Skip to main content

Gramloyal

Privacy Policy

Website: gramloyal.com
Company: Unitas Global Ltd
Last updated: 25 July 2026
Effective date: 25 July 2026

1. Who we are

GramLoyal is a trading name of Unitas Global Ltd, a company registered in England and Wales. Unitas Global Ltd is the data controller for the personal data described in this policy.

  • Registered name: Unitas Global Ltd
  • Company number: 12562965
  • Registered office: Suite Ra01 195-197 Wood Street, London, England, E17 3NU
  • Contact: hello@unitas-global.com

2. What this policy covers

This policy covers personal data collected from:

  • Visitors to gramloyal.com
  • Prospects who submit an enquiry through our contact form
  • Clients of GramLoyal services
  • Social media accounts a client authorises us to manage on their behalf (see section 6)

It does not cover third-party websites we link to, which have their own policies.

3. What we collect

Website visitors. Anonymised analytics about how the site is used. We do not use third-party advertising trackers.

Prospects. Information you submit through the contact form: first name, company name, email address, phone number, website, country and your message.

Clients. Information needed to deliver and support your services: billing details, primary contacts, project information, and the marketing assets and business information you share with us.

We do not collect payment card details, passwords, or special category data through this website.

4. Cookies

This website uses a minimal set of cookies. Essential cookies required for the site to function, and anonymised analytics. We do not use advertising cookies, third-party analytics, social media tracking pixels, or cross-site tracking of any kind.

5. Legal bases for processing

Under UK GDPR we rely on:

  • Consent for analytics and any marketing email you have opted into. You can withdraw consent at any time.
  • Legitimate interests for responding to enquiries and keeping our systems secure.
  • Contract where processing is necessary to deliver a service you have engaged us for.
  • Legal obligation where we must retain records for tax, accounting or regulatory purposes.

6. Social media accounts we manage for clients

Social media management is a core GramLoyal service. This section explains exactly what that involves.

  • Platforms: Instagram, Facebook, TikTok, LinkedIn, X, YouTube, Google Business Profile, Pinterest and Telegram. Only the platforms a client asks us to manage are used.
  • Authorisation: access is only ever created when the account holder signs in to that platform themselves and grants permission through the platform’s own authorisation screen. We never ask for, store, or use social media passwords. Permission can be withdrawn at any time from the platform’s own settings, and our access stops immediately.
  • What we access: the account identifier and profile or page name, the ability to publish content created by or for the account holder, comments on that account’s own posts where comment management is part of the engagement, and engagement statistics for that account’s own posts so we can report performance.
  • What we do not access: private messages unless the client has specifically asked us to manage them, other users’ personal data, follower lists, or any account that has not authorised us.
  • Storage and retention: platform access tokens are held on infrastructure in the UK and EU, kept separate per client, and deleted when an account is disconnected or the client relationship ends. Records of published content are kept for up to 24 months so clients can review their own history, then deleted. Earlier deletion can be requested at any time.
  • We never sell or share social media platform data, never use it for advertising or profiling, and never use it to train machine learning models.

Client-owned business data, content and branding remain the property of the client at all times. GramLoyal processes it only to deliver the agreed services, acting on the client’s instructions.

7. Who we share data with

We do not sell personal data. We share it only with service providers who help us operate, and only to the extent needed: website and hosting infrastructure, email delivery, domain providers, payment processing, and the cloud software used to deliver services. Each is bound by contract to protect the data and use it only on our instructions. We may also disclose data where required by law.

8. Where your data is held

Our infrastructure is located in the United Kingdom and the European Economic Area. Where a provider processes data outside the UK or EEA, we rely on appropriate safeguards recognised under UK data protection law, such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.

9. How long we keep data

  • Enquiries that do not become a client relationship: up to 24 months from last contact
  • Website analytics: up to 12 months
  • Social media platform data: as set out in section 6
  • Client records, contracts and financial records: 7 years, to meet UK accounting and tax obligations

We delete or anonymise data once it is no longer needed for the purpose it was collected for.

10. Your rights

Under UK GDPR you have the right to be informed about how your data is used, to request a copy of it, to have inaccurate data corrected, to request erasure, to restrict processing, to object to processing based on legitimate interests, to data portability, and to withdraw consent at any time where consent is the legal basis.

To exercise any of these, email hello@unitas-global.com. We will respond within one calendar month. There is no charge unless a request is manifestly unfounded or excessive.

If you are not satisfied with our response, you have the right to complain to the Information Commissioner’s Office, the UK supervisory authority for data protection, at ico.org.uk or on 0303 123 1113.

11. Security

We protect personal data with encrypted connections, access controls, separated client environments, encrypted backups and restricted administrative access. No internet-connected service can be guaranteed completely secure, but we take reasonable technical and organisational measures appropriate to the risk, and we will notify you and the ICO of a personal data breach where the law requires it.

12. Changes to this policy

We may update this policy from time to time. The “Last updated” date above will reflect any change. We will not retroactively reduce your rights under a previous version without your explicit consent. Where a change is material, we will notify active clients by email.

13. Contact

For any privacy question, or to exercise your rights: hello@unitas-global.com

GramLoyal
A trading name of Unitas Global Ltd
Company number 12562965
Suite Ra01 195-197 Wood Street, London, England, E17 3NU