Skip to content

Privacy policy

This Privacy Policy explains how grimstack.com/ collects, uses, and protects your personal data. We process only the personal data reasonably necessary to provide services, communicate with users, comply with legal obligations, and maintain the security and functionality of the website. We respect your privacy, never sell your data to third parties, and ensure your rights under the GDPR are fully protected. Please read the full policy below for detailed information on data retention, cookies, and your rights.

Privacy policy

1. General Information

This Privacy Policy explains how the www.grimstack.com website (hereinafter – the “Controller,” “we,” or “us”) processes the personal data of website visitors, clients, and potential clients. We are committed to processing your personal data transparently, securely, and strictly in accordance with the General Data Protection Regulation (GDPR) (EU 2016/679) and the applicable laws of the Republic of Latvia.

2. Controller Information

Note: As a sole proprietor whose core activities do not involve large-scale, regular, and systematic monitoring of data subjects, the Controller is not required to appoint a formal Data Protection Officer (DPO) under Article 37 of the GDPR.

3. What Data We Process

Depending on your interaction with us, we process the following data:

Communication Data (When you contact us)

  • Name and surname
  • Email address and phone number
  • Name of the legal entity
  • Content of your message and your website URL
  • Any other information you voluntarily provide

Project Data (When you request services)

  • Project descriptions and technical requirements
  • Access credentials required for project execution
  • Other information necessary for providing the requested service

Technical Data (Automatically processed upon visiting)

  • Administrative Activity Data (For user accounts/logins): Usernames, email addresses, backend actions performed, and anonymized IP/User-Agent data (strictly for security monitoring).
  • Technical & Analytics Data (Automatically processed upon visiting): Browser type, operating system, visited pages, date, and time of access. IP addresses are not stored; they are converted into a temporary, anonymous hash. Other technical data is processed as necessary for website stability and security.

We process personal data strictly for defined purposes, relying on the following legal bases under the GDPR:

  • Client Communication: To respond to inquiries and provide customer service. (Legal basis: Taking steps before entering a contract; Legitimate interests). Providing your name and email address is necessary for us to respond. If you choose not to provide this, we will be unable to respond to your inquiry.
  • Service Provision: For project development and requested service delivery. (Legal basis: Performance of a contract). Providing project requirements and access credentials is required. Without this information, we will be unable to perform the contract or deliver the services.
  • Accounting & Invoicing: To prepare invoices and manage finances. (Legal basis: Compliance with a legal obligation). Providing billing information is a statutory requirement. If you do not provide it, we will be unable to issue invoices or provide paid services.
  • Newsletters: To send updates and marketing communications. (Legal basis: Your voluntary consent). Providing your email for this is entirely voluntary. If you do not subscribe, you will not receive marketing communications.
  • Website Security: To ensure website operation and investigate security incidents. (Legal basis: Legitimate interests in technical security). Technical information is processed automatically. Without this, we cannot protect the website against malicious activity or ensure its operation.
  • Analytics: To gather aggregated performance statistics. (Legal basis: Legitimate interests in improving our website). Analytics data is processed in anonymized, cookieless form. Without this, our ability to identify technical issues and improve usability is significantly reduced.
  • Legal Claims: For fulfilling or defending against legal claims. (Legal basis: Compliance with a legal obligation; Legitimate interests). Failure to provide requested information where legally required will affect our ability to resolve disputes or comply with applicable laws.
  • Website Security & Audit Logging: To log administrative actions, prevent fraud, and investigate security incidents. (Legal basis: Legitimate interests in technical security).

5. Data Sources

We obtain personal data from the following sources:

  • Directly from you: When you submit forms, subscribe to newsletters, request services, or email us.
  • Automatically: Through the technical operation of our website, including server logs.
  • Third-Party Integrations: From services you voluntarily choose to use to interact with us (e.g., meeting booking tools), from which we receive categories of data such as your name, email address, and meeting schedule.

6. Specific Processing Activities

Newsletters

If you voluntarily subscribe to our newsletter, your email address is processed using our mailing system. Newsletters are only sent to individuals who have actively opted in. You can withdraw your consent and unsubscribe at any time using the link provided in every email. To minimize data storage, individual subscriber sending records and rendered email body templates are permanently purged after 30 days.

Booking Meetings

We offer the option to book meetings using Google Calendar, Google Meet, or similar services. By using this feature, your data is processed in accordance with Google’s privacy policy. Remote meetings can be recorded or automatically transcribed to document project requirements or ensure service quality. You will always be informed before any recording begins and can decline to be recorded.

Recordings are used to document project requirements and improve service quality. They are not used for automated decision-making or marketing purposes.

