Privacy Policy

Last updated: 25 June 2026
Template starting point — please have it reviewed by a solicitor and complete the bracketed entity details before launch.

This policy explains how [Gridly Ltd], London, United Kingdom ("we") handles personal data when you use Gridly. We act as a controller for account and billing data, and as a processor for the content you store in your workspaces. We comply with the UK GDPR and the Data Protection Act 2018.

1. Data we collect

2. How we use it & legal bases

3. Sharing & subprocessors

We share data only with providers that help us run the Service, under appropriate agreements:

We do not sell personal data.

4. Retention

We keep account and workspace data while your account is active. After deletion we remove or anonymise personal data within a reasonable period, except where we must retain it for legal, accounting, or security reasons.

5. Your rights

Subject to UK GDPR, you may request access, correction, deletion, restriction, portability (export), or object to certain processing. You can export your data from within the app, and you can delete your account. To exercise other rights, contact [email protected]. You may also complain to the UK Information Commissioner's Office (ICO).

6. Security

We use encryption in transit, hashed passwords, per-workspace data isolation, access controls, and rate limiting. No system is perfectly secure, but we work to protect your data and will notify you of breaches as required by law.

7. International transfers

Where data is processed outside the UK, we rely on appropriate safeguards such as adequacy decisions or standard contractual clauses.

8. Changes & contact

We may update this policy and will post the new version with a date. Questions or requests: [email protected].