Privacy Policy
Last updated: December 2024
1. Introduction
This Privacy Policy explains how Star Delta Software Ltd ("we", "us", "our") collects, uses, and protects your personal information when you use GB Grid Data ("Service").
We are the data controller for the personal data we collect through the Service. We are committed to protecting your privacy and complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Data Controller: Star Delta Software Ltd
Contact: support@griddata.uk
2. Information We Collect
Account Information
- Email address
- Name (if provided)
- Password (stored securely hashed)
Payment Information
Payment processing is handled by Paddle.com Market Limited ("Paddle"). We receive:
- Your email address and transaction details
- Paddle customer ID linked to your account
We do not receive or store your full card number. Paddle acts as the data controller for payment data.
Usage Data
- Search queries and filters used
- Pages and features accessed
- Date and time of access
Technical Data
- IP address
- Browser type and version
- Device type and operating system
3. How We Use Your Information
We use your information to:
- Provide the Service: Authenticate you, process searches, deliver data
- Process payments: Manage subscriptions via Paddle
- Communicate with you: Send service emails (password reset, subscription updates)
- Improve the Service: Analyse usage patterns, fix issues, develop features
- Prevent abuse: Detect and prevent fraud, enforce rate limits
- Legal compliance: Meet regulatory and legal obligations
4. Legal Basis for Processing
Under UK GDPR, we process your data based on:
- Contract performance: To provide the Service you signed up for
- Legitimate interests: For analytics, security, and service improvement
- Consent: For marketing communications (where applicable)
- Legal obligation: For tax records and regulatory compliance
5. Data Sharing
We share data with:
- Paddle: Payment processing (as Merchant of Record)
- Hosting providers: Server infrastructure
We do not sell your personal data. We may disclose data if required by law or to protect our legal rights.
6. Data Retention
- Account data: Retained until account deletion, plus 6 years for tax purposes
- Usage logs: 12 months
- Payment records: 7 years (legal requirement)
When you delete your account, we remove personal data except where retention is legally required.
7. Your Rights
Under UK GDPR, you have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate data
- Erasure: Request deletion of your data ("right to be forgotten")
- Restriction: Limit how we process your data
- Portability: Receive your data in a portable format
- Object: Object to certain processing activities
- Withdraw consent: Where processing is based on consent
To exercise your rights, contact us at support@griddata.uk. We will respond within 30 days.
8. Cookies
We use essential cookies for:
| Cookie | Purpose | Duration |
|---|---|---|
| session | User authentication | Session |
| auth_token | Remember login | 30 days |
| theme | Dark/light mode preference | 1 year |
These cookies are strictly necessary for the Service to function. We do not use tracking or advertising cookies.
9. International Transfers
Your data is primarily processed in the UK and European Economic Area. Where data is transferred outside these regions (e.g., Paddle's global infrastructure), appropriate safeguards such as Standard Contractual Clauses are in place.
10. Security
We protect your data through:
- HTTPS encryption for all connections
- Secure password hashing
- Regular security updates
- Access controls and monitoring
No system is completely secure. If you believe your account has been compromised, contact us immediately.
11. Children
The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal data from children. If we become aware of such data, we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified via email or a prominent notice on the Service. The "last updated" date at the top indicates when this policy was last revised.
13. Complaints
If you have concerns about how we handle your data, please contact us first at support@griddata.uk.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's supervisory authority for data protection:
14. Contact Us
For questions about this Privacy Policy or our data practices:
Star Delta Software Ltd
Email: support@griddata.uk
Payment Processing
We use Paddle.com Market Limited as our Merchant of Record for payment processing. When you make a purchase, Paddle collects and processes your payment information. Paddle's privacy policy is available at paddle.com/legal/privacy.