Privacy Policy
Gridjet Datacentres Ltd Document version: 1.0
Effective date: 14 April 2026
Last reviewed: 14 April 2026
Gridjet Datacentres Ltd (“Gridjet”, “we”, “our”, “us”) is a provider of dedicated server and datacentre infrastructure services. We are registered in England and Wales (company number: 15320312).
For the purposes of applicable data protection law, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, Gridjet Datacentres Ltd is the data controller in respect of personal data collected through our website and in connection with the management of customer accounts.
Where Gridjet processes personal data on behalf of customers in the course of delivering infrastructure services, Gridjet acts as a data processor. This distinction is explained further in Section 5.
Data protection contact: Email: [email protected]
Post: Data Protection, Gridjet Datacentres Ltd, Units 4–5 Tristram Centre, Brown Lane West, Leeds, England, LS12 6BF
ICO registration number: ZB662184
2. What personal data we collect and why
We collect personal data across several categories, each with a distinct purpose and lawful basis.
2.1 Website enquiries and contact forms
Data collected: Name, email address, telephone number, company name, and any information you voluntarily provide in a message or enquiry form.
Purpose: To respond to your enquiry and, where relevant, to progress a commercial relationship.
Lawful basis: Legitimate interests (responding to inbound commercial enquiries); contract (where an enquiry relates to an existing or prospective services agreement).
2.2 Customer account data
Data collected: Contact name, job title, company name, registered address, billing address, email address, telephone number, payment method details (processed via our payment provider — see Section 6), account credentials, and records of service orders and correspondence.
Purpose: To create and manage your account, provision services, issue invoices, and communicate with you about your services.
Lawful basis: Contract (performance of the services agreement); legal obligation (financial record-keeping requirements).
2.3 Network, traffic, and technical data
Data collected: IP addresses (source and destination), bandwidth usage data, connection logs, access logs, routing data, server utilisation metrics, and related technical records generated in the course of providing infrastructure services.
Purpose: To deliver, monitor, and maintain the services; to detect, investigate, and respond to security incidents, abuse, and acceptable use violations; to comply with legal and regulatory obligations.
Lawful basis: Legitimate interests (network security, service integrity, and abuse prevention); legal obligation (where retention or disclosure is required by law).
Retention note: Network and access logs are retained for 90 days as standard, unless a longer period is required for an active investigation or legal process.
2.4 Abuse and incident data
Data collected: Reports submitted to our abuse team, correspondence relating to abuse investigations, IP addresses and identifiers associated with reported activity, and records of actions taken.
Purpose: To investigate and respond to abuse reports within our standard 72-hour SLA; to protect the integrity of our network and the interests of third parties affected by activity on our infrastructure; to comply with obligations under applicable law.
Lawful basis: Legitimate interests (network security and protection of third-party rights); legal obligation (where we are required to investigate or report by law or regulatory requirement).
Note on third-party data: Abuse reports frequently contain personal data relating to individuals who have not directly interacted with Gridjet — for example, recipients of spam or targets of network attacks. We process such data only to the extent necessary to investigate and resolve the reported incident.
2.5 Website technical data
Data collected: IP address, browser type and version, operating system, pages visited, time and duration of visits, referral source, and cookie identifiers.
Purpose: To operate and improve our website; to understand how visitors use our site.
Lawful basis: Legitimate interests (website operation and improvement); consent (where cookies beyond strictly necessary are used — see Section 11).
3. Lawful basis summary
|
Processing activity |
Lawful basis |
|
Responding to website enquiries |
Legitimate interests |
|
Account creation and management |
Contract |
|
Service delivery and provisioning |
Contract |
|
Invoicing and financial records |
Legal obligation |
|
Network monitoring and security |
Legitimate interests |
|
Abuse investigation and response |
Legitimate interests / Legal obligation |
|
Marketing communications |
Consent |
|
Legal process and regulatory compliance |
Legal obligation |
Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and interests as a data subject. You may request further information about these assessments by contacting us at [email protected].
Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out prior to withdrawal.
4. How we use your information
We use the personal data we collect to:
- Respond to enquiries and provide requested information about our services.
- Create, manage, and maintain your customer account.
- Provision, deliver, monitor, and support the infrastructure services you have ordered.
- Issue invoices and process payments.
- Communicate with you about your services, including planned maintenance, incidents, and service updates.
- Investigate and respond to abuse reports, security incidents, and acceptable use violations.
- Comply with our legal and regulatory obligations, including responding to lawful requests from law enforcement and regulatory authorities.
- Improve our website and services.
- Send you information about our services, updates, or relevant industry information, where you have opted in to receive such communications.
We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects.
5. Our role as data processor
Where you use Gridjet’s infrastructure to host, store, or process your own data — including data relating to your customers, employees, or end users — Gridjet acts as a data processor on your behalf, and you act as the data controller of that data.
In this capacity, Gridjet processes your data only on your documented instructions, as set out in the services agreement and associated terms and conditions. Gridjet does not independently determine the purposes or means of processing your customer data.
Your obligations as a data controller — including ensuring you have a lawful basis for the data you ask us to process on your behalf, and providing appropriate notices to your own data subjects — remain your responsibility.
The data processing obligations applicable to Gridjet in its processor role are set out in Schedule A (Data Processing Annex) of the Gridjet Master Services Agreement, available at https://gridjet.co.uk/terms/.
6. Sharing your information
We do not sell, rent, or trade your personal data to third parties for their own marketing purposes.
We share personal data only in the following circumstances:
6.1 Sub-processors and service partners
Gridjet engages a number of third-party organisations to support the delivery of its services. These organisations act as sub-processors and are contractually bound to process personal data only on Gridjet’s instruction, to implement appropriate security measures, and to comply with applicable data protection law.
Our current sub-processors are listed in the Gridjet Sub-Processor Register, in Section 15 of this policy, and updated in accordance with our notification process. Key partners include:
- Heart Internet Ltd – customer support, inbound query handling, and abuse case management on behalf of Gridjet. Heart Internet Ltd engages Gapstars B.V. (Netherlands / Sri Lanka) and RS Hosting, a trading name of webhostpulse LLC (United States), as sub-contractors in connection with these functions.
- UK-2 Limited – operational support, abuse case escalation, and customer service delivery on behalf of Gridjet. UK-2 Limited engages SIDNET Solutions Sp. z o.o. (Poland) and individual contracters in Ukraine as sub-contractors in connection with these functions.
6.2 Legal and regulatory disclosure
We may disclose personal data to law enforcement agencies, regulatory bodies, or other public authorities where we are required to do so by applicable law, court order, or regulatory obligation. Where permitted by law, we will notify you of any such request before disclosing your data.
6.3 Business transfers
In the event of a merger, acquisition, or sale of all or part of Gridjet’s business, personal data held by Gridjet may be transferred to the relevant successor entity. We will provide reasonable notice of any such transfer and ensure appropriate data protection obligations continue to apply.
7. International data transfers
Gridjet is based in the United Kingdom. Where we transfer personal data to organisations located outside the UK or European Economic Area — including in connection with our service partners — we ensure that appropriate safeguards are in place, which may include:
- Transfers to countries covered by a UK adequacy decision.
- Standard Contractual Clauses (SCCs) approved for use under UK law (the International Data Transfer Agreement, or IDTA, where applicable).
- The UK–US Data Bridge, where applicable to certified US organisations.
- Other appropriate transfer mechanisms as permitted by UK GDPR.
Current international transfers in connection with our sub-processors include data flows to the United States (RS Hosting / webhostpulse LLC), the Netherlands and Sri Lanka (Gapstars B.V.), Poland (SIDNET Solutions), and Ukraine (individual contracted staff engaged by UK-2 Limited). Details of the transfer mechanisms applicable to each sub-processor are set out in the Sub-Processor Register at https://gridjet.co.uk/terms/.
