Privacy Policy
How Grilli OÜ — a private limited company registered in Estonia — collects, uses, and protects personal data, both through this website and in the course of professional service engagements.
1. Controller
The data controller is Grilli OÜ, registered in Estonia. For all data protection enquiries, rights requests, or complaints, contact privacy@grillisecurity.com.
Our lead supervisory authority is Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate). EEA residents may also contact their own national supervisory authority.
2. Cookies & Tracking
We do not set cookies. We do not use third-party analytics, advertising networks, tracking pixels, session recording, or fingerprinting on this website.
The automated data collection is request and security metadata generated by the CDN, form API, application, and storage services. Depending on the request this can include IP address, user-agent, timestamp, request identifier, origin/referrer, route, response status, latency, and security or error events. It is used for delivery, security, troubleshooting, and abuse prevention.
Global Privacy Control (GPC) and Do Not Track signals have no additional effect because we do not track, sell, or share personal data. Rights requests are always honoured regardless.
3. Website Data
When you use this website we collect:
- Contact requests — name, work email, enquiry, and NDA-request choice.
- Quote requests — name, work email, selected service, scope overview, and NDA-request choice.
- Booking requests — requested date/time, name, work email, company, selected topic, optional notes, and NDA-request choice. A requested slot is not confirmed until we respond.
- Unsubscribe requests — email and optional campaign contact or sequence identifiers carried in the unsubscribe link so the request can be applied accurately.
- Request metadata and logs — the request and security metadata described above. Stored submission records include the associated IP address, user-agent, origin/referrer, and timestamp.
Legal bases: contact, quote, and booking requests — Art. 6(1)(b) GDPR for requested pre-contractual steps, or Art. 6(1)(f) for general business communications; unsubscribe requests — Arts. 6(1)(c) and 6(1)(f), as applicable, to apply and evidence the preference; request metadata and logs — Art. 6(1)(f) for reliable delivery, security, troubleshooting, and abuse prevention.
Retention: website submission records up to 365 days; request, application, and security logs up to 90 days. A suppression record may be kept longer where needed to honour an unsubscribe request and prevent re-contact. See our Website Data Processing Notice for the data flow and controls.
4. Service Engagement Data
When you engage us for professional services we process additional personal data necessary to deliver those services, which may include:
- Contact details, role, and organisational information.
- Engagement context: scope documents, statements of work, proposals, and technical artefacts.
- Communications: emails, meeting notes, and correspondence.
- Billing and financial records.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract); Art. 6(1)(c) where processing is required by law (e.g. statutory accounting retention).
Retention: for the duration of the engagement and as required by applicable law thereafter. Financial and contractual records are retained for 7 years per Estonian accounting law. Data processing terms for engagements are negotiated separately — contact privacy@grillisecurity.com to request an engagement DPA.
5. Sharing & Processors
We do not sell, rent, or share personal data with third parties for commercial, advertising, or marketing purposes.
Amazon Web Services provides the static website origin, global CDN, regional form API, encrypted form storage, and operational logging. Hetzner provides dedicated infrastructure in Germany for self-hosted internal workflows and agreed service-delivery workloads. Hetzner is not the public website host or primary form endpoint, but an enabled internal workflow may retrieve a form record from AWS for follow-up or scheduling. See the subprocessors page for purposes, data categories, and regions.
Optional integration templates are inactive by default; their presence in code does not mean the named service processes personal data. Before an optional calendar, notification, email, messaging, or outreach-preference provider is activated with personal data, it must complete the applicable security and contractual review and be added to the public list or engagement subprocessor schedule. You may request deployed-state confirmation during diligence.
Engagement-specific processors, if any, are disclosed in the applicable Statement of Work and require written client approval.
We may disclose personal data where required by law, valid legal process, or to protect the rights, property, or safety of Grilli OÜ, our clients, or others.
6. Storage, Access & International Transfers
Website assets, form records, and primary application logs are stored in AWS's Frankfurt region. Relevant self-hosted internal workflows run on dedicated infrastructure in Germany.
