Privacy Policy

Effective date: 6 August 2026
Last updated: 6 August 2026

1. About this Privacy Policy

This Privacy Policy explains how Grillo Inc Ltd, trading as Grillo Realty Services and GRS, collects, uses, shares, stores and protects personal information.

It applies when you:

  • visit our website;
  • submit an online enquiry or Request a Visit form;
  • contact us by email, telephone, WhatsApp or another communication channel;
  • request a quotation;
  • engage us to provide property attendance or related services;
  • communicate with us on behalf of a client, property owner, agent, contractor or other organisation;
  • interact with us through a booking, referral or service platform.

This policy should be read alongside our Website Terms of Use and, where applicable, the separate Service Terms and Booking Conditions supplied before a service booking is accepted.

2. Who is responsible for your information?

For the purposes of applicable UK data-protection law, the data controller is:

Grillo Inc Ltd
Trading as Grillo Realty Services and GRS

Company number: 11530153

Registered office:
128 City Road
London
EC1V 2NX
United Kingdom

Privacy enquiries:
privacy@grillorealtyservices.com

References in this policy to “GRS”, “Grillo Realty Services”, “we”, “us” or “our” mean Grillo Inc Ltd.

Information processed on behalf of a business client

In some circumstances, a business client may provide us with personal information about property occupiers, contractors, viewers or other individuals and instruct us how that information should be used.

Where we process that information solely on the business client’s instructions, the business client may be the data controller and GRS may act as its data processor. In those circumstances, the business client’s privacy notice will also apply.

We remain responsible for personal information that we use for our own business administration, account management, legal compliance, service records and legitimate operational purposes.

3. Personal information we collect

Depending on how you interact with us, we may collect the following categories of information.

Identity and contact information

This may include:

  • your name;
  • organisation or business name;
  • job title or role;
  • email address;
  • telephone number;
  • postal or correspondence address;
  • preferred method of communication.

Enquiry and booking information

This may include:

  • the service requested;
  • property address or postcode;
  • preferred appointment date and time;
  • access arrangements;
  • key collection and return arrangements;
  • details of relevant agents, contractors, occupiers or representatives;
  • appointment instructions;
  • quotation and booking information;
  • correspondence relating to the enquiry or appointment.

Property and service information

Where necessary to provide an agreed service, this may include:

  • photographs of a property;
  • factual observations and visit notes;
  • accessible meter readings;
  • attendance and access records;
  • information about whether a property appeared occupied or vacant;
  • contractor arrival or non-attendance information;
  • viewer questions or comments;
  • records of issues reported during a visit.

Photographs or visit records may incidentally include personal belongings, documents or other information relating to an occupier. We aim to limit this to what is reasonably necessary for the agreed purpose.

Financial and transaction information

This may include:

  • quotation and invoice details;
  • billing address;
  • payment status;
  • transaction references;
  • records required for accounting and taxation;
  • correspondence concerning payment.

We do not ask you to submit full payment-card details through the general website enquiry form.

Communications

We may retain:

  • emails;
  • WhatsApp messages;
  • form submissions;
  • telephone notes;
  • complaints;
  • feedback;
  • instructions and confirmations;
  • records of consent or objections.

Website and technical information

When you use the website, our hosting, security or technology providers may collect:

  • IP address;
  • browser type and version;
  • device type;
  • operating system;
  • approximate location derived from the IP address;
  • pages visited;
  • date and time of access;
  • referring website;
  • error, security and server-log information;
  • cookie or consent preferences.

Information about other people

A client or enquirer may provide information about:

  • property occupiers;
  • tenants;
  • landlords;
  • viewers;
  • estate or letting agents;
  • contractors;
  • property managers;
  • keyholders;
  • authorised representatives.

The person providing that information must have a lawful reason and appropriate authority to share it with us.

Where reasonably practicable, they should also ensure that the individual has received appropriate privacy information.

4. Information you should not submit through general forms

Unless we expressly request it through an appropriate and secure channel, please do not submit:

  • alarm codes;
  • key-safe or lock-box codes;
  • banking or payment-card details;
  • copies of passports or other identity documents;
  • detailed medical information;
  • criminal-record information;
  • highly confidential tenancy or legal documents;
  • unnecessary information about children;
  • other special-category personal information.

Special-category information can include information about health, ethnicity, religious or philosophical beliefs, political opinions, trade-union membership, genetics, biometrics or sexual orientation.

We do not normally need this information to respond to a general property-attendance enquiry.

Where access information is required for a confirmed appointment, we will agree an appropriate method for providing it.

5. How we collect personal information

We may obtain information:

Directly from you

For example, when you:

  • complete a form;
  • email, call or message us;
  • request a quotation;
  • confirm a booking;
  • provide appointment instructions;
  • pay an invoice;
  • submit feedback or a complaint;
  • exercise a data-protection right.