8. Abuse handling and legal process
8.1 Abuse response SLA
Gridjet operates a standard 72-hour response SLA for abuse reports submitted to our abuse team at [email protected]. This SLA applies to initial acknowledgement and triage of reports. Resolution timescales will vary depending on the nature and complexity of the reported issue.
Abuse investigations are conducted by or on behalf of Gridjet’s support team, which includes staff from Heart Internet Ltd and UK-2 Limited acting as sub-processors. Personal data processed in the course of an abuse investigation — including data relating to reporters and third parties — is handled in accordance with this policy.
8.2 Data breach notification
Separately from abuse handling, in the event of a personal data breach affecting customer data for which Gridjet is acting as processor, Gridjet will notify the affected customer without undue delay and in any event within 72 hours of becoming aware of the breach, to the extent practicable. This is a distinct obligation from abuse response and operates in parallel.
Where Gridjet is acting as controller in respect of a breach affecting its own systems or website data, Gridjet will notify the Information Commissioner’s Office (ICO) within 72 hours where the breach is likely to result in a risk to individuals’ rights and freedoms.
8.3 Law enforcement requests
Where Gridjet receives a request for personal data from a law enforcement agency or regulatory authority, we will assess the request for legal validity. Subject to applicable legal constraints, we will seek to notify affected customers before disclosing their data. We will not voluntarily disclose personal data to law enforcement beyond what is required by law.
9. Data retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law.
|
Data category |
Standard retention period |
|
Website enquiry data |
12 months from date of enquiry |
|
Customer account data |
Duration of the services agreement + 7 years |
|
Invoices and financial records |
7 years (legal requirement) |
|
Network and access logs |
90 days (unless required for investigation) |
|
Abuse investigation records |
3 years from closure of investigation |
|
Support correspondence |
3 years from resolution |
|
Marketing consent records |
Until consent withdrawn + 12 months |
Where data is subject to an active legal investigation, regulatory inquiry, or dispute, retention may be extended for the duration of that matter.
On expiry of the applicable retention period, personal data is securely deleted or anonymised.
10. Data security
Gridjet implements technical and organisational security measures appropriate to the nature of the data we process and the risks involved. These measures include, but are not limited to:
- Physical security controls at datacentre facilities, including access control, CCTV, and environmental monitoring.
- Encryption of data in transit using industry-standard protocols.
- Access controls and role-based permissions limiting access to personal data to authorised personnel only.
- Regular security assessments and monitoring of our infrastructure.
- Staff training on data protection and information security obligations.
Notwithstanding these measures, no method of data transmission or storage is entirely secure. We encourage customers to adopt appropriate security practices in connection with their own use of our services.
11. Cookies and tracking technologies
11.1 What cookies are
Cookies are small text files placed on your device when you visit our website. They allow the website to recognise your device, remember your preferences, and collect information about how you use the site. Similar technologies include web beacons, pixels, and local storage — these work in a comparable way and are covered by this section.
11.2 Categories of cookies we use
Strictly necessary cookies These cookies are essential for the website to function and cannot be switched off. They are set in response to actions you take such as setting your privacy preferences, logging in, or filling in forms. No consent is required for these cookies.
|
Cookie purpose |
Description |
|
Session management |
Maintains your session as you navigate the site |
|
Security |
Protects against cross-site request forgery and similar threats |
|
Cookie consent |
Stores your cookie preference choices |
|
Load balancing |
Ensures consistent performance across our infrastructure |
Analytics and performance cookies These cookies help us understand how visitors use our website so we can improve it. All information collected is aggregated and anonymous. These cookies are only set with your consent.
|
Cookie purpose |
Description |
|
Page views and traffic |
Counts visits and tracks which pages are most visited |
|
User journey |
Helps us understand how visitors navigate between pages |
|
Error reporting |
Identifies pages where visitors encounter errors |
Preference cookies These cookies allow the website to remember choices you have made — such as your region or language – to provide a more personalised experience. These cookies are only set with your consent.
|
Cookie purpose |
Description |
|
Language and region |
Remembers your language or regional preferences |
|
Display settings |
Remembers any display preferences you have set |
11.3 Third-party cookies
Our website may include content or functionality from third-party services that set their own cookies. These may include:
- Analytics providers — such as Google Analytics, used to analyse website traffic and usage patterns
- Support tools — such as live chat or helpdesk widgets
- Embedded content — such as video players or social media widgets
We do not control third-party cookies. Where third parties set cookies on our site, those providers’ own privacy and cookie policies apply. We will update this section as our use of third-party tools changes.
