Privacy Policy
1. Who we are
Greymill ("we", "us", "our") operates the Greymill platform at greymill.ai. Greymill is a trading name of a company registered in England & Wales. We are registered with the UK Information Commissioner's Office (ICO). This policy explains what personal information we collect, how we use it, and the rights you have over your data, whether you are located in the UK, European Union, United States, or elsewhere.
2. Scope
This policy applies to all users of the Greymill platform worldwide. Where specific regional laws grant additional rights - such as the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR), and the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) - those rights are respected and are explained in sections 9 and 10 below.
3. What data we collect
We collect the following categories of personal information when you use Greymill:
- Account information: your email address, an encrypted password hash, your chosen workspace name, and optionally your full name and phone number.
- Business information: details about your business that you choose to share during onboarding, including industry, company name, and any context you provide to your AI specialists.
- Conversation data: the messages you send to Greymill's AI specialists and the responses you receive.
- Documents: any files or documents you upload to the platform.
- Usage data: which specialists you interact with, the frequency and length of your conversations, response times, and approximate timestamps.
- Connected account data (optional): if you connect Xero, QuickBooks, Google, Gmail or Outlook, the data we read from those accounts on your instruction, described in sections 7b, 7c and 12.
- Technical data: IP address, browser type, device type, and approximate location (city-level) derived from IP address, collected automatically for security and analytics purposes.
4. How we use your data
We use your data to:
- Provide and operate the Greymill service, including powering your AI specialists with the business context you have shared.
- Process subscription payments and manage your account.
- Generate usage reports and savings summaries that are visible only to you.
- Send transactional emails such as welcome messages, password resets, billing notifications, and weekly savings reports.
- Detect and prevent abuse, fraud, and security incidents.
- Respond to support requests and feedback.
- Improve the Greymill product based on aggregated, anonymised usage patterns.
5. Lawful basis for processing (UK and EU users)
For users in the UK and European Economic Area, we process your personal data on the following legal bases under UK GDPR and EU GDPR:
- Contract: to provide the service you have subscribed to.
- Legitimate interests: to secure the platform, prevent fraud, and improve our product, where these interests are not overridden by your rights.
- Legal obligation: where we must retain or disclose data to comply with law.
- Consent: for any non-essential cookies or marketing communications, which you may withdraw at any time.
6. How we protect your data
Your data is stored in encrypted databases hosted in the United Kingdom. Passwords are hashed using bcrypt. All communications with Greymill servers are encrypted in transit using HTTPS (TLS 1.2 or above). Access to production systems is restricted to authorised personnel using multi-factor authentication. We do not sell, rent, or trade your personal data to third parties for their marketing purposes under any circumstances.
7. AI processing and your conversations
Your conversations with Greymill's AI specialists are processed by large language models provided by a specialist AI infrastructure partner under a commercial agreement that prohibits the use of your data to train AI models.
So that your specialists can recall relevant details from your earlier conversations, the text of your messages and the business facts derived from them are also converted into numerical representations (known as embeddings) by a specialist retrieval infrastructure partner. We have contracted with that partner on terms that prohibit the use of your content to train or improve their models and that require your content to be deleted immediately after it has been processed for us. Embeddings themselves are stored in our own database alongside the facts they describe, inside your workspace, and are deleted when the underlying data is deleted.
Your business data and conversation history are used to personalise your experience within your own Greymill workspace. Each workspace is logically isolated - users cannot see or access any other user's conversations, documents, or business information.
7a. Anonymous industry benchmarks
There is one exception to the workspace-only rule above, and we want to be plain about it rather than bury it.
When you tell a specialist an operating figure about your business - for example a gross margin, a staff cost ratio, or an average order value - we may record that figure as a single anonymous observation, together with your industry, country, and broad revenue and headcount bands. We do not record who said it in any form that we can trace back to you, and we never record the surrounding conversation.
These observations are pooled so that we can tell any customer how their numbers compare with similar businesses. The following limits are built into the system rather than being a matter of policy:
- A comparison is only ever produced from a pool of five or more separate businesses. Below that threshold no benchmark is shown at all, because a comparison drawn from one or two companies would effectively reveal their figures.
- Only ranges and percentiles are shown. An individual business's number is never displayed to anyone else, and there is no way to work backwards from a benchmark to a particular company.
- Your own figures are excluded from the pool when a benchmark is shown to you, so you are compared against other businesses rather than against yourself.
We rely on legitimate interests as our lawful basis for this, the interest being the ability to give every customer a realistic sense of how their business is performing, which is a core part of what Greymill is for. We have weighed this against your rights and consider the impact to be low, because what is retained is a number and a set of broad categories rather than anything identifying.
