Privacy Policy

What we collect, why, who we share it with and how to use your rights.

Last updated: 1 October 2026

This policy explains what personal data GritSol Health collects through gritsolhealth.com, why we collect it, and the choices you have. We keep it short and plain.

Who we are

GritSol Health is a healthcare marketing and AI automation agency and a brand of GritSol Technologies, based in Lahore, Pakistan. We are the controller of the personal data described here.

Contact for anything about your data: mail@gritsolhealth.com.

Please do not send patient information

Our website forms are for business enquiries only. Do not enter patient names, medical records or any other health information about patients.

What we collect

  • Free growth audit form: your name, practice name, work email, website, an optional work phone number, your answer about your biggest challenge, and your agreement to be contacted.
  • Booking calendar: the details you enter when you book a call, such as your name, email and the time you choose.
  • Emails and calls: what you send us when you contact us directly.
  • Technical data: our hosting provider keeps standard server logs (such as IP address, browser type and pages requested) to run and protect the website.
  • Analytics and marketing data: pages you visit, the device and browser you use, and which buttons you click, collected with Google Analytics, the Meta Pixel and the Meta Conversions API. In Europe this only happens if you agree in the cookie banner. Elsewhere it is on by default and you can turn it off at any time. See our cookie policy.
  • Ad measurement after you send the audit form: if marketing cookies are on, we send Meta a scrambled (hashed) version of your email, phone and name, so Meta can tell us which ads led to an enquiry. Your answer about your biggest challenge is never shared.

Why we use it, and our legal basis

PurposeLegal basis (GDPR and UK GDPR)
Reply to your audit request, prepare the audit and hold the callSteps you asked us to take before a possible contract, and your consent
Send follow-up emails about your enquiryYour consent, which you can withdraw at any time
Deliver our services to clientsPerformance of a contract
Keep the website secure and workingOur legitimate interest in running a safe website
Measure website use and adsYour consent through the cookie banner (Europe); our legitimate interest in measuring our marketing, with an easy opt-out (elsewhere)
Keep business and tax recordsLegal obligation

We do not sell your personal data for money. Some US state laws treat sharing data with ad platforms for advertising as a "sale" or "sharing". You can opt out at any time with "Reject all" in the cookie banner or the "Cookie settings" link in the footer.

We do not use your personal data for automated decisions that have legal or similar effects on you.

Who we share it with

We only share data with service providers that help us run our business, under contracts that require them to protect it:

  • Brevo (Sendinblue SAS, France): forms, email and booking calendar.
  • Hostinger: website hosting and business email.
  • Google (Google Analytics) and Meta (Meta Pixel and Conversions API): analytics and ad measurement, subject to your cookie choice.

We may also share data if the law requires it, or to protect our rights.

International transfers

We are based in Pakistan and some of our providers are outside your country. When personal data from the European Economic Area or the UK is transferred to a country without an adequacy decision, we use appropriate safeguards such as the European Commission's Standard Contractual Clauses.

How long we keep it

  • Enquiries that do not lead to work: up to 24 months after our last contact, then deleted.
  • Client records: for the length of the contract and as long as tax and legal rules require after it ends.
  • Cookie choices: stored in your browser until you change or clear them.

Your rights

Depending on where you live, you can ask us to:

  • give you a copy of your data;
  • correct or delete it;
  • restrict or object to how we use it;
  • move it to another provider;
  • withdraw your consent at any time (this does not affect what we did before).

Email mail@gritsolhealth.com and we will reply within one month. If you are in the EEA or the UK, you can also complain to your local data protection authority, for example the ICO in the UK.

If you live in a US state with a privacy law, such as California, you can make the same requests. We will not treat you differently for using your rights.

Security

We use HTTPS, access controls and reputable providers to protect your data. No system is completely secure, so please contact us straight away if you think something is wrong.

Healthcare data and our clients

When we work with a practice, we follow that practice's instructions for any patient data and we keep it to the minimum needed. In the US we sign a Business Associate Agreement where HIPAA requires one. In Europe we sign a Data Processing Agreement under Article 28 of the GDPR.

Children

This website is for businesses and is not aimed at anyone under 16. We do not knowingly collect their data.

Changes

We may update this policy. The date at the top shows the latest version.