Granily
HomeFor managersFor caregiversFeaturesBlog
Book a call
HomeFor managersFor caregiversFeaturesBlogBook a call
Last updated: 12 August 2026Version 1.3

Privacy Policy

This privacy policy explains how Simple Code d.o.o. (“we”, “us”, “Granily”) collects, uses, and protects your personal data when you use our care home management software.

Contents
IntroductionData we collectHow we use dataLegal basisData sharingSecurity measuresYour rightsData retentionContact us

Introduction

Granily is a software platform for managing care homes. Because we handle care data — including resident health information, staff records, and incident reports — we take data protection seriously.

This policy covers data we collect when you use the Granily web and mobile applications, visit our marketing website, or communicate with us about the service.

Controller and processor roles: Simple Code d.o.o. acts as a data processor for resident care data entered by care homes. We act as a data controller for account and billing information, and for marketing website visitors.


Data we collect

Care data (we process on your behalf)

When you use Granily to run your care home, you enter and store the following types of data:

  • Resident information: names, photographs, dates of birth, gender, room and bed assignments, admission dates, allergies and dietary requirements, mobility and cognitive status, risk flags (such as falls, choking, pressure sores, wandering and infection), GP name and phone number, and health service identifiers such as an NHS number or hospital number
  • Next of kin and contacts: names, relationship to the resident, and contact details for the people a resident nominates
  • Medication records: medication plans, dose schedules, and a record of each administration, including who recorded it and when
  • Care notes and incidents: daily care notes, shift handover notes, incident reports, alerts, tasks, and any photographs or documents your staff attach to them
  • Absence and end-of-life records: where a resident is away from the home, transfers between facilities, and — where a resident dies — the date, the reason recorded, and the staff member who recorded it
  • Staff records: names, email addresses, phone numbers, job titles, profile photographs, training records and certificate uploads, shift schedules and assignments, leave requests and balances
  • Organisational data: facility names, rooms, rota templates and settings, roles and permissions
  • Activity records: an audit log of changes made in Granily — who changed what, and when — together with sign-in timestamps
  • Mobile app data: where your staff use the Granily mobile app, a push notification token for each device and the device platform (iOS or Android), so alerts can be delivered

Care data includes health data, which is a special category of personal data under Article 9 of the GDPR. Your care home decides what is recorded and why; we hold it only to run the service for you, under the terms of our Data Processing Agreement.

Account and billing data (we control)

  • Account holder name, email address, and phone number
  • Billing contact details, and the invoicing and accounting records for your subscription
  • Correspondence with us — support requests, enquiries, and the details you give when booking a call
  • Technical logs generated when the service is used (request timestamps, IP address, and error diagnostics), which we keep to run the service securely and reliably

Marketing website data

  • A cookie that remembers your cookie choices (essential — set whichever choice you make)
  • If you accept analytics cookies: pages visited, how you arrived, browser type, and an approximate location derived from your IP address. We set no analytics cookies unless you accept them, and we do not use advertising or cross-site tracking cookies at all.
  • Booking and enquiry details you give us when you book an intro call — your name, email address, the name of your care home, your role, roughly how many beds you have, and anything you ask us to cover on the call

How we use your data

Care data

We use care data you enter into Granily only to:

  • Provide the service (store, display, and allow you to export your data)
  • Maintain system security and reliability
  • Provide customer support when you report an issue

We do not use care data for marketing, product analytics, or any purpose outside of providing the service to you.

Account and billing data

  • To manage your subscription and issue invoices
  • To send important service updates (planned maintenance, security alerts)
  • To provide customer support
  • To comply with legal obligations (tax, invoicing)

Marketing website data

  • To understand how visitors use our website, where you have accepted analytics cookies
  • To respond to demo requests and enquiries
  • To improve our marketing content

Legal basis for processing

Under GDPR, we process data on the following legal bases:

Contract performance
We process account and billing data to deliver the service you have subscribed to.
Consent
We only set analytics cookies on our marketing website if you accept them in the cookie banner. You can change or withdraw that choice at any time from the cookie settings link in our footer.
Legitimate interests
We keep technical logs to keep the service secure and reliable, and we use the details you send us to answer your enquiries. Our legitimate interest is balanced against your privacy — we do not track individuals across sites or build advertising profiles.
Legal obligation
We retain invoicing records to comply with tax and accounting laws.
Your instructions (as processor)
We process care data on your behalf, under your instructions, as set out in our Data Processing Agreement.

Who we share data with

We do not sell your data. We share data only with the following categories of third parties, and only where necessary to provide the service:

Infrastructure providers

The Granily application and its databases run on servers provided by Hetzner Online GmbH, located in Germany. Our marketing website is served from Cloudflare’s network. Both act as sub-processors under our Data Processing Agreement.

Email delivery

Transactional emails — password resets, notifications, and reminders — are delivered through our email provider. These messages contain staff names and email addresses, and some notification emails include a resident’s name so the recipient knows what the message is about.

Mobile push notifications

Push notifications to the Granily mobile app are delivered through Expo, and from there through Apple and Google’s notification services. These receive your device’s push token and the notification text. That text is deliberately generic — for example “A task needs attention” — and never contains resident names, care notes, or medication details.

