Privacy policy
Written to be read. If anything here is unclear, email privacy@gridworks.engineering and a human will answer.
1. Who we are
GridWorks Engineering Ltd is a UK-registered infrastructure engineering consultancy with its registered office at Unit 4, Temple Studios, Bristol BS1 6QA. Where this policy says "we", "us" or "GridWorks", it means that company.
For personal data relating to our own business — enquiries, prospective clients, newsletter-free correspondence, job applicants and our own staff — we are the data controller. For personal data that exists inside a client's systems and which we may encounter while delivering an engagement, we are a data processor acting on that client's documented instructions under a separate data processing agreement.
2. What we collect
2.1 Information you give us
When you submit the enquiry form or email us, we receive your name, work email address, company, role if you provide it, a description of your technical stack and scale, and whatever you write in the problem field. That is the whole list — there are no hidden fields, tracking pixels or enrichment lookups against third-party databases.
2.2 Information from an engagement
During delivery we hold contact details for the people we work with, meeting notes, architecture documentation, and credentials or access grants issued to us. Access is always time-bound and issued through your identity provider, never as long-lived keys held by us.
2.3 Information generated automatically
Our web server records the IP address, user agent, requested path, response status and timestamp of each request, in a standard access log. We use this for security and capacity purposes and nothing else.
3. Why we process it, and on what basis
Under UK GDPR we must have a lawful basis for each processing purpose. Ours are:
- Legitimate interests — responding to a technical enquiry you sent us, corresponding about a possible engagement, keeping our website secure and available, and maintaining business records. We have assessed that you would reasonably expect all of this, and none of it is intrusive.
- Performance of a contract — delivering the services set out in a signed statement of work, including holding the contact details of the people we are working with.
- Legal obligation — retaining invoices and related records for the period required by UK tax law.
- Consent — only where you have explicitly given it, for example if you asked to be told when we publish something specific. Consent can be withdrawn at any time by replying to any message.
We do not sell personal data, we do not share it with advertising networks, and we do not use it to train any model.
4. Client systems and production data
This is the section that matters most in our line of work, so we will be specific.
Delivering an infrastructure engagement sometimes requires access to systems that contain personal data belonging to your customers — logs, traces, database contents, support tooling. Our standing position is that we design around not needing it:
- We request the narrowest access that lets us do the work, scoped to specific accounts, namespaces or roles, and time-boxed to the engagement.
- Where a task can be performed against synthetic or anonymised data, it is.
- We do not export client production data to GridWorks-controlled systems. Analysis happens inside your environment; what leaves it is aggregate metrics, findings and documentation.
- Access is issued via your SSO with short-lived credentials, is logged by you, and is revoked by you on the final day of the engagement. We ask clients to verify the revocation rather than take our word for it.
- If we encounter personal data we did not expect — for example identifiers leaking into application logs — we will tell you within one working day and will not retain a copy.
Where we act as processor, the client's own privacy notice governs the underlying data, and our obligations are set out in the data processing agreement attached to the statement of work. That agreement includes sub-processor notification, breach notification within 24 hours of becoming aware, and deletion or return of data at the end of the engagement.
5. This website
This site sets no cookies. There is no analytics script, no tag manager, no session recording and no advertising pixel. Nothing on these pages attempts to identify you across visits.
Web fonts are loaded from Google Fonts, which means your browser makes a request to fonts.googleapis.com and fonts.gstatic.com. That request discloses your IP address and user agent to Google. If you would prefer to avoid it, the site remains fully readable with those requests blocked — it will fall back to your system's monospace and sans-serif fonts.
Server access logs are retained for 30 days and then deleted automatically. They are not joined to any other dataset.
6. Who we share it with
A deliberately short list of service providers, each covered by a data processing agreement:
- Email and document hosting — a business productivity suite hosted in the EU/UK.
- Video conferencing — for calls, with recording off by default.
- Accounting and invoicing — UK-based, receives company and billing details only.
- Web hosting — for this site, which sees only the access logs described above.
We will also disclose information where we are legally required to, and we will tell you that this has happened unless we are legally prohibited from doing so.
7. International transfers
Our engineers work from countries inside and outside the UK and EEA. Where personal data is accessed from outside the UK, the transfer relies on either an adequacy regulation or the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, together with technical measures — encryption in transit, short-lived credentials and access logging.
If your engagement has a data residency requirement that excludes particular jurisdictions, tell us before signature and we will staff it accordingly. We have done this for healthcare and public sector clients and it is a normal request.
8. How long we keep it
| Category | Retention | Then |
|---|---|---|
| Enquiry that did not progress | 12 months | Deleted |
| Architecture review notes | 24 months | Deleted |
| Client contact records | Engagement + 24 months | Deleted |
| Engagement documentation | Engagement + 6 years | Deleted or returned |
| Invoices & financial records | 6 years | Legally required |
| Web server access logs | 30 days | Rotated out |
| Client production data | Not retained | Never copied out |
9. How we protect it
We hold ourselves to the standard we build for clients. In practice that means hardware-backed multi-factor authentication on every account, full-disk encryption on every device, no long-lived cloud credentials anywhere, secrets in a managed vault rather than in files or repositories, and access to client environments issued just-in-time through the client's own identity provider.
Internal systems are reviewed quarterly, our own supply chain is monitored for compromised dependencies, and we run the same policy checks against our repositories that we ship to clients. We are aligned to SOC 2 Type II control objectives and ISO 27001 Annex A; we will share our current control matrix under NDA.
No system is perfectly secure. If we suffer a personal data breach we will notify affected clients without undue delay and, where required, the ICO within 72 hours.
10. Your rights
Under UK GDPR you can ask us to:
- Access — tell you what personal data we hold about you and give you a copy.
- Rectify — correct anything inaccurate.
- Erase — delete it, where we have no overriding legal reason to keep it.
- Restrict — pause processing while a dispute about accuracy or legitimate interests is resolved.
- Port — provide it in a structured, machine-readable format.
- Object — to processing based on legitimate interests, including any profiling (we do none).
- Withdraw consent — where consent was the basis, at any time.
Email privacy@gridworks.engineering. We respond within one month and there is no charge. We may ask you to confirm your identity, but only to the extent needed to be sure we are not disclosing someone else's data to you.
If your data sits inside a client's systems where we act as processor, we will forward your request to that client, who is the controller, and tell you we have done so.
11. Children
Our services are sold to businesses and this website is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe we have, tell us and we will delete it.
12. Changes to this policy
When we change this policy we update the version number and last-modified date at the top. Material changes affecting existing clients are notified by email at least 30 days before they take effect. Previous versions are kept in the repository that publishes this site and can be produced on request.
13. Contact and complaints
Data protection queries: privacy@gridworks.engineering. Security reports: security@gridworks.engineering. Anything else: engineering@gridworks.engineering.
We are not required to appoint a statutory Data Protection Officer; responsibility sits with a named director, reachable at the address above.
If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office (ico.org.uk, 0303 123 1113). We would appreciate the chance to put it right first, but that is your right and not conditional on asking us.