Privacy Policy — Grabzies

Last updated: 6 May 2025 • Data Controller: Grabzies, United Kingdom • Email: help@grabzies.com

We may collect date of birth solely for the purpose of verifying age eligibility. This data is not used for marketing and is retained only as necessary for compliance.

Plain English summary

Short version: We collect the information you give us (like name, email, address) and some technical data (like IP address) so we can deliver our services, take payments, and keep the site secure. We don't sell your personal data. You control marketing emails and can ask us to see, correct, or delete your information. For full details read the sections below.

This summary is a quick guide only. The rest of the policy explains legal bases, retention, transfers, and your rights in full.

This Privacy Policy explains how Grabzies (“we”, “us”, “our”) collects, stores, uses and shares personal information when you visit grabzies.com, purchase services, or otherwise interact with our business. We treat all information relating to our projects and customers as proprietary and handle it accordingly.

Important: This policy reflects processing under UK data protection law (including the UK GDPR and the Data Protection Act 2018). If you are outside the UK, your data may still be transferred to and processed in the United Kingdom.

1. What personal information we collect

We collect information you provide directly and data collected automatically when you use our Website or Services. Typical categories include:

2. How we use your information

We use personal information for the following purposes (not exhaustive):

4. Cookies and similar technologies

We use cookies and similar technologies for essential site functionality, analytics and optional marketing. You can control cookie settings via the cookie banner (where shown) or through your browser.

Categories we use:

For a full list of cookies we use, see our Cookie Policy.

5. Sharing and recipients

Unless otherwise disclosed in a written agreement, all third-party vendors and subprocessors are treated as proprietary. Vendor names are intentionally represented as “Your Name Here”.

We may share your personal data with:

We require processors to maintain appropriate security and process data only under our documented instructions. A non-exhaustive list of categories of processors we use (replace placeholders with vendor names as applicable):

6. International transfers

Your data may be transferred to, stored in, or processed in the United Kingdom and (where our processors operate) other countries. When transfers occur outside the UK/EEA we apply appropriate safeguards (e.g. EU/UK standard contractual clauses, binding corporate rules, or reliance on an adequacy decision) to protect your rights.

7. Data retention

We retain personal data only as long as necessary to fulfil the purposes described above, to comply with legal obligations (for example, accounting records), resolve disputes, and enforce our agreements. Typical retention periods include:

8. Security

We implement organisational, technical and administrative measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures include encryption in transit, access controls, regular vulnerability testing and staff data protection training.

Despite these measures, no method of transmission over the Internet is 100% secure; we cannot guarantee absolute security.

9. Your rights

Under UK data protection law you may have the right to:

To exercise any right, contact help@grabzies.com. We will respond in accordance with statutory timeframes (usually within one month). We may request identity verification to process certain requests.

10. Eligibility

Our services are available only to individuals aged 18 years or older. By creating an account or using this website, you confirm that you are at least 18 years of age.

If we discover that an account has been created by someone under 18, we reserve the right to suspend or terminate access immediately.

If that does not stop you! your declaration or acceptance of our terms, gives me full rights to tell your mum.

11. Automated decision-making

We do not carry out automated decision-making that produces legal or similarly significant effects for individuals. If we introduce such processing we will notify you and provide information about the logic involved and your rights.

12. Complaints

If you are unhappy with our handling of your personal data you can:

13. Changes to this policy

We may update this Privacy Policy from time to time. Where changes are material we will provide a prominent notice on our Website or send notice to affected users. The “Last updated” date at the top indicates when the policy was last revised.

14. Contact

Data Controller: Grabzies (United Kingdom)

Email: help@grabzies.com

Postal address: [Insert company registered address — replace with official address]

Data Processing Addendum (DPA) — click to expand
Data Processing Addendum (DPA) — click to expand

DPA — Controller / Processor relationship

This Data Processing Addendum forms part of the Privacy Policy and sets out the responsibilities and obligations of Grabzies (the Controller) and its Processors with respect to processing of personal data on behalf of our customers.

1. Roles

Controller: Grabzies

Processors: third-party service providers engaged by Grabzies to perform specific services (e.g. payment, hosting, analytics). Examples: [Payment Processor], [Hosting Provider], [Email Provider]. Replace placeholders with names of actual processors used.

2. Processing instructions

Processors shall only process personal data in accordance with Grabzies’ documented instructions and for the purposes described in the Privacy Policy and any specific service agreement between the parties.

3. Security measures

Processors must implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including but not limited to:

4. Sub-processing

Processors must not engage sub-processors without our prior written authorisation. Where sub-processors are authorised, the processor must flow down equivalent data protection obligations to the sub-processor.

5. Assistance to controller

Processors shall assist Grabzies with data subject requests, security incidents, and with obligations under applicable data protection legislation (e.g. breach notification).

6. Return or deletion

Upon termination or expiry of the contractual relationship, processors shall, at Grabzies’ choice, return or securely delete personal data in their possession unless required by law to retain it.

7. Audit rights

Grabzies reserves the right to audit processors for compliance with this DPA and may request evidence of controls, certifications (e.g. ISO 27001), and data processing records.

8. Contact point

For matters relating to this DPA and data protection, contact: help@grabzies.com

Note: This DPA text is a standard operational template. For enterprise contracts we recommend having this reviewed and finalised with your legal counsel to fit your procurement and vendor-management terms.