Booking a call

The booking form on our website is provided by Calendly. The details you enter there — your name, email address, care home, role, and anything you tell us about your needs — are processed by Calendly and passed to us to arrange the call.

Payments

We invoice subscriptions directly. We do not take card payments through the Granily website or application, and no payment card details are stored in Granily.

Support

Support requests reach us by email and are handled in our email system. If you share a screenshot or an export while we troubleshoot, it is stored with that correspondence and deleted once it is no longer needed. Our staff do not browse your live care records; where we need to look at your data to resolve an issue, we do so only with your agreement and only for as long as the issue takes to fix. Separately, our platform administrators can manage account setup for your tenancy — creating staff accounts, resetting passwords, and assigning roles and facilities — using tools that do not provide access to resident care records.

Legal and regulatory authorities

We may disclose data if required by law, court order, or to protect our legal rights.

We do not share care data with marketing or analytics providers. No analytics or advertising tools run inside the Granily application. Analytics cookies exist only on our marketing website, and only if you accept them.


How we protect your data

We implement technical and organisational measures to protect data against unauthorised access, loss, or misuse:

Technical safeguards

  • Encryption in transit: All traffic between your devices and our servers is encrypted with TLS
  • Password protection: Passwords are hashed with Argon2 and are never stored in a readable form — not even we can recover them
  • Separation between customers: Each care home’s data lives in its own database, rather than sharing tables with other customers
  • Access controls: Role-based permissions limit who can view or edit data within your organisation, and every request is scoped to a facility the user belongs to
  • Audit logging: Changes to residents, care notes, incidents, medications, shifts, and staff records are logged with a timestamp and the user who made them
  • Infrastructure security: Servers are hosted in EU data centres with physical access control, redundant power, and monitoring

Organisational safeguards

  • Limited access: Only authorised staff can access customer systems, and only when resolving a support issue or maintaining the service
  • Confidentiality: Everyone with access to customer systems is bound by a written confidentiality obligation
  • Breach notification: If a personal data breach affects your data, we will notify you without undue delay so that you can meet your own reporting duty to your supervisory authority

Vulnerability management

  • We keep dependencies current and apply security patches promptly
  • New third-party libraries are reviewed before we adopt them
  • Security-relevant changes are reviewed before they reach production

For a detailed breakdown of our security practices, see our Security and Compliance page.


Your rights under GDPR

If you are located in the EU or UK, you have the following rights over your personal data:

Right of access

You can request a copy of the personal data we hold about you. For care data held in Granily, your care home can view and export records directly in the application (see portability below); for anything the built-in exports do not cover, email info@granily.com and we will produce a copy. For account data, email the same address.

Right to rectification

You can correct inaccurate personal data. Care home staff can update records directly in Granily. For account or billing data, contact support@granily.com.

Right to erasure (“right to be forgotten”)

You can request deletion of your personal data, subject to legal retention requirements. If you cancel your subscription, we will delete care data within 90 days unless you request otherwise. Invoicing records are retained for 7 years to comply with tax law.

Right to restrict processing

You can ask us to limit how we use your data while we investigate a complaint or dispute.

Right to data portability

From the Granily web app you can export tasks, incidents, audit logs, and the care documentation, compliance, and shift coverage reports as CSV at any time. For a complete structured export of your data — including resident records, care notes, and medication records — email info@granily.com and we will provide one within 30 days.

Right to object

You can object to processing based on legitimate interests. If you object to marketing emails, click “unsubscribe” in any email or email info@granily.com.

Right to lodge a complaint

If you believe we have mishandled your data, you can complain to your national data protection authority. In Croatia, this is the Croatian Personal Data Protection Agency (AZOP).

To exercise any of these rights, email info@granily.com. We will respond within 30 days.


How long we keep your data

Data typeRetention period
Care data (resident records, care notes, incidents, audit logs)Deleted 90 days after subscription ends, unless you request otherwise
Account data (logins, user profiles)Deleted within 30 days of subscription cancellation
Mobile push notification tokensRemoved when you sign out of the mobile app, or when the token stops working
Invoicing and accounting records7 years (required by Croatian tax law)
Support correspondence3 years
Your cookie preference6 months, then we ask again
Website analytics (only if you accept analytics cookies)Up to 26 months

Contact us about privacy

If you have questions about this privacy policy, how we handle your data, or want to exercise your data rights:

Email: info@granily.com
Post: Simple Code d.o.o., Zvonimira Rogoza 1, 10000 Zagreb, Croatia
Data Protection Officer: Robert Kavgic, robert@granily.com

Questions not answered here?

If you need clarification on how we handle data, or want to discuss data protection for your care home, get in touch.

info@granily.com
Granily

One platform for the daily work of running a care home.

Product

Features

Solutions

For owners and managersFor caregivers

Resources

Blog

Company

Book a callPrivacy policyTerms of serviceCookie policy

Granily is a product by Simple Code d.o.o., Zvonimira Rogoza 1, 10000 Zagreb, Croatia.
info@granily.com  ·  +385 99 2418 993  ·  © 2026 Simple Code d.o.o.

GDPR compliantHosted in the EU