Privacy Policy

Gridjet Datacentres Ltd Document version: 1.0
Effective date: 14 April 2026
Last reviewed: 14 April 2026

Gridjet Datacentres Ltd (“Gridjet”, “we”, “our”, “us”) is a provider of dedicated server and datacentre infrastructure services. We are registered in England and Wales (company number: 15320312).

For the purposes of applicable data protection law, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, Gridjet Datacentres Ltd is the data controller in respect of personal data collected through our website and in connection with the management of customer accounts.

Where Gridjet processes personal data on behalf of customers in the course of delivering infrastructure services, Gridjet acts as a data processor. This distinction is explained further in Section 5.

Data protection contact: Email: [email protected]
Post: Data Protection, Gridjet Datacentres Ltd, Units 4–5 Tristram Centre, Brown Lane West, Leeds, England, LS12 6BF

ICO registration number: ZB662184

2. What personal data we collect and why

We collect personal data across several categories, each with a distinct purpose and lawful basis.

2.1 Website enquiries and contact forms

Data collected: Name, email address, telephone number, company name, and any information you voluntarily provide in a message or enquiry form.

Purpose: To respond to your enquiry and, where relevant, to progress a commercial relationship.

Lawful basis: Legitimate interests (responding to inbound commercial enquiries); contract (where an enquiry relates to an existing or prospective services agreement).

2.2 Customer account data

Data collected: Contact name, job title, company name, registered address, billing address, email address, telephone number, payment method details (processed via our payment provider — see Section 6), account credentials, and records of service orders and correspondence.

Purpose: To create and manage your account, provision services, issue invoices, and communicate with you about your services.

Lawful basis: Contract (performance of the services agreement); legal obligation (financial record-keeping requirements).

2.3 Network, traffic, and technical data

Data collected: IP addresses (source and destination), bandwidth usage data, connection logs, access logs, routing data, server utilisation metrics, and related technical records generated in the course of providing infrastructure services.

Purpose: To deliver, monitor, and maintain the services; to detect, investigate, and respond to security incidents, abuse, and acceptable use violations; to comply with legal and regulatory obligations.

Lawful basis: Legitimate interests (network security, service integrity, and abuse prevention); legal obligation (where retention or disclosure is required by law).

Retention note: Network and access logs are retained for 90 days as standard, unless a longer period is required for an active investigation or legal process.

2.4 Abuse and incident data

Data collected: Reports submitted to our abuse team, correspondence relating to abuse investigations, IP addresses and identifiers associated with reported activity, and records of actions taken.

Purpose: To investigate and respond to abuse reports within our standard 72-hour SLA; to protect the integrity of our network and the interests of third parties affected by activity on our infrastructure; to comply with obligations under applicable law.

Lawful basis: Legitimate interests (network security and protection of third-party rights); legal obligation (where we are required to investigate or report by law or regulatory requirement).

Note on third-party data: Abuse reports frequently contain personal data relating to individuals who have not directly interacted with Gridjet — for example, recipients of spam or targets of network attacks. We process such data only to the extent necessary to investigate and resolve the reported incident.

2.5 Website technical data

Data collected: IP address, browser type and version, operating system, pages visited, time and duration of visits, referral source, and cookie identifiers.

Purpose: To operate and improve our website; to understand how visitors use our site.

Lawful basis: Legitimate interests (website operation and improvement); consent (where cookies beyond strictly necessary are used — see Section 11).

3. Lawful basis summary

 

Processing activity

Lawful basis

Responding to website enquiries

Legitimate interests

Account creation and management

Contract

Service delivery and provisioning

Contract

Invoicing and financial records

Legal obligation

Network monitoring and security

Legitimate interests

Abuse investigation and response

Legitimate interests / Legal obligation

Marketing communications

Consent

Legal process and regulatory compliance

Legal obligation

Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and interests as a data subject. You may request further information about these assessments by contacting us at [email protected].

Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out prior to withdrawal.

4. How we use your information

We use the personal data we collect to:

  • Respond to enquiries and provide requested information about our services.
  • Create, manage, and maintain your customer account.
  • Provision, deliver, monitor, and support the infrastructure services you have ordered.
  • Issue invoices and process payments.
  • Communicate with you about your services, including planned maintenance, incidents, and service updates.
  • Investigate and respond to abuse reports, security incidents, and acceptable use violations.
  • Comply with our legal and regulatory obligations, including responding to lawful requests from law enforcement and regulatory authorities.
  • Improve our website and services.
  • Send you information about our services, updates, or relevant industry information, where you have opted in to receive such communications.

We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects.

5. Our role as data processor

Where you use Gridjet’s infrastructure to host, store, or process your own data — including data relating to your customers, employees, or end users — Gridjet acts as a data processor on your behalf, and you act as the data controller of that data.

