Trust & Compliance

Gridmark Ltd (Company No. 17087910) is registered with the UK Information Commissioner's Office (Ref: ZC109151). Our infrastructure is hosted in the EU (London) on SOC 2 Type II certified platforms. All connections are encrypted with TLS 1.2+.

Gridmark Ltd is certified under the UK Government's Cyber Essentials scheme (Certificate: ffc8402c-96dd-4b89-895a-b46be21dfc3b, certified 25 March 2026).

Legal

Privacy Policy

Terms of Use

Cookie Policy

Policies

Health & Safety Policy

Anti-Bribery & Corruption Policy

Modern Slavery Statement

Data

Data Processing

Product Policies

SiteChip Trust & Compliance →

WorkTalkie Trust & Compliance →

Gridmark Ltd · Company No. 17087910 · Registered in England and Wales · 71-75 Shelton Street, London WC2H 9JQ

Privacy Policy

Last updated: 31 March 2026

Gridmark Ltd ("we", "us", "our") operates gridmark.co.uk and is the parent company behind SiteChip, WorkTalkie, and other products. This privacy policy explains what personal data we collect through the Gridmark website, why we collect it, how we use it, and your rights under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

For product-specific privacy information, please refer to the privacy policy on each product's website.

Data Controller

Gridmark Ltd is the data controller for personal data processed through gridmark.co.uk.

Gridmark Ltd
Company number: 17087910
ICO registration: ZC109151
71-75 Shelton Street
Covent Garden
London WC2H 9JQ

Email: [email protected]
Website: gridmark.co.uk

What Personal Data We Collect

Contact form data: When someone submits a contact form or emails us, we collect their name, email address, company name (if provided), and any message content.

Website analytics: We do not use cookies for tracking or analytics on gridmark.co.uk. We do not use Google Analytics or any third-party tracking scripts.

We do not collect: IP addresses for analytics, browsing behaviour, device fingerprints, or any data beyond what you explicitly provide to us.

Why We Collect This Data

Contact form submissions: Our legal basis is consent under Article 6(1)(a) UK GDPR. You provide your details voluntarily when contacting us.

Who We Share Data With

Cloudflare Inc: Our website hosting provider. Cloudflare serves web pages and may process IP addresses in transit. Privacy policy: cloudflare.com/privacypolicy

Google Workspace: Email infrastructure for handling enquiries. Privacy policy: policies.google.com/privacy

We do not sell personal data. We do not share data for marketing purposes. We do not use data for automated decision-making or profiling.

International Data Transfers

Where personal data is transferred outside the UK for platform support, transfers are protected by the UK International Data Transfer Agreement (UK IDTA) or the UK Addendum to EU Standard Contractual Clauses, as issued by the Information Commissioner's Office.

How Long We Keep Data

Contact form data: Retained for 2 years after submission, then deleted unless the enquiry has led to an active business relationship.

Your Rights

Under UK GDPR, you have the right to:

  • Access — request a copy of your personal data.
  • Rectification — request correction of inaccurate data.
  • Erasure — request deletion of your data.
  • Restriction — request that we limit processing.
  • Data portability — request your data in a machine-readable format.
  • Object — object to processing based on legitimate interest.

To exercise any of these rights, contact us at [email protected]. We will respond within one month.

If you are not satisfied with our response, you can lodge a complaint with the Information Commissioner's Office (ICO):
Website: ico.org.uk
Telephone: 0303 123 1113

Changes to This Policy

We may update this privacy policy from time to time. The date at the top of this page will be revised accordingly.

Contact

Gridmark Ltd
Company number: 17087910
71-75 Shelton Street
Covent Garden
London WC2H 9JQ

Email: [email protected]
Website: gridmark.co.uk

Terms of Use

Last updated: 31 March 2026

These terms of use ("Terms") govern your use of the Gridmark website at gridmark.co.uk, operated by Gridmark Ltd ("we", "us", "our"). By using this website, you agree to these Terms.

For product-specific terms, please refer to the terms of service on each product's website.

Gridmark Ltd
Company number: 17087910
71-75 Shelton Street
Covent Garden
London WC2H 9JQ

The Website

gridmark.co.uk is an informational website for Gridmark Ltd. It provides information about our company and our products. It does not provide a user account, subscription service, or transactional functionality.

Intellectual Property

All intellectual property on this website, including the Gridmark name, logo, design, and content, belongs to Gridmark Ltd. You may not reproduce, distribute, or create derivative works from any content on this website without our prior written consent.

Accuracy of Information

We aim to keep the information on this website accurate and up to date, but we do not guarantee that all content is complete or current. Information about our products is provided for general reference — for detailed and binding terms, refer to each product's own website.

Limitation of Liability

To the fullest extent permitted by law, Gridmark Ltd is not liable for any indirect, incidental, or consequential damages arising from your use of this website.

Nothing in these Terms limits our liability for death or personal injury caused by negligence, fraud, or any other liability that cannot be excluded by law.

External Links

This website may contain links to third-party websites and to our product websites. We are not responsible for the content or privacy practices of third-party websites.

Changes to These Terms

We may update these Terms from time to time. The date at the top of this page will be revised accordingly. Continued use of the website after changes constitutes acceptance.

Governing Law

These Terms are governed by the laws of England and Wales. Any disputes shall be subject to the exclusive jurisdiction of the courts of England and Wales.

Contact

Gridmark Ltd
Company number: 17087910
71-75 Shelton Street
Covent Garden
London WC2H 9JQ

Email: [email protected]
Website: gridmark.co.uk

Cookie Policy

Last updated: 31 March 2026

gridmark.co.uk does not use cookies for analytics, tracking, or advertising.

Strictly Necessary Storage

gridmark.co.uk may use localStorage or sessionStorage in the browser for strictly necessary functionality only (such as remembering whether the loading animation has been shown). This qualifies for the "strictly necessary" exemption under the Privacy and Electronic Communications Regulations 2003 (PECR), Regulation 6, and does not require prior consent.

Third-Party Cookies

We do not embed any third-party tracking, analytics, or advertising scripts on gridmark.co.uk. No third-party cookies are set.

Cloudflare, our hosting provider, may set a strictly necessary security cookie (__cf_bm) to distinguish between humans and bots. This is classified as strictly necessary and does not require consent. More information: cloudflare.com/privacypolicy

Product Websites

Our product websites (sitechip.co.uk, worktalkie.com, etc.) have their own cookie policies. Please refer to each product's trust page for details.

Contact

If you have questions about our use of cookies or local storage, contact us at [email protected].

Health & Safety Policy

Last updated: 22 March 2026

Gridmark Ltd is committed to ensuring the health, safety, and welfare of all employees, contractors, clients, and members of the public who may be affected by our activities, in accordance with the Health and Safety at Work etc. Act 1974 and the Management of Health and Safety at Work Regulations 1999.

Responsibilities

Gridmark Ltd accepts overall responsibility for health and safety. This includes ensuring that adequate resources are made available to implement this policy and that it is reviewed annually or following any significant change in our activities.

Our Activities

Gridmark Ltd develops and operates software, hardware, and NFC products for construction sites and workplaces. Our physical activities include the installation of NFC tags onto equipment at client sites and the deployment of hardware relay devices. Installation work takes place across supermarkets, retail stores, commercial kitchens, construction sites, hospitals, warehouses, and other workplace environments.

Installation Practices

When carrying out on-site installation work, Gridmark Ltd will:

  • Complete a site-specific safety induction where required by the client.
  • Comply with all client health and safety rules, signage, and access restrictions.
  • Maintain public liability insurance with a minimum cover of £5,000,000.
  • Never obstruct fire exits, escape routes, or emergency equipment during installation.
  • Not carry out any work at height. All NFC tag installations are performed at ground level or on equipment accessible without ladders or platforms.
  • Carry a personal first aid kit when attending client sites.

Risk Assessment

A risk assessment and method statement (RAMS) for NFC tag installation is maintained and reviewed annually. A copy is available on request for any client requiring one as part of their contractor approval process.

Incident Reporting

Any accident, near miss, or dangerous occurrence will be reported to the Director immediately. Where required, incidents will be reported under RIDDOR (Reporting of Injuries, Diseases and Dangerous Occurrences Regulations 2013).

Review

This policy is reviewed annually by the Director, or sooner if there is a significant change in the nature of our work.

Anti-Bribery & Corruption Policy

Last updated: 22 March 2026

Gridmark Ltd is committed to conducting business ethically and in compliance with the Bribery Act 2010. We maintain a zero-tolerance approach to bribery and corruption in all forms.

Scope

This policy applies to all employees, directors, contractors, agents, and any third party acting on behalf of Gridmark Ltd, in all jurisdictions in which we operate.

Prohibited Conduct

No person acting on behalf of Gridmark Ltd shall:

  • Offer, promise, give, request, or accept a bribe — whether in the form of cash, gifts, hospitality, or any other inducement.
  • Use a third party as a channel to direct bribes to any person or organisation.
  • Make facilitation payments of any kind.
  • Offer or accept gifts or hospitality where the purpose is to improperly influence a business decision.

