Legal
GDPR & Data Protection
Last updated
This page sets out how Grid Design handles personal data on behalf of clients, and answers the questions a legal, procurement or information security team usually asks before appointing us.
If you are looking for what we do with your own information when you contact us, that is in our Privacy & Cookies notice.
Our role
For our own business — enquiries, client relationships, invoicing, recruitment — we are a data controller.
For client work, we are a data processor. The client decides what personal data is processed and why; we act on their documented instructions. In practice we design against anonymised, pseudonymised or synthetic data wherever it is practicable, and we do not ask for live personal data unless the work genuinely requires it.
The agreement we work under
We provide a Data Processing Agreement written to Article 28 of the UK GDPR. It is offered alongside our Terms of Business at the start of an engagement, and we are equally happy to sign yours.
The agreement carries three annexes: the processing details, the security measures, and the approved sub-processors. Ask for the current version at dataprotection@griddesign.co.uk.
Sub-processors
We keep the list short, and we name it before anybody processes your data:
- Google Ireland Ltd / Google LLC — email, file storage, documents, calendar
- Figma, Inc. — design files, prototypes and design collaboration
- Notion Labs, Inc. — project documentation and delivery notes
- Slack Technologies (Salesforce, Inc.) — project communication with clients
- Specialist subcontractors — development, design, research and testing, where an engagement requires it
- Project hosting provider — as specified in the Statement of Work
Not all of these are used on every engagement. Subcontractors vary by project; they work under written confidentiality and data protection terms, their access is limited to what the task requires and revoked on completion, and they are named to the client before they process any of the client's personal data.
International transfers
Our primary data locations are the United Kingdom and the EEA. Where a named US sub-processor is involved, the transfer is covered by the EU Standard Contractual Clauses with the UK Addendum. Google's EEA processing is covered by UK adequacy.
Security
- Multi-factor authentication on email, cloud storage, design tooling and hosting
- Least-privilege access, revoked the day an engagement ends
- A managed password manager
- Encryption in transit and at rest in our managed cloud services
- Written confidentiality and data protection terms with every subcontractor
The full detail is at Annex 2 of the Data Processing Agreement.
Personal data breaches
We notify the client within 24 hours of becoming aware of a personal data breach affecting their data, with what we know at that point, and we keep them updated as we learn more. Our security incident contact is dataprotection@griddesign.co.uk and +44 (0)20 8050 0556.
Data subject requests
If a data subject contacts us about data we hold for a client, we pass the request to that client within 2 working days. We do not respond substantively on the client's behalf, because it is the client's decision to make. We assist with the response where we are asked to.
Return and deletion
At the end of an engagement, or on request at any time, we return or delete the client's personal data. Backups containing it expire within 90 days.
Artificial intelligence
We do not submit client confidential information or personal data to an AI tool without the client's prior written agreement. Where AI tooling is agreed, we confirm which tools are in use and that model training on our inputs is disabled. All AI-assisted output is reviewed by a person before delivery.
ICO registration
Grid Design Agency Limited is registered with the Information Commissioner's Office as a data controller, Tier 1, with the annual fee paid by direct debit. The registration number is available on request.
Documents we can provide
- Terms of Business
- Data Processing Agreement, with all three annexes
- Supplier Information Sheet, for vendor onboarding
- Certificate of insurance
- A signed copy of your own NDA or DPA, if you would rather use yours
Request any of these from hello@griddesign.co.uk.
Complaints
We operate a documented data protection complaints procedure and respond within one calendar month. Raise anything at dataprotection@griddesign.co.uk.
You may also complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint or on 0303 123 1113.
Company information
- Registered name
- Grid Design Agency Limited
- Trading as
- Grid Design
- Registered in
- England and Wales
- Company number
- 14577642
- VAT number
- 445 8819 53
- Registered office
- 124 City Road, London, EC1V 2NX, United Kingdom
- Telephone
- +44 (0)20 8050 0556