In this capacity, Gridjet processes your data only on your documented instructions, as set out in the services agreement and associated terms and conditions. Gridjet does not independently determine the purposes or means of processing your customer data.

Your obligations as a data controller — including ensuring you have a lawful basis for the data you ask us to process on your behalf, and providing appropriate notices to your own data subjects — remain your responsibility.

The data processing obligations applicable to Gridjet in its processor role are set out in Schedule A (Data Processing Annex) of the Gridjet Master Services Agreement, available at https://gridjet.co.uk/terms/.

6. Sharing your information

We do not sell, rent, or trade your personal data to third parties for their own marketing purposes.

We share personal data only in the following circumstances:

6.1 Sub-processors and service partners

Gridjet engages a number of third-party organisations to support the delivery of its services. These organisations act as sub-processors and are contractually bound to process personal data only on Gridjet’s instruction, to implement appropriate security measures, and to comply with applicable data protection law.

Our current sub-processors are listed in the Gridjet Sub-Processor Register, in Section 15 of this policy, and updated in accordance with our notification process. Key partners include:

  • Heart Internet Ltd – customer support, inbound query handling, and abuse case management on behalf of Gridjet. Heart Internet Ltd engages Gapstars B.V. (Netherlands / Sri Lanka) and RS Hosting, a trading name of webhostpulse LLC (United States), as sub-contractors in connection with these functions.
  • UK-2 Limited – operational support, abuse case escalation, and customer service delivery on behalf of Gridjet. UK-2 Limited engages SIDNET Solutions Sp. z o.o. (Poland) and individual contracters in Ukraine as sub-contractors in connection with these functions.

 

6.2 Legal and regulatory disclosure

We may disclose personal data to law enforcement agencies, regulatory bodies, or other public authorities where we are required to do so by applicable law, court order, or regulatory obligation. Where permitted by law, we will notify you of any such request before disclosing your data.

6.3 Business transfers

In the event of a merger, acquisition, or sale of all or part of Gridjet’s business, personal data held by Gridjet may be transferred to the relevant successor entity. We will provide reasonable notice of any such transfer and ensure appropriate data protection obligations continue to apply.

7. International data transfers

Gridjet is based in the United Kingdom. Where we transfer personal data to organisations located outside the UK or European Economic Area — including in connection with our service partners — we ensure that appropriate safeguards are in place, which may include:

  • Transfers to countries covered by a UK adequacy decision.
  • Standard Contractual Clauses (SCCs) approved for use under UK law (the International Data Transfer Agreement, or IDTA, where applicable).
  • The UK–US Data Bridge, where applicable to certified US organisations.
  • Other appropriate transfer mechanisms as permitted by UK GDPR.

Current international transfers in connection with our sub-processors include data flows to the United States (RS Hosting / webhostpulse LLC), the Netherlands and Sri Lanka (Gapstars B.V.), Poland (SIDNET Solutions), and Ukraine (individual contracted staff engaged by UK-2 Limited). Details of the transfer mechanisms applicable to each sub-processor are set out in the Sub-Processor Register at https://gridjet.co.uk/terms/.

8. Abuse handling and legal process

8.1 Abuse response SLA

Gridjet operates a standard 72-hour response SLA for abuse reports submitted to our abuse team at [email protected]. This SLA applies to initial acknowledgement and triage of reports. Resolution timescales will vary depending on the nature and complexity of the reported issue.

Abuse investigations are conducted by or on behalf of Gridjet’s support team, which includes staff from Heart Internet Ltd and UK-2 Limited acting as sub-processors. Personal data processed in the course of an abuse investigation — including data relating to reporters and third parties — is handled in accordance with this policy.

8.2 Data breach notification

Separately from abuse handling, in the event of a personal data breach affecting customer data for which Gridjet is acting as processor, Gridjet will notify the affected customer without undue delay and in any event within 72 hours of becoming aware of the breach, to the extent practicable. This is a distinct obligation from abuse response and operates in parallel.

Where Gridjet is acting as controller in respect of a breach affecting its own systems or website data, Gridjet will notify the Information Commissioner’s Office (ICO) within 72 hours where the breach is likely to result in a risk to individuals’ rights and freedoms.

8.3 Law enforcement requests

Where Gridjet receives a request for personal data from a law enforcement agency or regulatory authority, we will assess the request for legal validity. Subject to applicable legal constraints, we will seek to notify affected customers before disclosing their data. We will not voluntarily disclose personal data to law enforcement beyond what is required by law.

9. Data retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law.

Data category

Standard retention period

Website enquiry data

12 months from date of enquiry

Customer account data

Duration of the services agreement + 7 years

Invoices and financial records

7 years (legal requirement)

Network and access logs

90 days (unless required for investigation)

Abuse investigation records

3 years from closure of investigation

Support correspondence

3 years from resolution

Marketing consent records

Until consent withdrawn + 12 months

Where data is subject to an active legal investigation, regulatory inquiry, or dispute, retention may be extended for the duration of that matter.

