
PRIVACY NOTICE
Last updated October 6th, 2025
This privacy notice for Gridraven OÜ (hereinafter “Gridraven”, "we," "us," or "our"), describes how and why we might collect, store, use, and/or share (hereinafter "process") your information when you use our services (“Services”), such as when you:
Gridraven is a business-to-business (B2B) company. This means our Services are targeted at other companies. This privacy notice explains how we process the personal data of the contact persons of our clients, potential clients, and website visitors (hereinafter “you”).
Questions or concerns? Reading this privacy notice will help you understand your privacy rights and choices. If you do not agree with our policies and practices, please do not use our Services. If you still have any questions or concerns, please contact us at [INSERT E-MAIL].
Definitions
For a better understanding, we hereby explain some data protection terms used herein.
GDPR means the General Data Protection Regulation (EU) 2016/679), implementation of which started on 25 May 2018 and which is directly applicable in all European Union member states.
Personal data means any information relating to an identified or identifiable natural person (data subject); an identifiable natural person is one who can be identified, directly or indirectly, by a name, an identification number, location data, an online identifier or by one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Processing means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Controller means the entity that decides why and how the personal data is processed.
Processor means the entity which processes personal data on behalf of the controller.
Gridraven OÜ
Registration code: 16819721
Address: Telliskivi tn 57b/1, 10412, Estonia
E-mail: support@gridraven.com
When you contact us via the contact form on our website you provide us with your name and e-mail, in the message box you may reveal some other information, such as the name of the company you are representing. As said above, we are a B2B business, hence we primarily use your personal data to communicate with the company you are representing, and we assume that the personal data you share (e.g. your e-mail) is for professional communication.
When you visit our website, we may use cookies and similar tracking technologies (like web beacons and pixels) to access or store information. Specific information about how we use such technologies and how you can consent to the use and refuse of certain cookies is set out in our Cookie Notice: https://www.gridraven.com/cookies.
We mainly use your personal data for communicating (e.g. answering website inquiries) with the client/potential client/business partner you represent.
The legal basis for doing this is our legitimate interest (GDPR. Art.6 (1)(a)) –we need to communicate with the legal person and if you act as representative of one, we assume that there is a balance of interest and we do not conflict with your interests, rights and freedoms.
For use of certain website cookies and similar tracking technologies we also ask for your consent (GDPR. Art.6 (1)(f)).
If you represent an existing client, or if you have provided us with your professional contact details when inquiring about our Services, we may send you marketing communications by e-mail. These communications will be relevant to your professional interests and concern our similar products or services. We process your personal data for this purpose based on our legitimate interest (GDPR. Art.6 (1)(f)) to develop our business relationship and keep you informed of our offerings. You have the right to opt out of receiving these communications at any time by clicking the "unsubscribe" link provided in every e-mail.
Your personal data is accessible to our employees on a need-to-know basis. We may also share your information with the following categories of third parties:
International Transfers
Your information is primarily processed within the European Economic Area (EEA). If we transfer your personal data to a service provider outside the EEA, we will ensure that the transfer is lawful and that your data is protected by implementing appropriate safeguards, such as Standard Contractual Clauses (SCCs) approved by the European Commission.
We will only keep your personal information for as long as it is necessary for the purposes set out in this privacy notice, unless a longer retention period is required or permitted by law (such as tax, accounting, or other legal requirements).
When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymize it.
Rights under GDPR
Right to access – you have the right to know which data we hold about you (if any).
Right to data rectification – you have the right to require corrections to your personal data in case they are inaccurate or incomplete.
Right to data deletion – you have the right under certain conditions to request the deletion of your personal data including in situations where the processing of your personal data is no longer necessary for the purposes for which it was collected, or if the processing of your personal data was based on your consent and you wish to withdraw your consent, and there are no other grounds for processing your personal data.
Right to restrict processing – you have the right under certain circumstances to forbid or restrict the processing of your personal data for a certain period (e.g. you have submitted an objection concerning data processing).
Right to object – You have the right to object to data processing which is based on our legitimate interest. We will stop processing your personal data upon such objection, unless we can demonstrate compelling legitimate grounds for the processing or processing is needed for the establishment, exercise, or defense of legal claims. You also have the right to object at any time to processing of your personal data for direct marketing. Upon receiving such objection, we shall stop processing your personal data for direct marketing.
Additional rights under CCPA
If you are a resident of California, you are granted specific rights regarding your personal information.
Right to Know: You have the right to request that we disclose what personal information we collect, use, disclose, and sell about you over the past 12 months.
Right to Delete: You have the right to request the deletion of your personal information, subject to certain exceptions.
Right to Opt-Out of Sale or Sharing: We do not sell or share personal information, so there is no need to opt out.
Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights.
"Shine the Light" Law: California Civil Code Section 1798.83 permits users who are California residents to request and obtain from us, once a year and free of charge, information about categories of personal information (if any) we disclosed to third parties for their direct marketing purposes. However, we do not share your personal information with third parties for their own direct marketing purposes.
To exercise any of your rights, please contact us at support@gridraven.com.
We will need to verify your identity before processing your request. We will respond to your request within the timeframe required by law (typically within 30 days for GDPR and 45 days for CCPA).
You may also designate an authorized agent to make a request on your behalf. We will require written proof that you have designated the agent and will also need to verify your own identity directly with us.
Should you desire further information concerning your personal data or exercising your rights, you have the possibility to contact us at support@gridraven.com
If you believe that the processing of your personal data breaches the requirements of the GDPR, you have the right, without prejudice to any other administrative or judicial remedy, to file a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement. In Estonia, the relevant supervisory authority is Data Protection Inspectorate (Andmekaitse Inspektsioon).
We may update this privacy notice from time to time. The updated version will be indicated by a revised "Last updated" date. We encourage you to review this privacy notice frequently to be informed of how we are protecting your information.