Privacy Policy

Last updated: 19 October 2025
Company: Grovi Media Ltd (“Grovi Media”, “we”, “us”, “our”)
Contact for privacy: [email protected]

Grovi Media builds, ranks, and operates private, SEO-driven websites that generate enquiries (“Leads”) for local service businesses (“Partners”). We respect your privacy and handle personal data in line with the UK GDPR, Data Protection Act 2018, PECR, and, where relevant, US TCPA and CAN-SPAM.

If anything here is unclear, email [email protected].

1) Who this policy applies to

  • Website visitors to https://grovimedia.com/
  • Enquirers/Leads who call us or submit a form on our properties.
  • Partners & prospects who discuss or enter into lead-supply relationships.
  • Vendors/contractors who provide services to us.

2) Personal data we collect

We only collect what we need to operate our services, optimise performance, and meet legal obligations.

2.1 Website & analytics

  • Technical data: IP address, user-agent, device/OS/browser, pages viewed, timestamps, referrer, approximate location.
  • Cookies/trackers: see Cookies & similar tech below.

2.2 Enquiry forms (Leads)

  • Identity & contact: name, email, phone.
  • Service info: requested service, location/area, timing/notes.
  • Metadata: form timestamp, page URL, IP/country, UTM parameters.
  • Consent signals (checkboxes, preferences).

2.3 Calls (Leads)

  • Call metadata: caller number, destination number, date/time, duration.
  • Transcripts or summaries (where enabled).

2.4 Partners & prospects

  • Identity & contact: name, company, role, email, phone.
  • Commercial data: sector, geographies, capacity, pricing, contracts, billing.
  • Communications history: emails, proposals, NDAs, notes.

2.5 Vendors/contractors

  • Identity & contact, contractual/payment details, and compliance documentation.

We do not intentionally collect special category data (e.g., health, religion) or data of children. See Children below.

3) Why we use your data (purposes) & lawful bases

PurposeExamplesLegal basis
Provide and improve our websitesRouting, performance, security, debugging, analyticsLegitimate interests (operate secure, useful sites)
Handle enquiries and deliver LeadsProcess forms/calls; match to a suitable PartnerLegitimate interests (connect consumers with services); Consent (where required)
Record & quality-assure callsVerify Lead quality; resolve disputes; trainingLegitimate interests; Legal obligation (where applicable)
Partner onboarding & performanceNDAs, contracts, billing, reportingContract; Legitimate interests
Marketing to Partners/prospectsEmails about services, capacity checksConsent or Legitimate interests (B2B soft opt-in; opt-out anytime)
Compliance & enforcementRespond to rights requests; prevent fraudLegal obligation; Legitimate interests

Where we rely on consent, you can withdraw it at any time (see Your rights).

4) Cookies & similar technologies

We use cookies/SDKs to operate our sites and understand performance.

Categories we use:

  • Strictly necessary: security, load balancing, consent storage.
  • Analytics: aggregated usage (e.g., page views, conversions).
  • Functional: remember preferences (e.g., region).
  • Marketing/attribution: measure which channels drive enquiries.

You can manage preferences via our Cookie Preferences tool at any time
Browser settings can also block cookies, but essential features may break.

5) Call tracking & recording

Our phone numbers play a short consent message before connection. If you continue, you agree to recording for quality, verification, and dispute resolution. If you object, please end the call and contact us via email or form instead.

  • Recordings and metadata are stored securely by our telephony providers (see Processors).
  • Retention is limited (see Retention).
  • We may share specific clips with a Partner solely to validate Lead quality.

US callers: We follow one-party or all-party consent requirements depending on state. Our universal consent message is designed to meet varying laws, but please do not proceed if you object.

