Skip to content
Available. Now booking select projects for Q4 - Talk to us →
Hire us

Legal

GDPR & Data Protection

Last updated 9 September 2026

Contents

  • Our role
  • The agreement we work under
  • Sub-processors
  • International transfers
  • Security
  • Personal data breaches
  • Data subject requests
  • Return and deletion
  • Artificial intelligence
  • ICO registration
  • Documents we can provide
  • Complaints
  • Company information

This page sets out how Grid Design handles personal data on behalf of clients, and answers the questions a legal, procurement or information security team usually asks before appointing us.

If you are looking for what we do with your own information when you contact us, that is in our Privacy & Cookies notice.

Our role

For our own business — enquiries, client relationships, invoicing, recruitment — we are a data controller.

For client work, we are a data processor. The client decides what personal data is processed and why; we act on their documented instructions. In practice we design against anonymised, pseudonymised or synthetic data wherever it is practicable, and we do not ask for live personal data unless the work genuinely requires it.

The agreement we work under

We provide a Data Processing Agreement written to Article 28 of the UK GDPR. It is offered alongside our Terms of Business at the start of an engagement, and we are equally happy to sign yours.

The agreement carries three annexes: the processing details, the security measures, and the approved sub-processors. Ask for the current version at dataprotection@griddesign.co.uk.

Sub-processors

We keep the list short, and we name it before anybody processes your data:

  • Google Ireland Ltd / Google LLC — email, file storage, documents, calendar
  • Figma, Inc. — design files, prototypes and design collaboration
  • Notion Labs, Inc. — project documentation and delivery notes
  • Slack Technologies (Salesforce, Inc.) — project communication with clients
  • Specialist subcontractors — development, design, research and testing, where an engagement requires it
  • Project hosting provider — as specified in the Statement of Work

Not all of these are used on every engagement. Subcontractors vary by project; they work under written confidentiality and data protection terms, their access is limited to what the task requires and revoked on completion, and they are named to the client before they process any of the client's personal data.

International transfers

Our primary data locations are the United Kingdom and the EEA. Where a named US sub-processor is involved, the transfer is covered by the EU Standard Contractual Clauses with the UK Addendum. Google's EEA processing is covered by UK adequacy.

Security

  • Multi-factor authentication on email, cloud storage, design tooling and hosting
  • Least-privilege access, revoked the day an engagement ends
  • A managed password manager
  • Encryption in transit and at rest in our managed cloud services
  • Written confidentiality and data protection terms with every subcontractor

The full detail is at Annex 2 of the Data Processing Agreement.

Personal data breaches

We notify the client within 24 hours of becoming aware of a personal data breach affecting their data, with what we know at that point, and we keep them updated as we learn more. Our security incident contact is dataprotection@griddesign.co.uk and +44 (0)20 8050 0556.

Data subject requests

If a data subject contacts us about data we hold for a client, we pass the request to that client within 2 working days. We do not respond substantively on the client's behalf, because it is the client's decision to make. We assist with the response where we are asked to.

Return and deletion

At the end of an engagement, or on request at any time, we return or delete the client's personal data. Backups containing it expire within 90 days.

Artificial intelligence

We do not submit client confidential information or personal data to an AI tool without the client's prior written agreement. Where AI tooling is agreed, we confirm which tools are in use and that model training on our inputs is disabled. All AI-assisted output is reviewed by a person before delivery.

ICO registration

Grid Design Agency Limited is registered with the Information Commissioner's Office as a data controller, Tier 1, with the annual fee paid by direct debit. The registration number is available on request.

Documents we can provide

  • Terms of Business
  • Data Processing Agreement, with all three annexes
  • Supplier Information Sheet, for vendor onboarding
  • Certificate of insurance
  • A signed copy of your own NDA or DPA, if you would rather use yours

Request any of these from hello@griddesign.co.uk.

Complaints

We operate a documented data protection complaints procedure and respond within one calendar month. Raise anything at dataprotection@griddesign.co.uk.

You may also complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint or on 0303 123 1113.

Company information

Registered name
Grid Design Agency Limited
Trading as
Grid Design
Registered in
England and Wales
Company number
14577642
VAT number
445 8819 53
Registered office
124 City Road, London, EC1V 2NX, United Kingdom
Email
hello@griddesign.co.uk
Telephone
+44 (0)20 8050 0556
See grid

We design for founders, brands & digital products

WorkServicesPeopleContactInsights
LinkedinInstagram
New Business
hello@griddesign.co.uk
Careers
careers@griddesign.co.uk
Phone
+44 20 8050 0556
Recognition
Awwwards
London (HQ)
124 City Rd, London, England, EC1V 2NX
Toronto (Remote)
5063 North Service Rd, Burlington, ON L7L 5H6
Fully RemoteSy CramptonChloe McNeillEd HatwellHannah Mitchell
The right person, not the nearest
<div class="payload-richtext">

© 2026 Grid Design Agency Ltd.

</div>
Privacy & CookiesT&CsAccessibilityGDPRClient Suitability Policy