You can object to your figures being used this way at any time by emailing support@greymill.ai, and we will exclude your account from the pool. Doing so does not affect your ability to see benchmarks yourself.
7b. Connected Google data
If you choose to connect a Google account, you can give Greymill read-only access to your Google Search Console and Google Analytics data so that your marketing specialist can advise you on your own figures rather than on general assumptions. This is optional, it is off unless you turn it on, and it can be disconnected at any time from Settings.
What we read: the search queries your site appeared for, impressions, clicks, average position, pages, sessions by channel, landing pages, and the conversion events you have configured. We read aggregate reporting data only. We do not read individual visitor records, and we never write, post or change anything in your Google account.
What we store: an encrypted access credential, which site and property you selected, and a cached summary of those figures so that your specialist can answer without calling Google on every message. Disconnecting deletes the credential and the cached figures, and we also ask Google to revoke our access.
Greymill's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use this data for advertising, we do not sell it, and we do not transfer it except as needed to provide the feature you asked for. No human at Greymill reads it except where you have asked us to help with a specific problem or where the law requires it, and it is never used to train any AI model.
7c. Connected email (Gmail and Outlook)
If you choose to connect a Gmail or Outlook mailbox, you give Greymill read-only access to it so that your specialists can sort your email and help you deal with it. This is optional, it is off unless you turn it on, and it can be disconnected at any time from Settings.
What we read: the sender, subject, date and a short preview of the messages that arrive in your inbox, so that each one can be sorted to the specialist best placed to help and marked by urgency. When you open a message in Greymill, we fetch its text from your mailbox at that moment to show it to you.
What we never do: we never send, delete, move, label or change anything in your mailbox. Our access is read-only. When you ask a specialist about an email, Greymill places it in that specialist's message box as a draft, and nothing happens until you choose to send it. Replies are written by you, in your own email app.
What we store: an encrypted access credential and, for each sorted message, the sender, subject, date, a preview of no more than 400 characters and the result of the sorting. We do not store the full text of your emails or their attachments. Sorted messages are deleted automatically 30 days after we receive them. Disconnecting deletes the credential and every sorted message straight away; for Gmail we also ask Google to revoke our access, and for Outlook you can remove Greymill at myapps.microsoft.com.
How it is processed: the sender, subject and preview are sent to our AI infrastructure partner, under the terms described in section 7, solely to sort the message. The full text of a message is only sent there if you ask a specialist about it. That includes questions that need your mailbox searched: when you ask a specialist about something that would be in your email, the specialist searches your mailbox at that moment, reads up to a handful of matching emails, and uses them to answer. Those emails are not stored by Greymill; the search happens live each time you ask.
Greymill's use and transfer of information received from Google APIs, including Google Workspace APIs, adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use your email data only to provide the sorting and assistance features you can see in Greymill. We do not use it for advertising, we do not sell it, we do not transfer it to anyone except as needed to provide those features, to comply with the law, or as part of a merger or acquisition with your notice, and no human at Greymill reads it unless you ask us to or the law requires it. We never use data from your mailbox to develop, improve or train generalised AI or machine learning models, whether ours or anyone else's.
8. Cookies and analytics
We use strictly necessary cookies to maintain your login session and deliver the service. We use a product analytics tool to understand how the platform is used in aggregate; this tool is hosted in the EU and is configured so that personally identifying information is pseudonymised where possible. We do not use advertising cookies and do not sell your personal information. When you arrive from one of our adverts, we measure whether that advert led to a signup using cookieless, consent-restricted conversion measurement (Google consent mode with every storage signal denied); no advertising cookies are set, no advertising profile is built, and we do not share your data for cross-context behavioural advertising. You can control cookies through your browser settings, though disabling essential cookies will prevent you from using the service.
9. Your rights under UK and EU GDPR
If you are located in the UK or EEA, you have the following rights regarding your personal data:
- Access: request a copy of the personal data we hold about you.
- Rectification: ask us to correct any inaccurate or incomplete data.
- Erasure ("right to be forgotten"): request deletion of your data.
- Restriction: ask us to stop processing your data in certain circumstances.
- Portability: receive your data in a structured, commonly-used format.
- Objection: object to processing based on legitimate interests.
- Withdraw consent: where processing is based on consent, withdraw it at any time.
- Complain: lodge a complaint with your local supervisory authority. In the UK, this is the Information Commissioner's Office (ico.org.uk).
To exercise any of these rights, email support@greymill.ai. We will respond within one month.
