Privacy Policy
GroBird is committed to protecting the privacy of our clients, contacts, and website visitors. This policy describes how we collect, use, and protect personal information.
Information We Collect
We collect information in connection with our services, our website, and our business relationships. The categories of information we may collect include:
Information you provide directly
Contact information (name, email address, phone number, job title, organization name)
Business information provided in the course of scoping or delivering services
Communications you send us via email, contact forms, or other channels
Account credentials for platforms we access on your behalf under a service agreement
Information collected automatically
Website usage data including pages visited, time on site, and referring URLs
Device information including browser type, operating system, and IP address
Cookies and similar tracking technologies (see Section 07)
Information from third parties
We may receive information about you from business partners, publicly available sources, and data enrichment providers, which we use to better understand our prospective and current clients.
How We Use Information
We use the information we collect to:
Deliver, operate, and improve our services
Communicate with you about your engagement, support requests, and service updates
Send relevant business communications and, where permitted, marketing about our services
Generate anonymized, aggregated insights about operations and industry trends
Comply with legal obligations and enforce our agreements
Protect the security and integrity of our systems and services
We do not sell personal information to third parties. We do not use personal information for automated decision-making that produces legal or similarly significant effects.
Our legal basis for processing personal data (where applicable under GDPR or similar frameworks) is typically: (a) performance of a contract; (b) legitimate interests; or (c) your consent where explicitly requested.
Information Sharing
We do not sell, trade, or rent personal information. We may share information in the following limited circumstances:
Service providers
We engage trusted third-party vendors to support our operations — including cloud hosting, communication tools, analytics platforms, and payment processors. These vendors are contractually bound to process data only as directed by us and under appropriate security standards.
Business transfers
In the event of a merger, acquisition, or sale of assets, client data may be transferred as part of that transaction. We will provide notice before personal information is transferred and becomes subject to a different privacy policy.
Legal requirements
We may disclose information when required by law, court order, or government authority, or when we believe in good faith that disclosure is necessary to protect the rights, property, or safety of GroBird, our clients, or others.
Data Security
We implement industry-standard technical and organizational measures to protect personal information from unauthorized access, disclosure, alteration, and destruction. These measures include:
Encryption of data in transit using TLS 1.2 or higher
Encryption of sensitive data at rest
Access controls and role-based permissions for internal systems
Regular security assessments and vulnerability reviews
Employee training on data handling and security practices
Despite these measures, no security system is impenetrable. We cannot guarantee the absolute security of information transmitted over the internet. In the event of a data breach that affects your personal information, we will notify you as required by applicable law.
If you suspect any unauthorized access to or misuse of your information, contact us immediately at security@grobird.io.
Data Retention
We retain personal information for as long as necessary to fulfill the purposes for which it was collected, to comply with our legal obligations, and to resolve disputes or enforce our agreements.
Specifically:
Client engagement data is retained for the duration of the contract plus seven (7) years for legal and accounting purposes
Marketing contact data is retained until you opt out or request deletion
Website analytics data is retained for up to twenty-four (24) months
Communications are retained for five (5) years unless otherwise required
When retention periods expire, data is securely deleted or anonymized so it can no longer be associated with an individual.
Your Rights
Depending on your location, you may have certain rights regarding your personal information. These may include:
Access: Request a copy of the personal information we hold about you
Correction: Request correction of inaccurate or incomplete information
Deletion: Request deletion of your personal information (subject to legal retention obligations)
Portability: Receive your data in a structured, machine-readable format
Objection: Object to processing based on legitimate interests
Restriction: Request restriction of processing in certain circumstances
Opt-out of marketing: Unsubscribe from marketing communications at any time
To exercise any of these rights, contact us at privacy@grobird.io. We will respond within 30 days. We may need to verify your identity before fulfilling a request.
Third-Party Services
Our website and services may contain links to or integrations with third-party platforms and tools. This Privacy Policy does not apply to third-party services. We encourage you to review the privacy policies of any third-party services you access through our platform.
Current third-party services we work with include (but are not limited to) cloud infrastructure providers, CRM platforms, analytics services, and payment processors. Each is governed by their own privacy terms and data processing agreements with GroBird.
International Transfers
GroBird operates globally and may transfer personal information across international borders. When we transfer personal data from the European Economic Area (EEA), United Kingdom, or Switzerland, we use appropriate safeguards such as:
Standard Contractual Clauses (SCCs) approved by the European Commission
Adequacy decisions where the receiving country is deemed to provide adequate data protection
Binding Corporate Rules where applicable
If you have questions about the safeguards we use for international data transfers, contact us at privacy@grobird.io.
Changes to Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other reasons. When we make material changes, we will notify you by:
Posting a prominent notice on our website prior to the change becoming effective
Sending an email to clients and contacts for whom we have an email address
Your continued use of our services or website after changes take effect constitutes acceptance of the revised policy.
Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
General privacy inquiries
privacy@grobird.ioData security concerns
security@grobird.ioLegal & compliance
legal@grobird.ioSubject access requests
privacy@grobird.ioResponse time commitment
We respond to all privacy inquiries within thirty (30) days. For urgent matters related to data security or potential breaches, we aim to respond within 48 hours.

