Privacy Policy.
Last updated: 22 July 2026
This policy is maintained by Merrion Asset Management to explain how we handle personal information across every jurisdiction we operate in. It reflects the standards of South Africa's POPIA, the EU and UK GDPR, California's CCPA/CPRA, Brazil's LGPD, Canada's PIPEDA, and other comparable global privacy frameworks.
1. Who we are
Merrion Asset Management ("MAM", "we", "us", "our") is a global public relations agency for entrepreneurs and investors, operating as MAM.Limited. We act as the Controller (GDPR / UK GDPR / LGPD), Business (CCPA/CPRA), and Responsible Party (POPIA) for personal information you share with us through this website, our contact channels, and our affiliated partner network.
Where we process personal information on behalf of a client engagement (for example, managing investor relations for a client's stakeholders), we act as a Processor or Operator under our client's instructions and our data processing agreement.
2. Information Officer & Data Protection contact
Our designated Information Officer (POPIA), Data Protection contact (GDPR / UK GDPR), and privacy contact for all other jurisdictions is Gwen Swan. All privacy, access, correction, deletion, portability, and objection requests may be sent to info@mam.limited.
For EU/UK residents: where required, we will designate an Article 27 GDPR representative on request.
3. Information we collect
- Contact details you submit — name, email address, phone number, and the content of any enquiry.
- Service context — the practice area you indicate interest in (podcast, startup promotion, investor mentorship, investor relations, or other).
- Consent evidence — a record that you agreed to this policy, the version acknowledged, and the timestamp.
- Engagement information you voluntarily share during our work together — company details, financials, investor lists, media assets, and related documents.
- Technical data — IP address, device and browser type, referring pages, and interaction events collected via essential and, where you consent, analytics cookies.
We do not knowingly collect special categories of personal data (health, race, religion, political opinions, biometric or genetic data, sexual orientation, etc.) and ask that you do not send such information through our forms.
4. Children's data
Our services are directed to businesses and professionals. We do not knowingly collect personal information from children under 16 (or the equivalent minimum age in your jurisdiction). If you believe a child has provided information to us, contact our Information Officer and we will delete it promptly.
5. Purpose of processing & legal bases
We process personal information only for these purposes:
- Responding to your enquiry and coordinating next steps — consent and steps prior to entering a contract.
- Delivering the specific service you engage us for — performance of a contract.
- Coordinating with affiliated production, media, and advisory partners where required — legitimate interests in fulfilling the engagement, balanced against your rights.
- Meeting legal, regulatory, tax, and anti-money-laundering obligations — legal obligation.
- Protecting our systems, preventing fraud, and enforcing our terms — legitimate interests.
Under GDPR, UK GDPR, and LGPD we rely on the legal bases noted above. Under POPIA, we rely on the corresponding justifications in section 11. You may request a legitimate-interests balancing summary from our Information Officer at any time.
6. Sharing your information
We share personal information only with:
- Affiliated producers, journalists, advisors, and service providers strictly as required to deliver the service you engaged us for.
- Regulators, courts, and law enforcement where legally required.
- Infrastructure processors (hosting, database, email delivery, analytics) bound by written data processing agreements and appropriate technical safeguards.
- A successor entity in the event of a merger, acquisition, or restructuring — subject to equivalent privacy commitments.
We do not sell your personal information, we do not share it for cross-context behavioural advertising, and we do not use it for third-party marketing. This includes the meaning of "sell" and "share" under the CCPA/CPRA.
7. International data transfers
MAM operates globally. Personal information may be processed outside your country of residence, including in South Africa, the European Economic Area, the United Kingdom, and the United States. When we transfer personal data across borders we rely on one or more of the following safeguards:
- European Commission or UK adequacy decisions where they apply.
- Standard Contractual Clauses (EU 2021/914 and the UK International Data Transfer Addendum), supplemented by technical and organisational measures where required by a transfer impact assessment.
- POPIA section 72 conditions for cross-border transfers, including binding rules and contractual protections substantially similar to POPIA.
You may request a copy of the transfer mechanism applied to your data by contacting our Information Officer.
8. Retention
Enquiry records are kept for up to 24 months from your last interaction with us, then deleted or de-identified. Engagement records (agreements, briefs, investor communications, media assets) are retained for the periods required by applicable law — typically five to seven years from completion. Consent and preference logs are retained for the life of the record they evidence, plus the applicable limitation period.
9. Security
We apply reasonable and appropriate technical and organisational safeguards — encrypted transport (TLS), encryption at rest for our managed database, role-based access controls, audit logging, least-privilege access, and vendor due diligence — to protect personal information against loss, unauthorised access, disclosure, alteration, or destruction. No system is perfectly secure; where a personal-data breach is likely to result in a risk to your rights, we will notify the relevant regulator and, where required, you directly, within the timeframes required by applicable law (including the 72-hour window under GDPR / UK GDPR).
10. Cookies & analytics
We use a small number of strictly necessary cookies to operate the site and, where permitted, privacy-respecting analytics to understand aggregate usage. You can control cookies through your browser and, where a consent banner is presented, through its preferences. We honour Global Privacy Control (GPC) signals as a valid opt-out of "sale" or "sharing" under the CCPA/CPRA.
11. Automated decision-making & AI
We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing, and we do not use your personal information to train third-party generative AI models. Where we use AI tools internally (for example, drafting or transcription) we do so under contracts that prohibit the vendor from using your content to train their models.
12. Your rights
Subject to applicable law, you have the right to:
- Access the personal information we hold about you and receive a copy.
- Correct or update inaccurate or incomplete information.
- Delete your information ("right to erasure" / "right to be forgotten") where a lawful ground applies.
- Restrict or object to our processing, including for direct marketing.
- Data portability — receive a machine-readable copy of information you provided to us.
- Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.
- Opt out of sale, sharing, or targeted advertising (CCPA/CPRA and similar US state laws) — we do not do any of these, but you may still submit a request for the record.
- Non-discrimination — we will not treat you differently for exercising any privacy right.
- Appeal a denied request where your local law (e.g. Virginia, Colorado, Connecticut) provides an appeal right.
To exercise any right, email info@mam.limited. We respond within the timeframes required by your local law (typically 30 days under GDPR / UK GDPR / POPIA and 45 days under CCPA/CPRA, extendable once where permitted). We may need to verify your identity before acting on a request. Authorised agents may submit requests on your behalf with proof of authority.
13. Regulator complaints
You may lodge a complaint with your local data protection authority, including:
- South Africa — Information Regulator, inforegulator.org.za.
- European Economic Area — your national Data Protection Authority (list at edpb.europa.eu).
- United Kingdom — Information Commissioner's Office, ico.org.uk.
- Brazil — Autoridade Nacional de Proteção de Dados (ANPD).
- Canada — Office of the Privacy Commissioner of Canada.
- California — California Privacy Protection Agency or the Attorney General.
We would appreciate the opportunity to address your concerns directly before you contact a regulator.
14. Changes to this policy
We may update this policy from time to time to reflect changes in law, technology, or our practices. The "Last updated" date above reflects the current version. Where changes are material we will provide additional notice. When you submit an enquiry, we record the version of the policy you agreed to.