Legal
Privacy notice
This site collects two things: what you type into the enquiry form, and the ordinary server logs that come with serving a web page, and our own analytics measures how the site is used. There is no advertising pixel and no mailing list behind it.
- Last updated
- Applies to groovymark.com
- Version 1.0 · template
Who we are
GroovyMark builds custom AI content production and publishing systems, and runs them as a managed service. In this notice, “we” and “us” mean GroovyMark, which is the controller of any personal data collected through this website.
We are established in Colombo, Sri Lanka, with a branch in Perth, Australia. Because we offer services to people in the United Kingdom and the EEA, this notice is written to the standard the UK and EU GDPR set, and we apply that standard to everyone who contacts us rather than only to those two regions.
Registered details: GroovyMark PVT Ltd, company number PV 00299314, GM HQ, Trace City, Colombo 10, Sri Lanka. Privacy and data rights requests go to privacy@groovymark.com.
What this notice covers
This notice covers the website at groovymark.com and
the enquiries sent through it. It does not cover client project work. If we go on to
build or run a system for you, the data your team puts into that system is governed
by the signed engagement agreement and the data processing terms attached to it,
where we act as your processor rather than as a controller.
What we collect
Four things, and nothing beyond them.
- Enquiry form submissions. Your name, work email and company, which are required; your role and website, which are optional; the channels, volume, timeline and engagement options you select; and whatever you write in the brief field. We also record that you ticked the consent box, and when.
- Email you send us directly. If you write to hello@groovymark.com instead of using the form, we hold that message and whatever it contains on the same terms as a form submission.
- Server logs. Our hosting provider records the ordinary request data needed to serve and defend a website: IP address, user agent, the URL requested, the response code and a timestamp. We use it to keep the site up and to investigate abuse. We do not join it to enquiry data, and we do not build profiles from it.
- Your cookie choice. Which categories you allowed, the date, and your browser, operating system and device type. It carries no name and no email address, and it is not joined to any enquiry you send us. It exists so we can show that consent was asked for and what was chosen — see cookies.
There are no accounts on this site, so there is nothing to sign up for and no password for us to hold. We do not ask for special category data, and you should not send any in the brief field.
What we do not do
This list is as much a part of the notice as the rest of it. These are build decisions, not intentions.
- No third-party analytics. There is no Google Analytics, no product analytics SDK, no session recording and no heatmap tool on this site. Our own analytics measures how the site is used — it runs on our own system, the data stays with us, and it is not used to follow you anywhere else. Full detail, including every entry it writes, is in the cookie policy.
- No advertising trackers. No conversion pixels, no remarketing audiences, no cross-site identifiers, no fingerprinting. The only device details we hold are the browser, operating system and device type recorded against your cookie choice, which are not combined into an identifier and are not used to recognise you anywhere else.
- No selling or sharing. We do not sell personal data, we do not trade it, and we do not pass it to advertising networks, data brokers or partners for their own purposes.
- No mailing list you did not ask for. Sending an enquiry subscribes you to nothing. There is no drip sequence and no newsletter behind the form. If we ever run one, you will have to ask for it.
- No automated decision-making. Nothing about your enquiry is scored, ranked or decided by a machine. A person reads it and replies.
Why we process it, and on what basis
- Answering your enquiry — legitimate interests. Under Article 6(1)(f) of the UK and EU GDPR. Our interest is running a business and replying to people who deliberately contacted it; yours is getting an answer. We have weighed the two and consider the processing to be what you would reasonably expect when you press send.
- Contacting you about it — consent. Under Article 6(1)(a). The tick box on the form is the consent, and it is specific to the enquiry it accompanies. You can withdraw it at any time by replying to us or writing to privacy@groovymark.com. Withdrawal does not affect anything we did before you withdrew it.
- Keeping the site available and secure — legitimate interests. Server logs exist so that outages and abuse can be investigated. The interest is operating a service that stays up and is not used to attack other people.
- Storing your cookie choice — consent. Under Article 6(1)(a), and under the ePrivacy rules that govern storing anything on your device. The strictly necessary entries are exempt from that consent requirement because they do nothing except carry out the choice you made.
- Keeping proof of that choice — legitimate interests. Under Article 6(1)(f). Article 7(1) requires us to be able to demonstrate that consent was given, which we cannot do without keeping a record of it.
- Records we are required to keep — legal obligation. Under Article 6(1)(c). This applies only if an enquiry becomes an engagement, where tax and contract records have to be retained for the period the law sets.
How long we keep it
- Enquiries that do not lead to work: kept for 12 months from the last message between us, then deleted. Long enough that we recognise you if you come back next quarter, short enough that the inbox does not become an archive.
- Enquiries that become engagements: the correspondence moves under the retention terms of the signed agreement, which are set out there rather than here.
- Server logs: retained for a short rolling window, no more than 30 days, and then overwritten.
- Cookie consent records: kept while the choice stands, and deleted when you withdraw it. Withdrawing through Cookie settings in the footer erases the record immediately rather than marking it inactive.
Ask us to delete your enquiry earlier and we will, unless we are required to keep it — see your rights.
Who else touches it
Two outside providers, and the list is short on purpose. Every processor is another place your data can be exposed from, so we add one only when it replaces something we cannot sensibly do ourselves. The same principle runs through the product: one AI vendor rather than data scattered across five SaaS tools.
