Privacy Policy and Cookies

This page explains how Grey Matters Consultancy uses personal data, how cookies and similar technologies operate on our website, and how you can manage your privacy and consent preferences. Our Privacy and Cookie information is managed using Complianz to help keep it up to date and compliant with UK data protection law.

You may also wish to read our Website Terms of Use, which govern use of this website, and our Terms & Conditions, which apply to the services we provide.

Privacy Policy

This privacy statement was last updated on 19 December 2025 and applies to citizens and legal permanent residents of the United Kingdom.

In this privacy statement, we explain what we do with the data we obtain about you via https://www.grey-matters-consultancy.com. We recommend you carefully read this statement. In our processing we comply with the requirements of privacy legislation. That means, among other things, that:

  • we clearly state the purposes for which we process personal data. We do this by means of this privacy statement;
  • we aim to limit our collection of personal data to only the personal data required for legitimate purposes;
  • we first request your explicit consent to process your personal data in cases requiring your consent;
  • we take appropriate security measures to protect your personal data and also require this from parties that process personal data on our behalf;
  • we respect your right to access your personal data or have it corrected or deleted, at your request.

If you have any questions, or want to know exactly what data we keep of you, please contact us.

1. Purpose, data and retention period

We may collect or receive personal information for a number of purposes connected with our business operations which may include the following: (click to expand)

2. Sharing with other parties

We only share or disclose this data to processors for the following purposes:

Processors

Name: Microsoft Corporation (Microsoft 365)
Country: United Kingdom / European Union
Purpose: Provision of email, calendars, document storage, internal communications and business records necessary for the operation of our services.
Name: Intuit Mailchimp
Country: United States
Purpose: Distribution of email communications and newsletters to subscribers who have provided consent.
Name: CRM Direct
Country: United Kingdom
Purpose: Client relationship management, case tracking, and secure storage of client records.
Name: Complianz
Country: European Union
Purpose: Client consent records

3. Cookies

Our website uses cookies. For more information about cookies, please refer to our Cookie Policy

4. Disclosure practices

We disclose personal information if we are required by law or by a court order, in response to a law enforcement agency, to the extent permitted under other provisions of law, to provide information, or for an investigation on a matter related to public safety.

If our website or organisation is taken over, sold, or involved in a merger or acquisition, your details may be disclosed to our advisers and any prospective purchasers and will be passed on to the new owners.

We have concluded a data processing agreement with Google.

5. Security

We are committed to the security of personal data. We take appropriate security measures to limit abuse of and unauthorised access to personal data. This ensures that only the necessary persons have access to your data, that access to the data is protected, and that our security measures are regularly reviewed.

6. Third-party websites

This privacy statement does not apply to third-party websites connected by links on our website. We cannot guarantee that these third parties handle your personal data in a reliable or secure manner. We recommend you read the privacy statements of these websites prior to making use of these websites.

7. Amendments to this privacy statement

We reserve the right to make amendments to this privacy statement. It is recommended that you consult this privacy statement regularly in order to be aware of any changes. In addition, we will actively inform you wherever possible.

8. Accessing and modifying your data

If you have any questions or want to know which personal data we have about you, please contact us. You can contact us by using the information below. You have the following rights:

  • You have the right to know why your personal data is needed, what will happen to it, and how long it will be retained for.
  • Right of access: You have the right to access your personal data that is known to us.
  • Right to rectification: you have the right to supplement, correct, have deleted or blocked your personal data whenever you wish.
  • If you give us your consent to process your data, you have the right to revoke that consent and to have your personal data deleted.
  • Right to transfer your data: you have the right to request all your personal data from the controller and transfer it in its entirety to another controller.
  • Right to object: you may object to the processing of your data. We comply with this, unless there are justified grounds for processing.

Please make sure to always clearly state who you are, so that we can be certain that we do not modify or delete any data of the wrong person.

9. Submitting a complaint

If you are not satisfied with the way in which we handle (a complaint about) the processing of your personal data, you have the right to submit a complaint to the Information Commissioner's Office:


Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF

10. Children

Our website is not designed to attract children and it is not our intent to collect personal data from children under the age of consent in their country of residence. We therefore request that children under the age of consent do not submit any personal data to us.

11. Contact details

Grey Matters Consultancy
136 Whyteladyes Lane, Cookham, Maidenhead, SL6 9LD
United Kingdom
Website: https://www.grey-matters-consultancy.com
Email: info@ex.comgrey-matters-consultancy.com
Phone number: 03301340166

Annex

Solid Security

What personal data we collect and why

Cookies

This website uses security-related cookies only in connection with login and account access. They are not used to track general browsing.

These cookies include:

Temporary cookies used when logging in via secure email links.

Cookies that support enhanced security checks during the login process.

A short-term cookie set when visiting the login page to ensure compatibility with alternative login methods.

All security cookies are temporary, expire automatically (within 30 minutes to 1 hour), and are used solely to protect user accounts.

Security logs

To protect the site from unauthorised access and malicious activity, we record limited information only when login-related or security-sensitive actions occur. This may include:

IP addresses

User IDs (for logged-in users)

Usernames used during login attempts

Logging occurs during events such as login attempts, logouts, suspicious requests, content changes, and password updates.
This information is not collected during normal browsing.

Security log data is retained for 60 days.

Who we share your data with

SolidWP services
Certain security features rely on services provided by SolidWP.

When setting up two-factor authentication, a QR code is generated using a SolidWP-hosted service. Your username is sent for this purpose only and is not stored.

The site may be scanned for malware and vulnerabilities. No personal data is deliberately sent, although publicly visible information (such as comments) may be detected during scanning.

To protect against distributed brute-force login attempts, the IP address of visitors attempting to log in may be shared with SolidWP’s security network.

WordPress.org and related services
To verify file integrity and updates, the site connects to WordPress.org and related services. These requests include technical information such as the WordPress version, site language, and installed plugin versions. No personal data is sent.

Amazon Web Services (AWS)
Some security resources are delivered via AWS as part of SolidWP’s infrastructure. No personal data is shared directly, and processing is covered by AWS data protection policies.

How long we retain your data

Security-related logs are retained for 60 days and then automatically deleted.


 

Cookie Policy