On expiry of the applicable retention period, personal data is securely deleted or anonymised.

10. Data security

Gridjet implements technical and organisational security measures appropriate to the nature of the data we process and the risks involved. These measures include, but are not limited to:

  • Physical security controls at datacentre facilities, including access control, CCTV, and environmental monitoring.
  • Encryption of data in transit using industry-standard protocols.
  • Access controls and role-based permissions limiting access to personal data to authorised personnel only.
  • Regular security assessments and monitoring of our infrastructure.
  • Staff training on data protection and information security obligations.

Notwithstanding these measures, no method of data transmission or storage is entirely secure. We encourage customers to adopt appropriate security practices in connection with their own use of our services.

11. Cookies and tracking technologies

11.1 What cookies are

Cookies are small text files placed on your device when you visit our website. They allow the website to recognise your device, remember your preferences, and collect information about how you use the site. Similar technologies include web beacons, pixels, and local storage — these work in a comparable way and are covered by this section.

11.2 Categories of cookies we use

Strictly necessary cookies These cookies are essential for the website to function and cannot be switched off. They are set in response to actions you take such as setting your privacy preferences, logging in, or filling in forms. No consent is required for these cookies.

Cookie purpose

Description

Session management

Maintains your session as you navigate the site

Security

Protects against cross-site request forgery and similar threats

Cookie consent

Stores your cookie preference choices

Load balancing

Ensures consistent performance across our infrastructure

 Analytics and performance cookies These cookies help us understand how visitors use our website so we can improve it. All information collected is aggregated and anonymous. These cookies are only set with your consent.

Cookie purpose

Description

Page views and traffic

Counts visits and tracks which pages are most visited

User journey

Helps us understand how visitors navigate between pages

Error reporting

Identifies pages where visitors encounter errors

 Preference cookies These cookies allow the website to remember choices you have made — such as your region or language – to provide a more personalised experience. These cookies are only set with your consent.

Cookie purpose

Description

Language and region

Remembers your language or regional preferences

Display settings

Remembers any display preferences you have set

 

11.3 Third-party cookies

Our website may include content or functionality from third-party services that set their own cookies. These may include:

  • Analytics providers — such as Google Analytics, used to analyse website traffic and usage patterns
  • Support tools — such as live chat or helpdesk widgets
  • Embedded content — such as video players or social media widgets

We do not control third-party cookies. Where third parties set cookies on our site, those providers’ own privacy and cookie policies apply. We will update this section as our use of third-party tools changes.

11.4 How we obtain consent

When you first visit our website, a cookie banner will ask for your consent to non-essential cookies. You can:

  • Accept all – consent to analytics, preference, and third-party cookies
  • Reject non-essential – only strictly necessary cookies will be set
  • Manage preferences – choose which categories of non-essential cookies to allow

Your preferences are stored and applied on subsequent visits. You can change your preferences at any time using the cookie settings link in the footer of our website.

11.5 Managing cookies in your browser

You can also control cookies through your browser settings. Most browsers allow you to view, delete, and block cookies from specific websites. Note that blocking strictly necessary cookies may affect how the website functions. Guidance on managing cookies is available from your browser provider and from the ICO at ico.org.uk/for-the-public/online/cookies.

11.6 Cookie retention

Strictly necessary cookies are typically session cookies that expire when you close your browser. Analytics and preference cookies are persistent and may remain on your device for up to 13 months from the date they are set, after which they expire automatically.

11.7 Changes to our cookie use

If we introduce new cookies or change how we use existing ones in a material way, we will update this section and, where required by law, seek your consent again.

12. Your rights

Under UK GDPR, you have the following rights in relation to personal data for which Gridjet is the data controller:

  • Right of access – to request a copy of the personal data we hold about you.
  • Right to rectification – to request correction of inaccurate or incomplete data.
  • Right to erasure – to request deletion of your data, subject to applicable legal obligations.
  • Right to restriction – to request that we limit our processing of your data in certain circumstances.
  • Right to object – to object to processing based on legitimate interests.
  • Right to data portability – to receive your data in a structured, machine-readable format where processing is based on consent or contract.
  • Right to withdraw consent – where processing is based on consent, to withdraw it at any time.

To exercise any of these rights, please contact us at [email protected]. We will respond within one calendar month of receipt of your request. Where requests are complex or numerous, we may extend this period by a further two months, in which case we will notify you.

If you are not satisfied with how we handle your request, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO): Website: ico.org.uk Telephone: 0303 123 1113

13. Third-party links

Our website may contain links to third-party websites. Gridjet is not responsible for the privacy practices or content of those sites. We encourage you to review the privacy policies of any external sites you visit.