11.4 How we obtain consent
When you first visit our website, a cookie banner will ask for your consent to non-essential cookies. You can:
- Accept all – consent to analytics, preference, and third-party cookies
- Reject non-essential – only strictly necessary cookies will be set
- Manage preferences – choose which categories of non-essential cookies to allow
Your preferences are stored and applied on subsequent visits. You can change your preferences at any time using the cookie settings link in the footer of our website.
11.5 Managing cookies in your browser
You can also control cookies through your browser settings. Most browsers allow you to view, delete, and block cookies from specific websites. Note that blocking strictly necessary cookies may affect how the website functions. Guidance on managing cookies is available from your browser provider and from the ICO at ico.org.uk/for-the-public/online/cookies.
11.6 Cookie retention
Strictly necessary cookies are typically session cookies that expire when you close your browser. Analytics and preference cookies are persistent and may remain on your device for up to 13 months from the date they are set, after which they expire automatically.
11.7 Changes to our cookie use
If we introduce new cookies or change how we use existing ones in a material way, we will update this section and, where required by law, seek your consent again.
12. Your rights
Under UK GDPR, you have the following rights in relation to personal data for which Gridjet is the data controller:
- Right of access – to request a copy of the personal data we hold about you.
- Right to rectification – to request correction of inaccurate or incomplete data.
- Right to erasure – to request deletion of your data, subject to applicable legal obligations.
- Right to restriction – to request that we limit our processing of your data in certain circumstances.
- Right to object – to object to processing based on legitimate interests.
- Right to data portability – to receive your data in a structured, machine-readable format where processing is based on consent or contract.
- Right to withdraw consent – where processing is based on consent, to withdraw it at any time.
To exercise any of these rights, please contact us at [email protected]. We will respond within one calendar month of receipt of your request. Where requests are complex or numerous, we may extend this period by a further two months, in which case we will notify you.
If you are not satisfied with how we handle your request, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO): Website: ico.org.uk Telephone: 0303 123 1113
13. Third-party links
Our website may contain links to third-party websites. Gridjet is not responsible for the privacy practices or content of those sites. We encourage you to review the privacy policies of any external sites you visit.
14. Updates to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal requirements.
Where we make material changes, we will provide no less than 30 days’ prior notice by email to registered account holders, or by prominent notice in the customer portal. Continued use of our services or login to the customer portal following the notice period constitutes acceptance of the updated policy.
The current version of this policy, including the effective date and version number, is always available at https://gridjet.co.uk/privacy-policy/.
15. Sub-processor register
We engage the following sub-processors and sub-contractors in connection with the delivery of our services.
This register lists only those processors and sub-contractors whose activities are relevant to the processing of personal data in connection with Gridjet services specifically.
Register version: 1.0 Last updated: 14/04/2026 Next scheduled review: 14/04/2027
Sub-processor changes are managed under a two-tier notification model.
Material changes – those affecting data location, introducing new international transfers, or materially changing the nature of processing – are notified to affected customers no less than 14 days before taking effect.
Routine operational tooling changes are reflected in this register within 30 days without individual notification. See our Master Services Agreement for full details.