From organisations or people involved in an appointment

This may include:

  • estate or letting agents;
  • landlords and property owners;
  • property managers;
  • contractors;
  • booking or referral platforms;
  • authorised representatives;
  • employers or organisations for whom you work.

Through our service activities

For example, when we:

  • attend a property;
  • take agreed photographs;
  • record factual observations;
  • confirm access or attendance;
  • prepare a visit record;
  • communicate with relevant appointment contacts.

Automatically through the website

Certain technical information may be collected through:

  • server logs;
  • security tools;
  • cookies;
  • embedded forms;
  • consent-management tools;
  • website-performance technologies.

6. How we use personal information and our lawful bases

We only process personal information where we have a lawful basis.

The basis used will depend on the nature of the relationship, the information concerned and the purpose for which it is being used.

Responding to enquiries and preparing quotations

We use information to:

  • assess an enquiry;
  • understand the requested service;
  • check location and availability;
  • clarify the appointment brief;
  • prepare and communicate a quotation.

Our lawful basis is normally:

  • taking steps at your request before entering into a contract; or
  • our legitimate interests in responding to business enquiries and developing our services.

Accepting and delivering service bookings

We use information to:

  • confirm appointments;
  • communicate instructions;
  • arrange lawful property access;
  • provide the agreed attendance service;
  • produce agreed photographs or visit notes;
  • manage changes, cancellations or access issues;
  • communicate with authorised parties.

Our lawful basis is normally:

  • performance of a contract with you;
  • taking steps connected with a proposed contract; or
  • our legitimate interests in delivering services to a business client and communicating with its representatives.

Managing client and supplier relationships

We use information to:

  • maintain business contact records;
  • administer client accounts;
  • communicate with agents, contractors and representatives;
  • manage service quality;
  • respond to operational questions.

Our lawful basis is our legitimate interest in operating and administering GRS efficiently.

Invoicing, payment and accounting

We use information to:

  • issue invoices;
  • record payments;
  • manage amounts due;
  • maintain accounting and taxation records;
  • comply with legal and regulatory requirements.

Our lawful bases may be:

  • performance of a contract;
  • compliance with a legal obligation; and
  • our legitimate interest in managing and protecting the financial position of the business.

Maintaining service records and handling claims

We may retain information to:

  • demonstrate what was instructed and delivered;
  • investigate complaints;
  • resolve disputes;
  • respond to insurance matters;
  • establish, exercise or defend legal claims;
  • protect the rights, property and safety of GRS, its clients and others.

Our lawful bases may be:

  • our legitimate interests in maintaining appropriate records and protecting legal rights; and
  • compliance with legal obligations.

Operating and protecting the website

We use technical information to:

  • operate the website;
  • maintain security;
  • identify errors;
  • prevent misuse, fraud or unauthorised access;
  • investigate technical or security incidents;
  • understand basic website performance.

Our lawful basis is normally our legitimate interest in maintaining a functional and secure website.

Where consent is legally required for a non-essential cookie or similar technology, we rely on your consent.

Complying with law and regulatory requirements

We may process information to:

  • meet taxation and accounting obligations;
  • respond to lawful requests from courts, regulators or public authorities;
  • prevent or investigate unlawful activity;
  • comply with data-protection and other legal duties.

Our lawful basis is compliance with a legal obligation or, where relevant, our legitimate interest in protecting the business and others.

Direct marketing

Making an enquiry does not automatically add you to a general marketing list.

Where we send direct marketing, we will do so only where permitted by law. Depending on the circumstances, we may rely on consent or legitimate interests, subject to the requirements of applicable electronic-marketing law.

Every electronic marketing communication will provide an appropriate way to opt out.

You may object to direct marketing at any time by contacting us at:

privacy@grillorealtyservices.com

7. Our legitimate interests

Where we rely on legitimate interests, those interests may include:

  • responding to business enquiries;
  • operating and improving GRS;
  • managing client and professional relationships;
  • delivering services requested by business clients;
  • protecting properties, systems and information;
  • preventing fraud and misuse;
  • keeping appropriate records;
  • resolving disputes and defending legal rights;
  • understanding whether the website is functioning correctly.

Before relying on legitimate interests, we consider whether the processing is necessary and whether your interests, rights or freedoms override our interests.

You may object to processing based on legitimate interests. We will consider the circumstances and whether we have compelling legitimate grounds to continue.

8. What happens if you do not provide information?

You are not generally required by law to provide personal information to us.

However, if you do not provide information that is reasonably necessary, we may be unable to:

  • respond fully to an enquiry;
  • assess the requested work;
  • provide an accurate quotation;
  • verify authority or access arrangements;
  • accept or deliver an appointment;
  • produce the requested visit record;
  • meet legal or accounting obligations.

