Privacy Policy

Effective date
September 22, 2026
Last updated
September 22, 2026
Version
1.0.0

1. Introduction

GRISANT LTD ("we", "us", or "our") is committed to protecting and respecting your privacy. This Privacy Policy outlines our practices regarding the collection, use, and disclosure of your personal data when you visit our website (grisant.co), use our mobile applications, or interact with our digital software services. We act as the Data Controller in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. Information We Collect

A. Information You Provide to Us

We collect information you directly submit when contacting us via email, signing up for accounts, or requesting customer support. This may include your name, email address, and any correspondence you send us.

B. Technical and Device Information

When you access our software, we may automatically process non-personally identifiable diagnostic and telemetry data, including device model, operating system version, unique device identifiers, locale settings, and crash logs to ensure application stability.

C. Usage and Analytics Data

We process aggregated interaction metrics to understand user flows and enhance application features. We do not engage in cross-app tracking without explicit prior opt-in consent.

4. How We Use Your Information

  • To provide, maintain, and support our digital products and mobile applications.
  • To diagnose bugs, troubleshoot software errors, and monitor infrastructure stability.
  • To respond to support requests, inquiries, and business communications.
  • To enforce our Terms of Service and comply with applicable statutory obligations.

5. Data Sharing and Third-Party Disclosures

We do not sell, rent, or trade your personal data. We only share information with trusted third-party service providers (such as hosting infrastructure, analytics frameworks, and platform providers including Apple Inc.) solely to operate our services under strict confidentiality agreements. We may also disclose data if required by statutory law or lawful authority orders.

6. Data Retention and Security

We retain personal information only for as long as necessary to fulfill the purposes set out in this policy or to comply with statutory retention laws. We employ industry-standard technical and organizational security controls—including TLS encryption and restricted access environments—to protect your personal data from unauthorized access, disclosure, or alteration.

7. Your Data Protection Rights (UK & EU)

Under the UK GDPR, you retain the following rights regarding your data:

Right of Access
Request a copy of the personal data we hold about you.
Right to Rectification
Request correction of inaccurate or incomplete personal records.
Right to Erasure ('Right to be Forgotten')
Request complete deletion of your personal data where retention is no longer necessary.
Right to Restriction & Objection
Object to or request restriction of our processing of your data.
Right to Data Portability
Request the transfer of your data in a structured, machine-readable format.

8. Account and Data Deletion (Apple Guideline 5.1.1)

In compliance with Apple App Store review standards, any user with an active account in our mobile applications may initiate complete deletion of their account and associated data directly within the app settings or by submitting an explicit deletion request to privacy@grisant.co. All personal records are purged within 30 days of receiving the verified request.

9. Children's Privacy

Our applications and services are not intended for children under the age of 13 (or under 16 in the UK/EEA). We do not knowingly solicit or collect personal information from minors. If we discover that a minor has provided us with personal data, we take immediate measures to delete that information from our records.

10. International Data Transfers

Where data is transferred outside the United Kingdom or European Economic Area, we implement appropriate safeguards, such as the UK International Data Transfer Agreement (IDTA) or European Commission Standard Contractual Clauses (SCCs), to maintain an adequate level of data protection.

11. Changes to This Privacy Policy

We reserve the right to amend this Privacy Policy periodically. Any updates will be published directly on this page with a revised 'Last Updated' date. Significant modifications will be communicated through our services or via direct contact where feasible.

12. Contact Us and Supervisory Authority

For privacy requests, inquiries, or exercising statutory rights, contact us at privacy@grisant.co or by writing to GRISANT LTD, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. If you reside in the UK and believe your rights have not been respected, you have the right to lodge a formal complaint with the Information Commissioner's Office (ICO) at ico.org.uk.