10. Your rights under California law (CCPA / CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act as amended by the California Privacy Rights Act:
- Right to know: request disclosure of the categories and specific pieces of personal information we have collected about you, the sources of that information, the business purposes for collecting it, and the categories of third parties with whom we share it.
- Right to delete: request that we delete personal information we have collected from you, subject to certain exceptions.
- Right to correct: request that we correct inaccurate personal information.
- Right to opt out of sale or sharing: Greymill does not sell your personal information and does not share it for cross-context behavioural advertising, so there is nothing to opt out of.
- Right to limit use of sensitive personal information: we do not use sensitive personal information beyond what is necessary to provide the service.
- Right to non-discrimination: you will not receive discriminatory treatment for exercising any of your privacy rights.
California residents may exercise these rights by emailing support@greymill.ai. We will verify your identity before acting on any request and respond within 45 days.
11. International data transfers
Greymill is operated from the United Kingdom, and our primary database is hosted in the United Kingdom. For users in the European Economic Area, transfers to the United Kingdom are covered by the European Commission adequacy decision for the UK. Your data may also be transferred to and processed in other countries, including the United States. Where we transfer personal data from the UK or EEA to a country not deemed to have adequate data protection, we rely on Standard Contractual Clauses approved by the UK ICO and European Commission to ensure an equivalent level of protection.
12. Data retention
We retain your personal data for as long as your account is active.
If you cancel, we keep everything for 30 days so that you can reactivate without losing your history. After those 30 days an automated process runs and permanently deletes the following, with no way for us to recover it:
- every conversation with every specialist;
- every document and file you uploaded, including from our file storage;
- everything the specialists had learned and remembered about your business;
- any contracts, briefs and saved work held in your workspace;
- your connections to Xero or QuickBooks, and any accounting figures we had cached from them;
- your Google connection, and any Search Console or Analytics figures we had cached from it;
- your Gmail or Outlook connection, and the sorted list of emails we kept from it;
- your password and login sessions.
Two things are deliberately kept, and we would rather explain them than describe this as a complete erasure when it is not:
- A reduced account record. We keep a stripped-back record of the account itself. Your email address is replaced, and your name, phone number, workspace name, company name, password and IP address are all erased. What remains is the plan you were on, the dates you joined and left, your industry and your country. We keep this because we are required to retain business and tax records (in the UK, generally for six years), and because it lets us understand why customers leave without holding anything that identifies you.
- Anonymous benchmark observations. Any operating figures described in section 7a stay in the pooled dataset. Once the reduced account record above has been stripped, these can no longer be connected to you or to your business.
Backup copies may persist for up to a further 30 days before being overwritten. During that window they are not accessed for any purpose and are not used in any decision about anyone.
You may request immediate deletion at any time by emailing support@greymill.ai, subject to any legal or contractual retention obligations we may have. If you do, the same process runs straight away rather than after 30 days.
13. Children's privacy
Greymill is not intended for use by anyone under the age of 18, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact support@greymill.ai and we will delete it promptly.
14. Service providers
To deliver the Greymill service, we share certain personal data with a small set of trusted infrastructure providers, including those who provide AI model inference, search and retrieval indexing, authentication and database hosting, web hosting and edge delivery, transactional email, and product analytics. Each is contractually bound by a Data Processing Agreement with Greymill and may only process your data on our instructions. A current named list with full company details is available on request to support@greymill.ai, and is provided to enterprise customers as part of our Data Processing Agreement. We will notify active users by email at least thirty (30) days before adding or replacing a service provider that materially changes how personal data is processed.
For data transferred to the United States or other third countries, we rely on the European Commission's Standard Contractual Clauses (or the equivalent UK International Data Transfer Agreement) together with supplementary technical measures, including encryption in transit and at rest.
15. Changes to this policy
We may update this policy from time to time to reflect changes in our practices or applicable law. When we make material changes, we will notify active users by email and update the "Last updated" date at the top of this page. Your continued use of the Greymill service after the effective date of an updated policy constitutes acceptance of the changes. If you do not agree to an updated policy, you may close your account at any time.
16. Contact
For any questions about this policy, to exercise your data protection rights, or to raise a privacy concern, please contact our data protection team at support@greymill.ai. We aim to respond to all enquiries within five working days.
Subscription billing is provided by FastSpring (Bright Market, LLC, United States) acting as Merchant of Record. See our Terms of Service for the billing relationship and FastSpring's privacy policy for how billing data is handled.
Greymill Limited · Registered in England and Wales · Company number 17144930 · 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