Cattle Grid Ltd - Privacy Policy

Version 1.0  –  March 2026  –  cattlegrid.uk

Who this applies to

This policy applies to anyone whose personal data CattleGrid Ltd processes: visitors to cattlegrid.uk, prospective and current customers, and the authorised users of the CattleGrid service within customer organisations. It does not apply to the content of AI prompts inspected by the gateway, which is subject to our zero-retention architecture and never stored.

1. Who We Are

CattleGrid Ltd is the data controller responsible for the personal data described in this policy.

DetailInformation
Registered nameCattleGrid Ltd
Company number17020793 (England and Wales)
Registered address32 Salisbury Avenue, Cheltenham, GL51 3BS
General enquiriessupport@cattlegrid.uk
Data protection contactcompliance@cattlegrid.uk
Websitecattlegrid.uk

We have not appointed a Data Protection Officer. For any question regarding your personal data, contact us at compliance@cattlegrid.uk.

2. Personal Data We Collect

We collect personal data in three distinct contexts. The categories, purposes, and legal bases for each are set out below.

2.1  Website Visitors

When you visit cattlegrid.uk, we may collect:

  • Contact form submissions: name, business email address, company name, and the content of your message.
  • Technical data: IP address, browser type, device type, pages visited, and timestamps, collected via cookies and server logs. See Section 8 (Cookies) for detail.

Legal basis: Legitimate interests (UK GDPR Article 6(1)(f)) in operating our website securely and responding to enquiries. Our legitimate interests do not override your rights; you may object to this processing at any time.

2.2  Customers and Account Holders

When you subscribe to CattleGrid (or when your organisation does), we collect:

  • Account data: name, job title, business email address, and company name.
  • Billing data: billing address and VAT number. Payment card details are processed directly by our payment processor and are never transmitted to or stored by CattleGrid.
  • Subscription data: plan type, subscription start and renewal dates, usage tier.
  • Correspondence: the content of support requests, emails, and other communications you send us.

Legal basis: Performance of a contract (UK GDPR Article 6(1)(b)) for data necessary to provide the service and manage the subscription. Legal obligation (Article 6(1)(c)) for billing and tax records. Legitimate interests (Article 6(1)(f)) for security, fraud prevention, and service improvement.

2.3  Authorised Users of the CattleGrid Service

When individuals within your organisation use the CattleGrid gateway, we collect:

  • Identity data: name and business email address of each authorised user.
  • Audit log metadata: user identifier, timestamp of each gateway interaction, which policy rules were triggered, and the action taken (permitted or blocked). We do not log the content of AI prompts. See Section 3 on our zero-retention architecture.

Legal basis: Performance of a contract (Article 6(1)(b)) for the delivery of the service. Legal obligation (Article 6(1)(c)) for audit trail requirements under ISO 42001 and the EU AI Act.

2.4  Marketing Communications

Where you have opted in, we may send you information about CattleGrid products, regulatory developments, and related content.

Legal basis: Consent (UK GDPR Article 6(1)(a)). You may withdraw consent at any time by clicking the unsubscribe link in any marketing email or by contacting compliance@cattlegrid.uk.

3. Our Zero-Retention Architecture

Important: how we handle the content of AI prompts

CattleGrid operates a zero-retention architecture for the content of AI prompts passing through the gateway. Customer Data — the substantive content of what your employees send to AI services — exists only in memory for the milliseconds required to inspect it against your policy rules. It is never written to disc, never stored in our database, and never transmitted to CattleGrid’s infrastructure beyond the inspection process itself.

What we do log is metadata: who triggered an inspection, when, which rules were applied, and what the outcome was. The content itself is gone before we have finished reading it.

This architecture has direct implications for data subject rights requests. When a data subject asks what data CattleGrid holds about them, the honest answer is: account and audit metadata, not the substance of their AI interactions. We will always say so plainly.

4. How We Use Your Personal Data

We use personal data only for the purposes for which it was collected. The table below summarises the key uses.

