Demo environment — every organisation here is fictional, and the whole world resets nightly. Explore freely; nothing you do is kept.

Privacy notice

How Grantary handles personal data. Last updated 29 July 2026.

Who we are

Grantary is operated by PRODRO GROUP LIMITED, registered in England and Wales (company no. 17268651), registered office 71-75, Shelton Street, London, England, WC2H 9JQ. General contact: info@prodro.co.uk. Data-protection contact: Kieran McCloud, kieran@prodro.co.uk.

Our two roles — controller and processor

  • We are the controller for the data needed to run the platform itself: your account (name, email, credentials), sign-in and security logs, billing and licence records, support and website enquiries. For this data, this notice is the complete picture.
  • We are a processor for the grant records your organisation keeps on the platform — budgets, activity, spend, evidence, reports. Your organisation (and the funder or charity it shares each grant with) is the controller of that content, under our Data Processing Agreement. If you have questions about grant content, your organisation's administrator is the right first door.
  • A grant record is shared by design: the funder side and recipient side of a grant each control what their people enter, and both see the same record. Where you apply to a funder's programme, the funder is controller of its own application process — read their programme privacy notice alongside this one.

What we hold and why

  • Account data — name, work email, organisation role; a salted password hash and an authenticator (TOTP) secret used solely for sign-in. Lawful basis: performing our contract with you and your organisation.
  • Security records — sessions, sign-in failures, lockouts, and the append-only audit trail attributing every change to the person who made it. Lawful basis: legitimate interest in a secure, tamper-evident service — this attribution IS the product.
  • Grant records and evidence (as processor) — what your organisation and its counterparties enter. Activity records hold attendee counts, not names; uploaders are asked to redact beneficiary details from documents. Do not upload personal data of the people your services help unless genuinely necessary.
  • Registry-check data — we look up organisation numbers you provide against public registers (Companies House, the Charity Commission, including CIC status) and keep the results with a history of checks. Lawful basis: legitimate interest in verified organisation identity. If a result looks wrong, tell us — we re-check against the registry, and the underlying record is corrected at source (the registry), not painted over here.
  • Billing and licence records — plan choices and payment status per organisation. Lawful bases: contract and our legal (accounting) obligations. Card details, when card payments launch, will be held by the payment provider, not by us — and this notice will be updated first.
  • Emails we send — verification codes, invitations, digests and scheduled summaries you can switch off in your account. We do not send marketing without consent.

Who receives data

  • The other side of each shared grant record, and anyone your administrators share documents with (passport shares are scoped, revocable and visible to you).
  • Our infrastructure providers (hosting, database, email) — the current list, with locations, is at /subprocessors.
  • Public authorities where the law requires it. We do not sell personal data, share it for advertising, or use it to train AI models.

Where data lives

PRODRO GROUP LIMITED is a UK company, and your grant records — documents, ledgers and the audit trail — are stored and processed in Frankfurt, Germany, so they do not routinely leave the European Economic Area. Our providers are US-headquartered companies and transactional email is delivered from the United States; those transfers are covered by UK GDPR safeguards (Vercel's certification under the UK Extension to the EU-US Data Privacy Framework, and Standard Contractual Clauses with the UK Addendum for email). The provider-by-provider position, with links to each mechanism, is at /subprocessors.

How long we keep things

  • Grant records — for the retention period the funder sets, typically six years after the grant closes (UK grant-audit expectations), then deleted.
  • Accounts — while active; disabled or departed accounts keep only what the audit trail needs (who did what remains attributable — history is never anonymous).
  • Audit trail — permanent for the life of the record it protects. It cannot be edited, by us or anyone: corrections happen by appending a new entry that says what changed and why, never by rewriting.
  • Security and email logs — short-lived; sessions expire after inactivity and sign-in challenges expire in minutes.
  • Billing records — six years, as UK accounting law requires.

Your rights

Under UK GDPR you have the right of access, rectification, erasure, restriction, objection, and portability, and rights around automated decisions. Two honest caveats: erasure cannot rewrite the append-only audit trail (the legal basis for keeping it is the service's core purpose and your organisation's and its funders' legal obligations around grant accountability); and grant content is controlled by your organisation, so requests about it may be passed to your administrator. To exercise any right, contact Kieran McCloud at kieran@prodro.co.uk — we respond within one month. We make no solely-automated decisions with legal or similar effect: compliance flags are surfaced for humans to review, and humans make every decision.

Cookies

The app sets two cookies, both strictly necessary: a session cookie that keeps you signed in, and a preference cookie remembering whether the sidebar is collapsed. There are no analytics, advertising or cross-site tracking cookies, no third-party embeds, and therefore no consent banner — there is nothing to consent to. Draft forms may be held temporarily in your browser's own storage and never leave your device. If this ever changes, this notice and the product will say so first.

Complaints and changes

If you are unhappy with how we handle personal data, contact kieran@prodro.co.uk— and you can complain to the Information Commissioner's Office: ico.org.uk, 0303 123 1113, or Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. When this notice changes materially we will say so in the app; the date at the top is always current.