Our commitment to GDPR
Graftie is designed and operated in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This page summarises how we meet our obligations as a data controller.
Data controller
Robert Brewer, trading as Graftie, is the data controller for personal data processed through the Graftie platform. For all data protection queries:
Email: [email protected]
Data processing activities
- Purpose: Providing trade business management software (quoting, scheduling, invoicing, certificates, messaging)
- Categories of data: Name, email, company details, customer contacts, job/financial data, communications
- Legal basis: Contract (service provision), legal obligation (tax records), legitimate interest (security, service improvement, product analytics), consent (marketing communications)
- Recipients: Clerk (auth), Stripe (payments), OpenRouter (AI), Twilio (messaging), Resend (email), Vercel/Neon (hosting)
- Retention: Account data: 30 days after closure. Business data: 60 days after closure. Payment records: 6 years (legal requirement). Server logs: 90 days.
- International transfers: Some processors operate outside the UK/EEA. All transfers use appropriate safeguards (adequacy decisions or Standard Contractual Clauses).
Data subject rights
We facilitate the following rights for all users and their customers whose data is processed through the platform:
- Access (Art. 15): Users can export their data via the platform. Additional requests via email.
- Rectification (Art. 16): Users can edit their data at any time through the platform UI.
- Erasure (Art. 17): Users can delete their account, which triggers data deletion within 30-60 days.
- Restriction (Art. 18): Users can request processing restrictions via email.
- Portability (Art. 20): Users can export their data in CSV and JSON formats.
- Objection (Art. 21): Users can object to processing based on legitimate interests.
- Withdrawal of consent (Art. 7): Users can withdraw consent for optional processing at any time.
Security measures
- Multi-tenant data isolation — tenant ID enforced at database query level
- Encryption in transit (TLS 1.2+) and at rest (database-level encryption)
- Authentication via Clerk (no plaintext password storage)
- Payment data handled exclusively by Stripe (PCI DSS compliant)
- Rate limiting on API endpoints to prevent abuse
- Webhook signature verification (Stripe, Twilio, Resend)
- Security headers (CSP, X-Frame-Options, HSTS, X-Content-Type-Options)
- Regular dependency updates and security audits
Data breach procedure
In the event of a personal data breach, we will:
- Assess the breach within 24 hours of discovery
- Notify the ICO within 72 hours if the breach is likely to result in a risk to data subjects (Art. 33)
- Notify affected users without undue delay if the breach is likely to result in high risk (Art. 34)
- Document the breach, its effects, and remedial actions taken
Sub-processors
We use the following sub-processors. Users are notified of any new sub-processors before they are engaged:
- Clerk (USA) — Authentication
- Stripe (USA/Ireland) — Payment processing
- OpenRouter — AI model routing
- Twilio — SMS and WhatsApp messaging
- Resend — Transactional email
- Vercel — Web hosting
- Neon — PostgreSQL database hosting
Complaints
You have the right to lodge a complaint with the Information Commissioner's Office (ICO):
ico.org.uk | Phone: 0303 123 1113