Gifts and Hospitality

Any gift or hospitality offered or received with a value exceeding £50 must be recorded and approved by the Director before acceptance. A register of gifts and hospitality is maintained and available for inspection.

Business Relationships

All business relationships are conducted transparently and on merit. Gridmark Ltd selects suppliers, partners, and clients based on quality, value, and suitability — never on the basis of improper inducements.

Financial Records

Gridmark Ltd maintains accurate and complete financial records. All transactions are recorded with sufficient detail to demonstrate that payments are legitimate and properly authorised.

Reporting Concerns

Any person who suspects a breach of this policy should report their concerns immediately to [email protected]. Reports will be treated confidentially and investigated promptly. No person will be penalised for raising a genuine concern in good faith.

Consequences of Breach

A breach of this policy by an employee may result in disciplinary action up to and including dismissal. A breach by a contractor or third party will result in termination of the business relationship. Gridmark Ltd will report suspected criminal conduct to the relevant authorities.

Modern Slavery Statement

Last updated: 22 March 2026

This voluntary statement is made pursuant to Section 54 of the Modern Slavery Act 2015. Although Gridmark Ltd is not required by turnover threshold to publish a modern slavery statement, we choose to do so as a demonstration of our commitment to ethical business practices.

Our Business

Gridmark Ltd develops and operates software, hardware, and NFC products for construction sites and workplaces, including SiteChip, WorkTalkie, and other products.

Our Supply Chain

Our supply chain consists of:

  • NFC tags: Sourced from a verified supplier. NFC tags are passive electronic labels manufactured in controlled factory environments.
  • BLE relay hardware: SiteNode devices use Raspberry Pi hardware sourced from authorised UK distributors.
  • Cloud infrastructure: Provided by Supabase Inc (SOC 2 Type II certified) and Cloudflare Inc (publicly listed company with published modern slavery statement).
  • Design and professional services: Procured via established platforms with their own terms of service and labour protections.

Due Diligence

Gridmark Ltd conducts due diligence on new suppliers before entering into a business relationship. We assess whether suppliers have appropriate policies in place regarding labour practices and ethical conduct.

Our Commitment

Gridmark Ltd will not knowingly engage any supplier or partner that uses forced labour, bonded labour, child labour, or any form of modern slavery. If we become aware of any such practices within our supply chain, we will take immediate steps to address the situation, including termination of the business relationship where necessary.

Reporting Concerns

Any concerns regarding modern slavery in our business or supply chain should be reported to [email protected].

Data Processing

Last updated: 22 March 2026

When processing personal data on behalf of our clients, Gridmark Ltd acts as a data processor under the UK General Data Protection Regulation (UK GDPR). Our clients (site managers and their organisations) are the data controllers.

Data Processing Agreements

Gridmark Ltd maintains data processing agreements (DPAs) with all infrastructure providers that process personal data on our behalf. We offer a standard DPA to all customers on request.

Sub-processors

The following sub-processors are used in the delivery of Gridmark products:

  • Supabase Inc — Database, authentication, and file storage. SOC 2 Type II certified. DPA in place. Privacy policy: supabase.com/privacy
  • Cloudflare Inc — Website hosting and content delivery. DPA in place. Privacy policy: cloudflare.com/privacypolicy
  • Stripe Payments Europe Ltd — Payment processing and subscription billing. DPA in place. Privacy policy: stripe.com/privacy
  • Google Workspace — Email and business productivity. DPA in place. Privacy policy: policies.google.com/privacy

Data Handling Principles

Gridmark Ltd does not sell personal data. We do not share personal data for marketing purposes. We do not use personal data for automated decision-making or profiling. Payment card details are processed exclusively by Stripe Payments Europe Ltd and are never stored on Gridmark infrastructure.

Data Retention

  • Worker data: Retained while the worker's account is active. Deleted when a worker is removed by a manager, or on request.
  • Compliance records: Retained for a minimum of 6 years after the site subscription ends, in line with industry best practice for fire safety and workplace inspection records.
  • Lead data: Retained for 2 years after submission, then deleted unless the lead has become a customer.

Cyber Essentials certified — UK Government-backed cybersecurity certification. Certificate: ffc8402c-96dd-4b89-895a-b46be21dfc3b. Scope: Whole organisation. Certified: 25 March 2026. Recertification due: 25 March 2027.

Gridmark Ltd maintains a standard Data Processing Agreement for all customers, compliant with UK GDPR Article 28.

Download Data Processing Agreement (PDF) →