Legal

Privacy Policy

How we collect, use, and protect your personal information — and your rights under UK, EU, Swiss and US law.

Last updated: 23 July 2026

This Privacy Policy explains how Greytek ("Greytek", "we", "us", "our"), a company registered in Italy, collects, uses and protects your personal data when you use our website or submit an enquiry through our contact form.

We are committed to protecting your privacy and handling your data in compliance with:

  • UK the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018
  • EU/EEA EU Regulation 2016/679 (GDPR), and the equivalent national data protection laws of EU/EEA member states — including, since we are based there, Italy's D.Lgs. 196/2003 as amended by D.Lgs. 101/2018 (Codice Privacy)
  • Switzerland the revised Swiss Federal Act on Data Protection (FADP)
  • US the California Consumer Privacy Act (CCPA) as amended by the CPRA, and applicable US federal and state privacy laws

Our contact form also accepts enquiries from a number of other countries. Wherever you are contacting us from, we apply the same core protections described in this policy — see Section 9 for details.


1. Who We Are (Data Controller)

The data controller responsible for your personal information is:

For any privacy-related queries, please contact us at [email protected].


2. What Personal Data We Collect

We only collect personal data that you voluntarily provide to us through our contact form. This includes:

  • Name — your first and last name
  • Email address
  • Phone number — including your country dialling code
  • Service of interest — the service you have selected from our dropdown menu
  • Message — the content of your enquiry

We do not collect sensitive (special category) personal data, and we do not collect data from minors under the age of 18. If you believe a minor has submitted data to us, please contact us and we will delete it promptly.


3. How We Use Your Data

We use the information you provide solely to:

  • Respond to your enquiry and provide information about our services
  • Follow up on your request and manage our ongoing business relationship with you
  • Keep a record of communications for our legitimate business operations

We do not use your data for automated decision-making or profiling, and we do not sell, rent, or trade your personal data to any third party.


4. Legal Basis for Processing

UK EU/EEA Under UK GDPR and EU GDPR, we rely on the following legal bases:

  • Article 6(1)(b) — processing is necessary for steps taken at your request prior to entering into a contract (i.e., responding to your service enquiry)
  • Article 6(1)(f) — processing is necessary for our legitimate interests in managing and responding to business enquiries, provided those interests are not overridden by your rights and freedoms

Switzerland Under the Swiss FADP, we rely on the same grounds: processing necessary to respond to your enquiry, and our legitimate interest in managing business communications.

US For residents of California and other US states: we collect your information because you have provided it voluntarily when submitting a contact enquiry. We do not sell or share personal information as defined under the CCPA/CPRA.

If you are contacting us from a country not specifically named above, we still process your data on the same basis — because you asked us to, in order to respond to your enquiry, or because we have a legitimate interest in managing our business communications.


5. Data Retention

We retain the personal data in your enquiry (name, email, phone number and message) for up to 3 years from the date you submitted it. This period is enforced automatically: after 3 years, your personal details are permanently anonymised — irreversibly removed from the record — while we keep a small amount of non-identifying data (such as the enquiry type, service requested, and date received) for internal reporting on enquiry volumes. Once anonymised, a record can no longer be linked back to you.

If your enquiry leads to a business relationship with us, any separate records we hold for that relationship — such as signed agreements, invoices, and accounting records — are retained for as long as required by Italian and EU accounting and tax law (typically 7 years), independently of the enquiry data described above.


6. Who We Share Your Data With

We do not sell, rent or otherwise disclose your personal data to third parties for marketing purposes. We may share your data with:

  • Email service providers — used solely to deliver and manage enquiry communications (e.g., transactional email infrastructure). These providers act as data processors under a data processing agreement and are only permitted to use your data on our instructions.
  • Cloudflare, Inc. — we use Cloudflare Turnstile on our contact and enquiry forms to detect and block automated spam and abuse. Turnstile processes limited technical data (such as your IP address and browser signals) to verify you are not a bot. This is strictly necessary for the security of our forms and does not require consent.
  • Google LLC — where enabled, we use Google Analytics / Google Tag Manager to understand how visitors use our site. This only runs, and only sets analytics cookies, if you click "Accept All" on our cookie banner — see Section 8 below.
  • Legal or regulatory authorities — where required by applicable law, court order, or to protect our rights.

Any third-party processors we engage are required to provide sufficient guarantees about their technical and organisational security measures, and are bound by contract to process data only on our instructions. Where a processor is based outside the UK/EEA (such as Google or Cloudflare, both US-based), transfers are made under an appropriate safeguard, such as the EU Standard Contractual Clauses or an equivalent UK mechanism.