PurposeLegal Basis
Responding to website enquiries and pre-sales conversationsLegitimate interests
Creating and managing customer accountsContract performance
Delivering and operating the CattleGrid serviceContract performance
Processing subscription payments and issuing invoicesContract performance / Legal obligation
Maintaining audit logs for ISO 42001 and EU AI Act complianceLegal obligation
Providing technical support and responding to incidentsContract performance / Legitimate interests
Detecting and preventing security threats and fraudLegitimate interests / Legal obligation
Sending service notifications (downtime, policy changes, renewal reminders)Contract performance
Sending marketing communications (where consent given)Consent
Complying with legal and regulatory obligationsLegal obligation
Improving the service using aggregated, anonymised usage analyticsLegitimate interests

We do not use personal data for automated decision-making that produces legal or significant effects on individuals.

5. Who We Share Personal Data With

We do not sell personal data. We share it only where necessary to deliver the service or meet legal obligations.

5.1  Sub-processors

CattleGrid uses a small number of third-party service providers who process personal data on our behalf. We maintain a current sub-processor schedule at cattlegrid.uk/sub-processors. Current sub-processors include:

Sub-processorPurpose and Data Processed
Infrastructure provider (EU)Cloud hosting of the CattleGrid application and database. Account and audit metadata only. No prompt content.
[PAYMENT PROCESSOR]Payment card processing for online subscriptions. Card data is processed directly by the payment processor and not passed to CattleGrid.
Email delivery providerTransactional emails (account notifications, alerts, invoices) and marketing communications where consent has been given.

Infrastructure note: CattleGrid is hosted on European infrastructure. We do not use US-domiciled cloud providers for data storage or application hosting. This means your data does not fall within the scope of the US CLOUD Act. Where any sub-processor is US-domiciled, appropriate Standard Contractual Clauses (SCCs) are in place. Our current sub-processor schedule is maintained at cattlegrid.uk/sub-processors.

5.2  Legal and Regulatory Disclosure

We may disclose personal data where required to do so by law, by a court order, or by a regulatory authority with jurisdiction over CattleGrid, including the ICO. We will tell you about any such disclosure unless we are legally prohibited from doing so.

5.3  Business Transfer

In the event of a merger, acquisition, or sale of CattleGrid’s business, personal data held by us may be transferred to a successor entity. We will notify affected individuals in advance of any such transfer and ensure equivalent protections are in place.

6. International Data Transfers

CattleGrid’s primary infrastructure is hosted in the European Economic Area (EEA). In the ordinary course of service delivery, we do not transfer personal data outside the UK or EEA.

Where any sub-processor is located outside the UK or EEA, we ensure one of the following safeguards is in place:

  • UK adequacy regulations confirm the receiving country provides equivalent protection; or
  • Standard Contractual Clauses (SCCs) approved by the ICO or European Commission are in place with the sub-processor; or
  • Another approved transfer mechanism under UK GDPR Article 46 applies.

A copy of the relevant safeguard is available on request at compliance@cattlegrid.uk.

7. How Long We Keep Your Data

Data CategoryRetention Period
Website enquiry and contact form data2 years from last contact, or until request to delete
Customer account dataDuration of the subscription, plus 6 years after termination (UK Limitation Act 1980)
Billing and financial records6 years from the end of the relevant financial year (HMRC requirement)
Audit log metadata (user ID, timestamp, rule triggered, outcome)Defined by customer policy configuration. Default: 12 months. No prompt content is ever stored.
Marketing communications preferencesUntil consent is withdrawn
Support correspondence3 years from resolution of the relevant matter

At the end of any retention period, data is securely deleted or anonymised. We do not archive personal data beyond the periods set out above.

8. Cookies

We use cookies on cattlegrid.uk. A cookie is a small text file placed on your device. Cookies help us operate the website, understand how it is being used, and (where you have consented) support marketing activity.

