Privacy Policy

Effective Date: 29 June 2026
Last Updated: 29 June 2026

1. Introduction

GRICORE LTD (“GRICORE”, “we”, “our” or “us”) is committed to protecting your privacy and handling personal data in a lawful, fair and transparent manner.

This Privacy Policy explains how we collect, use, disclose, store and protect personal data when you:

  • Visit our website;
  • Contact us by email, telephone, social media or contact forms;
  • Request information about our services;
  • Engage us to provide software development, IT consulting or related services;
  • Apply for employment or contractor opportunities; or
  • Interact with us as a client, supplier or business partner.

We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and, where applicable, the Privacy and Electronic Communications Regulations (PECR).


2. Data Controller

The data controller responsible for your personal data is:

GRICORE LTD
Company Number: 13408725
Demsa Accounts
565 Green Lanes
Haringey
London
England
N8 0RL.

Privacy Enquiries:
Email: privacy@gricore.com


3. Information Commissioner’s Office (ICO) Registration

GRICORE LTD is registered with the Information Commissioner’s Office (ICO) as a data controller.

ICO Registration Reference: ZC083694
Date Registered: 24 January 2026
Registration Expiry Date: 23 January 2027


4. Personal Data We Collect

We may collect and process the following categories of personal data.

Information You Provide

  • Full name
  • Business name
  • Job title
  • Email address
  • Telephone number
  • Postal address
  • Project and service requirements
  • Information contained in correspondence with us

Information Collected Automatically

When you visit our website, we may collect:

  • IP address
  • Browser type and version
  • Device identifiers
  • Operating system information
  • Referral source information
  • Website usage data
  • Time and date of visits
  • Cookie and analytics information

Recruitment Information

If you apply for a role with us, we may collect:

  • CVs and resumes
  • Employment history
  • Qualifications
  • References
  • Interview records and notes

5. How We Use Personal Data

We may use personal data to:

  • Respond to enquiries and requests;
  • Provide quotations and proposals;
  • Deliver software development and consulting services;
  • Manage customer accounts and relationships;
  • Provide technical support and maintenance;
  • Communicate with suppliers and partners;
  • Improve our website and services;
  • Monitor website security and performance;
  • Prevent fraud and misuse;
  • Recruit employees and contractors; and
  • Comply with legal and regulatory obligations.

6. Lawful Bases for Processing

Under UK GDPR, we rely on one or more of the following lawful bases.

Contract

Where processing is necessary to fulfil a contract with you or your organisation, or to take steps prior to entering into a contract.

Legitimate Interests

Where processing is necessary for our legitimate business interests, including:

  • Managing our business operations;
  • Providing and improving services;
  • Responding to enquiries;
  • Ensuring website and system security;
  • Preventing fraud; and
  • Managing customer relationships.

Legal Obligation

Where processing is necessary to comply with legal, regulatory, accounting or taxation requirements.

Consent

Where required by law, including certain marketing communications and non-essential cookies, we rely on your consent. You may withdraw consent at any time.


7. Marketing Communications

We may send information relating to our services, updates and business communications where permitted by applicable law.

Where required, we will obtain your consent before sending marketing communications.

You can opt out at any time by:

  • Clicking the unsubscribe link in a marketing email; or
  • Contacting us directly.

We do not sell personal data to third parties.


8. Cookies and Similar Technologies

Our website may use cookies and similar technologies to:

  • Ensure website functionality;
  • Remember preferences;
  • Analyse website usage;
  • Improve user experience;
  • Support website performance and security.

Where required by law, we will obtain your consent before placing non-essential cookies on your device.

You can manage cookie settings through your browser or through any cookie preference tools available on our website.

We recommend users review our Cookie Policy for further information regarding the specific cookies and technologies we use.


9. Sharing Personal Data

We may share personal data with trusted third parties where necessary, including:

  • Cloud hosting providers;
  • IT service providers;
  • Website and analytics providers;
  • Professional advisers;
  • Accountants and auditors;
  • Payment processors;
  • Regulatory bodies;
  • Law enforcement agencies where required by law.

We require all third-party service providers to process personal data securely and only for authorised purposes.


10. International Transfers

Some of our service providers may process or store personal data outside the United Kingdom.

Where personal data is transferred internationally, we ensure appropriate safeguards are in place, including:

  • UK International Data Transfer Agreements (IDTAs);
  • UK Addendum to Standard Contractual Clauses;
  • Transfers to countries recognised as providing adequate protection; or
  • Other lawful transfer mechanisms permitted under UK GDPR.

11. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including compliance with legal, regulatory, accounting and reporting requirements.

Typical retention periods include:

  • Website enquiries: up to 24 months;
  • Customer records: duration of the relationship plus up to 7 years;
  • Financial records: up to 7 years;
  • Recruitment records: up to 12 months;
  • Website security and technical logs: normally up to 12 months.

Retention periods may be extended where necessary for legal claims or compliance obligations.


12. Security

We implement appropriate technical and organisational measures designed to protect personal data, including:

  • Access controls;
  • Authentication measures;
  • Secure hosting environments;
  • Encryption where appropriate;
  • Security monitoring;
  • Software updates and patch management;
  • Staff confidentiality obligations.

While we take reasonable steps to protect information, no method of electronic transmission or storage can be guaranteed completely secure.


13. Your Rights

Under UK GDPR, individuals have the following rights:

  • Right to be informed;
  • Right of access;
  • Right to rectification;
  • Right to erasure;
  • Right to restrict processing;
  • Right to data portability;
  • Right to object; and
  • Rights relating to automated decision-making and profiling.

To exercise any of your rights, please contact:

Email: privacy@gricore.com

We may request evidence of identity before responding to requests.


14. Complaints

If you have concerns about how we process your personal data, please contact us first and we will attempt to resolve the matter promptly.

You also have the right to make a complaint to the Information Commissioner’s Office (ICO), the UK’s supervisory authority for data protection matters.

Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF

Website: https://ico.org.uk

Telephone: 0303 123 1113


15. Third-Party Websites

Our website may contain links to third-party websites and services.

We do not control and are not responsible for the privacy practices or content of third-party websites. We encourage users to review the privacy policies of any external sites they visit.


16. Children’s Privacy

Our services are intended for businesses and professional users.

We do not knowingly collect personal data from children. If you believe a child has provided personal data to us, please contact us so that appropriate action can be taken.


17. Controller and Processor Roles

GRICORE LTD acts as a data controller in respect of personal data collected through our website, marketing activities, supplier management and business operations.

Where we provide services to clients involving the processing of personal data on their behalf, we may act as a data processor. In those circumstances, we process personal data only in accordance with our client’s instructions and any applicable data processing agreement.


18. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect legal, technical or business developments.

Any updates will be published on this page and the “Last Updated” date will be revised accordingly.


Contact Us

GRICORE LTD
Demsa Accounts
565 Green Lanes
Haringey
London
England
N8 0RL

Company Number: 13408725

ICO Registration Reference: ZC083694 (valid until 23 January 2027)

Email: privacy@gricore.com