7. International Data Transfers

Our business is based in Italy (EU/EEA). If you are contacting us from the UK, your data may transfer to the EU under the UK–EU adequacy decision. If you are contacting us from Switzerland, your data may transfer to the EU under the mutual EU–Switzerland adequacy recognition. If you are contacting us from the United States or another country outside the EEA/Switzerland, your data will be received and processed in Italy (EU), which is widely recognised as providing an adequate level of data protection.

We take appropriate steps to ensure that any international transfers comply with applicable data protection law.


8. Cookies

Our website uses a cookie consent banner that allows you to accept or reject non-essential cookies. We only set non-essential cookies (e.g., analytics) if you explicitly accept them. Strictly necessary cookies (such as session security cookies and our anti-spam check) are always active, as they do not require consent under UK/EU cookie law (PECR / ePrivacy).

You can withdraw your consent at any time by clearing your cookies in your browser settings. The banner will reappear on your next visit, allowing you to make a new choice.


9. Your Rights

Depending on where you are located, you have the following rights regarding your personal data:

UK EU/EEA Right of Access

You have the right to request a copy of the personal data we hold about you and information about how we use it.

UK EU/EEA Right to Rectification

You have the right to ask us to correct inaccurate or incomplete personal data we hold about you.

UK EU/EEA US Right to Erasure ("Right to be Forgotten")

You can ask us to delete your personal data where there is no compelling reason for us to continue holding it. California residents also have this right under the CCPA.

UK EU/EEA Right to Restriction of Processing

You can ask us to restrict the processing of your data in certain circumstances — for example, while we are verifying the accuracy of data you have contested.

UK EU/EEA Right to Data Portability

You have the right to receive the personal data you provided to us in a structured, commonly used and machine-readable format, and to transmit it to another controller where technically feasible.

UK EU/EEA Right to Object

You have the right to object at any time to processing of your personal data based on our legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms.

US Right to Know

California residents have the right to know what personal information we collect, the purposes for which it is used, and whether it is disclosed to third parties.

US Right to Opt Out of Sale

We do not sell or share personal information as defined under the CCPA/CPRA. There is nothing to opt out of, but you may contact us to confirm this.

US Right to Non-Discrimination

We will not discriminate against you for exercising any of your privacy rights. Exercising your rights will not affect the quality of service you receive from us.

Switzerland Your rights under the FADP

Swiss residents have broadly equivalent rights to access, correct, and request deletion of their personal data, and to object to processing, under the revised Federal Act on Data Protection.

Contacting us from another country

Our contact form accepts enquiries from a number of countries not listed individually above. Wherever you are contacting us from, we apply the same core protections described in this policy — you can ask us what data we hold about you, ask us to correct it, or ask us to delete it — and we will honour your request in line with your local law where applicable.

To exercise any of these rights, please contact us at [email protected]. We will respond within 30 days (or 45 days for CCPA requests where permitted). We may need to verify your identity before processing your request.


10. How to Complain

If you are unhappy with how we have handled your personal data, please contact us first at [email protected] so we can try to resolve your concern.

You also have the right to lodge a complaint with the relevant supervisory authority:

UK Information Commissioner's Office (ICO)

Italy Garante per la protezione dei dati personali

EU/EEA Other EU/EEA countries

If you are located in an EU/EEA country other than Italy, you have the right to lodge a complaint with your own national data protection authority instead of (or as well as) the Garante. The European Data Protection Board maintains a directory of national authorities:

Switzerland Federal Data Protection and Information Commissioner (FDPIC)

US California residents

Other countries

If you are located elsewhere, please contact us first at [email protected] — we will do our best to resolve your concern directly. You may also be able to lodge a complaint with your own country's data protection or consumer protection authority, where one exists.


11. Security

We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, destruction or alteration. Our website uses HTTPS encryption for all data transmitted between your browser and our servers. Access to your personal data is restricted to authorised personnel who need it to handle your enquiry.

No method of transmission over the internet is 100% secure. If you have concerns about the security of your data, please contact us.


12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in the law or our practices. When we do, we will update the "Last updated" date at the top of this page. We encourage you to review this policy periodically. Continued use of our website after any changes constitutes your acknowledgement of the updated policy.


13. Contact Us

If you have any questions about this Privacy Policy or how we handle your personal data, please contact us: