Introduction
Granily is a software platform for managing care homes. Because we handle care data — including resident health information, staff records, and incident reports — we take data protection seriously.
This policy covers data we collect when you use the Granily web and mobile applications, visit our marketing website, or communicate with us about the service.
Controller and processor roles: Simple Code d.o.o. acts as a data processor for resident care data entered by care homes. We act as a data controller for account and billing information, and for marketing website visitors.
Data we collect
Care data (we process on your behalf)
When you use Granily to run your care home, you enter and store the following types of data:
- Resident information: names, dates of birth, medical conditions, care plans, medication schedules, dietary requirements, next of kin details
- Care notes: daily observations, shift handover notes, risk assessments, incident reports
- Staff records: names, email addresses, phone numbers, training certificates, shift schedules, leave requests
- Organisational data: facility names, room assignments, rota templates
We process this data only on your instructions, as set out in our Data Processing Agreement.
Account and billing data (we control)
- Account holder name and email address
- Billing contact details and payment method information
- Subscription tier and billing history
- Login activity and usage logs
Marketing website data
- IP address and browser type (via analytics)
- Pages visited and time on site
- Form submissions (demo requests, contact enquiries)
How we use your data
Care data
We use care data you enter into Granily only to:
- Provide the service (store, display, and allow you to export your data)
- Maintain system security and reliability
- Provide customer support when you report an issue
We do not use care data for marketing, product analytics, or any purpose outside of providing the service to you.
Account and billing data
- To manage your subscription and process payments
- To send important service updates (planned maintenance, security alerts)
- To provide customer support
- To comply with legal obligations (tax, invoicing)
Marketing website data
- To understand how visitors use our website
- To respond to demo requests and enquiries
- To improve our marketing content
Legal basis for processing
Under GDPR, we process data on the following legal bases:
- Contract performance
- We process account and billing data to deliver the service you have subscribed to.
- Legitimate interests
- We use website analytics to improve our marketing and understand product demand. Our legitimate interest is balanced against visitor privacy — we do not track individuals across sites or build advertising profiles.
- Legal obligation
- We retain billing records to comply with tax and accounting laws.
- Your instructions (as processor)
- We process care data on your behalf, under your instructions, as set out in our Data Processing Agreement.
Who we share data with
We do not sell your data. We share data only with the following categories of third parties, and only where necessary to provide the service:
Infrastructure providers
We use AWS (Amazon Web Services) in the EU region to host Granily. Care data is stored on servers physically located in Frankfurt, Germany. AWS acts as a sub-processor under our Data Processing Agreement.
Payment processor
We use Stripe to process subscription payments. Stripe receives your billing details (name, email, payment method) to handle transactions. Stripe is GDPR compliant and certified under the EU-US Data Privacy Framework.
Support tools
We use [Support Tool Name] to manage customer support requests. When you contact us, your email and the content of your message are stored in this system. Support staff may view care data screenshots you share when troubleshooting an issue, but only with your consent and only for the duration of the support case.
Legal and regulatory authorities
We may disclose data if required by law, court order, or to protect our legal rights.
We do not share care data with marketing or analytics providers. Tools like Google Analytics are only used on our marketing website, never inside the Granily application.
How we protect your data
We implement technical and organisational measures to protect data against unauthorised access, loss, or misuse:
Technical safeguards
- Encryption in transit: All data sent between your devices and our servers is encrypted using TLS 1.3
- Encryption at rest: Database backups and file storage are encrypted using AES-256
- Access controls: Role-based permissions limit who can view or edit data within your organisation
- Audit logging: Every data access and modification is logged with a timestamp and user ID
- Infrastructure security: Servers are hosted in AWS data centres with physical security, redundant power, and 24/7 monitoring
Organisational safeguards
- Limited access: Only authorised support staff can access customer data, and only when resolving a support ticket
- Background checks: All employees undergo background checks before accessing production systems
- Security training: Staff complete annual data protection and security training
- Incident response plan: We have documented procedures for responding to data breaches
Vulnerability management
- Regular penetration testing by third-party security firms
- Automated security scanning of dependencies
- Prompt patching of known vulnerabilities
For a detailed breakdown of our security practices, see our Security and Compliance page.
Your rights under GDPR
If you are located in the EU or UK, you have the following rights over your personal data:
Right of access
You can request a copy of the personal data we hold about you. For care data stored in Granily, you can export this directly from the application at any time. For account data, email privacy@granily.com.
Right to rectification
You can correct inaccurate personal data. Care home staff can update records directly in Granily. For account or billing data, contact support@granily.com.
Right to erasure (“right to be forgotten”)
You can request deletion of your personal data, subject to legal retention requirements. If you cancel your subscription, we will delete care data within 90 days unless you request otherwise. Billing records are retained for 7 years to comply with tax law.
Right to restrict processing
You can ask us to limit how we use your data while we investigate a complaint or dispute.
Right to data portability
You can export your data in a structured, machine-readable format (CSV or JSON) at any time from the Granily web app.
Right to object
You can object to processing based on legitimate interests. If you object to marketing emails, click “unsubscribe” in any email or email privacy@granily.com.
Right to lodge a complaint
If you believe we have mishandled your data, you can complain to your national data protection authority. In Croatia, this is the Croatian Personal Data Protection Agency (AZOP).
To exercise any of these rights, email privacy@granily.com. We will respond within 30 days.
How long we keep your data
| Data type | Retention period |
|---|---|
| Care data (resident records, care notes, incidents) | Deleted 90 days after subscription ends, unless you request otherwise |
| Account data (logins, user profiles) | Deleted within 30 days of subscription cancellation |
| Billing records (invoices, payment history) | 7 years (required by Croatian tax law) |
| Support tickets | 3 years |
| Marketing website analytics | 26 months (Google Analytics default) |
Contact us about privacy
If you have questions about this privacy policy, how we handle your data, or want to exercise your data rights:
Email: privacy@granily.com
Post: Simple Code d.o.o., Zvonimira Rogoza 1, 10000 Zagreb, Croatia
Data Protection Officer: Robert Kavčić, robert@granily.com
Questions not answered here?
If you need clarification on how we handle data, or want to discuss data protection for your care home, get in touch.
privacy@granily.com