GRIBIT LTD
Privacy notice
Updated 22 September 2026
How we handle personal information, who can access it and how to exercise your rights.
GRIBIT LTD · Registered in England and Wales · 16910534
Registered office: 17 Hunsbury Green, Northampton, NN4 9UL
support@gribit.co.uk
What this notice covers
GRIBIT LTD provides gribit to UK businesses and organisations. This notice covers people who visit the website, create or use an account, are named in a staff directory or logbook, receive an invitation or reminder, pay for a plan or contact us.
We are the controller for account administration, our customer relationship, support, billing and service security. Your organisation normally acts as controller for personal data it adds to its staff directory, checks, records and documents; we process that content on its behalf. See the data-processing terms. An individual’s privacy rights are not limited to the person who pays for the account.
Information and where it comes from
- Accounts: your name, email address, password hash, verification and security information, selected/default site, account and access status, ownership handover participants, authority-review references, choices, notifications and audit events. We receive these from you, your use of gribit and account-security events.
- Optional signup profile: business type, how you heard about Gribit and any Other details you choose to provide. We store these with your account to understand our customer base, measure where signups come from and inform service improvements. They are included in your account export and removed when your account is deleted.
- Sites and staff: site names, default recorders, staff names and optional email addresses, assignments, access permissions, invitations, responsible people and reminder preferences. Your organisation or an authorised owner may supply these details, including details of people who do not have a login.
- Logbook content: check names, schedules, items/locations, results, references, dates, recorder and signed-in account identities, notes, follow-ups, resolutions and change history. Authorised users provide this information.
- Files: uploaded certificates and other documents, their contents, names, titles, notes, links to records, uploader identity and time, and business logos.
- Billing: Stripe customer/subscription identifiers, plan and payment status, relevant amounts and dates. Stripe sends us information needed to administer your plan. Payment-card details are entered on Stripe’s hosted pages; gribit does not store full card numbers.
- Support and operations: contact details, messages, correspondence and information needed to investigate a problem. Our service and infrastructure also process network/request information such as IP addresses, timestamps, errors and security/administrative events to operate and protect the service.
We need account/contact details to provide an account or respond to you, and billing details to administer a paid plan. Optional fields are identified in the forms. If you do not provide required information, we may be unable to provide the requested function. Keep sensitive or unnecessary personal details out of notes, uploads and support messages.
Why we use personal information
| Purpose | Lawful basis when we are controller |
|---|---|
| Provide an account, paid plan and requested support to an individual customer | Performance of our contract, or steps you request before entering it. |
| Administer an organisation’s account, staff access and service communications | Legitimate interests in supplying the organisation’s requested service and communicating with its authorised people. A contract with an organisation is not automatically a contract with each employee. |
| Secure the service, troubleshoot faults and prevent abuse | Legitimate interests in protecting people, information and service reliability; legal obligations where applicable. |
| Handle enquiries, feedback, complaints and claims | Legitimate interests in responding and improving/supporting the service; contractual or legal obligations where applicable. |
| Keep required accounting records and comply with binding legal requirements | Legal obligations. |
Your organisation chooses its lawful basis for the logbook and directory data we process on its instructions. Service emails include verification, password resets, invitations, ownership handover/recovery notices and reminders; they are not advertising subscriptions. The software calculates schedules, reminder eligibility and access based on permissions and billing status. Contact us if you think one of these results is wrong. We do not use behavioural advertising or sell personal information.
Who can access your information
Owners can see and manage their organisation’s sites and staff. Authorised staff can view, record and export data for their assigned sites, including records and documents entered by colleagues. Do not upload information that those users should not see. An accepted ownership handover gives the new owner access to all transferred sites and their history. Corrections retain earlier values and the account responsible for each change. Removing access prevents future access through gribit but cannot recall files already downloaded or remove a person’s name from historical records.
Authorised service personnel may access information where needed for support, security, administration or a legal requirement. We may share relevant information with professional advisers, regulators or authorities where necessary and lawful. Customer exports and onward sharing are controlled by the customer.
Providers and international processing
Our app and primary database use DigitalOcean hosting in the UK. This does not mean every provider operation or support activity is confined to the UK.
- DigitalOcean: application hosting, managed database and recovery infrastructure. Its data-processing agreement describes its subprocessors and international-transfer arrangements, including the UK extension to the Data Privacy Framework and contractual fallback mechanisms.