Cookie TypePurpose and Basis
Strictly necessaryRequired for the website and customer portal to function. No consent required.
Performance / analyticsUsed to understand how visitors use the site (page views, session duration, referral sources). We use aggregated, anonymised data only. Requires consent.
MarketingUsed to track engagement with our content and deliver relevant communications. Requires consent.

When you visit the site, our cookie banner will ask for your consent to non-essential cookies. You can change your preferences at any time via the cookie settings link in the footer. Withdrawing consent does not affect the lawfulness of processing before withdrawal.

9. Your Rights

Under UK GDPR, you have the following rights in relation to personal data we hold about you. These rights apply except where a specific legal exemption overrides them.

RightWhat it means
AccessTo receive a copy of the personal data we hold about you and information about how we use it (subject access request).
RectificationTo have inaccurate data corrected and incomplete data completed.
ErasureTo have your personal data deleted where there is no legitimate reason for us to continue processing it.
RestrictionTo ask us to pause processing your data in certain circumstances, for example while the accuracy of the data is disputed.
PortabilityTo receive personal data you have provided to us in a structured, commonly used, machine-readable format, or to have it transferred directly to another controller.
ObjectTo object to processing based on legitimate interests. We will stop unless we can demonstrate compelling legitimate grounds that override your interests.
Withdraw consentTo withdraw consent for marketing or cookies at any time. Withdrawal does not affect prior processing.
Automated decision-makingNot to be subject to solely automated decisions that produce legal or significant effects. CattleGrid does not operate such processes.

To exercise any of these rights, contact us at compliance@cattlegrid.uk. We will respond within one calendar month. We may ask you to verify your identity before processing the request. We do not charge for exercising your rights unless a request is manifestly unfounded or excessive.

10. Subject Access Requests

You may submit a subject access request (SAR) at any time by emailing compliance@cattlegrid.uk, clearly identifying yourself and the data you wish to access.

Because CattleGrid operates a zero-retention architecture, SARs relating to AI prompt content will be straightforward: we hold no such content. SARs relating to account data, audit log metadata, and correspondence will be fulfilled within one calendar month of receipt.

Under the Data (Use and Access) Act 2025, we may pause the response period if we require additional information from you to verify your identity or locate the relevant data. We will notify you promptly if this applies.

11. Complaints

If you have a concern about how we handle your personal data, we ask that you contact us first at compliance@cattlegrid.uk so that we can try to resolve it.

If you remain unsatisfied, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection:

Contact methodDetails
Websiteico.org.uk/make-a-complaint
Telephone0303 123 1113
PostInformation Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

If you are located in the EU and your complaint concerns EU personal data, you may also contact the supervisory authority in your country of residence.

12. Security

We take the security of personal data seriously. Our technical and organisational measures include:

  • Encryption of personal data in transit (TLS) and at rest.
  • Role-based access controls limiting who within CattleGrid can access personal data.
  • Infrastructure hosted entirely on European servers outside US CLOUD Act jurisdiction.
  • Zero-retention processing of AI prompt content: no prompt content is ever written to disc.
  • Regular review of sub-processor security arrangements.

No method of transmission over the internet is entirely secure. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and, where required, notify affected individuals without undue delay.

13. Changes to This Policy

We will update this policy when our practices change or when legislation requires. Material changes will be notified to customers by email at least 14 days before taking effect. The current version will always be published at cattlegrid.uk/privacy.

The version number and date at the top of this document confirm which version you are reading.

14. Contact Us

Query typeContact
General enquiriessupport@cattlegrid.uk
Data protection and privacycompliance@cattlegrid.uk
Subject access requestscompliance@cattlegrid.uk
PostCattleGrid Ltd, 32 Salisbury Avenue, Cheltenham, GL51 3BS

CattleGrid Ltd is registered in England and Wales (Company No. 17020793). This policy is published in compliance with UK GDPR, the Data (Use and Access) Act 2025, and ICO guidance on privacy notices. It does not constitute legal advice. Version 1.0 – March 2026.