Who we are
Groundcuvva is run by BigThumb Digital Ltd, a company registered in England and Wales (company number 11489879), registered office Unit 8 The Courtyard, Gaulby Lane, Stoughton, Leicester, LE2 2FL. We are registered with the Information Commissioner’s Office (ICO) under number [ICO REGISTRATION NUMBER].
Questions about this notice or your personal data go to privacy@groundcuvva.com. We don’t have a statutory Data Protection Officer; the same address reaches the person responsible for data protection.
Two roles: controller and processor
We are the controller for the personal data we decide to collect to run our own business: people who visit groundcuvva.com, people who create or use a Groundcuvva account (for sign-in and account security), billing contacts, and anyone who writes to us. This notice covers that data.
We are a processor for everything our customers (garden and grounds maintenance companies) put into Groundcuvva about their own staff and clients: employee records, holidays and sickness, time-clock entries, visits, site notes and photos, certificates, incident reports and the like. The customer is the controller of that data and decides why it is held and for how long; we only handle it on their instructions under our data processing agreement. If you are an employee or a client of one of our customers, contact that company first: they can see, correct, export and delete your records. We will help them, and pass on any request we receive for their data.
What we collect, why, and on what basis
| Data | Why we use it | Lawful basis (UK GDPR Art. 6) |
|---|---|---|
| Account details: name, email address, password (stored only as a salted hash), company name and web address, company postcode | Create and run your account, sign you in, send the emails the service depends on (sign-in links, password resets, invitations, reminders) | Contract with you or your employer (6(1)(b)); for staff accounts created by an employer, our legitimate interest in operating the service they bought (6(1)(f)) |
| Sign-in and security data: session records, IP address, browser user agent, how you signed in, two-step sign-in settings, rate-limit counters | Keep accounts secure, stop brute-force and abuse, investigate incidents | Legitimate interests in securing the service (6(1)(f)); legal obligation to keep personal data secure (6(1)(c), Art. 32) |
| Google account identifier and email, if you choose “Continue with Google” | Sign you in without a separate password | Contract (6(1)(b)) |
| Billing contact name, email and billing address; subscription status. Card details are entered on Stripe’s pages and never reach us | Take payment, issue invoices, manage the subscription | Contract (6(1)(b)); legal obligation to keep accounting records (6(1)(c)) |
| Messages you send us and our replies | Answer questions and support requests | Legitimate interests in running our business (6(1)(f)) |
| Technical logs: requests to our servers (address without query strings, time, status, IP address, browser), errors | Keep the service running, detect and investigate security incidents | Legitimate interests (6(1)(f)) |
| Operator audit log: what our own staff did inside the admin area, with IP and browser | Accountability for staff access to customer accounts | Legitimate interests (6(1)(f)); legal obligation (Art. 5(2), 32) |
We don’t use analytics, advertising or tracking cookies, we don’t sell personal data, and we don’t make decisions about you by automated means that have legal or similarly significant effects. We only send marketing emails to business contacts who have asked for them or are existing customers, and every one has an unsubscribe link (PECR reg. 22).
How long we keep it
- Account and company data: for as long as the subscription runs. When a paid subscription ends we delete the company, its records and files 30 days later; a free trial that ends without a subscription is deleted 60 days after it ends. Owners are emailed a week before, and can export first or delete the company straight away from Settings.
- Unaccepted invitations (with the contract details typed into them): 30 days after they expire.
- Backups: deleted data leaves our database provider’s point-in-time recovery history within [BACKUP RETENTION, e.g. 7 days].
- Sessions: expire after three days (one day if “keep me signed in” is off); expired sessions are removed.
- Sign-in links expire after 15 minutes; password reset links after an hour; email verification links after a day.
- Activity log (who changed what inside a company account): two years.
- Billing records: six years after the end of the financial year they relate to (Companies Act 2006, HMRC).
- Support emails: two years after the conversation ends.
- Server logs: a few days, under our hosting provider’s log retention.
International transfers
Our database is in London and files are stored by Cloudflare. Some providers are based in, or give support access from, the United States. Where personal data leaves the UK we rely on UK adequacy regulations (for example for the EEA and Switzerland), the UK Extension to the EU–US Data Privacy Framework where the recipient is certified, or the ICO’s International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment. Ask us for a copy of the relevant safeguards.
How we protect it
Everything travels over HTTPS, the database and file storage are encrypted at rest, passwords are hashed, accounts can use two-step sign-in, and every company’s data is kept apart. More detail is on our security page.
Your rights
Under UK GDPR you can ask us to:
- give you a copy of your personal data (access);
- correct it if it is wrong (rectification);
- delete it (erasure), where we have no lawful reason to keep it;
- restrict how we use it while a complaint is resolved;
- give you the data you provided in a portable format (portability);
- stop using it where we rely on legitimate interests (objection), and stop direct marketing at any time.
Email privacy@groundcuvva.com. We answer within one month, and may need to confirm who you are first. If the data belongs to a customer’s account (you are their employee or client), we will pass your request to them and help them answer it.
Complaints
Please tell us first and we will try to put it right. You can also complain to the Information Commissioner’s Office: ico.org.uk/make-a-complaint or 0303 123 1113.
Changes to this notice
When we change this notice we update the date at the top. If a change affects how we use your data in a significant way, we will tell account holders by email first.