- Brevo: delivery of account, invitation, reminder and support-form emails. It receives recipients, message content and delivery information. Brevo describes EU database storage; its wider provider arrangements may involve international processing.
- Microsoft 365: hosts the support@gribit.co.uk mailbox and processes support correspondence, including messages submitted through the contact form. Its data-protection terms describe processing and transfer safeguards. Mailbox and support-processing locations depend on the tenant and service; we do not claim that all Microsoft processing stays in the UK.
- Stripe: hosted payment and billing services. Stripe also has its own purposes and legal obligations when handling payment data. See its privacy notice and Privacy Center for locations and transfer arrangements.
Where our use of a provider involves a restricted transfer outside the UK, the applicable arrangement must use UK adequacy regulations or suitable safeguards, such as approved contractual terms and any required additional measures. Provider arrangements can include the EEA and the United States. Contact support for the arrangements applying to your data and how to obtain a copy of relevant safeguards.
Retention, closure and deletion
We use the following periods and criteria. There is no automatic promise to delete all information when you cancel a subscription, retire a site or delete a single file.
- Active accounts and customer content: held while needed to provide the service and preserve the organisation’s records under its instructions. Archiving a check or retiring a site retains history. The organisation decides its own evidence-retention requirements.
- Expired paid sites: customer records stay available for read-only viewing and export for 12 calendar months after that site’s paid access ends. The site’s schedules, records, correction history, follow-ups and documents are then automatically deleted after email warnings to the current owner at least 30 days and 7 days beforehand. Late or unsuccessful warning sends delay deletion. Renewed paid access resets the deadline; a necessary legal hold can suspend deletion. Site access assignments and pending invitations are removed or invalidated. Account and financial records are not automatically deleted with one expired site. Keep your own exports where your organisation needs evidence for longer.
- Closure: an account closure request starts a 30-day recovery/export window for owned sites. Deletion is then reviewed, not automatic. Active billing, legal requirements and records controlled by another organisation may require separate action. A privacy-rights request is assessed on its own legal basis, not automatically delayed by the recovery window.
- Invitations and security links: verification and password-reset links expire after one hour. Expiry stops their use; it is not a promise that related invitation, account or security history is erased at the same time. Those records are assessed with the associated account and security purpose.
- Support, security and administrative records: retained as needed to resolve an enquiry, investigate incidents, demonstrate the action taken, manage continuing disputes and meet legal obligations. The relevant criteria include whether the matter is closed, its security significance and any applicable claim or statutory period. A minimal deletion audit is kept to avoid reintroducing deleted data after recovery.
- Accounting records: normally six years from the end of the company financial year they concern, and longer where a legal requirement or ongoing tax enquiry requires it. Stripe may independently retain payment information under its own obligations.
- Backups: copies may remain after deletion from the live system until the provider’s backup retention cycle expires. They are restricted to recovery, not ordinary customer use. Deletion decisions must be reapplied before a restored backup returns to service. Contact us for the backup period and any other retention applicable to your request.
Before requesting deletion, export the logbook and download original documents separately. A CSV or JSON export is not a download of the original uploaded files. If another organisation controls a record about you, we will assist that organisation with your request rather than delete its records solely at another account holder’s instruction.
Your rights and how to contact us
Depending on the processing and applicable exceptions, you can request access, correction, erasure, restriction or portability of your personal data. Email support@gribit.co.uk or write to our registered office. You do not need an account or a particular form. We may ask for proportionate information to verify identity or clarify the request.
Your right to object
You can object to processing based on legitimate interests, explaining your particular circumstances. We will consider the objection and explain whether we must stop or have a lawful reason to continue.
We respond without undue delay and normally within one calendar month. Where the law allows an extension or affects when the response period runs, we will explain this and any further information needed. Requests about organisation-controlled records may need to be handled with that organisation; we will assist where we act as its processor. A customer export does not replace your right to make a request.
Privacy complaints
To raise a data-protection complaint, email support@gribit.co.uk or write to our registered office. Tell us what happened and how to contact you; please avoid sending unnecessary sensitive information. We will acknowledge the complaint within 30 days, investigate without undue delay, keep you appropriately informed and communicate the outcome.
You can also complain to the Information Commissioner’s Office. Our internal complaint route does not take away that right.
Changes to this notice
We will update the date on this page when our information changes and draw material changes to your attention where appropriate. Contact us if you need an earlier version or information about an arrangement that applies to your organisation.