14. Updates to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal requirements.

Where we make material changes, we will provide no less than 30 days’ prior notice by email to registered account holders, or by prominent notice in the customer portal. Continued use of our services or login to the customer portal following the notice period constitutes acceptance of the updated policy.

The current version of this policy, including the effective date and version number, is always available at https://gridjet.co.uk/privacy-policy/.

15. Sub-processor register

We engage the following sub-processors and sub-contractors in connection with the delivery of our services.

This register lists only those processors and sub-contractors whose activities are relevant to the processing of personal data in connection with Gridjet services specifically.

Register version: 1.0 Last updated: 14/04/2026 Next scheduled review: 14/04/2027

Sub-processor changes are managed under a two-tier notification model.

Material changes – those affecting data location, introducing new international transfers, or materially changing the nature of processing – are notified to affected customers no less than 14 days before taking effect.

Routine operational tooling changes are reflected in this register within 30 days without individual notification. See our Master Services Agreement for full details.

15.1 Own infrastructure

   

Entity

Gridjet Datacentres Ltd (15320312)

Role

Data controller / data processor

Activities

Provisioning, hosting, and management of dedicated server infrastructure; storage and transmission of customer data as directed by the customer

Data location

United Kingdom

Transfer mechanism

Not applicable

Gridjet Datacentres Ltd sub-contractors and third-party processors:

Entity

Role

Location

Transfer Mechanism

Victory Digital

Marketing services and campaign management

United Kingdom

N/A (no international transfer)

Meta Platforms, Inc.

Advertising platform and campaign delivery (Meta Ads)

United States

UK–US Data Bridge

LinkedIn Corporation

Advertising platform and campaign delivery (LinkedIn Ads)

United States

UK–US Data Bridge

Google LLC

Advertising platform and campaign delivery (Google Ads)

United States

UK–US Data Bridge

Create Succeed

Marketing services and campaign support

United Kingdom

N/A (no international transfer)

 

15.2 Customer support and operations – Heart Internet Ltd

   

Entity

Heart Internet Ltd (15319281)

Role

Sub-processor

Activities

Customer support, inbound query handling, abuse case management, billing queries, and technical and SRE functions on behalf of Gridjet

Data location

United Kingdom

Transfer mechanism

Not applicable — data remains in UK

DPA in place

Yes

Privacy contact

[email protected]

Heart Internet Ltd sub-contractors:

Entity

Role

Location

Transfer mechanism

Gapstars B.V.

Software development and SRE support

Netherlands (primary); Sri Lanka (operational)

Netherlands: UK–EU adequacy; Sri Lanka: IDTA

RS Hosting (webhostpulse LLC)

Technical support

United States

UK–US Data Bridge

 Heart Internet Ltd’s full third-party processor list is available here  

15.3 Customer support and operations – UK-2 Limited

Field

Detail

Entity

UK-2 Limited (16828837) including its trading names UK2, Midphase and WestHost 

Role

Sub-processor

Activities

Operational support, abuse case escalation, customer service delivery, billing queries, and technical and SRE functions on behalf of Gridjet

Data location

United Kingdom

Transfer mechanism

Not applicable — data remains in UK

DPA in place

Yes

Privacy contact

[email protected]

UK-2 Limited sub-contractors:

Entity

Role

Location

Transfer mechanism

SIDNET Solutions Sp. z o.o.

Software development and technical support

Poland

UK–EU adequacy

Individual contracted staff

SRE, technical, support, and abuse handling

Ukraine

IDTA (via individual Data Processing Addendum — Annex 6)

 UK-2 Limited’s full third-party processor list is available here

15.4 Change log

Version

Date

Change

Notification issued

1.0

14.04.2026

Initial register published

N/A

15.5 Website analytics and B2B visitor identification – Leadfeeder

   

Entity

Dealfront Group GmbH, trading as Leadfeeder

Role

Sub-processor

Activities

Website visitor identification, B2B lead intelligence, website analytics, and sales and marketing insight in connection with visits to the Gridjet website 

Data location

European Union

Transfer mechanism

UK–EU adequacy

 

15.6 Website analytics and B2B visitor identification – Lead Forensics

   

Entity

Lead Forensics Limited

Role

Sub-processor

Activities

Website visitor identification, B2B lead intelligence, website analytics, and sales and marketing insight in connection with visits to the Gridjet website 

Data location

United Kingdom

Transfer mechanism

Not applicable  data remains in UK

To raise a query about our sub-processor arrangements or to exercise your rights in relation to data processing, contact [email protected].

Gridjet Datacentres Ltd — registered in England and Wales, company number 15320312. Registered office: Units 4–5 Tristram Centre, Brown Lane West, Leeds, England, LS12 6BF. ICO registration number ZB662184. For data protection enquiries: [email protected]