Skip to content

Privacy notice

Clear information about how personal data is used.

This notice covers the Grimberg Labs public website, direct communications and the restricted workspace operated by BERNARDO CHOURIK GROUP LTD.

1. Who is responsible

BERNARDO CHOURIK GROUP LTD is the controller for processing described in this notice when it determines why and how personal data is used. It is registered in England and Wales under company number 16553222.

Registered office: 167-169 Great Portland Street, London, England, W1W 5PF. Privacy enquiries and rights requests can be sent to bernardo@grimberglabs.com.

Official Companies House record

2. Data we process and where it comes from

  • Public-site data: network and request information such as IP address, browser or device headers, requested URL, timestamps and security events. This is generated when a visitor connects to the site and may be recorded by our hosting and security infrastructure.
  • Communications: name, business contact details, organisation, message, attachments and correspondence supplied directly by the sender or their organisation.
  • Authorised-user data: account identity and contact details, authentication and access records, role and approval information, and administrative data required for the person’s employment, contractor or operating relationship. This may include address, payment or statutory identifier information where genuinely required.
  • Operational data: information supplied by authorised affiliated businesses or retrieved from connected commerce, advertising, media and other business platforms at their direction.
  • Publicly accessible sources: relevant product catalogues, storefronts, advertisements, business profiles and official registers. Public accessibility does not remove privacy, intellectual-property, database or contractual rights.

3. Why we process data and our lawful bases

Operate and secure the website and workspace

Data
Request, device, authentication, account, access and security-event data.
Lawful basis
Legitimate interests in delivering and protecting our systems; contract where access is provided under an agreement.

Manage authorised users and business administration

Data
Identity, contact, role, approval, employment or contractor and, where required, payment or statutory records.
Lawful basis
Contract, legal obligations and legitimate interests in administering the business and its workforce.

Handle enquiries, notices and rights requests

Data
Contact details, message content, attachments and related correspondence.
Lawful basis
Legitimate interests in responding and maintaining accountable records; legal obligations for certain requests.

Support authorised commerce operations and research

Data
Business, product, catalogue, storefront, advertising and platform information relevant to a defined workflow.
Lawful basis
Contract and legitimate interests in operating and improving affiliated commerce activities, subject to applicable law and third-party rights.

Where we rely on legitimate interests, those interests are running secure systems, responding to legitimate enquiries, administering the business and conducting proportionate commerce operations. We consider the necessity and impact of the processing and do not rely on this basis where the individual’s rights and interests override ours.

If we ask for consent for a separate optional activity, that request will explain the choice and how to withdraw it. We do not combine consent with these terms.

You are not required by law or contract to browse the public pages or send us a general enquiry. If an approved account, employment, contractor relationship or other agreement requires particular identity, authentication, payment or statutory details, we will identify what is required and why. Without those required details, we may be unable to create or secure the account, grant access, administer the relationship, perform the agreement or meet the relevant legal obligation.

Where data comes from a source other than the individual, this website is one layer of transparency. If applicable law requires notice to be brought directly to the individual’s attention, we will use an appropriate contact route within the applicable period; publication here does not replace that step.

4. Cookies and similar technologies

At the date of this notice, the public institutional pages do not deploy advertising, cross-site tracking or non-essential analytics cookies. The restricted workspace uses technologies that are strictly necessary to authenticate users, maintain sessions and protect accounts.

If non-essential technologies are added to the public site, we will update this notice and provide any information, controls or prior consent required by applicable law before using them.

5. Who receives data

Access is limited according to role and operational need. Data may be processed by affiliated businesses where required for the relevant workflow and by vetted providers supporting hosting, security, database and authentication, email, cloud processing, commerce and connected business platforms.

Data may also be disclosed to professional advisers, insurers, auditors, prospective transaction parties or public authorities when necessary and lawful. We do not sell personal data through this public website.

6. International transfers

Some providers and affiliated operations may process data outside the United Kingdom. Before making a restricted transfer, we assess the destination and use an applicable legal mechanism, such as UK adequacy regulations or appropriate contractual safeguards, where required. Contact us for current information relevant to a specific transfer.

7. How long we keep data

We retain personal data only for as long as necessary for the purpose for which it was collected and for legitimate security, audit, dispute, contractual and legal requirements. The criteria include the nature and sensitivity of the data, operational need, account or business relationship, legal limitation periods and whether a record can be securely deleted or anonymised.

8. Your rights

Depending on the circumstances and lawful basis, UK data-protection law may give you rights to access, correct or erase personal data; restrict processing; receive portable data; and object to certain processing. Where processing is based on consent, you may withdraw it without affecting earlier lawful processing.

Your right to object

You may object to processing based on legitimate interests. Tell us which processing concerns you and why; we will assess the request under the applicable law.

Send a request to bernardo@grimberglabs.com. We may need proportionate information to verify identity and protect the data from unauthorised disclosure.

9. Automated decisions

The public website does not make decisions based solely on automated processing that produce legal or similarly significant effects. Internal systems may assist staff with research, organisation or content, but material operational decisions and exceptions remain subject to human review.

10. Security

We apply technical and organisational controls appropriate to the nature of the data and the risk, including restricted access, authentication, role controls and secure transport. No system is completely risk-free, so suspected security issues should be reported promptly through our contact channel without including credentials or unnecessary personal data.

11. Complaints and updates

Please contact us first so we can investigate a concern. You also have the right to complain to the UK Information Commissioner’s Office (ICO). The ICO provides current contact and complaint options at ico.org.uk/make-a-complaint.

We review this notice when our processing or legal obligations change. Material changes will be reflected on this page with a new update date and, where required, brought directly to affected people’s attention before the new processing begins.