15.1 Own infrastructure
|
Entity |
Gridjet Datacentres Ltd (15320312) |
|
Role |
Data controller / data processor |
|
Activities |
Provisioning, hosting, and management of dedicated server infrastructure; storage and transmission of customer data as directed by the customer |
|
Data location |
United Kingdom |
|
Transfer mechanism |
Not applicable |
Gridjet Datacentres Ltd sub-contractors and third-party processors:
|
Entity |
Role |
Location |
Transfer Mechanism |
|
Victory Digital |
Marketing services and campaign management |
United Kingdom |
N/A (no international transfer) |
|
Meta Platforms, Inc. |
Advertising platform and campaign delivery (Meta Ads) |
United States |
UK–US Data Bridge |
|
LinkedIn Corporation |
Advertising platform and campaign delivery (LinkedIn Ads) |
United States |
UK–US Data Bridge |
|
Google LLC |
Advertising platform and campaign delivery (Google Ads) |
United States |
UK–US Data Bridge |
|
Create Succeed |
Marketing services and campaign support |
United Kingdom |
N/A (no international transfer) |
15.2 Customer support and operations – Heart Internet Ltd
|
Entity |
Heart Internet Ltd (15319281) |
|
Role |
Sub-processor |
|
Activities |
Customer support, inbound query handling, abuse case management, billing queries, and technical and SRE functions on behalf of Gridjet |
|
Data location |
United Kingdom |
|
Transfer mechanism |
Not applicable — data remains in UK |
|
DPA in place |
Yes |
|
Privacy contact |
Heart Internet Ltd sub-contractors:
|
Entity |
Role |
Location |
Transfer mechanism |
|
Gapstars B.V. |
Software development and SRE support |
Netherlands (primary); Sri Lanka (operational) |
Netherlands: UK–EU adequacy; Sri Lanka: IDTA |
|
RS Hosting (webhostpulse LLC) |
Technical support |
United States |
UK–US Data Bridge |
Heart Internet Ltd’s full third-party processor list is available here
15.3 Customer support and operations – UK-2 Limited
|
Field |
Detail |
|
Entity |
UK-2 Limited (16828837) including its trading names UK2, Midphase and WestHost” |
|
Role |
Sub-processor |
|
Activities |
Operational support, abuse case escalation, customer service delivery, billing queries, and technical and SRE functions on behalf of Gridjet |
|
Data location |
United Kingdom |
|
Transfer mechanism |
Not applicable — data remains in UK |
|
DPA in place |
Yes |
|
Privacy contact |
UK-2 Limited sub-contractors:
|
Entity |
Role |
Location |
Transfer mechanism |
|
SIDNET Solutions Sp. z o.o. |
Software development and technical support |
Poland |
UK–EU adequacy |
|
Individual contracted staff |
SRE, technical, support, and abuse handling |
Ukraine |
IDTA (via individual Data Processing Addendum — Annex 6) |
UK-2 Limited’s full third-party processor list is available here
15.4 Change log
|
Version |
Date |
Change |
Notification issued |
|
1.0 |
14.04.2026 |
Initial register published |
N/A |
15.5 Website analytics and B2B visitor identification – Leadfeeder
|
Entity |
Dealfront Group GmbH, trading as Leadfeeder |
|
Role |
Sub-processor |
|
Activities |
Website visitor identification, B2B lead intelligence, website analytics, and sales and marketing insight in connection with visits to the Gridjet website |
|
Data location |
European Union |
|
Transfer mechanism |
UK–EU adequacy |
15.6 Website analytics and B2B visitor identification – Lead Forensics
|
Entity |
Lead Forensics Limited |
|
Role |
Sub-processor |
|
Activities |
Website visitor identification, B2B lead intelligence, website analytics, and sales and marketing insight in connection with visits to the Gridjet website |
|
Data location |
United Kingdom |
|
Transfer mechanism |
Not applicable – data remains in UK |
To raise a query about our sub-processor arrangements or to exercise your rights in relation to data processing, contact [email protected].
Gridjet Datacentres Ltd — registered in England and Wales, company number 15320312. Registered office: Units 4–5 Tristram Centre, Brown Lane West, Leeds, England, LS12 6BF. ICO registration number ZB662184. For data protection enquiries: [email protected]