Legal
Privacy Policy
Last updated: 15 September 2026
This Privacy Policy explains how Greatfy (“Greatfy”, “we”, “us”) collects and uses personal data when you visit greatfy.io or contact us about our business process automation services. We are based in London, United Kingdom, and we act as the data controller for the personal data described here.
If you have any questions about this policy or how we handle your data, email us at hello@greatfy.io.
1. The data we collect
Information you give us
When you request an operational audit or custom plan through the form on our website, we collect:
- your full name;
- your business email address;
- your company name;
- the primary manual bottleneck you select, and any notes you choose to add;
- if you used our savings calculator before submitting, the estimate you generated (team size, weekly hours, hourly rate and estimated savings).
We also collect any information you include when you email us directly.
Information collected automatically
When you visit the website, our hosting provider’s servers automatically record technical information such as your IP address, browser type, device information, the pages you visit and the date and time of your visit. This is standard server log data used to keep the website secure and working.
We do not currently use advertising trackers or third-party analytics on this website. If that changes, we will update this policy and, where required, ask for your consent first.
2. How and why we use your data
Under UK GDPR and EU GDPR we must have a lawful basis for using your personal data. We use it as follows:
- To respond to your enquiry and prepare your audit or proposal — because you have asked us to take steps before potentially entering into a contract with us, and in our legitimate interest in responding to business enquiries.
- To deliver services if you become a client — to perform our contract with you.
- To keep the website secure and working properly — in our legitimate interest in protecting our systems and preventing abuse or spam.
- To send occasional relevant updates to business contacts who have enquired about our services — in our legitimate interest in B2B marketing. You can opt out at any time by replying to any message or emailing us.
- To meet legal, tax and accounting obligations — to comply with the law.
We do not sell your personal data, and we do not use it for automated decision-making that has legal or similarly significant effects on you.
3. Cookies
The public pages of this website do not set advertising or analytics cookies. Essential cookies may be set if you log in to the website administration area, and our security and caching systems may use short-lived technical cookies needed for the site to function. These strictly necessary cookies do not require consent.
4. Who we share your data with
We only share personal data with trusted service providers who help us run our business, under contracts that require them to protect it:
- Website hosting — Hostinger, which hosts this website and its server logs.
- Email — our email provider, which delivers form notifications and our correspondence with you.
- Web fonts — Google Fonts, which serves the typefaces used on this website. Your browser connects to Google’s servers to load them, which shares your IP address with Google.
- Professional advisers — such as accountants or lawyers, where necessary.
If you become a client, we may process data within automation tools and platforms agreed with you as part of the project. That processing is covered by the agreement and Data Processing Agreement we sign with you.
We may also disclose data where required by law, or to protect our rights, property or safety.
5. International transfers
Some of our service providers (for example Google) may process data outside the UK and European Economic Area. Where this happens, we rely on appropriate safeguards such as UK adequacy regulations, the UK International Data Transfer Addendum or the EU Standard Contractual Clauses.
6. How long we keep your data
- Enquiries that do not become projects: up to 24 months after our last contact, then deleted.
- Client records: for the length of our relationship and up to 6 years afterwards, to meet legal and accounting obligations.
- Server logs: retained by our hosting provider for a limited period for security purposes.
7. How we protect your data
We use appropriate technical and organisational measures to protect personal data, including encryption in transit (HTTPS/TLS), access controls and least-privilege credentials. No method of transmission over the internet is completely secure, but we work to protect your information and review our safeguards regularly.
8. Your rights
Under data protection law you have the right to:
- access the personal data we hold about you;
- ask us to correct inaccurate or incomplete data;
- ask us to delete your data;
- object to or ask us to restrict how we use your data, including objecting to marketing at any time;
- ask for your data to be transferred to you or another organisation (data portability);
- withdraw consent at any time, where we rely on consent.
To exercise any of these rights, email hello@greatfy.io. We will respond within one month. There is normally no fee.
9. Complaints
If you are unhappy with how we have handled your data, please contact us first so we can try to put it right. You also have the right to complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk, or to the data protection authority in your country if you are in the EU.
10. Changes to this policy
We may update this policy from time to time. The latest version will always be published on this page, with the “last updated” date shown at the top.