This website is delivered via a global CDN. Your IP address may be transiently processed at an edge location outside the EEA. AWS's DPA and transfer mechanisms apply to that infrastructure processing.
Grilli operates from Tallinn and Buenos Aires. Authorised personnel in Estonia or Argentina may access website or engagement data on a need-to-know basis. Where GDPR Chapter V applies, the relevant contractual and organisational safeguards are documented for the data flow. A buyer that requires EU-only access must agree that restriction before sharing sensitive information.
For service engagements, the SoW and engagement DPA where applicable define storage region, permitted access locations, providers, retention, deletion, and any transfer mechanism.
7. Security
- Encryption in transit (TLS 1.2+) and at rest for all stored data.
- Least-privilege access control; MFA enforced on all systems handling personal data.
- Access to personal data restricted to named personnel with a documented need.
- Secure deletion when documented retention periods expire.
- Incident response processes covering detection, containment, and notification.
8. Breach Notification
Where Grilli acts as controller, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hoursof becoming aware when the breach is likely to result in a risk to individuals' rights and freedoms (Art. 33 GDPR).
Where Grilli acts as controller and the breach is likely to result in a high risk, we will also notify affected individuals without undue delay where Art. 34 GDPR requires it.
Where Grilli acts as processor, we notify the relevant controller without undue delay and provide the assistance agreed in the engagement DPA. The controller remains responsible for authority and data-subject notification decisions.
9. Your Rights
Under GDPR you have the following rights:
- Access — obtain a copy of your personal data (Art. 15).
- Rectification — correct inaccurate data (Art. 16).
- Erasure — request deletion where there is no overriding legal basis to retain (Art. 17).
- Restriction — limit how we use your data in certain circumstances (Art. 18).
- Portability — receive data you provided in a structured, machine-readable format, where processing is based on contract or consent and carried out by automated means (Art. 20).
- Objection — object to processing based on legitimate interests (Art. 21).
To exercise any right, contact privacy@grillisecurity.com. We will verify your identity and respond without undue delay and in any event within one month. Where GDPR permits an extension for a complex request or number of requests, that period may be extended by two further months, with notice and reasons provided within the first month.
10. Complaints
If you believe we have not handled your personal data in accordance with applicable law, please contact us first at privacy@grillisecurity.com so we can attempt to resolve the matter.
You also have the right to lodge a complaint with a supervisory authority at any time. Our lead authority is the Estonian Data Protection Inspectorate (aki.ee). EEA residents may alternatively contact their own national authority.
11. Children
This website and our services are directed to business users only. We do not knowingly collect personal data from individuals under the age of 16. If you believe a minor has submitted data to us, contact privacy@grillisecurity.com and we will delete it promptly.
12. Data Protection Contact
Grilli OÜ is not required to appoint a Data Protection Officer under Article 37 GDPR. Our processing activities do not constitute large-scale processing of special categories of data and do not involve systematic monitoring of individuals at scale.
All data protection enquiries are handled through privacy@grillisecurity.com.
13. Automated Decision-Making
We do not carry out automated decision-making, including profiling, that produces legal effects or similarly significantly affects individuals (Art. 22 GDPR). No personal data submitted through this website is used for automated scoring, profiling, or algorithmic decisions.
Provision of personal data through our contact, quote, and booking forms is voluntary. You are not legally or contractually required to submit it. The consequence of not providing required fields is that we may be unable to respond, quote, or process a booking request ( Art. 13(2)(e) GDPR). An unsubscribe request requires an email address so we can locate and suppress the relevant outreach record.
14. Changes to This Policy
We may update this policy to reflect changes in our practices or applicable law. Material changes will be indicated by a revised effective date at the top of this page. We encourage you to review this policy periodically.
Continued use of the website after a material change constitutes acceptance of the updated policy.
Contact
Data protection enquiries and rights requests: privacy@grillisecurity.com. See also our Website Data Processing Notice, Subprocessors, and Terms of Service.
