Privacy Policy

Last updated: December 2024

1. Introduction

This Privacy Policy explains how Star Delta Software Ltd ("we", "us", "our") collects, uses, and protects your personal information when you use GB Grid Data ("Service").

We are the data controller for the personal data we collect through the Service. We are committed to protecting your privacy and complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Data Controller: Star Delta Software Ltd

Contact: support@griddata.uk

2. Information We Collect

Account Information

  • Email address
  • Name (if provided)
  • Password (stored securely hashed)

Payment Information

Payment processing is handled by Paddle.com Market Limited ("Paddle"). We receive:

  • Your email address and transaction details
  • Paddle customer ID linked to your account

We do not receive or store your full card number. Paddle acts as the data controller for payment data.

Usage Data

  • Search queries and filters used
  • Pages and features accessed
  • Date and time of access

Technical Data

  • IP address
  • Browser type and version
  • Device type and operating system

3. How We Use Your Information

We use your information to:

  • Provide the Service: Authenticate you, process searches, deliver data
  • Process payments: Manage subscriptions via Paddle
  • Communicate with you: Send service emails (password reset, subscription updates)
  • Improve the Service: Analyse usage patterns, fix issues, develop features
  • Prevent abuse: Detect and prevent fraud, enforce rate limits
  • Legal compliance: Meet regulatory and legal obligations

4. Legal Basis for Processing

Under UK GDPR, we process your data based on:

  • Contract performance: To provide the Service you signed up for
  • Legitimate interests: For analytics, security, and service improvement
  • Consent: For marketing communications (where applicable)
  • Legal obligation: For tax records and regulatory compliance

5. Data Sharing

We share data with:

  • Paddle: Payment processing (as Merchant of Record)
  • Hosting providers: Server infrastructure

We do not sell your personal data. We may disclose data if required by law or to protect our legal rights.

6. Data Retention

  • Account data: Retained until account deletion, plus 6 years for tax purposes
  • Usage logs: 12 months
  • Payment records: 7 years (legal requirement)

When you delete your account, we remove personal data except where retention is legally required.

7. Your Rights

Under UK GDPR, you have the right to:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate data
  • Erasure: Request deletion of your data ("right to be forgotten")
  • Restriction: Limit how we process your data
  • Portability: Receive your data in a portable format
  • Object: Object to certain processing activities
  • Withdraw consent: Where processing is based on consent

To exercise your rights, contact us at support@griddata.uk. We will respond within 30 days.

8. Cookies

We use essential cookies for:

CookiePurposeDuration
sessionUser authenticationSession
auth_tokenRemember login30 days
themeDark/light mode preference1 year

These cookies are strictly necessary for the Service to function. We do not use tracking or advertising cookies.

9. International Transfers

Your data is primarily processed in the UK and European Economic Area. Where data is transferred outside these regions (e.g., Paddle's global infrastructure), appropriate safeguards such as Standard Contractual Clauses are in place.

10. Security

We protect your data through:

  • HTTPS encryption for all connections
  • Secure password hashing
  • Regular security updates
  • Access controls and monitoring

No system is completely secure. If you believe your account has been compromised, contact us immediately.

11. Children

The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal data from children. If we become aware of such data, we will delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified via email or a prominent notice on the Service. The "last updated" date at the top indicates when this policy was last revised.

13. Complaints

If you have concerns about how we handle your data, please contact us first at support@griddata.uk.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's supervisory authority for data protection:

Information Commissioner's Office

Website: ico.org.uk

Helpline: 0303 123 1113

14. Contact Us

For questions about this Privacy Policy or our data practices:

Star Delta Software Ltd

Email: support@griddata.uk

Payment Processing

We use Paddle.com Market Limited as our Merchant of Record for payment processing. When you make a purchase, Paddle collects and processes your payment information. Paddle's privacy policy is available at paddle.com/legal/privacy.