Privacy Policy
What we collect, why, who we share it with and how to use your rights.
Last updated: 1 October 2026
This policy explains what personal data GritSol Health collects through gritsolhealth.com, why we collect it, and the choices you have. We keep it short and plain.
Who we are
GritSol Health is a healthcare marketing and AI automation agency and a brand of GritSol Technologies, based in Lahore, Pakistan. We are the controller of the personal data described here.
Contact for anything about your data: mail@gritsolhealth.com.
Please do not send patient information
Our website forms are for business enquiries only. Do not enter patient names, medical records or any other health information about patients.
What we collect
- Free growth audit form: your name, practice name, work email, website, an optional work phone number, your answer about your biggest challenge, and your agreement to be contacted.
- Booking calendar: the details you enter when you book a call, such as your name, email and the time you choose.
- Emails and calls: what you send us when you contact us directly.
- Technical data: our hosting provider keeps standard server logs (such as IP address, browser type and pages requested) to run and protect the website.
- Analytics and marketing data: pages you visit, the device and browser you use, and which buttons you click, collected with Google Analytics, the Meta Pixel and the Meta Conversions API. In Europe this only happens if you agree in the cookie banner. Elsewhere it is on by default and you can turn it off at any time. See our cookie policy.
- Ad measurement after you send the audit form: if marketing cookies are on, we send Meta a scrambled (hashed) version of your email, phone and name, so Meta can tell us which ads led to an enquiry. Your answer about your biggest challenge is never shared.
Why we use it, and our legal basis
| Purpose | Legal basis (GDPR and UK GDPR) |
|---|---|
| Reply to your audit request, prepare the audit and hold the call | Steps you asked us to take before a possible contract, and your consent |
| Send follow-up emails about your enquiry | Your consent, which you can withdraw at any time |
| Deliver our services to clients | Performance of a contract |
| Keep the website secure and working | Our legitimate interest in running a safe website |
| Measure website use and ads | Your consent through the cookie banner (Europe); our legitimate interest in measuring our marketing, with an easy opt-out (elsewhere) |
| Keep business and tax records | Legal obligation |
We do not sell your personal data for money. Some US state laws treat sharing data with ad platforms for advertising as a "sale" or "sharing". You can opt out at any time with "Reject all" in the cookie banner or the "Cookie settings" link in the footer.
We do not use your personal data for automated decisions that have legal or similar effects on you.
Who we share it with
We only share data with service providers that help us run our business, under contracts that require them to protect it:
- Brevo (Sendinblue SAS, France): forms, email and booking calendar.
- Hostinger: website hosting and business email.
- Google (Google Analytics) and Meta (Meta Pixel and Conversions API): analytics and ad measurement, subject to your cookie choice.
We may also share data if the law requires it, or to protect our rights.
International transfers
We are based in Pakistan and some of our providers are outside your country. When personal data from the European Economic Area or the UK is transferred to a country without an adequacy decision, we use appropriate safeguards such as the European Commission's Standard Contractual Clauses.
How long we keep it
- Enquiries that do not lead to work: up to 24 months after our last contact, then deleted.
- Client records: for the length of the contract and as long as tax and legal rules require after it ends.
- Cookie choices: stored in your browser until you change or clear them.
Your rights
Depending on where you live, you can ask us to:
- give you a copy of your data;
- correct or delete it;
- restrict or object to how we use it;
- move it to another provider;
- withdraw your consent at any time (this does not affect what we did before).
Email mail@gritsolhealth.com and we will reply within one month. If you are in the EEA or the UK, you can also complain to your local data protection authority, for example the ICO in the UK.
If you live in a US state with a privacy law, such as California, you can make the same requests. We will not treat you differently for using your rights.
Security
We use HTTPS, access controls and reputable providers to protect your data. No system is completely secure, so please contact us straight away if you think something is wrong.
Healthcare data and our clients
When we work with a practice, we follow that practice's instructions for any patient data and we keep it to the minimum needed. In the US we sign a Business Associate Agreement where HIPAA requires one. In Europe we sign a Data Processing Agreement under Article 28 of the GDPR.
Children
This website is for businesses and is not aimed at anyone under 16. We do not knowingly collect their data.
Changes
We may update this policy. The date at the top shows the latest version.