Third-Party Content (e.g., YouTube)

Some pages include embedded third-party content (like YouTube videos). We have designed the site so this content does not load automatically. It is only activated after a conscious “click-to-load” action from you. Once you choose to load it, the respective service provider may receive technical information about your device and apply their own privacy policies.

Privacy-Friendly Website Analytics

We use a self-hosted analytics system to analyze traffic and improve website performance.

  • This system runs entirely on our server and does not communicate with external third parties.
  • It does not use cookies and does not store your personal data or IP address. Instead, it uses a temporary, one-way hash (combining your anonymized IP and browser details) that automatically resets every 24 hours.
  • Because it is a one-way hash without encryption keys, this data cannot be reversed to identify you.

Security & Audit Logging

  • To protect the website from unauthorized access, we maintain an internal audit log of administrative actions (e.g., login attempts, content modifications).
  • This applies strictly to logged-in administrative users and failed login attempts: not general public visitors.
  • This system utilizes zero cookies, anonymizes IP addresses by default, and is accessible only to site administrators.

Server Logs

Our web server automatically logs technical access data strictly for security, performance, and incident investigation. These logs include IP addresses, request times, requested resources, and browser information, and are typically retained for 30 to 90 days.

Grimstack does not display a cookie consent pop-up because our website is fundamentally designed to respect your privacy by default. We operate without non-essential tracking cookies or advertising technologies.

  • Cookieless Analytics: Our analytics system relies solely on the temporary 24-hour one-way hashing described above, completely bypassing the need for tracking cookies.
  • No Tracking in Security Logs: Our administrative activity logging operates entirely without cookies or Local Storage.
  • Consent by Action: Any cookies related to our newsletter forms are strictly functional and are only created if you actively engage with the form to subscribe.
  • Click-to-Load Embeds: Third-party services cannot place tracking cookies on your device unless you explicitly click to activate their embedded content.

(Note: We use standard browser Local Storage strictly for user interface functionality, such as saving your light/dark mode preference via grimstack_theme_mode. This data is not used for tracking or profiling).

8. Data Recipients and Transfers

To provide our services, we use trusted third-party service providers (Data Processors):

  • Infrastructure & Security: DELSKA Latvia, SIA (hosting) and RunCloud (server management).
  • Workspace & Cloud Storage: Google Workspace (Google Ireland Limited) for document storage, email hosting, and meeting bookings.
  • Communications: MailPoet for newsletter delivery.

If data is transferred outside the EU/EEA (e.g., via Google), it is done in compliance with GDPR using appropriate safeguards recognized under the GDPR, such as the EU–US Data Privacy Framework (where applicable) or the European Commission’s Standard Contractual Clauses. We never sell your personal data to third parties.

9. Data Security

We implement appropriate technical and organizational measures to protect your data against unauthorized access, loss, or alteration. These include strict access controls, encryption where appropriate, regular software updates, and secure backups. While we strive for maximum security, no electronic transmission can be guaranteed to be 100% secure.

10. Data Retention Periods

We store personal data only as long as necessary to fulfill its processing purpose:

  • Contact Requests: Up to 2 years after the last communication.
  • Newsletter Data: Until you withdraw your consent/unsubscribe. Specific sending records and rendered email templates are automatically purged after 30 days.
  • Meeting Recordings/Transcripts: Until project completion or up to 12 months.
  • Accounting Data (Invoices): At least 5 years, as required by Latvian Accounting Law.
  • Security Audit Logs: 60 days, after which they are permanently deleted.
  • Analytics Visitor ID Hash: Maximum 24 hours.

Once data is no longer necessary, it is permanently deleted or securely anonymized.

11. Rights of the Data Subject

Under the GDPR, you have the right to:

  • Access the personal data we hold about you.
  • Request the rectification of incorrect data.
  • Request the erasure of your data (“right to be forgotten”).
  • Restrict the processing of your data.
  • Object to processing (including an absolute right to object to direct marketing).
  • Request data portability.
  • Withdraw your consent at any time (where processing is based on consent).

12. Automated Decision-Making

We do not engage in automated decision-making or profiling that produces legal or significant effects concerning you. All decisions regarding proposals, services, and communication involve human intervention.

13. Protection of Minors

Our services are intended for business professionals and adults. We do not knowingly collect personal data from anyone under the age of 16. If we discover we have inadvertently collected such data, it will be deleted immediately.

14. Submitting Complaints

If you believe your data is being processed in violation of applicable regulations, you have the right to lodge a complaint with the Data State Inspectorate of Latvia (Datu valsts inspekcija).

15. Policy Changes

We reserve the right to update this Privacy Policy as our services evolve. The most current version will always be available on this page.

16. Contact Us

To exercise your rights or ask any questions regarding this policy, contact the Controller at: Email: info@grimstack.com. We will respond to your request within one month, unless the GDPR permits an extension.