- Email delivery — Resend. Carries the enquiry to our inbox and the confirmation to yours. It handles the message in transit and keeps a delivery log of it; it is not where your enquiry is stored, and it is not used to market anything to you.
- Hosting and mail — Hostinger. Runs the server these pages are served from, writes the server logs, and hosts the mailbox the enquiry lands in and our reply is sent from.
Each of them acts on our instructions under a written processing agreement. We may also disclose data where the law requires it, or to establish or defend a legal claim. That is the whole list — there are no “trusted partners” and nothing is sold or shared for anyone else's marketing.
One more system holds data, but it is ours rather than a third party's: the customer
system at crm.groovymark.com, which we run and which stores the cookie
consent records described under cookies. We mention it here
because it is a second place your data can sit, and a list that leaves out our own
systems is not an honest list.
International transfers
We work with clients in the United States, the United Kingdom, Western Europe and the Gulf, so correspondence crosses borders by nature. We are ourselves established in Sri Lanka, which is not covered by a UK or EU adequacy decision.
That matters less than it sounds, because of who is sending what to whom. When you fill in the form or write to us, you are giving your information to us directly. Data protection law treats that as a direct disclosure by you rather than as a restricted transfer between organisations, so the transfer rules in Chapter V do not attach to it. We hold it to the UK and EU standard regardless — that is the whole point of this notice.
Where the rules do attach is anything we pass on afterwards, and that is a short list. Hostinger, which hosts the server and the mailbox, is established in the European Union. Resend, which delivers the two emails, is established in the United States.
Where a provider sits outside the UK and EEA and no adequacy decision covers it, the basis we use is the European Commission’s standard contractual clauses together with the UK International Data Transfer Addendum. Ask us and we will tell you which basis applies to your enquiry and send you the relevant terms.
Your rights
Under UK and EU data protection law you can ask us to do any of the following. Write to privacy@groovymark.com.
- Access — get a copy of the personal data we hold about you.
- Rectification — have anything inaccurate or incomplete corrected.
- Erasure — have it deleted where we have no continuing reason to hold it.
- Restriction — have us pause processing while a dispute about accuracy or legitimate interests is resolved.
- Objection — object to processing we base on legitimate interests, including the handling of your enquiry.
- Portability — receive the data you gave us in a structured, machine-readable form, or have it sent onward.
- Withdraw consent — at any time, where consent is what we relied on.
We do not charge for this and we will respond within one month. We may ask you to confirm who you are first, which normally means replying from the address the enquiry came from.
If you think we have got it wrong, tell us and we will look again. You also have the right to complain to a supervisory authority: in the UK, the Information Commissioner’s Office at ico.org.uk; in the EU or EEA, the authority in the country where you live or work.
Cookies
This site sets no cookies. Not analytics cookies, not advertising cookies, not preference cookies. What it does keep is three entries in your browser's local storage, and all three exist to record and honour the cookie choice you are asked to make on your first visit.
Our own analytics runs on every visit while the site is new, and the consent panel does not offer a switch for it today — a switch we ignored would be worse than none. It is set out in full, entry by entry, in the cookie policy. The functional and marketing categories have nothing behind them at all, and we show them anyway because your answer is what decides whether anything is ever added under them.
Your choice is stored on your device and a copy is sent to our own system
at crm.groovymark.com, which we run ourselves rather than buying in from
a consent vendor. That copy records the date, your browser, operating system and
device type, and nothing that identifies you by name. We keep it because consent is
worth nothing if we cannot show it was asked for, which makes our legitimate interest
in demonstrating compliance the basis for holding it.
Cookie settings in the footer of every page reopens the panel with your current choice loaded, so changing your mind or withdrawing entirely takes the same single click as consenting did. Withdrawing clears the entries that record your choice and deletes the record we hold. The reference is kept only if we cannot reach our own system to delete that record, so the erasure can be retried. The full list of what is stored, with the purpose and lifetime of each entry, is in the cookie policy.
Your browser will also cache pages, fonts and images the way it caches any website. That is ordinary browser behaviour, it stays on your device, and it is not tracking.
Security
Every page on this site is built in advance and served as a file over HTTPS. The single exception is the enquiry form, which runs on request so it can send the two emails — and even that writes nothing to disk. There is no database anywhere behind this site, which removes most of the attack surface a database-backed site carries. Enquiry data lives in an inbox, not in an application, and access to that inbox is limited to the people who answer enquiries and protected by two-factor authentication. No system is beyond reach, so if we ever have a breach that is likely to result in a risk to your rights, we will report it to the relevant supervisory authority within 72 hours and tell you directly where the risk is high.
Changes to this notice
We update this notice when what we do changes, not on a schedule and not for the sake of a fresh date. The stamp at the top of the page is the version: this one was last updated on .
If a change is material — a new processor, a new purpose, a longer retention period — we will say what changed at the top of the page, and where we hold your contact details and the change affects you, we will tell you directly rather than expecting you to notice. Earlier versions are available on request.
Contact and complaints
Questions about this notice, or about anything we hold, go to privacy@groovymark.com. A person reads it, normally within one business day, and a rights request gets a substantive answer within one month.
Postal address for formal correspondence: GroovyMark PVT Ltd, GM HQ, Trace City, Colombo 10, Sri Lanka. If our answer does not satisfy you, you can take it to the supervisory authority named under your rights.