Effective Date: 29 June 2026
Last Updated: 29 June 2026
1. Introduction
GRICORE LTD (“GRICORE”, “we”, “our” or “us”) is committed to protecting your privacy and handling personal data in a lawful, fair and transparent manner.
This Privacy Policy explains how we collect, use, disclose, store and protect personal data when you:
- Visit our website;
- Contact us by email, telephone, social media or contact forms;
- Request information about our services;
- Engage us to provide software development, IT consulting or related services;
- Apply for employment or contractor opportunities; or
- Interact with us as a client, supplier or business partner.
We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and, where applicable, the Privacy and Electronic Communications Regulations (PECR).
2. Data Controller
The data controller responsible for your personal data is:
GRICORE LTD
Company Number: 13408725
Demsa Accounts
565 Green Lanes
Haringey
London
England
N8 0RL.
Privacy Enquiries:
Email: privacy@gricore.com
3. Information Commissioner’s Office (ICO) Registration
GRICORE LTD is registered with the Information Commissioner’s Office (ICO) as a data controller.
ICO Registration Reference: ZC083694
Date Registered: 24 January 2026
Registration Expiry Date: 23 January 2027
4. Personal Data We Collect
We may collect and process the following categories of personal data.
Information You Provide
- Full name
- Business name
- Job title
- Email address
- Telephone number
- Postal address
- Project and service requirements
- Information contained in correspondence with us
Information Collected Automatically
When you visit our website, we may collect:
- IP address
- Browser type and version
- Device identifiers
- Operating system information
- Referral source information
- Website usage data
- Time and date of visits
- Cookie and analytics information
Recruitment Information
If you apply for a role with us, we may collect:
- CVs and resumes
- Employment history
- Qualifications
- References
- Interview records and notes
5. How We Use Personal Data
We may use personal data to:
- Respond to enquiries and requests;
- Provide quotations and proposals;
- Deliver software development and consulting services;
- Manage customer accounts and relationships;
- Provide technical support and maintenance;
- Communicate with suppliers and partners;
- Improve our website and services;
- Monitor website security and performance;
- Prevent fraud and misuse;
- Recruit employees and contractors; and
- Comply with legal and regulatory obligations.
6. Lawful Bases for Processing
Under UK GDPR, we rely on one or more of the following lawful bases.
Contract
Where processing is necessary to fulfil a contract with you or your organisation, or to take steps prior to entering into a contract.
Legitimate Interests
Where processing is necessary for our legitimate business interests, including:
- Managing our business operations;
- Providing and improving services;
- Responding to enquiries;
- Ensuring website and system security;
- Preventing fraud; and
- Managing customer relationships.
Legal Obligation
Where processing is necessary to comply with legal, regulatory, accounting or taxation requirements.
Consent
Where required by law, including certain marketing communications and non-essential cookies, we rely on your consent. You may withdraw consent at any time.
7. Marketing Communications
We may send information relating to our services, updates and business communications where permitted by applicable law.
Where required, we will obtain your consent before sending marketing communications.
You can opt out at any time by:
- Clicking the unsubscribe link in a marketing email; or
- Contacting us directly.
We do not sell personal data to third parties.
8. Cookies and Similar Technologies
Our website may use cookies and similar technologies to:
- Ensure website functionality;
- Remember preferences;
- Analyse website usage;
- Improve user experience;
- Support website performance and security.
Where required by law, we will obtain your consent before placing non-essential cookies on your device.
You can manage cookie settings through your browser or through any cookie preference tools available on our website.
We recommend users review our Cookie Policy for further information regarding the specific cookies and technologies we use.
9. Sharing Personal Data
We may share personal data with trusted third parties where necessary, including:
- Cloud hosting providers;
- IT service providers;
- Website and analytics providers;
- Professional advisers;
- Accountants and auditors;
- Payment processors;
- Regulatory bodies;
- Law enforcement agencies where required by law.
We require all third-party service providers to process personal data securely and only for authorised purposes.
10. International Transfers
Some of our service providers may process or store personal data outside the United Kingdom.
Where personal data is transferred internationally, we ensure appropriate safeguards are in place, including:
- UK International Data Transfer Agreements (IDTAs);
- UK Addendum to Standard Contractual Clauses;
- Transfers to countries recognised as providing adequate protection; or
- Other lawful transfer mechanisms permitted under UK GDPR.
11. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including compliance with legal, regulatory, accounting and reporting requirements.
Typical retention periods include:
- Website enquiries: up to 24 months;
- Customer records: duration of the relationship plus up to 7 years;
- Financial records: up to 7 years;
- Recruitment records: up to 12 months;
- Website security and technical logs: normally up to 12 months.
Retention periods may be extended where necessary for legal claims or compliance obligations.
12. Security
We implement appropriate technical and organisational measures designed to protect personal data, including:
- Access controls;
- Authentication measures;
- Secure hosting environments;
- Encryption where appropriate;
- Security monitoring;
- Software updates and patch management;
- Staff confidentiality obligations.
While we take reasonable steps to protect information, no method of electronic transmission or storage can be guaranteed completely secure.
13. Your Rights
Under UK GDPR, individuals have the following rights:
- Right to be informed;
- Right of access;
- Right to rectification;
- Right to erasure;
- Right to restrict processing;
- Right to data portability;
- Right to object; and
- Rights relating to automated decision-making and profiling.
To exercise any of your rights, please contact:
Email: privacy@gricore.com
We may request evidence of identity before responding to requests.
14. Complaints
If you have concerns about how we process your personal data, please contact us first and we will attempt to resolve the matter promptly.
You also have the right to make a complaint to the Information Commissioner’s Office (ICO), the UK’s supervisory authority for data protection matters.
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Website: https://ico.org.uk
Telephone: 0303 123 1113
15. Third-Party Websites
Our website may contain links to third-party websites and services.
We do not control and are not responsible for the privacy practices or content of third-party websites. We encourage users to review the privacy policies of any external sites they visit.
16. Children’s Privacy
Our services are intended for businesses and professional users.
We do not knowingly collect personal data from children. If you believe a child has provided personal data to us, please contact us so that appropriate action can be taken.
17. Controller and Processor Roles
GRICORE LTD acts as a data controller in respect of personal data collected through our website, marketing activities, supplier management and business operations.
Where we provide services to clients involving the processing of personal data on their behalf, we may act as a data processor. In those circumstances, we process personal data only in accordance with our client’s instructions and any applicable data processing agreement.
18. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect legal, technical or business developments.
Any updates will be published on this page and the “Last Updated” date will be revised accordingly.
Contact Us
GRICORE LTD
Demsa Accounts
565 Green Lanes
Haringey
London
England
N8 0RL
Company Number: 13408725
ICO Registration Reference: ZC083694 (valid until 23 January 2027)
Email: privacy@gricore.com