We will not ask for more personal information than we reasonably need for the relevant purpose.

9. Who we share personal information with

We do not sell or rent personal information.

Where necessary and lawful, information may be shared with the following categories of recipient.

Clients and authorised appointment contacts

This may include:

  • the person or organisation instructing us;
  • property owners or managers;
  • estate or letting agents;
  • authorised contractors;
  • representatives nominated for the appointment.

We limit sharing to information reasonably necessary for the agreed service or legitimate operational purpose.

Technology and service providers

These may include providers of:

  • website hosting;
  • website security and maintenance;
  • embedded forms;
  • email and productivity services;
  • cloud storage;
  • business messaging;
  • accounting and invoicing systems;
  • data backup and recovery;
  • IT support.

Depending on the communication method used, this may include services provided by Microsoft, Google and Meta/WhatsApp.

Some providers act as processors on our behalf. Others may act as separate controllers for aspects of their service and provide their own privacy information.

Representatives and subcontractors

Where appropriate, information may be shared with an authorised representative or subcontractor assisting with an accepted appointment.

They will only receive information reasonably required for the relevant task and will be expected to protect it appropriately.

Professional advisers and insurers

This may include:

  • accountants;
  • solicitors;
  • insurance providers;
  • claims handlers;
  • other professional advisers.

Public authorities and legal recipients

We may disclose information where required or permitted by law, including to:

  • HM Revenue and Customs;
  • law-enforcement agencies;
  • courts and tribunals;
  • regulatory authorities;
  • fraud-prevention bodies;
  • government departments.

Business transfers

If Grillo Inc Ltd is involved in a restructuring, merger, acquisition, financing exercise or sale of all or part of its business, relevant information may be disclosed to advisers and prospective parties subject to appropriate confidentiality and legal safeguards.

10. International transfers

Some technology, cloud, communications and service providers operate internationally. As a result, personal information may be processed or made accessible outside the United Kingdom.

Where UK data-protection transfer rules apply, we take steps to ensure that an appropriate legal mechanism is in place. This may include:

  • UK adequacy regulations;
  • the UK International Data Transfer Agreement;
  • the UK Addendum to approved standard contractual clauses;
  • another lawful safeguard or exception.

You may contact us for further information about the transfer mechanisms relevant to your personal information.

Transfers outside the UK require an appropriate lawful mechanism or safeguard where they amount to a restricted transfer.

11. How long we keep personal information

We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, insurance and dispute-resolution requirements.

Our normal retention periods are as follows.

Enquiries that do not become bookings

Normally up to 12 months after the last meaningful contact.

We may retain limited details for longer where necessary to record an objection, complaint, legal issue or instruction not to contact the person again.

Client, booking and service records

Normally up to six years after the relevant appointment or the end of the client relationship, depending on the nature of the record.

This may include:

  • accepted quotations;
  • booking confirmations;
  • instructions;
  • correspondence;
  • visit records;
  • agreed photographs;
  • invoices;
  • records needed to manage disputes or legal claims.

Information that is not necessary for these purposes may be deleted sooner.

Property photographs and visit reports

Normally retained for the duration required by the client relationship and, where reasonably necessary to evidence the service or manage a claim, for up to six years after the appointment.

A client may specify a shorter agreed period where appropriate and where no legal or operational reason requires longer retention.

Access codes and temporary access information

Access codes and similar details are removed from active operational records as soon as they are no longer required, normally within 30 days after the appointment or completion of the relevant instruction.

Information may remain temporarily in secure backups until those backups are overwritten in the ordinary course.

Accounting and taxation records

Normally retained for six years from the end of the relevant company financial year, or longer where legally required.

UK government guidance requires limited companies to retain relevant accounting and company tax records for six years from the end of the financial year to which they relate, subject to specified exceptions.

Website security and server logs

Normally retained for up to 12 months, although shorter or longer periods may apply where necessary to investigate a security incident or comply with legal requirements.

Complaints and data-protection requests

Normally retained for up to three years after closure, or longer where reasonably necessary for a continuing dispute, regulatory matter or legal claim.

Opt-out and suppression records

We may retain a minimal record of an opt-out for as long as reasonably necessary to ensure that the person is not added back to the relevant marketing list.

We may retain information for longer where:

  • a legal claim is pending or reasonably anticipated;
  • a regulator, court or law-enforcement body requires it;
  • legislation requires a longer period;
  • deletion would prejudice the establishment, exercise or defence of legal rights.

12. Cookies and similar technologies

The website may use cookies and similar technologies.

Strictly necessary technologies

These may be used to:

  • operate core website functions;
  • maintain security;
  • remember privacy or cookie preferences;
  • enable forms or requested functionality;
  • prevent fraud or misuse.