6) When we share data

We do not sell personal data. We share data only as needed:

  • With Partners (Lead delivery): If you submit a form or call about a service, we may share your enquiry with a vetted Partner that can help in your area.
  • With processors/vendors: Hosting, analytics, security, telephony, CRM, payments, and support tools under contract (see Processors).
  • With authorities: If required by law or to protect rights/safety.
  • Business changes: In a merger, acquisition, or asset transfer, data may transfer under equivalent safeguards.

7) International transfers

We are UK-based but use global vendors. Where data is transferred outside the UK/EEA, we use lawful safeguards such as the UK International Data Transfer Addendum and/or Standard Contractual Clauses (SCCs), plus vendor risk assessments and technical controls.

8) Security

We apply a layered approach: HTTPS, reputable hosting, firewalls/CDN, access controls, MFA, least-privilege, encryption in transit, and vendor diligence. No system is perfectly secure; we monitor and improve continuously.

9) Retention

We keep data only as long as necessary:

  • Web logs/analytics: typically 6–24 months (aggregated thereafter).
  • Forms/Leads: typically 12–24 months for verification and performance analysis.
  • Metadata: typically 3–12 months (clips retained longer if needed for a dispute).
  • Contracts/billing: 6–7 years to meet legal/tax obligations.

We may anonymise data for long-term statistics.

10) Your privacy rights (UK/EU & similar regimes)

You can:

  • Request access to your data and a copy
  • Ask for correction (rectification) or deletion (erasure)
  • Ask us to restrict or object to certain processing
  • Request data portability
  • Withdraw consent where used

To exercise rights, email [email protected]. We may need to verify your identity.

UK complaints: You can contact the ICO (ico.org.uk). We’d appreciate the chance to resolve concerns first.

11) US notices (TCPA/CAN-SPAM/State laws)

If you provide your phone number, you consent (where required) to be contacted regarding your enquiry by call or SMS (carrier rates may apply). You can opt out anytime by replying STOP to SMS or by telling us or the Partner on a call.

For marketing emails, we include an unsubscribe link.
If you are a California resident and believe CPRA applies, contact us to exercise access/deletion/opt-out of “sale/share” requests. We do not sell data in the common sense and do not use sensitive personal information for inferring characteristics.

12) Children

Our services are aimed at adults. We do not knowingly collect data from anyone under 18. If you believe a minor has provided data, contact [email protected] and we will act promptly.

13) Automated decision-making

We do not make decisions producing legal or similarly significant effects solely by automated means. We may use scoring/rules to route Leads, followed by human review.

14) Processors & categories of recipients

We use reputable providers under data-processing agreements. Typical categories include:

  • Hosting & CDN/Security: e.g., cloud hosting, Cloudflare
  • Analytics & diagnostics: e.g., Google Analytics/GA4, error logging
  • Telephony & call recording: e.g., Twilio / CallRail or similar
  • CRMs/spreadsheets/databases: e.g., HubSpot/Pipedrive, Google Workspace, Airtable/BigQuery
  • Payment & invoicing (Partners): e.g., Stripe, accounting platforms
  • Automation: e.g., Zapier/Make
  • Email & support: e.g., transactional email services

On request, and subject to confidentiality, we can share a current list of sub-processors.

15) Controller vs processor roles

  • For website visitors and our portfolio sites, Grovi Media is the controller.
  • For Lead delivery, Grovi Media is typically the controller up to the point of sharing with a Partner. The Partner becomes an independent controller of the Lead they receive and should provide their own privacy information.
  • Where we process Partner personnel data (e.g., within a CRM on their behalf), we may act as a processor under a Data Processing Addendum.

16) Marketing preferences

  • Email (B2B): We may contact relevant Partner prospects on a legitimate-interest basis; you can opt out at any time.
  • SMS/calls: Only with appropriate consent where required; opt-out available.
  • We do not use consumer Leads for unrelated marketing.

17) How to contact us

Email: [email protected]
We aim to respond within 48 hours.

18) Changes to this policy

We may update this policy to reflect changes in law or our services. We’ll post the new version with a new “Last updated” date. Material changes may be notified on-site or by email where appropriate.