Website Data Processing Notice
This notice explains how Grilli OÜ, an Estonian private limited company, processes personal data collected through grillisecurity.com. For this website processing Grilli OÜ acts as Controller. This is not the Article 28 Data Processing Agreement used when Grilli acts as a processor during a client engagement.
This notice covers website data only. Professional-service data roles and terms are set in the applicable MSA, SoW, and engagement DPA where required. Depending on the service and data flow, Grilli may act as a processor, an independent controller, or both for distinct processing activities.
1. Data We Collect
Through the website we process the following categories:
- Contact requests — name, work email, enquiry, and whether you request an NDA.
- Quote requests — name, work email, selected service, scope overview, and whether you request an NDA.
- Booking requests — requested date and time, name, work email, company, topic, optional notes, and whether you request an NDA. A submitted slot is a request until we confirm it.
- Unsubscribe requests — email address and, when present in the link, campaign contact or sequence identifiers used to apply the request accurately.
- Request and security metadata — IP address, user-agent, origin or referrer, timestamp, request identifiers, response status, latency, and security or error events. Submission records retain the IP, user-agent, origin/referrer, and timestamp associated with that request.
We set no cookies, use no analytics, and deploy no tracking pixels or fingerprinting. See our Privacy Policy for full details.
The forms use a hidden anti-spam field and may use a self-hosted proof-of-work challenge. The challenge response is checked transiently and is not stored in the submission record.
2. Purpose & Legal Basis
Contact, quote, and booking data is processed to respond to your request and take requested pre-contractual steps — legal basis: Article 6(1)(b) GDPR. General business enquiries that are not pre-contractual are handled under Article 6(1)(f) GDPR, our legitimate interest in managing business communications.
Unsubscribe data is processed to apply and evidence your communication preference — legal bases: Articles 6(1)(c) and 6(1)(f) GDPR, as applicable to the communication and our obligation and legitimate interest in respecting objections and avoiding further unwanted outreach.
Server access logs are processed to ensure the security and integrity of the website — legal basis: Article 6(1)(f) GDPR (legitimate interests).
Inbound enquiry, quote, and booking content is not used for unrelated advertising or profiling. Unsubscribe identifiers are used only to locate the relevant outreach record and apply the request.
3. Website Infrastructure Providers
Amazon Web Services provides the static-site origin, global CDN, regional form API, encrypted S3 submission storage, and CloudWatch/S3 logging. Form execution and origin storage are configured in Frankfurt (eu-central-1); CloudFront may process request metadata at a global edge location.
Hetzner provides dedicated infrastructure in Germany for self-hosted internal workflows and agreed service-delivery workloads. It is not the public website host or primary form endpoint. When an internal workflow is enabled it may retrieve a form record from AWS for follow-up or scheduling. See the subprocessors page for the current data-flow description.
4. Security Measures
- Transport encrypted with TLS 1.2+; stored submission records use KMS-managed encryption.
- Access to form submission data restricted to named personnel on a need-to-know basis.
- MFA enforced on all systems with access to website data.
- Website, API, and security logs are stored in dedicated AWS logging services with restricted access and time-bound retention.
- Secure deletion applied when retention periods expire.
5. Retention & Deletion
Website submission records are retained for up to 365 days from receipt, unless deleted earlier when no longer needed. If an engagement proceeds, relevant business records may move into the engagement record and be retained under the contract and applicable law.
CloudFront, API Gateway, Lambda, S3, and security/operational logs are retained for up to 90 days. A suppression record may be retained longer than the raw unsubscribe submission where necessary to honour an opt-out and prevent re-contact.
To request early deletion of your data, contact privacy@grillisecurity.com.
6. Data Subject Rights
Under GDPR you have the right to access, rectify, erase, restrict, and object to processing based on legitimate interests. The right to portability (Art. 20) applies to form data processed under Art. 6(1)(b) but not to server access logs processed under legitimate interests. To exercise any right, contact privacy@grillisecurity.com. We will respond without undue delay and in any event within one month. Where GDPR permits an extension for a complex request or number of requests, that period may be extended by two further months, with notice and reasons provided within the first month.
You may also lodge a complaint with your local supervisory authority. EEA residents may contact the Estonian Data Protection Inspectorate (our lead supervisory authority) or their own national authority.
7. Breach Notification
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware, and inform affected individuals without undue delay where required by applicable law.
Notifications will describe the nature of the breach, likely consequences, and measures taken or proposed to address it.
8. Storage, Access & International Transfers
Website assets, form records, and primary application logs are stored in the EU. The site is delivered through CloudFront, so IP addresses and request metadata may be processed transiently at an edge location outside the EEA.
Grilli operates from Tallinn and Buenos Aires. Authorised personnel in Estonia or Argentina may access a website enquiry on a need-to-know basis to respond to it. Where GDPR Chapter V applies, we use the applicable contractual and organisational transfer safeguards and can describe them during diligence. If you require EU-only access, request and agree that restriction before submitting sensitive details.
9. Service Engagement DPAs
This notice covers website data only. If you engage Grilli OÜ for professional services — penetration testing, DFIR, SOC monitoring, compliance advisory, or any other service — data processing roles and terms for that engagement are agreed separately in the MSA, SoW, and an Article 28 DPA where Grilli acts as a processor.
To request a Data Processing Addendum for a service engagement, contact privacy@grillisecurity.com.
10. Governing Law
This notice is governed by the laws of Estonia and the applicable provisions of the GDPR. Disputes are subject to the jurisdiction of Estonian courts, without prejudice to your right to lodge a complaint with a supervisory authority.
Contact
Data protection enquiries, rights requests, or questions about this notice: privacy@grillisecurity.com. See also our Privacy Policy and Subprocessors.
