, request and security information | Our legitimate interest in keeping our systems reliable and secure and, where applicable, meeting legal obligations |
| Establish or defend legal rights | Relevant contact, contract and technical records | Our legitimate interest in protecting our legal rights and complying with the law |
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing that was lawful before you withdrew consent.
We do not use the website data described in this policy to make decisions about you solely by automated means that have legal or similarly significant effects.
4. Who receives the information?
We limit access to people who need the information for the purposes above. Recipients may include:
- authorised Merus staff and contractors;
- website hosting, network and security providers;
- database and backup providers;
- email delivery providers and Merus's business email service;
- professional advisers such as lawyers, accountants and auditors; and
- public authorities where disclosure is required by law or needed to protect legal rights.
These providers may process information only for the service they provide to us and under appropriate confidentiality and data-protection terms.
We do not sell personal data, rent contact lists or share website visitors' data with advertising networks.
5. Where is the information stored?
Rwandan law regulates storing or transferring personal data outside Rwanda. To ensure our website is fast and reliable globally, we utilize modern distributed hosting infrastructure, edge networks, and Content Delivery Networks (CDNs). As a result, your data may be temporarily processed in or routed through various countries worldwide. Our primary databases, email, and support services are hosted in the United States, UK & EU.
Where personal data is stored in or transferred to another country, we will do so only as permitted by applicable law, including obtaining any required authorisation and using appropriate contractual, organisational and security safeguards.
You may contact privacy@merushq.com to ask whether your personal data has been transferred outside Rwanda and to request information about the relevant safeguards.
6. How long do we keep information?
We keep information for the following periods:
- Contact enquiries: up to 24 months after our last meaningful contact, unless the enquiry becomes a client engagement or we need the record for a legal reason.
- Website analytics: up to 12 months, after which the event-level data is deleted or irreversibly aggregated.
- Security and application logs: normally up to 90 days, unless a longer period is needed to investigate an incident or meet a legal obligation.
- Client and contract records: for the life of the engagement and then for the period required by tax, accounting, contractual or other applicable law.
We may keep information longer where necessary to establish, exercise or defend a legal claim, respond to a lawful authority, investigate fraud or preserve evidence relating to a security incident. When we no longer need personal data, we delete it, anonymise it or securely isolate it until deletion is possible.
7. How do we protect information?
We use reasonable technical and organisational safeguards appropriate to the risk. These include access controls, encrypted website connections, server-side validation, rate limiting, restricted secrets, parameterised database queries, security headers and logs designed not to contain contact-form contents or raw IP addresses.
No system is perfectly secure. If a personal-data breach creates a high risk to you, we will notify you and the relevant authority as required by law.
8. Your choices and rights
Subject to applicable law, you may ask us to:
- explain how we use your personal data;
- give you access to or a copy of it;
- correct incomplete or inaccurate data;
- erase data we no longer need;
- restrict how we use it;
- stop or object to certain processing, including direct marketing;
- provide data you gave us in a structured, readable format and, where technically feasible, transfer it to another controller;
- withdraw consent where consent is our basis for processing; and
- explain whether your data has been transferred outside Rwanda.
To make a request, email privacy@merushq.com. Please describe what you need. We may ask for enough information to confirm your identity and protect your data from unauthorised access. We will respond within the time required by law, generally within 30 days for the rights for which Rwandan law sets that period.
Some rights have legal exceptions. For example, we may keep information needed to comply with a legal obligation or to establish, exercise or defend a legal claim. If we cannot fully grant a request, we will explain why.
9. Children
The website and its business enquiry form are not directed to children under 16. Please do not submit a child's personal data through the general contact form. If we learn that we collected a child's personal data without the required permission, we will take appropriate steps to delete it.
Merus projects that intentionally involve children must use a project-specific notice, safeguards and consent process appropriate to the project and applicable law.
10. Other websites
Our website may link to client, partner or third-party websites. Their privacy practices are controlled by their own policies. Please review those policies before providing them with personal data.
11. Changes to this policy
We may update this policy when our services, technology or legal obligations change. We will post the updated version with a new effective date. If a change materially affects how we use information already collected, we will provide a more prominent notice or request consent where the law requires it.
12. Questions or complaints
Please contact us first so we can try to resolve your concern:
Merus privacy contact / Data Protection Officer
Gedeon Niyonkuru
privacy@merushq.com
+250783041610
Kigali, Rwanda