Where a technology is strictly necessary for a service requested by the user, consent may not be required, although appropriate information should still be provided.

Analytics and other non-essential technologies

Where non-essential analytics, advertising or similar technologies are used, they will not be activated before consent where consent is legally required.

You should be able to accept, reject or manage non-essential technologies through the website’s cookie banner or cookie-settings tool.

Withdrawing consent will not affect the lawfulness of processing carried out before withdrawal.

A privacy policy alone is not sufficient consent for non-essential cookies. Consent must be informed and involve a positive choice, and analytics cookies do not automatically fall within the strictly necessary exemption.

13. Embedded forms and third-party communications

The website may contain an embedded Microsoft Form or direct you to a form hosted by Microsoft.

When you use such a form:

  • Microsoft may receive technical information such as your IP address, browser and device information;
  • the information entered in the form is processed through Microsoft’s systems;
  • GRS receives and uses the submitted information for the purposes described in this policy.

Where you contact us through WhatsApp, WhatsApp and Meta may process information relating to your account, device and communications under their own privacy terms.

Where emails are sent through Microsoft, Google or another email provider, those providers may process message and technical information as part of delivering their services.

You should avoid sending highly sensitive information through general email, WhatsApp or an unencrypted enquiry form unless we have specifically requested it and agreed an appropriate method.

14. Data security

We use technical and organisational measures appropriate to the nature of the information and the risks involved.

These measures may include:

  • access controls;
  • password protection;
  • multi-factor authentication where available;
  • restricted access based on business need;
  • device and account security;
  • secure cloud services;
  • appropriate backup arrangements;
  • staff or representative confidentiality requirements;
  • secure deletion or disposal procedures;
  • review of service-provider security and privacy arrangements.

No internet, email, messaging or storage system can be guaranteed to be completely secure.

If we become aware of a personal-data breach, we will assess it and take the actions required by applicable law, which may include notifying affected individuals and the Information Commissioner’s Office.

15. Your data-protection rights

Depending on the circumstances, you may have the right to:

Access

Request confirmation of whether we process your personal information and receive a copy of it.

Rectification

Ask us to correct inaccurate or incomplete information.

Erasure

Ask us to delete personal information where there is no lawful reason for us to continue holding it.

Restriction

Ask us to restrict how information is used in certain circumstances.

Objection

Object to processing based on legitimate interests and object at any time to direct marketing.

Data portability

Receive certain information in a structured, commonly used and machine-readable format where the legal requirements for portability apply.

Withdraw consent

Withdraw consent at any time where processing is based on consent.

Withdrawal does not affect processing that was lawful before consent was withdrawn.

Complain

Make a complaint about how we have handled your personal information.

These rights are not absolute and may be subject to legal conditions or exemptions.

To exercise a right, contact:

privacy@grillorealtyservices.com

We may ask for information reasonably necessary to confirm your identity and understand your request. We will normally respond within the applicable legal time limit.

ICO guidance recognises rights including access, rectification, erasure, restriction, portability and objection, although the availability of a particular right depends on the processing and lawful basis involved.

16. Automated decision-making

We do not currently make decisions about individuals solely through automated processing where those decisions produce legal or similarly significant effects.

If this changes, we will update this policy and provide the information required by law.

17. Children’s information

The website and GRS services are not directed at children.

We do not knowingly invite children to submit enquiries or enter into service arrangements.

Clients and other users should not provide information about children unless it is reasonably necessary, they have lawful authority to do so, and an appropriate communication method has been agreed.

If we become aware that unnecessary information about a child has been submitted, we may delete or restrict it.

18. Third-party websites

The website may contain links to websites or platforms operated by other organisations.

Those organisations control their own processing activities and privacy practices. We are not responsible for their websites or privacy policies.

You should review the relevant third party’s privacy information before providing personal information to it.

19. Data-protection complaints

Please contact us first if you have concerns about how we have used your personal information:

Email:
privacy@grillorealtyservices.com

We will investigate the concern and respond appropriately.

You also have the right to complain to the Information Commissioner’s Office:

Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF

Helpline: 0303 123 1113

The ICO generally expects individuals to raise their concern with the relevant organisation first, and organisations must maintain an appropriate data-protection complaint process.

20. Changes to this policy

We may update this Privacy Policy to reflect:

  • changes to our services;
  • changes to the website or technology providers;
  • legal or regulatory developments;
  • changes to how we use personal information;
  • improvements in clarity.

The current version will be published on this page with a revised effective date.

Material changes will not retrospectively alter the lawful basis on which information was originally collected.

21. Contact us

Questions, requests or complaints concerning this Privacy Policy or our use of personal information should be sent to:

Email:
privacy@grillorealtyservices.com