Last updated: 19 July 2026
GripNews.uk (“GripNews”, “we”, “our”, “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our website and services, in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Data Controller
GripNews is the data controller for personal data collected through our website and services. For any data protection queries, contact us via the GripNews Dashboard.
2. What Data We Collect
Data you provide directly:
- Account information: Email address, username, and password when you register for a Dashboard account
- Contact information: Any details you provide when contacting us
- Newsletter subscriptions: Email address if you subscribe to our newsletter
Data collected automatically:
- Usage data: Pages visited, features used, timestamps, and referring URLs
- Device information: Browser type, operating system, screen resolution, and language preferences
- IP address: Used for security, analytics, and approximate geolocation
- Cookies: As described in our Cookie Policy
API usage data:
- API requests, endpoints accessed, and response times
- API key identifiers (not the keys themselves)
3. How We Use Your Data
We process your data under the following lawful bases (UK GDPR Article 6):
- Contract performance: To provide and maintain your account and services
- Legitimate interests: To improve our services, ensure security, and prevent fraud
- Consent: For newsletter communications and non-essential cookies
- Legal obligation: To comply with applicable laws and regulations
4. Data Sharing
We do not sell your personal data. We may share data with:
- Service providers: Hosting, analytics, and email services that help us operate (all bound by data processing agreements)
- Legal authorities: When required by law or to protect our rights
5. Data Retention
- Account data is retained while your account is active and for up to 12 months after deletion
- Usage analytics are retained in aggregated, anonymised form
- API logs are retained for 90 days for debugging and security purposes
6. Your Rights
Under UK GDPR, you have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase your data (“right to be forgotten”)
- Restrict processing of your data
- Data portability — receive your data in a structured format
- Object to processing based on legitimate interests
- Withdraw consent at any time for consent-based processing
To exercise any of these rights, contact us via the Dashboard. We will respond within 30 days.
7. Data Security
We implement appropriate technical and organisational measures to protect your data, including:
- SSL/TLS encryption on all connections
- Hashed and salted password storage
- Regular security monitoring via GripShield
- Access controls and audit logging
8. International Transfers
Your data is primarily processed within the UK and EEA. If data is transferred outside these regions, we ensure appropriate safeguards are in place as required by UK GDPR.
9. Children’s Privacy
Our Services are not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us immediately.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be posted on this page with a revised date. We encourage you to review this page periodically.
11. Complaints
If you are unsatisfied with how we handle your data, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk.